Valid Consent under Indonesia’s PDP Law: Requirements, Dark Patterns & Fixes

A pre-ticked “I agree to everything” checkbox = invalid under the PDP Law. Consent must be as clear as pressing “Yes, I allow X for Y.”

  1. Clear & explicit — not implied; silence ≠ consent
  2. Specific per purpose — one consent per purpose; marketing ≠ analytics
  3. Informed — controller identity, purposes, data types, subject rights, retention period — in plain Indonesian
  4. Freely given — no coercion; refusing must not block core services (unless strictly necessary)
  5. As easy to withdraw as to give — the withdraw button must be as visible as the agree button

Prohibited Patterns (treated as dark patterns)

  • Bundled consent — 1 checkbox for 6 purposes at once
  • Pre-ticked / opt-out — already checked, users must uncheck
  • Cookie wall with no alternative — blocking access unless non-essential analytics is accepted
  • 10-page legal jargon — not informed consent
  • Granular toggles: [ ] Loan profiling [ ] WhatsApp marketing [ ] Partners
  • Consent logs: timestamp, notice version, IP/device, source — evidence during audits
  • Withdraw Consent button in account → process within 14 days maximum, downstream to processors within 3x24 hours

Note for specific data (Article 25): DPIA + explicit consent + risk assessment are mandatory; “legitimate interest” alone is not enough.

Next: Right to Withdraw Consent → · Free Consent Banner Audit →