Valid Consent under Indonesia’s PDP Law: Requirements, Dark Patterns & Fixes
A pre-ticked “I agree to everything” checkbox = invalid under the PDP Law. Consent must be as clear as pressing “Yes, I allow X for Y.”
5 Requirements for Valid Consent (Articles 22-23)
- Clear & explicit — not implied; silence ≠ consent
- Specific per purpose — one consent per purpose; marketing ≠ analytics
- Informed — controller identity, purposes, data types, subject rights, retention period — in plain Indonesian
- Freely given — no coercion; refusing must not block core services (unless strictly necessary)
- As easy to withdraw as to give — the withdraw button must be as visible as the agree button
Prohibited Patterns (treated as dark patterns)
- Bundled consent — 1 checkbox for 6 purposes at once
- Pre-ticked / opt-out — already checked, users must uncheck
- Cookie wall with no alternative — blocking access unless non-essential analytics is accepted
- 10-page legal jargon — not informed consent
How to Fix Consent UX (Snipeyes Checklist)
- Granular toggles: [ ] Loan profiling [ ] WhatsApp marketing [ ] Partners
- Consent logs: timestamp, notice version, IP/device, source — evidence during audits
- Withdraw Consent button in account → process within 14 days maximum, downstream to processors within 3x24 hours
Note for specific data (Article 25): DPIA + explicit consent + risk assessment are mandatory; “legitimate interest” alone is not enough.
Next: Right to Withdraw Consent → · Free Consent Banner Audit →