Law / Indonesia

Indonesia

privacy

Indonesia's comprehensive private-sector data-protection law is Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi, UU PDP), signed and promulgated 17 October 2022, with a two-year adjustment period reported to have ended 17 October 2024.

Article 4 distinguishes specific personal data, the sensitive category, from general personal data; the official elucidation to Article 4(2)(b) defines biometric data as data enabling unique identification from a person's physical, physiological, or behavioral characteristics, naming a facial image expressly and, more broadly, reaching a voice-derived identifier on the same general language.

The Act's substantive duties, including consent, sensitive-category handling, breach notification, cross-border adequacy, and data-subject rights, are themselves statutory and binding today, but nine mandated implementing regulations (Peraturan Pemerintah) remained unissued and the dedicated supervisory institution had not been formally established as of this research, so the procedural mechanics for several duties, including the fine-calculation procedure and the automated-decision objection procedure, are left to regulations that do not yet exist.

Article 12 grants a statutory right to sue for compensation, and Article 57 sets an administrative fine of up to 2 percent of annual revenue, with its own imposition procedure likewise awaiting the pending regulation.

13 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Law on Personal Data Protection, biometric data definition

cite Law No. 27 of 2022 on Personal Data Protection, Article 4(2)(b) and its official elucidation stage IN FORCE in force since 2022-10-17 binds private bodies source government (.go.id) legal-documentation network mirror
What it requires

Article 4 distinguishes specific personal data (the sensitive category) from general personal data, listing biometric data among health data, genetic data, criminal records, children's data, and personal financial data. The official elucidation to Article 4(2)(b) defines biometric data as data relating to a person's physical, physiological, or behavioral characteristics enabling unique identification, naming a facial image expressly as an example alongside fingerprint, retinal, and DNA data.

A direct search for suara (voice) in the elucidation returned zero hits, so voiceprint coverage rests on the general definitional language rather than an express example. As specific personal data, biometric data processing requires stricter consent under Article 21 and related provisions.

Breach notification

Law on Personal Data Protection, breach notification

cite Law No. 27 of 2022 on Personal Data Protection, Article 46 stage IN FORCE in force since 2022-10-17 binds private bodies source government (.go.id) legal-documentation network mirror
What it requires

Article 46(1) requires a Personal Data Controller to give written notification no later than 3 times 24 hours (72 hours) to the personal data subject and to the supervisory institution on a failure of personal data protection. The notification must at minimum describe the data disclosed, when and how it was disclosed, and the controller's handling and recovery efforts; in certain cases the controller must also notify the public.

Comprehensive regime

Law on Personal Data Protection, comprehensive regime

cite Law No. 27 of 2022 on Personal Data Protection, State Gazette 2022 No. 196, signed and promulgated 17 October 2022 stage IN FORCE in force since 2022-10-17 binds private bodies source government (.go.id) legal-documentation network mirror
What it requires

Law No. 27 of 2022 (UU PDP) is Indonesia's first standalone, comprehensive personal-data statute, running lawful basis primarily through Article 20's consent model. Enforcement and rulemaking authority sits with a to-be-established supervisory institution under Chapter IX, referred to in the Act as lembaga; as of this research, that institution had not been formally established, with a draft Presidential Regulation on it still in stakeholder discussion.

Nine mandated Peraturan Pemerintah delegated implementing detail, including the fine-calculation procedure, the automated-decision objection procedure, and the compensation-claim procedure, and remained unissued as of this research, though the Act's own substantive duties are themselves statutory and binding now.

This document was read at a city-government legal-documentation network (JDIH) mirror of the Act after the derived candidate's peraturan.go.id URL returned unreachable, corroborated against the national Audit Board's legal database.

Cross border transfer

Law on Personal Data Protection, cross-border transfer

cite Law No. 27 of 2022 on Personal Data Protection, Article 56 stage IN FORCE in force since 2022-10-17 binds private bodies source government (.go.id) legal-documentation network mirror
What it requires

Article 56 permits a Personal Data Controller to transfer personal data to a controller or processor outside Indonesia's legal territory, provided the recipient's country of domicile has a level of personal data protection equal to or higher than the Act's own standard. Later paragraphs of Article 56, understood from the visible structure to provide fallback mechanisms such as binding instruments or consent where the adequacy standard is not met, were not read verbatim this pass. No data-localization mandate was found in the paragraphs read.

Enforcement supervision

Law on Personal Data Protection, enforcement and private right to sue

cite Law No. 27 of 2022 on Personal Data Protection, Articles 12, 57-58 stage IN FORCE in force since 2022-10-17 binds private bodies source government (.go.id) legal-documentation network mirror
What it requires

Article 12(1) gives a Personal Data Subject the right to sue and receive compensation for a violation, with the detailed procedure delegated to a Government Regulation not yet issued as of this research.

Article 57 subjects a violating controller to administrative sanctions, including written warning, temporary suspension of processing, deletion or destruction of data, and an administrative fine of up to 2 percent of annual revenue or income, with the fine-imposition procedure likewise delegated to a pending Government Regulation.

Enforcement authority sits with the not-yet-formally-established supervisory institution under Chapter IX, whose confirmed duties include compliance oversight, imposing sanctions, cross-border cooperation with peer regulators, and receiving complaints.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.