Quick Answer
Law No. 27 of 2022 on Personal Data Protection (the PDP Law) has been fully in force since October 17, 2024 — the two-year transition period has ended. Every organization processing Indonesian citizens' personal data must comply: 3×24-hour breach notification to data subjects and the supervisory authority, DPO appointment under certain criteria, DPIAs for high-risk processing, and security of processing. Administrative violations carry fines of up to 2% of annual revenue; criminal sanctions reach 6 years' imprisonment and IDR 6 billion in fines, with corporate fines up to 10 times the maximum.
What Is the PDP Law?
Law No. 27 of 2022 on Personal Data Protection (the PDP Law) is Indonesia's first comprehensive regulation specifically governing how personal data is collected, processed, stored, and deleted. Enacted on October 17, 2022, the law provided a two-year transition period — meaning that since October 17, 2024, every obligation under the PDP Law is fully in force and enforceable.
The PDP Law applies to every individual, public body, and international organization that processes the personal data of Indonesian citizens — including entities outside Indonesian territory whose processing has legal consequences in Indonesia. In other words: virtually every organization operating in or serving customers in Indonesia falls within its scope.
The Transition Period Has Ended
Since October 17, 2024, there is no more grace period. Non-compliant organizations face administrative fines of up to 2% of annual revenue, data deletion orders, and public disclosure of violations — plus criminal exposure for certain offenses.
What Data Is Protected?
The PDP Law divides personal data into two categories with different levels of protection. Specific personal data demands stricter safeguards because its exposure carries greater harm for the data subject.
Two Key Roles: Controller & Processor
A Personal Data Controller determines the purposes of and controls the processing (for example, your company with respect to customer data). A Personal Data Processor processes data on the controller's behalf (for example, a payroll vendor or cloud provider). Both carry legal obligations — but primary accountability rests with the controller.
General Personal Data
- Full name
- Gender
- Nationality
- Religion
- Marital status
- Personal data combined to identify an individual (email, phone number, IP address)
Specific Personal Data
- Health data and information
- Biometric data (fingerprints, face, retina)
- Genetic data
- Criminal records
- Children's data
- Personal financial data
Data Subject Rights
The PDP Law grants individuals (data subjects) a set of rights that your organization must be able to fulfill. Every rights request must be answered — and failing to do so is a violation in its own right.
Right to Information
Data subjects are entitled to clarity about the controller's identity, the purpose of processing, and the accountability of the party requesting the data — before processing takes place.
Right of Access
Data subjects may access and obtain a copy of their personal data being processed by your organization.
Right to Rectification
Data subjects may complete, update, and correct errors or inaccuracies in their personal data.
Right to Erasure
Data subjects may request the deletion or destruction of their personal data — the equivalent of the GDPR's 'right to erasure'.
Right to Withdraw Consent
Consent once given can be withdrawn at any time, and processing based on that consent must stop.
Right to Object
Data subjects may object to decisions based solely on automated processing, including profiling.
Right to Restrict Processing
Data subjects may postpone or restrict the processing of their personal data proportionally to the purpose of processing.
Right to Portability & Compensation
Data subjects may obtain and reuse their data in a commonly used format, and may sue for and receive compensation for violations.
Lawful Bases for Processing
Every processing of personal data must rest on at least one lawful basis. Consent is only one of them — and often not the most appropriate one for a given business context.
- 1
Explicit Consent
Valid consent must be explicit, informed, and documented — whether written or recorded. Consent buried in lengthy terms and conditions does not meet this standard.
- 2
Performance of a Contract
Processing is necessary to fulfill an agreement to which the data subject is a party — for example, processing a customer's address to deliver goods.
- 3
Legal Obligation
Processing is necessary to comply with statutory obligations, such as tax reporting or employment regulations.
- 4
Vital Interest
Processing to protect the data subject's vital interests — for example, a medical emergency.
- 5
Public Interest Task
Performance of a task in the public interest, public service, or the controller's statutory authority.
- 6
Legitimate Interest
Pursuit of other legitimate interests, balancing the controller's purpose against the data subject's rights — requiring a documented balancing test.
Controller & Processor Obligations
This is where the bulk of the PDP compliance burden lies. The following obligations demand changes to processes, technology, and organizational structure — not merely policy documents.
