Law / Indonesia

Personal Data Protection Law, scraped personal data

Law No. 27 of 2022, Article 20, Personal Data Protection Law

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 17 October 2022.

A personal data rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Have a lawful basis under Article 20 before collecting or otherwise processing the personal data of an individual in Indonesia, including data collected from a public website; the Act carries no basis keyed to the data already being public.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 19 defines a Personal Data Controller to include every person, public body, and international organisation, and Article 20(1) requires a Controller to have a lawful basis before processing personal data.

Article 20(2) lists six lawful bases exhaustively: explicit consent for one or more stated purposes, performance of a contract to which the data subject is a party, compliance with the Controller's legal obligation, protection of the data subject's vital interest, performance of a public-interest or public-service task, or another legitimate interest balanced against the data subject's rights.

No basis in that list turns on the data having already been made public or being otherwise publicly accessible, so personal data collected from a public Indonesian website remains subject to the Act's ordinary lawful-basis, notice, and cross-border-transfer requirements on the same footing as personal data collected by any other means.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics

Read the law

government (.go.id) legal-documentation network mirror

Back to the example  ·  Lint your app