Comprehensive Privacy Law
Law No. 27 of 2022 on Personal Data Protection
Indonesia · October 17, 2022; two-year transition period ended October 17, 2024
Verify detailsArticle 2 gives the PDP Law explicit extraterritorial application: it binds any person, corporation, public body or international organization located in Indonesia, and those located outside Indonesia whose actions have legal consequences within Indonesia or for Indonesian citizens outside Indonesia — a consequences-based test that is, on its face, broader than GDPR Article 3. The transition period expired October 17, 2024, so full compliance has been required since then: lawful bases, data-subject rights, DPO appointment for qualifying processing, breach notification within 72 hours, and criminal as well as administrative liability. Two practical caveats a reviewer should confirm: the implementing government regulation elaborating the statute has been slower to arrive than the statute itself, and the independent supervisory authority contemplated by the law has not been established on the original timetable — so obligations are legally in force while the enforcement machinery is still incomplete.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.