Understanding Indonesia’s PDP Law No. 27 of 2022: The New Foundation for Data Protection

Enacted on 17 October 2022 after 8 years of deliberation, the PDP Law changes how every company in Indonesia manages data — from consent to fines of IDR 60 billion.

Why the PDP Law Matters Now

Before 2022, data protection was fragmented across the EIT Law, PP PSTE & sectoral regulations (OJK, BI). PDP Law No. 27/2022 unifies the standard much like the GDPR — with extraterritorial effect: as long as you process data of Indonesian citizens, you must comply even if your servers are abroad.

What Counts as Personal Data?

General Data: name, national ID (NIK), address, email, phone number, vehicle plate.
Specific (sensitive) Data: biometrics, genetics, health, financial, criminal records, political views — processing requires explicit consent + DPIA.

Who Is Regulated?

  • Data Subject: Indonesian citizens / foreigners whose data is processed
  • Data Controller: determines purposes & means of processing (e.g., banks, e-commerce, hospitals)
  • Data Processor: processes on behalf of the controller (e.g., cloud, payroll vendors, call centers)
  • Personal Data Protection Authority: to be established by the President (entered finalization stage in February 2026)

Lawful Processing Principles (Articles 16-29)

Processing must satisfy one lawful basis: data subject consent, contractual/legal obligation, vital interest, public interest, or balanced legitimate interest. Without a basis, processing = unlawful.

Practical Impact for Enterprise

  • 2-year transition period until October 2024 — after that, sanctions apply
  • Must maintain ROPA (Record of Processing Activities), ready for 72-hour audits
  • Processor contracts must include PDP clauses — legacy vendors need amendments

Start here: Data inventory → ROPA → gap assessment against Articles 20-60. Snipeyes helps with a 10-day PDP Readiness Assessment — NDA-protected, board-ready.

Read Data Subject Rights → · Request PDP Gap Assessment →