Law note · Indonesia
Law on Personal Data Protection, comprehensive regime
What it requires
- An app that collects, uses, or discloses the personal data of an individual in Indonesia must establish a lawful basis under Article 20, most commonly consent, though the procedural detail for several related duties awaits implementing regulations that had not yet issued as of this research.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
What we found
Law No. 27 of 2022 (UU PDP) is Indonesia's first standalone, comprehensive personal-data statute, running lawful basis primarily through Article 20's consent model. Enforcement and rulemaking authority sits with a to-be-established supervisory institution under Chapter IX, referred to in the Act as lembaga; as of this research, that institution had not been formally established, with a draft Presidential Regulation on it still in stakeholder discussion.
Nine mandated Peraturan Pemerintah delegated implementing detail, including the fine-calculation procedure, the automated-decision objection procedure, and the compensation-claim procedure, and remained unissued as of this research, though the Act's own substantive duties are themselves statutory and binding now.
This document was read at a city-government legal-documentation network (JDIH) mirror of the Act after the derived candidate's peraturan.go.id URL returned unreachable, corroborated against the national Audit Board's legal database.
Primary source
government (.go.id) legal-documentation network mirror
corroborated against the national Audit Board's legal database (peraturan.bpk.go.id)