3×24-Hour Breach Notification
In the event of a personal data protection failure, the controller must deliver written notification within 3×24 hours to both the data subjects and the supervisory authority — covering what data was exposed, when and how it happened, and remediation efforts.
Appointing a DPO (Data Protection Officer)
Mandatory for organizations processing data for public services, conducting regular and systematic large-scale monitoring of data subjects, or processing specific personal data at scale.
Impact Assessments (DPIA)
High-risk processing — specific data, large scale, automated decision-making, use of new technologies — must be preceded by a personal data protection impact assessment.
Records of Processing Activities
Controllers must record all processing activities (Records of Processing Activities) as the foundation for accountability and audits.
Security of Processing
Technical and organizational measures are mandatory to secure data — encryption, access controls, pseudonymization — proportionate to the processing risk.
Cross-Border Data Transfers
Transfers outside Indonesia are only permitted if the destination country provides an equal or higher level of protection, binding safeguards exist, or the data subject consents.
Deletion & Retention
Data must be deleted or destroyed when the retention period ends, the processing purpose is fulfilled, or upon the data subject's request — requiring a defined retention policy.
Vendor & Processor Oversight
Controllers remain accountable for processing performed by processors on their behalf. Vendor contracts must contain adequate data protection clauses.
Administrative & Criminal Sanctions
The PDP Law takes a layered approach: administrative sanctions for negligent organizations, and criminal penalties for deliberate unlawful conduct. For corporations, criminal fines can be increased up to tenfold.
A 2% Annual Revenue Fine Is Not a Small Number
For a company with IDR 500 billion in annual revenue, the maximum administrative fine reaches IDR 10 billion — before counting incident response costs, reputational damage, and potential compensation claims from harmed data subjects.
| Violation Type | Maximum Sanction | Basis |
|---|---|---|
| Breach of administrative obligations (notification, security, etc.) | Written warning, temporary suspension of processing, data deletion, and administrative fines of up to 2% of annual revenue | Article 57 |
| Unlawfully obtaining/collecting personal data | Imprisonment up to 5 years and/or fines up to IDR 5 billion | Article 67(1) |
| Unlawfully disclosing personal data | Imprisonment up to 4 years and/or fines up to IDR 4 billion | Article 67(2) |
| Unlawfully using another person's data | Imprisonment up to 5 years and/or fines up to IDR 5 billion | Article 67(3) |
| Falsifying personal data for personal gain | Imprisonment up to 6 years and/or fines up to IDR 6 billion | Article 68 |
| Violations by corporations | Fines up to 10× the maximum, plus additional penalties: profit confiscation, business suspension, license revocation, up to dissolution | Article 70 |
PDP Law vs GDPR: Similarities & Differences
The PDP Law adopts many GDPR principles — so organizations already GDPR-compliant have a strong foundation. There are, however, important differences that must not be overlooked, particularly the notification window and the size of sanctions.
| Aspect | PDP Law (Indonesia) | GDPR (European Union) |
|---|---|---|
| Breach notification | 3×24 hours to data subjects AND the supervisory authority | 72 hours to the authority; to data subjects only when high-risk |
| Maximum administrative fine | 2% of annual revenue | 4% of global revenue or €20 million (whichever is greater) |
| Criminal sanctions | Yes — imprisonment up to 6 years for certain offenses | Not regulated at EU level (left to member states) |
| Lawful bases | 6 lawful bases (mirroring GDPR) | 6 lawful bases |
| DPO | Mandatory under certain criteria | Mandatory under similar criteria |
| Supervisory authority | PDP Authority under the President (being established) | Independent authorities per member state (e.g., CNIL, DPC) |
| Extraterritorial scope | Yes — legal consequences in Indonesia | Yes — offering goods/services to EU data subjects |
Data Breach Cases in Indonesia
The string of incidents below shows why the PDP Law was born — and why regulators and the public are now far more critical of organizations that fail to protect data. Under a fully enforceable PDP regime, similar incidents carry far heavier legal consequences.
