Understanding Indonesia’s PDP Law No. 27 of 2022: The New Foundation for Data Protection
Enacted on 17 October 2022 after 8 years of deliberation, the PDP Law changes how every company in Indonesia manages data — from consent to fines of IDR 60 billion.
Why the PDP Law Matters Now
Before 2022, data protection was fragmented across the EIT Law, PP PSTE & sectoral regulations (OJK, BI). PDP Law No. 27/2022 unifies the standard much like the GDPR — with extraterritorial effect: as long as you process data of Indonesian citizens, you must comply even if your servers are abroad.
What Counts as Personal Data?
General Data: name, national ID (NIK), address, email, phone number, vehicle plate.
Specific (sensitive) Data: biometrics, genetics, health, financial, criminal records, political views — processing requires explicit consent + DPIA.
Who Is Regulated?
- Data Subject: Indonesian citizens / foreigners whose data is processed
- Data Controller: determines purposes & means of processing (e.g., banks, e-commerce, hospitals)
- Data Processor: processes on behalf of the controller (e.g., cloud, payroll vendors, call centers)
- Personal Data Protection Authority: to be established by the President (entered finalization stage in February 2026)
Lawful Processing Principles (Articles 16-29)
Processing must satisfy one lawful basis: data subject consent, contractual/legal obligation, vital interest, public interest, or balanced legitimate interest. Without a basis, processing = unlawful.
Practical Impact for Enterprise
- 2-year transition period until October 2024 — after that, sanctions apply
- Must maintain ROPA (Record of Processing Activities), ready for 72-hour audits
- Processor contracts must include PDP clauses — legacy vendors need amendments
Start here: Data inventory → ROPA → gap assessment against Articles 20-60. Snipeyes helps with a 10-day PDP Readiness Assessment — NDA-protected, board-ready.