Skip to main content

Compliance · UU PDP

UU PDP compliance: the complete guide for Indonesian businesses

Indonesia's Personal Data Protection Law has been enforceable since October 2024. This guide explains what UU PDP requires, who it applies to, the penalties for getting it wrong, and the practical steps to become compliant.

In short

UU PDP is Indonesia's Personal Data Protection Law (Law 27 of 2022). Enforcement has been active since October 2024. Any organisation that processes the personal data of people in Indonesia must comply or risk administrative fines of up to 2 percent of annual revenue tied to the violation.

2%

Maximum administrative fine, as a share of annual revenue

6 yrs

Maximum imprisonment for the most serious violations

Oct 2024

Enforcement active since this date

27/2022

The statute: Law Number 27 of 2022

Definition

What is UU PDP?

UU PDP stands for Undang-Undang Perlindungan Data Pribadi, Indonesia's Personal Data Protection Law, enacted as Law Number 27 of 2022. It is the country's first comprehensive data protection statute and sets out how organisations may collect, use, store, and share the personal data of individuals.

The law gives individuals rights over their data and places clear obligations on the organisations that handle it. After a two-year transition period, its requirements and sanctions became enforceable in October 2024, which is why compliance is now a priority for any business that holds customer or employee data.

Oct 2022

Enacted

Law 27/2022 is signed, Indonesia's first comprehensive data protection statute.

2022 to 2024

Transition

Pasal 74 gives controllers, processors and other parties two years from promulgation to bring processing into line with the law.

Oct 2024

Enforcement

The transition period ends. Obligations and sanctions become enforceable.

2026

Ongoing

Supervision and enforcement continue under a dedicated data protection authority.

Scope

Who must comply?

UU PDP applies to any organisation that processes the personal data of individuals in Indonesia, whether the organisation is based inside the country or abroad. Answer the questions below to see whether it is likely to apply to you.

  • Do you collect or process personal data of people in Indonesia?
  • Does your organisation decide how that data is used, or process it for someone who does?
  • Do you share personal data with vendors or transfer it across borders?

The law distinguishes between a data controller, which decides why and how data is processed, and a data processor, which processes data on the controller's behalf. Both carry obligations, and the law reaches organisations outside Indonesia whose processing affects Indonesian individuals.

Obligations

What UU PDP requires

The law sets out a set of core obligations for organisations that process personal data.

01

Lawful basis and consent

Pasal 20 requires a controller to have a lawful basis before processing, and lists them: explicit valid consent for one or more specified purposes, performance of a contract, a legal obligation, protection of the vital interests of the data subject, public interest, and legitimate interests. Where consent is the basis, Pasal 20 ayat (2) huruf a requires it to be explicit and tied to purposes the controller has stated.

02

Data subject rights

Pasal 5 to Pasal 13 set out the rights: information about who is processing and why (Pasal 5), correction (Pasal 6), ending processing and deletion (Pasal 8), withdrawal of consent (Pasal 9), objection to decisions based solely on automated processing (Pasal 10), and portability in a commonly used machine-readable format (Pasal 13). Pasal 14 requires requests to be made in recorded form, electronically or otherwise.

03

Purpose limitation

Pasal 16 ayat (2) states the processing principles: collection must be limited and specific, lawful and transparent, and processing must be carried out in accordance with its stated purpose.

04

Security safeguards

Pasal 35 obliges a controller to protect and secure the data it processes by putting technical and operational measures in place and by determining the level of security the data warrants.

05

Breach notification

Pasal 46 ayat (1) requires written notice within 3 times 24 hours to both the data subject and the supervisory body. Pasal 46 ayat (2) sets the minimum contents: which data was exposed, when and how, and the handling and recovery steps taken. In certain cases Pasal 46 ayat (3) also requires notifying the public.

06

Data protection officer

Pasal 53 ayat (1) puts the duty on controllers and processors alike, under any of three conditions: processing for public services, a core activity that requires regular and systematic monitoring of personal data at large scale, or a core activity involving large-scale processing of specific personal data or data relating to criminal offences. Alpha Code offers DPO as a Service (DPOaaS) for organisations that need one without an in-house hire.

07

Cross-border transfers

Pasal 56 governs transfers outside Indonesian jurisdiction as a strict cascade. Ayat (2) is the primary test: the recipient's country of domicile must have a level of data protection equal to or higher than this law. Only where that fails does ayat (3) allow adequate and binding protection instead, and only where both fail does ayat (4) permit relying on the data subject's consent. Pasal 55 covers transfers to another controller inside Indonesia, where both sides remain responsible for protection.

Risk

Penalties for non-compliance

Pasal 57 ayat (2) lists the administrative sanctions: written warning, temporary suspension of processing, deletion or destruction of personal data, and an administrative fine. Pasal 57 ayat (3) caps that fine at 2 percent of annual revenue or receipts measured against the variable of the violation, so it is not a flat ceiling on the whole business.

Criminal liability sits separately in Pasal 67 and Pasal 68, and the terms differ by offence: up to 5 years and Rp 5 billion for unlawfully obtaining or collecting data that is not yours, up to 4 years and Rp 4 billion for unlawfully disclosing it, up to 5 years and Rp 5 billion for unlawfully using it, and up to 6 years and Rp 6 billion for falsifying personal data. Pasal 70 extends liability to corporations. Use the estimator below to see an illustrative maximum administrative fine for your organisation.

Illustrative penalty estimator

Maximum administrative fine

Rp 5.0 billion

Up to 2 percent of annual revenue, per Pasal 57 ayat (3)

This is an illustrative maximum based on the 2 percent ceiling in Pasal 57 ayat (3), which is measured against the variable of the violation rather than total turnover. It is not legal advice or a prediction of any specific penalty.

Action plan

10-step UU PDP compliance checklist

Use this checklist to track your readiness. Tick each step as you complete it to see your progress. Your answers are not saved.

0%

Your compliance readiness

0 / 10

How we help

How Alpha Code helps you comply

Alpha Code maps each UU PDP obligation to a concrete service, so compliance becomes a clear programme of work rather than a legal abstraction.

Frequently asked questions

UU PDP stands for Undang-Undang Perlindungan Data Pribadi, Indonesia's Personal Data Protection Law. It was enacted as Law Number 27 of 2022 and is the country's first comprehensive data protection statute.

Find your UU PDP gaps before a regulator does

A compliance assessment maps your current state against UU PDP and gives you a prioritised plan to close the gaps.

Get in touch
WhatsApp