When Is a DPIA Mandatory under Indonesia’s PDP Law? Data Protection Impact Assessment Guide

Launching an AI-based credit scoring feature without a DPIA = high risk + the PDP Authority can order processing to stop.

When Is a DPIA Mandatory? (Articles 35-36 interpretation + GDPR best practice)

Mandatory where there is high risk to subject rights, especially:

  • Large-scale specific data (health, biometrics, financial, 100k+ subjects)
  • Systematic monitoring of public areas (AI CCTV, facial recognition)
  • Profiling / scoring for legal / financial decisions (credit scoring, e-KYC, HR screening)
  • New technologies (generative AI, medical IoT, blockchain identity)
  • High-risk cross-border transfers

Minimum DPIA Contents (1-2 pages, not a thesis)

  1. Systematic description — purposes, data flows, parties involved, retention
  2. Necessity & proportionality — why can’t you achieve it with less data?
  3. Risk assessment — likelihood x severity against rights (privacy, discrimination, financial)
  4. Mitigations — encryption, pseudonymization, minimization, access control, logging, retention
  5. Residual risk — if still high → prior consultation with the PDP Authority before go-live

1-Page Template (Snipeyes)

| Risk | Initial Score | Mitigation | Residual Score | Owner | |—|—|—|—|—| | BOLA in customer profile API | High | ABAC + mTLS + logging | Low | CTO |

Don’t forget re-DPIA — every change of purpose, technology, or new vendor requires a DPIA update.

Download DPIA Template → · Full Controller Obligations →