Indonesia PDP Law Compliance Checklist
A compliance checklist against Law No. 27 of 2022 on Personal Data Protection (PDP Law).
In short
Indonesia's Law 27/2022 requires every personal data controller and processor to meet obligations including a lawful basis for processing, fulfilment of data subject rights, records of processing activities, and breach notification within 3×24 hours. This checklist turns those obligations into questions that can be answered and evidenced.
- Format
- XLSX · DOCX
- Size
- 16 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
Many organisations equate PDP Law compliance with publishing a privacy policy. The actual obligations reach much further: knowing what personal data you hold and on what basis, being able to satisfy data subject requests within deadline, and being able to notify a breach within 3×24 hours — which is impossible if the records were never prepared.
This checklist lays those obligations out as a list an internal team can work through without legal training. Each row names the obligation, the evidence that shows it is met, and who typically owns it. Anything marked unmet becomes the work list.
Most Useful For
- Organisations processing customer or employee personal data at scale
- Legal and IT teams needing shared language to map PDP Law obligations
- Companies asked about PDP Law readiness by clients or partners during due diligence
What's Inside
Lawful basis
Mapping each processing activity to its legal basis, including consent management where consent is relied on.
Data subject rights
Readiness to satisfy access, correction, erasure, consent withdrawal, and objection rights within their response deadlines.
Processing records
Completeness of the records of processing activities required of personal data controllers.
Impact assessment
DPIA triggers and documentation completeness for high-risk processing.
Breach notification
Readiness of the 3×24 hour procedure: who decides, what is reported, and to whom.
Transfers & processors
Arrangements for transferring data outside Indonesia and agreements with third-party processors.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| Law 27/2022 (PDP Law) | Controller obligations | Lawful basis, data subject rights fulfilment, and records of processing activities. |
| Law 27/2022 (PDP Law) | Breach notification | The duty to notify a failure of personal data protection within 3×24 hours. |
| ISO/IEC 27701 | PIMS | Privacy controls extending ISO 27001, overlapping substantially with PDP Law obligations. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Must every organisation appoint a DPO?
Not every one. The PDP Law requires appointing a data protection officer in specific circumstances — among them processing for public service purposes, core activities requiring regular and systematic monitoring of personal data on a large scale, or large-scale processing of specific personal data. This checklist includes the screening questions.
How does the PDP Law relate to ISO 27001?
ISO 27001 secures information; the PDP Law governs personal data processing. They overlap on access control, incident management, and vendor management — so running both together saves considerable work. ISO 27701 is the formal bridge.
Is this checklist legal advice?
No. It is an operational tool for mapping readiness. Legal interpretation for your organisation's specific circumstances still needs review by counsel, particularly for high-risk processing and cross-border transfers.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
ISO 27001 Internal Audit Checklist
A complete ISMS internal audit guide with verification points for every clause and control.
Free DownloadISO 27001 Gap Assessment Checklist
Measure your organization's readiness against ISO 27001:2022 and find gaps before certification.
Free DownloadPenetration Test Preparation Checklist
Prepare for a pentest the right way: asset scoping, test accounts, testing windows, PICs, and legal aspects — so testing runs smoothly from day one.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.