Definition
What is UU PDP?
UU PDP stands for Undang-Undang Perlindungan Data Pribadi, Indonesia's Personal Data Protection Law, enacted as Law Number 27 of 2022. It is the country's first comprehensive data protection statute and sets out how organisations may collect, use, store, and share the personal data of individuals.
The law gives individuals rights over their data and places clear obligations on the organisations that handle it. After a two-year transition period, its requirements and sanctions became enforceable in October 2024, which is why compliance is now a priority for any business that holds customer or employee data.
Enacted
Law 27/2022 is signed, Indonesia's first comprehensive data protection statute.
Transition
Pasal 74 gives controllers, processors and other parties two years from promulgation to bring processing into line with the law.
Enforcement
The transition period ends. Obligations and sanctions become enforceable.
Ongoing
Supervision and enforcement continue under a dedicated data protection authority.
Enacted
Law 27/2022 is signed, Indonesia's first comprehensive data protection statute.
Transition
Pasal 74 gives controllers, processors and other parties two years from promulgation to bring processing into line with the law.
Enforcement
The transition period ends. Obligations and sanctions become enforceable.
Ongoing
Supervision and enforcement continue under a dedicated data protection authority.
Scope
Who must comply?
UU PDP applies to any organisation that processes the personal data of individuals in Indonesia, whether the organisation is based inside the country or abroad. Answer the questions below to see whether it is likely to apply to you.
- Do you collect or process personal data of people in Indonesia?
- Does your organisation decide how that data is used, or process it for someone who does?
- Do you share personal data with vendors or transfer it across borders?
The law distinguishes between a data controller, which decides why and how data is processed, and a data processor, which processes data on the controller's behalf. Both carry obligations, and the law reaches organisations outside Indonesia whose processing affects Indonesian individuals.
Obligations
What UU PDP requires
The law sets out a set of core obligations for organisations that process personal data.
Lawful basis and consent
Pasal 20 requires a controller to have a lawful basis before processing, and lists them: explicit valid consent for one or more specified purposes, performance of a contract, a legal obligation, protection of the vital interests of the data subject, public interest, and legitimate interests. Where consent is the basis, Pasal 20 ayat (2) huruf a requires it to be explicit and tied to purposes the controller has stated.
Data subject rights
Pasal 5 to Pasal 13 set out the rights: information about who is processing and why (Pasal 5), correction (Pasal 6), ending processing and deletion (Pasal 8), withdrawal of consent (Pasal 9), objection to decisions based solely on automated processing (Pasal 10), and portability in a commonly used machine-readable format (Pasal 13). Pasal 14 requires requests to be made in recorded form, electronically or otherwise.
Purpose limitation
Pasal 16 ayat (2) states the processing principles: collection must be limited and specific, lawful and transparent, and processing must be carried out in accordance with its stated purpose.
Security safeguards
Pasal 35 obliges a controller to protect and secure the data it processes by putting technical and operational measures in place and by determining the level of security the data warrants.
Breach notification
Pasal 46 ayat (1) requires written notice within 3 times 24 hours to both the data subject and the supervisory body. Pasal 46 ayat (2) sets the minimum contents: which data was exposed, when and how, and the handling and recovery steps taken. In certain cases Pasal 46 ayat (3) also requires notifying the public.
Data protection officer
Pasal 53 ayat (1) puts the duty on controllers and processors alike, under any of three conditions: processing for public services, a core activity that requires regular and systematic monitoring of personal data at large scale, or a core activity involving large-scale processing of specific personal data or data relating to criminal offences. Alpha Code offers DPO as a Service (DPOaaS) for organisations that need one without an in-house hire.
Cross-border transfers
Pasal 56 governs transfers outside Indonesian jurisdiction as a strict cascade. Ayat (2) is the primary test: the recipient's country of domicile must have a level of data protection equal to or higher than this law. Only where that fails does ayat (3) allow adequate and binding protection instead, and only where both fail does ayat (4) permit relying on the data subject's consent. Pasal 55 covers transfers to another controller inside Indonesia, where both sides remain responsible for protection.
Risk
Penalties for non-compliance
Pasal 57 ayat (2) lists the administrative sanctions: written warning, temporary suspension of processing, deletion or destruction of personal data, and an administrative fine. Pasal 57 ayat (3) caps that fine at 2 percent of annual revenue or receipts measured against the variable of the violation, so it is not a flat ceiling on the whole business.
Criminal liability sits separately in Pasal 67 and Pasal 68, and the terms differ by offence: up to 5 years and Rp 5 billion for unlawfully obtaining or collecting data that is not yours, up to 4 years and Rp 4 billion for unlawfully disclosing it, up to 5 years and Rp 5 billion for unlawfully using it, and up to 6 years and Rp 6 billion for falsifying personal data. Pasal 70 extends liability to corporations. Use the estimator below to see an illustrative maximum administrative fine for your organisation.
Illustrative penalty estimator
Maximum administrative fine
Rp 5.0 billion
Up to 2 percent of annual revenue, per Pasal 57 ayat (3)
This is an illustrative maximum based on the 2 percent ceiling in Pasal 57 ayat (3), which is measured against the variable of the violation rather than total turnover. It is not legal advice or a prediction of any specific penalty.
Action plan
10-step UU PDP compliance checklist
Use this checklist to track your readiness. Tick each step as you complete it to see your progress. Your answers are not saved.
Your compliance readiness
0 / 10
How we help
How Alpha Code helps you comply
Alpha Code maps each UU PDP obligation to a concrete service, so compliance becomes a clear programme of work rather than a legal abstraction.
Gap assessments, data inventories, privacy impact assessments, and evidence for examinations.
Identify the security weaknesses that put personal data at risk before they are exploited.
24/7 monitoring that supports the security safeguards the law expects.
Rapid containment and the forensics needed to meet the breach-notification window.
We act as your outsourced Data Protection Officer where the law requires one, without the cost of an in-house hire.
Frequently asked questions
UU PDP stands for Undang-Undang Perlindungan Data Pribadi, Indonesia's Personal Data Protection Law. It was enacted as Law Number 27 of 2022 and is the country's first comprehensive data protection statute.