WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Asia-Pacific

Indonesia Privacy & Data Protection Laws

Every regime below can apply to a business handling Indonesia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

October 17, 2022; two-year transition period ended October 17, 2024
Law No. 27 of 2022 on Personal Data Protection
Indonesia PDP Law
Verify details

Article 2 gives the PDP Law explicit extraterritorial application: it binds any person, corporation, public body or international organization located in Indonesia, and those located outside Indonesia whose actions have legal consequences within Indonesia or for Indonesian citizens outside Indonesia — a consequences-based test that is, on its face, broader than GDPR Article 3. The transition period expired October 17, 2024, so full compliance has been required since then: lawful bases, data-subject rights, DPO appointment for qualifying processing, breach notification within 72 hours, and criminal as well as administrative liability. Two practical caveats a reviewer should confirm: the implementing government regulation elaborating the statute has been slower to arrive than the statute itself, and the independent supervisory authority contemplated by the law has not been established on the original timetable — so obligations are legally in force while the enforcement machinery is still incomplete.

Undang-Undang No. 27 Tahun 2022, Art. 2 (scope)Read regulation →

Children & Minors Protections · 1

October 17, 2024 (end of the PDP Law's two-year transition); GR No. 33 of 2026 sanctions from approximately January 16, 2027
Law No. 27 of 2022 on Personal Data Protection — personal data of children and of persons with disabilities
Indonesia PDP Law Arts. 25-26
Verify details

Art. 25 requires that children's personal data be processed in a specific manner and with the consent of a parent or guardian. The Law itself sets NO age threshold, which is the practical problem — the implementing regulation supplies it, defining a child as an individual under 18 and unmarried, so confirm the current definition rather than assuming 13 or 16. Art. 26 is unusual enough to note separately: Indonesia gives persons with disabilities a parallel protected status, requiring processing in a specified manner and consent from the person or their guardian, with further rules on how controllers must communicate with them. Very few regimes in this dataset pair the two that way, and a compliance program scoped only to minors will miss half of it. Marked 'check': the primary texts are Indonesian-language, the implementing regulation is recent, and Indonesia's supervisory authority was still being stood up.

Law No. 27 of 2022, Arts. 25-26; Government Regulation No. 33 of 2026Read regulation →

Cross-Border Data Transfer · 1

October 17, 2024 (end of the PDP Law's two-year transition); GR No. 33 of 2026 sanctions from approximately January 16, 2027
Law No. 27 of 2022 on Personal Data Protection — transfer of personal data outside Indonesia
Indonesia PDP Law Art. 56
Verify details

Art. 56 is a strict waterfall, taken in order rather than chosen from: transfer is permitted if the recipient country's level of personal data protection is equal to or higher than Indonesia's; if it is not, then only where adequate and binding protection exists in the recipient country; and if neither holds, only with the data subject's consent. Consent is the last resort here, not a parallel option — the opposite of how many businesses structure their analysis. GR 33 of 2026 confirms that adequacy assessments are made by the supervisory authority, which will maintain a whitelist of adequate jurisdictions, and gives a six-month transition from its July 16, 2026 promulgation before administrative sanctions attach around January 16, 2027. Marked 'check': the primary texts are Indonesian-language, the whitelist did not exist at the time of writing, and Indonesia's supervisory authority was still being stood up.

Law No. 27 of 2022, Arts. 55-56; Government Regulation No. 33 of 2026 (promulgated July 16, 2026)Read regulation →

Data Security & Breach Notification · 1

October 17, 2024 (end of the PDP Law's two-year transition); GR No. 33 of 2026 in force approximately January 16, 2027
Law No. 27 of 2022 on Personal Data Protection — notification of failure to protect personal data
Indonesia PDP Law Art. 46
Verify details

There are two deadlines here and which one applies depends on the date. The PDP Law itself, Art. 46, gives 3 x 24 hours from becoming aware to notify both the affected data subject and the supervisory authority in writing, stating the personal data disclosed, when and how it happened, and the handling and recovery efforts made. The implementing Government Regulation promulgated July 16, 2026 restates that 3 x 24 hour window and clarifies that it runs from the point the failure is known with certainty and on reasonable grounds — but it does not enter into force until roughly six months after promulgation. Marked 'check' for two reasons a reviewer must resolve: Indonesia's supervisory authority was still being stood up rather than fully operational through this period, and independent sources differ on whether Art. 46's own window is 3 x 24 hours or 14 days. Read the Indonesian text of Art. 46 before relying on either.

Law No. 27 of 2022, Art. 46; Government Regulation No. 33 of 2026 (implementing regulation, promulgated July 16, 2026)Read regulation →

Other Asia-Pacific jurisdictions