Country:印尼 · Data Privacy
Indonesia · Data Privacy
Indonesia's Personal Data Protection Law (PDP Law 27/2022) took full effect on 2024-10-17, establishing GDPR-like consent, purpose-limitation and data-subject-rights frameworks, and creating an independent Personal Data Protection Authority (Komdigi). Processing needs a lawful basis, a appointed Data Protection Officer (DPO) and breach-notification duty. Cross-border transfer needs adequacy or standard contractual clauses. Where an Indonesian subsidiary processes Chinese employees' or customers' data, dual compliance with China's PIPL arises.
Key points
- PDP Law 27/2022 (full effect 2024-10-17) establishes consent, purpose-limitation, minimisation and security principles.
- Independent regulator: Personal Data Protection Authority (Komdigi) replaces prior fragmented supervision.
- Obligations: lawful basis, appoint DPO, notify breach within 72 hours, cross-border compliance.
- Cross-border: receiving country must have adequate protection, or sign standard clauses & obtain consent.
- Penalty: up to 2% of annual revenue or administrative sanctions (warning, suspension, revocation).
- China data-export obligations (pkulaw-verified 2026-07): transfers to/back to China need one of security assessment (CAC Order 11), standard contract (Order 13) or certification (CAC-SAMR Order 20, 2025-10-14); 2024–2025 relaxed via Provisions on Promoting and Regulating Cross-Border Data Flows (Order 16) and Network Data Security Regulation (State Council Order 790), some scenarios exempt.
Procedure
- Data mapping & classification (does it involve Indonesian residents' personal data).
- Establish lawful basis, obtain consent or sign contractual clauses.
- Appoint DPO and build internal data-protection system.
- Assess receiving-country adequacy or sign SCC before cross-border transfer.
- Build breach-response and regulator-reporting mechanism.
Hard requirements
- Lawful basis; DPO; cross-border compliance; breach-notification mechanism.
Costs
Compliance-system build; DPO staffing; possible certification.⏱ ⏱ Timeline:System build weeks; ongoing compliance.⚠ Common risks
- No DPO or missing system → penalty.
- Cross-border without adequacy → violation (stacks with PIPL).
- Late breach notification → amplified liability.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese enterprises processing Indonesian residents' personal data in Indonesia, or transferring it back to China (governed by PDP Law 27/2022, full effect 2024-10-17, supervised by Komdigi).
Prerequisites
- Clear processing activities & lawful basis.
- Must appoint a Data Protection Officer (DPO).
- Reserve DPO staffing & compliance-system budget.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data mapping & classification Determine if processing Indonesian residents' personal data; map data categories, purposes and recipients. | Legal / IT | 2 weeks | Internal | Data inventory | Same principles as GDPR Penalty:Up to 2% of annual revenue or admin sanction |
| 2 | Establish lawful basis & obtain consent Determine lawful basis under PDP Law (consent/contract/law), obtain consent or sign clauses. | Legal | 1–2 weeks | Internal | Privacy policy, consent/clauses | Purpose-limitation, minimisation Penalty:Same upper limit as step 1 |
| 3 | Appoint DPO & build system Appoint DPO per law, build internal data-protection system & accountability. | Management | Ongoing | DPO staffing | DPO appointment & internal policy | Mandatory Penalty:No DPO → penalty |
| 4 | Cross-border assessment & SCC Before transfer, assess receiving-country adequacy; if inadequate, sign standard clauses or obtain consent, and link with PIPL export requirements. | Legal | 3–6 weeks | Internal & legal fees | Adequacy assessment, SCC, PIPL export docs | China not on adequacy list Penalty:No lawful transfer mechanism → violation (stacks with PIPL) |
| 5 | Breach notification within 72 hours On personal-data breach, notify regulator (Komdigi) and data subjects within 72 hours. | DPO / IT | Within 72 hours | Internal | Komdigi breach notification | Set auto-trigger Penalty:Late or concealed report → aggravated liability |
| 6 | Data-subject rights response Build process for access, correction, deletion, withdrawal requests. | DPO or support | Ongoing | Internal | DSAR process | Must record Penalty:Refusal to respond → penalty |
| 7 | Ongoing compliance & annual audit Periodically review policy, update, train staff. | Compliance | Annual | Internal | Annual audit, training | Komdigi enforcement normalised Penalty:Continuous violations accumulate |
✅ Self-check list
⚠ Common pitfalls
No DPO appointed影响:Direct violation & penalty规避:Mandatory appointment per law
Cross-border without adequacy影响:Violation (stacks with PIPL)规避:Sign standard clauses or obtain consent
China transfer ignores PIPL export影响:Dual violation规避:Handle China-side compliance in parallel
Breach reported after 72 hours影响:Expanded liability规避:Set auto-trigger reporting
Secondary use beyond purpose without re-consent影响:Violates purpose-limitation规避:Re-consent for secondary use
Assume PDP Law not in effect影响:Fully effective since Oct 2024规避:Start compliance immediately
📅 Ongoing post-incorporation obligations
- DPO continues duties.
- Report breaches to Ministry of Communication within 72 hours.
- Continuously respond to data-subject access requests.
- China PIPL export mechanism remains effective.
- Annual audit & staff training.
🔗 Official portals
📎 Source:https://kdpri.kominfo.go.id ; https://www.kominfo.go.id ; https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.