Cross-Border Data Transfer under Indonesia’s PDP Law: Requirements, Safeguards & Adequacy

Using Singapore cloud or a support center in India? PDP Law Article 56 governs it — you cannot just assume “it’s secure.”

Lawful Transfer Hierarchy (Article 56)

Transfers outside Indonesia are allowed only if one of the following is met:

  1. Destination country offers adequate protection — list to be published by the PDP Authority (similar to GDPR adequacy decisions)
  2. Adequate protection via safeguardsSCCs (Standard Contractual Clauses), BCRs (Binding Corporate Rules) or binding contracts
  3. Explicit data subject consent after being informed of transfer risks
  4. Narrow exemptions: contract performance, vital / public interests, or law enforcement

Practical Enterprise Checklist

  • Map data residency: DB, backups, logs, analytics — in which region?
  • Cloud contracts: ensure PDP-ID SCCs + audit rights + 72-hour breach clause + explicit processing location
  • For US SaaS — add a light Transfer Impact Assessment (TIA): government access laws in the destination country
  • Record in your ROPA a “cross-border transfer = Yes/No, basis = SCC/Adequacy/Consent” column

Fatal Mistakes

  • Assuming a vendor ISO 27001 certificate = adequacy — it does not.
  • Bulk transfers on app consent alone — consent must be per transfer, informed, not thousands of records without assessment

See DPIA for High-Risk Transfers → · PDP SCC Template — Request →