Back to Frameworks

Indonesia PDPL

Indonesia
22 domains
39 controls

Indonesia Personal Data Protection Law (Law No. 27 of 2022, full enforcement Oct 2024).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (22)

Accountability

1 controls
Controls in the Accountability domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art37Controller obligations and accountability

Audit

1 controls
Controls in the Audit domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art30Logging and supervision of processing

Breach notification

2 controls
Controls in the Breach notification domain of Indonesia PDPL2 controls
CodeTitle
PDPL-Art46Personal data breach notification (3x24 hours)
PDPL-Art47Public disclosure of breach in certain cases

Children

1 controls
Controls in the Children domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art25Processing of children's data

Consent

1 controls
Controls in the Consent domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art22Consent requirements

Cross-border transfer

1 controls
Controls in the Cross-border transfer domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art56Cross-border personal data transfer

DPIA

1 controls
Controls in the DPIA domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art31Data Protection Impact Assessment (DPIA)

Data classification

1 controls
Controls in the Data classification domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art4Specific (sensitive) personal data categories

Data quality

1 controls
Controls in the Data quality domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art28Accuracy and validity of personal data

Data subject rights

9 controls
Controls in the Data subject rights domain of Indonesia PDPL9 controls
CodeTitle
PDPL-Art10Right to object to automated decision-making
PDPL-Art11Right to restrict processing
PDPL-Art12Right to data portability
PDPL-Art13Right to claim and receive compensation
PDPL-Art5Right to information about processing
PDPL-Art6Right to complete, update, and rectify personal data
PDPL-Art7Right of access to personal data
PDPL-Art8Right to terminate processing, delete, or destroy personal data
PDPL-Art9Right to withdraw consent

Governance

3 controls
Controls in the Governance domain of Indonesia PDPL3 controls
CodeTitle
PDPL-Art35Data Protection Officer (DPO) appointment
PDPL-Art40Joint controllers
PDPL-Art58Personal Data Protection Authority (Lembaga PDP)

Lawful basis

1 controls
Controls in the Lawful basis domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art20Lawful basis for processing

Localization

1 controls
Controls in the Localization domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art57Data localization for strategic data (sector-specific)

Penalties

4 controls
Controls in the Penalties domain of Indonesia PDPL4 controls
CodeTitle
PDPL-Art57AdminAdministrative sanctions up to 2% of annual revenue
PDPL-Art65Criminal offenses: unlawful obtaining or disclosing of personal data
PDPL-Art66Criminal offenses: falsifying personal data
PDPL-Art67Criminal offenses: corporate liability and additional sanctions

Processing principles

1 controls
Controls in the Processing principles domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art16Principles of personal data processing

Programme

1 controls
Controls in the Programme domain of Indonesia PDPL1 controls
CodeTitle
PDPL-TransOct2024Transition period and full enforcement

Retention

2 controls
Controls in the Retention domain of Indonesia PDPL2 controls
CodeTitle
PDPL-Art48Retention and destruction of personal data
PDPL-Art50Personal data destruction procedures

Scope

1 controls
Controls in the Scope domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art1Definitions and scope of personal data

Security

3 controls
Controls in the Security domain of Indonesia PDPL3 controls
CodeTitle
PDPL-Art27Anonymization and pseudonymization
PDPL-Art29Confidentiality and security of personal data
PDPL-Art45Personal data breach prevention measures

Transparency

1 controls
Controls in the Transparency domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art21Information to be provided before consent or processing

Vendor management

1 controls
Controls in the Vendor management domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art39Processor obligations and controller-processor contracts

Vulnerable subjects

1 controls
Controls in the Vulnerable subjects domain of Indonesia PDPL1 controls
CodeTitle
PDPL-Art26Processing of personal data of persons with disabilities

Frequently Asked Questions

What is Indonesia PDPL?

Indonesia PDPL is a compliance framework from Indonesia with 22 domains and 39 controls. Indonesia Personal Data Protection Law (Law No. 27 of 2022, full enforcement Oct 2024). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Indonesia PDPL have?

Indonesia PDPL has 39 controls organised across 22 domains. The largest domains are Data subject rights (9 controls), Penalties (4 controls), Governance (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Indonesia PDPL map to?

Indonesia PDPL does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Indonesia PDPL compliance?

Start your Indonesia PDPL compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Indonesia PDPL requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required