Data Subject Rights under Indonesia’s PDP Law: 8 Rights Controllers Must Honor

GDPR has the Right to be Forgotten. Under Indonesia’s PDP Law, that right now has legal teeth in Indonesia — with response duties ranging from 72-hour notification to reasonable internal deadlines.

8 Data Subject Rights (PDP Law Articles 5-15)

  1. Right to information — purposes, lawful basis, data types, retention period
  2. Right of access — data copy + processing logs (similar to GDPR SAR)
  3. Right to rectification / update — correct inaccurate data
  4. Right to erasure — when purposes are fulfilled, consent is withdrawn, or processing is unlawful
  5. Right to withdraw consent — at any time, without burdensome conditions
  6. Right to object — refuse profiling & processing for legitimate / public interests
  7. Right to delay / restrict — request a processing freeze during disputes
  8. Right to portability — receive data in a structured format & transmit it to another controller (where systems are interoperable)

Response SLAs You Must Prepare

The PDP Law does not set an hour count for SARs, but implementing regulations & OJK/BI practice push for 14-30 days. Snipeyes best practice: 3-day triage, 14-day SLA — documented in the DPO SOP.

Response Template (Redacted)

Your request has been received (Ticket PDP-2023-xxx). We will verify your identity via national ID OTP and respond within a maximum of 14 days. If your data sits with a processor, we will forward it within 3x24 hours.

Common Mistakes

  • Stalling without written reasons — treated as obstruction of rights (administrative sanction)
  • Requesting a physical ID card via unencrypted email — itself violates data minimization
  • Refusing deletion for “internal archive” reasons without a legal retention basis

Next: Controller & Processor Obligations → · DPO SOP Template — Download →