279M
Resident records in the claimed 2021 BPJS Kesehatan breach
National Media Reports
282
Government institutions affected by the June 2024 PDN ransomware incident
Kominfo/BSSN
403M+
Traffic anomalies / suspected cyber attacks against Indonesia throughout 2023
BSSN
Tokopedia — 2020
E-CommerceRoughly 91 million user account records (names, emails, password hashes) were traded on dark web forums. One of Southeast Asia's largest e-commerce breaches at the time.
BPJS Kesehatan — 2021
Public SectorData claimed to cover 279 million Indonesian residents — including national ID numbers, phone numbers, and family data — was offered on hacker forums, fueling public pressure to pass the PDP Law.
Bjorka — 2022
Multi-SectorThe actor 'Bjorka' claimed to sell 1.3 billion SIM card registration records along with data from multiple government institutions. The case dominated national headlines just before the PDP Law was passed.
BSI Ransomware — May 2023
BankingBank Syariah Indonesia was crippled by LockBit ransomware; services were disrupted for days and 1.5 TB of data — claimed to cover 15 million customers — was leaked after negotiations failed.
KPU / Voter Rolls — November 2023
Public SectorVoter roll data claimed to cover 204 million voters — containing national ID numbers, addresses, and identity data — was offered by the actor 'Jimbo' ahead of the 2024 elections.
National Data Center — June 2024
Public SectorBrain Cipher ransomware paralyzed the temporary National Data Center, disrupting 282 government institutions including immigration services — exposing weak backup practices and national data governance.
A Phased PDP Compliance Roadmap
PDP compliance is an ongoing program, not a one-off project. The following phased roadmap can be adapted to your organization's scale and complexity.
Data Mapping & Inventory
Map all the personal data you process: what it is, where it comes from, where it is stored, who accesses it, and which third parties it flows to. The output becomes your Records of Processing Activities (RoPA).
Gap Assessment Against the PDP Law
Compare current practices against every PDP obligation. Identify gaps in lawful bases, consent mechanisms, security, retention, and vendor contracts — then prioritize by risk.
Fix Lawful Bases & Consent Mechanisms
Ensure every processing activity has the correct lawful basis. Overhaul consent forms to be explicit and granular, and provide a consent withdrawal mechanism as easy as giving consent.
Draft Policies & Procedures
An external privacy policy, an internal data protection policy, data subject rights procedures, a retention policy, and cross-border transfer procedures — all aligned with real business processes.
- Clear privacy notices at every data collection point
- Data subject request SOPs with measurable SLAs
- Data protection clauses in every vendor contract
Appoint a DPO & Build Governance
Appoint a Data Protection Officer if you meet the mandatory criteria, or designate a privacy lead. Establish a governance forum involving legal, IT, information security, and business process owners.
Strengthen Technical Security
Implement encryption at rest and in transit, role-based access controls, logging and monitoring, and periodic security testing (VAPT) for systems processing personal data.
Prepare Incident Response & the 3×24-Hour Notification
The 3×24-hour window is very short. Build a data breach playbook, define escalation paths and notification templates, then test them through tabletop exercises at least annually.
Train Staff & Audit Periodically
Build data protection awareness across all lines, run DPIAs for high-risk initiatives, and audit compliance regularly. Consider ISO 27701 as a certifiable privacy management framework.
Closing
The PDP Law transforms personal data protection from a 'good practice' into a legal obligation with real sanctions. Organizations that delay face not only fines and criminal exposure — but also the loss of customer trust in an increasingly privacy-aware market.
The good news: PDP compliance can be built on mature, proven frameworks. Organizations that integrate the PDP Law into their GRC program and an ISO 27001/27701-based ISMS will find that privacy compliance, information security, and risk management reinforce one another — rather than being three separate burdens.
Meeting the PDP Law is far easier when the obligations live in one place — that is what PrivacySphere does, from ROPA through data subject request handling. For implementation support, see our GRC services.
Start with Data Mapping
You cannot protect — let alone be accountable for — data you do not know you have. Data mapping and a RoPA are the foundation of any PDP compliance program, and the single best step to start this week.
PDP Law compliance is more than a policy document — it demands end-to-end data governance. Cloudsphere helps your organization run gap assessments, draft privacy policies, and build a personal data protection program aligned with the PDP Law and ISO 27701.
Frequently Asked Questions
What is the PDP Law and when did it become fully enforceable?
