Checklists

Indonesia PDP Law Compliance Checklist

A compliance checklist against Law No. 27 of 2022 on Personal Data Protection (PDP Law).

Format
XLSX · DOCX
Size
16 KB
Language
Indonesian & English
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

In short

Indonesia's Law 27/2022 requires every personal data controller and processor to meet obligations including a lawful basis for processing, fulfilment of data subject rights, records of processing activities, and breach notification within 3×24 hours. This checklist turns those obligations into questions that can be answered and evidenced.

What This Document Is For

Many organisations equate PDP Law compliance with publishing a privacy policy. The actual obligations reach much further: knowing what personal data you hold and on what basis, being able to satisfy data subject requests within deadline, and being able to notify a breach within 3×24 hours — which is impossible if the records were never prepared.

This checklist lays those obligations out as a list an internal team can work through without legal training. Each row names the obligation, the evidence that shows it is met, and who typically owns it. Anything marked unmet becomes the work list.

Most Useful For

  • Organisations processing customer or employee personal data at scale
  • Legal and IT teams needing shared language to map PDP Law obligations
  • Companies asked about PDP Law readiness by clients or partners during due diligence

What's Inside

01
Lawful basis
Mapping each processing activity to its legal basis, including consent management where consent is relied on.
02
Data subject rights
Readiness to satisfy access, correction, erasure, consent withdrawal, and objection rights within their response deadlines.
03
Processing records
Completeness of the records of processing activities required of personal data controllers.
04
Impact assessment
DPIA triggers and documentation completeness for high-risk processing.
05
Breach notification
Readiness of the 3×24 hour procedure: who decides, what is reported, and to whom.
06
Transfers & processors
Arrangements for transferring data outside Indonesia and agreements with third-party processors.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
Law 27/2022 (PDP Law)Controller obligationsLawful basis, data subject rights fulfilment, and records of processing activities.
Law 27/2022 (PDP Law)Breach notificationThe duty to notify a failure of personal data protection within 3×24 hours.
ISO/IEC 27701PIMSPrivacy controls extending ISO 27001, overlapping substantially with PDP Law obligations.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Must every organisation appoint a DPO?

Not every one. The PDP Law requires appointing a data protection officer in specific circumstances — among them processing for public service purposes, core activities requiring regular and systematic monitoring of personal data on a large scale, or large-scale processing of specific personal data. This checklist includes the screening questions.

How does the PDP Law relate to ISO 27001?

ISO 27001 secures information; the PDP Law governs personal data processing. They overlap on access control, incident management, and vendor management — so running both together saves considerable work. ISO 27701 is the formal bridge.

Is this checklist legal advice?

No. It is an operational tool for mapping readiness. Legal interpretation for your organisation's specific circumstances still needs review by counsel, particularly for high-risk processing and cross-border transfers.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.