PDP Law Compliance Check

Sixteen yes/no questions that map your organisation's readiness for Indonesia's Law No. 27/2022 on Personal Data Protection (PDP Law): governance, data subject rights, security, and third parties. Results and next steps appear instantly.

  • 16 questions
  • ± 8 minutes
  1. 1Details
  2. 2
  3. 3
Before you start

Before you start

Four short fields so we can send you the result and follow up if you wish.

The result summary is sent to this address.

By continuing you agree that these details are used to send your result and to follow up, per our Privacy Policy.

16 questions · ± 8 minutes

Frequently asked questions

Since when has the PDP Law been fully in force in Indonesia?

Law No. 27 of 2022 on Personal Data Protection was enacted in October 2022 with a two-year compliance transition period for existing data controllers, with enforcement running since that transition period ended.

Does the PDP Law apply to companies based outside Indonesia?

Yes. The PDP Law also applies to any person, public body, or international organisation outside Indonesia's jurisdiction that processes the personal data of Indonesian citizens and has legal effect in Indonesia.

What sanctions apply for non-compliance?

Administrative sanctions such as written warnings, temporary suspension of processing, deletion or destruction of data, and administrative fines, plus criminal sanctions for the responsible individual in certain violations.

What is the difference between a data controller and a data processor?

A data controller determines the purpose and means of processing personal data. A data processor processes personal data on behalf of, and per the instructions of, the controller. Each carries different obligations under the PDP Law.

Who should complete this questionnaire?

The data protection officer (PIC PDP), a legal or compliance officer, or the head of IT who understands how personal data flows through the organisation.

Discuss PDP Law compliance with our consultants

We support you from gap analysis and building a RoPA and DPIA through to appointing a data protection officer.