The PDP Law (Law No. 27 of 2022) is Indonesia's first comprehensive regulation governing how personal data is collected, processed, stored, and deleted. Enacted on October 17, 2022 with a two-year transition period, all of its obligations have been fully in force and enforceable since October 17, 2024. Its scope is broad: every individual, public body, and international organization processing Indonesian citizens' personal data — including entities outside Indonesia whose processing has legal consequences in Indonesia.
What are the sanctions for violating the PDP Law?
Administrative sanctions include written warnings, temporary suspension of processing, data deletion, and fines of up to 2% of annual revenue (Article 57). Criminal sanctions: imprisonment up to 5 years and/or fines up to IDR 5 billion for unlawfully obtaining or using personal data (Article 67), 4 years and/or IDR 4 billion for unlawfully disclosing data, and 6 years and/or IDR 6 billion for falsifying personal data (Article 68). For corporations, fines can be increased up to 10 times the maximum, plus profit confiscation, business suspension, license revocation, up to dissolution (Article 70).
What is the data breach notification deadline under the PDP Law?
No later than 3×24 hours. In the event of a personal data protection failure, the controller must deliver written notification to both the data subjects AND the supervisory authority — covering what data was exposed, when and how it happened, and remediation efforts. This is stricter than the GDPR, which gives 72 hours to the authority and only requires notifying data subjects when the risk is high — so organizations need a tested data breach playbook.
What data does the PDP Law protect?
The PDP Law divides personal data into two categories. General personal data includes full name, gender, nationality, religion, marital status, and data combined to identify an individual (email, phone number, IP address). Specific personal data — which demands stricter safeguards — includes health data, biometric data, genetic data, criminal records, children's data, and personal financial data.
Are organizations required to appoint a DPO under the PDP Law?
It is mandatory under certain criteria: organizations processing data for public services, conducting regular and systematic large-scale monitoring of data subjects, or processing specific personal data at scale. Outside those criteria, organizations are still advised to designate a privacy lead and establish a governance forum involving legal, IT, information security, and business process owners.
How does the PDP Law differ from the GDPR?
The PDP Law adopts many GDPR principles — both have 6 lawful bases for processing and DPO obligations under similar criteria — but there are important differences. The PDP Law's breach notification is 3×24 hours to both data subjects and the supervisory authority, versus the GDPR's 72 hours to the authority alone. The PDP Law's maximum administrative fine is 2% of annual revenue, versus the GDPR's 4% of global revenue or €20 million. The PDP Law also carries criminal sanctions of up to 6 years' imprisonment, which the GDPR does not regulate at the EU level.
How should an organization start PDP Law compliance?
Start with data mapping and inventory — map all the personal data you process into Records of Processing Activities (RoPA), because you cannot protect data you do not know you have. Follow with a gap assessment against every PDP obligation, fixing lawful bases and consent mechanisms, drafting policies, appointing a DPO, strengthening technical security (encryption, access controls, VAPT), preparing 3×24-hour incident response, and periodic training and audits. Integrate this with an ISO 27001/27701-based ISMS so privacy compliance, security, and risk management reinforce one another.
Related Templates & Checklists
Supporting material to act on what this article covers. Free — one email, once.
PDP Law Compliance Checklist
A compliance checklist against Law No. 27 of 2022 on Personal Data Protection (PDP Law).
Download freeVendor & Third-Party Register Template
Record every vendor with its criticality tier, data accessed, due diligence status, and review date — aligned with ISO 27001 controls A.5.19–A.5.22.
Download freeAbout the Author
Cloudsphere Consulting Team
GRC & Compliance
Cloudsphere's GRC consulting team, guiding Indonesian organizations to ISO 27001 certification and PDP Law compliance from gap analysis through audit.
Share Article
Related Topics
Related Articles
GRC Software
GRC Software in Indonesia: Must-Have Features, Options Compared, and Pricing (2026)
August 15, 2026
EDR Pricing
Endpoint Security & EDR Cost in Indonesia: Price Ranges per Device and the Components Teams Miss
July 30, 2026
Vulnerability Assessment
Vulnerability Assessment vs Penetration Testing: The Difference, When to Use Which, and Why They Pair as VAPT
July 28, 2026