Indonesia PDP Law
Indonesia PDP Marketing + Profiling

Indonesia PDP Law IDPdp-Marketing-Profiling-DirectCommunication-Art18-OptOut-PreferenceCenter-Cookies: Indonesia PDP Marketing + Profiling + Direct Communication + Article 18 Marketing Consent + Opt-Out + Preference Center + Cookies + Tracking Technologies + Behavioural Advertising

Direct marketing + profiling + tracking technologies are subject to UU PDP consent + lawful basis requirements + Indonesian sectoral law overlays. (1) Direct Marketing: per Article 18 + general marketing communications require Data Subject opt-in consent + may rely on legitimate interests for non-electronic mail to existing customers with clear opt-out + each electronic marketing communication shall include unsubscribe/opt-out mechanism. (2) Profiling: any automated processing including profiling that has legal effects or substantial similar effects requires opt-out per Article 11 + Data Protection Impact Assessment per Article 45. (3) Cookies + Similar Tracking Technologies: per UU PDP + coordinated with UU ITE (Electronic Information and Transactions Law) + PP 71/2019 on Electronic System and Transaction Implementation - websites and apps must (a) provide notice of cookie use; (b) obtain consent for non-essential cookies including analytics + advertising + social media + functional non-essential; (c) provide cookie preference center allowing granular consent; (d) allow withdrawal as easy as giving. (4) Behavioural Advertising: opt-in consent required + transparency about data shared with ad partners + ad tech vendors + DMP Data Management Platforms + DSP Demand-Side Platforms + SSP Supply-Side Platforms + Real-Time Bidding (RTB) + retargeting + cross-device tracking. (5) Sensitive Categories: behavioural targeting based on Specific Personal Data (sensitive) prohibited without explicit consent including health + political + religious + sexual + biometric + genetic + child. (6) Children Behavioural Advertising: no targeted advertising to children under 17 except as authorised by parental consent + restricted to age-appropriate content. (7) Marketing Preference Center: customer-accessible preference center showing all marketing channels (email + SMS + push + WhatsApp + voice + postal) + opt-in/opt-out controls + frequency settings + records + audit. (8) Indonesian e-Commerce: coordinated with Indonesia e-Commerce Roadmap + Trade Law + Consumer Protection Law (UU Perlindungan Konsumen) + OJK financial promotion regulations + BI payment regulations. (9) Cross-Border Ad Tech: data shared with foreign ad tech vendors subject to UU PDP cross-border transfer requirements. Coordinates with GDPR ePrivacy + UK ICO cookie guidance + India DPDP + Singapore PDPA DNC + Indonesia UU Trade + Indonesia Consumer Protection + KPI Indonesian Broadcasting Commission. Indonesia PDP Marketing + Profiling applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 71 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)

Bahrain PDPL · 2 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • CAT-D5-1 Incident planning and strategy
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))

IEEE 1686 · 1 control

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills

ISO/IEC 27010:2015 · 1 control

  • 27010-16.1 Continuity of Sharing

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response
  • INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • DSOMM-1 Culture, Organization, Education, and Governance

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • PSPF24-1 Security Culture, Governance, Risk Management
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 71 it maps to, and the evidence behind each claim, over MCP and REST.