Law note · Indonesia

Law on Personal Data Protection, cross-border transfer

cite Law No. 27 of 2022 on Personal Data Protection, Article 56 stage IN FORCE in force since 2022-10-17 kind Cross border transfer binds private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal data of an individual in Indonesia, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Indonesia must ensure the recipient's country of domicile provides a level of personal data protection equal to or higher than this Law's standard.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_voice
  • processes_biometrics

What we found

Article 56 permits a Personal Data Controller to transfer personal data to a controller or processor outside Indonesia's legal territory, provided the recipient's country of domicile has a level of personal data protection equal to or higher than the Act's own standard. Later paragraphs of Article 56, understood from the visible structure to provide fallback mechanisms such as binding instruments or consent where the adequacy standard is not met, were not read verbatim this pass. No data-localization mandate was found in the paragraphs read.

← Back to the example  ·  Lint your app →