Data Subject Rights under Indonesia’s PDP Law: 8 Rights Controllers Must Honor
GDPR has the Right to be Forgotten. Under Indonesia’s PDP Law, that right now has legal teeth in Indonesia — with response duties ranging from 72-hour notification to reasonable internal deadlines.
8 Data Subject Rights (PDP Law Articles 5-15)
- Right to information — purposes, lawful basis, data types, retention period
- Right of access — data copy + processing logs (similar to GDPR SAR)
- Right to rectification / update — correct inaccurate data
- Right to erasure — when purposes are fulfilled, consent is withdrawn, or processing is unlawful
- Right to withdraw consent — at any time, without burdensome conditions
- Right to object — refuse profiling & processing for legitimate / public interests
- Right to delay / restrict — request a processing freeze during disputes
- Right to portability — receive data in a structured format & transmit it to another controller (where systems are interoperable)
Response SLAs You Must Prepare
The PDP Law does not set an hour count for SARs, but implementing regulations & OJK/BI practice push for 14-30 days. Snipeyes best practice: 3-day triage, 14-day SLA — documented in the DPO SOP.
Response Template (Redacted)
Your request has been received (Ticket PDP-2023-xxx). We will verify your identity via national ID OTP and respond within a maximum of 14 days. If your data sits with a processor, we will forward it within 3x24 hours.
Common Mistakes
- Stalling without written reasons — treated as obstruction of rights (administrative sanction)
- Requesting a physical ID card via unencrypted email — itself violates data minimization
- Refusing deletion for “internal archive” reasons without a legal retention basis
Next: Controller & Processor Obligations → · DPO SOP Template — Download →