Cross-Border Data Transfer under Indonesia’s PDP Law: Requirements, Safeguards & Adequacy
Using Singapore cloud or a support center in India? PDP Law Article 56 governs it — you cannot just assume “it’s secure.”
Lawful Transfer Hierarchy (Article 56)
Transfers outside Indonesia are allowed only if one of the following is met:
- Destination country offers adequate protection — list to be published by the PDP Authority (similar to GDPR adequacy decisions)
- Adequate protection via safeguards — SCCs (Standard Contractual Clauses), BCRs (Binding Corporate Rules) or binding contracts
- Explicit data subject consent after being informed of transfer risks
- Narrow exemptions: contract performance, vital / public interests, or law enforcement
Practical Enterprise Checklist
- Map data residency: DB, backups, logs, analytics — in which region?
- Cloud contracts: ensure PDP-ID SCCs + audit rights + 72-hour breach clause + explicit processing location
- For US SaaS — add a light Transfer Impact Assessment (TIA): government access laws in the destination country
- Record in your ROPA a “cross-border transfer = Yes/No, basis = SCC/Adequacy/Consent” column
Fatal Mistakes
- Assuming a vendor ISO 27001 certificate = adequacy — it does not.
- Bulk transfers on app consent alone — consent must be per transfer, informed, not thousands of records without assessment
See DPIA for High-Risk Transfers → · PDP SCC Template — Request →