ChecklistsFree

Indonesia PDP Law Compliance Checklist

A compliance checklist against Law No. 27 of 2022 on Personal Data Protection (PDP Law).

In short

Indonesia's Law 27/2022 requires every personal data controller and processor to meet obligations including a lawful basis for processing, fulfilment of data subject rights, records of processing activities, and breach notification within 3×24 hours. This checklist turns those obligations into questions that can be answered and evidenced.

Format
XLSX · DOCX
Size
16 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

Many organisations equate PDP Law compliance with publishing a privacy policy. The actual obligations reach much further: knowing what personal data you hold and on what basis, being able to satisfy data subject requests within deadline, and being able to notify a breach within 3×24 hours — which is impossible if the records were never prepared.

This checklist lays those obligations out as a list an internal team can work through without legal training. Each row names the obligation, the evidence that shows it is met, and who typically owns it. Anything marked unmet becomes the work list.

Most Useful For

  • Organisations processing customer or employee personal data at scale
  • Legal and IT teams needing shared language to map PDP Law obligations
  • Companies asked about PDP Law readiness by clients or partners during due diligence

What's Inside

01

Lawful basis

Mapping each processing activity to its legal basis, including consent management where consent is relied on.

02

Data subject rights

Readiness to satisfy access, correction, erasure, consent withdrawal, and objection rights within their response deadlines.

03

Processing records

Completeness of the records of processing activities required of personal data controllers.

04

Impact assessment

DPIA triggers and documentation completeness for high-risk processing.

05

Breach notification

Readiness of the 3×24 hour procedure: who decides, what is reported, and to whom.

06

Transfers & processors

Arrangements for transferring data outside Indonesia and agreements with third-party processors.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
Law 27/2022 (PDP Law)Controller obligationsLawful basis, data subject rights fulfilment, and records of processing activities.
Law 27/2022 (PDP Law)Breach notificationThe duty to notify a failure of personal data protection within 3×24 hours.
ISO/IEC 27701PIMSPrivacy controls extending ISO 27001, overlapping substantially with PDP Law obligations.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Must every organisation appoint a DPO?

Not every one. The PDP Law requires appointing a data protection officer in specific circumstances — among them processing for public service purposes, core activities requiring regular and systematic monitoring of personal data on a large scale, or large-scale processing of specific personal data. This checklist includes the screening questions.

How does the PDP Law relate to ISO 27001?

ISO 27001 secures information; the PDP Law governs personal data processing. They overlap on access control, incident management, and vendor management — so running both together saves considerable work. ISO 27701 is the formal bridge.

Is this checklist legal advice?

No. It is an operational tool for mapping readiness. Legal interpretation for your organisation's specific circumstances still needs review by counsel, particularly for high-risk processing and cross-border transfers.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.