Indonesia PDPL
Indonesia Personal Data Protection Law (Law No. 27 of 2022, full enforcement Oct 2024).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Accountability
| Code | Title |
|---|---|
| PDPL-Art37 | Controller obligations and accountability |
Audit
| Code | Title |
|---|---|
| PDPL-Art30 | Logging and supervision of processing |
Breach notification
| Code | Title |
|---|---|
| PDPL-Art46 | Personal data breach notification (3x24 hours) |
| PDPL-Art47 | Public disclosure of breach in certain cases |
Children
| Code | Title |
|---|---|
| PDPL-Art25 | Processing of children's data |
Consent
| Code | Title |
|---|---|
| PDPL-Art22 | Consent requirements |
Cross-border transfer
| Code | Title |
|---|---|
| PDPL-Art56 | Cross-border personal data transfer |
DPIA
| Code | Title |
|---|---|
| PDPL-Art31 | Data Protection Impact Assessment (DPIA) |
Data classification
| Code | Title |
|---|---|
| PDPL-Art4 | Specific (sensitive) personal data categories |
Data quality
| Code | Title |
|---|---|
| PDPL-Art28 | Accuracy and validity of personal data |
Data subject rights
| Code | Title |
|---|---|
| PDPL-Art10 | Right to object to automated decision-making |
| PDPL-Art11 | Right to restrict processing |
| PDPL-Art12 | Right to data portability |
| PDPL-Art13 | Right to claim and receive compensation |
| PDPL-Art5 | Right to information about processing |
| PDPL-Art6 | Right to complete, update, and rectify personal data |
| PDPL-Art7 | Right of access to personal data |
| PDPL-Art8 | Right to terminate processing, delete, or destroy personal data |
| PDPL-Art9 | Right to withdraw consent |
Governance
| Code | Title |
|---|---|
| PDPL-Art35 | Data Protection Officer (DPO) appointment |
| PDPL-Art40 | Joint controllers |
| PDPL-Art58 | Personal Data Protection Authority (Lembaga PDP) |
Lawful basis
| Code | Title |
|---|---|
| PDPL-Art20 | Lawful basis for processing |
Localization
| Code | Title |
|---|---|
| PDPL-Art57 | Data localization for strategic data (sector-specific) |
Penalties
| Code | Title |
|---|---|
| PDPL-Art57Admin | Administrative sanctions up to 2% of annual revenue |
| PDPL-Art65 | Criminal offenses: unlawful obtaining or disclosing of personal data |
| PDPL-Art66 | Criminal offenses: falsifying personal data |
| PDPL-Art67 | Criminal offenses: corporate liability and additional sanctions |
Processing principles
| Code | Title |
|---|---|
| PDPL-Art16 | Principles of personal data processing |
Programme
| Code | Title |
|---|---|
| PDPL-TransOct2024 | Transition period and full enforcement |
Retention
| Code | Title |
|---|---|
| PDPL-Art48 | Retention and destruction of personal data |
| PDPL-Art50 | Personal data destruction procedures |
Scope
| Code | Title |
|---|---|
| PDPL-Art1 | Definitions and scope of personal data |
Security
| Code | Title |
|---|---|
| PDPL-Art27 | Anonymization and pseudonymization |
| PDPL-Art29 | Confidentiality and security of personal data |
| PDPL-Art45 | Personal data breach prevention measures |
Transparency
| Code | Title |
|---|---|
| PDPL-Art21 | Information to be provided before consent or processing |
Vendor management
| Code | Title |
|---|---|
| PDPL-Art39 | Processor obligations and controller-processor contracts |
Vulnerable subjects
| Code | Title |
|---|---|
| PDPL-Art26 | Processing of personal data of persons with disabilities |
Frequently Asked Questions
What is Indonesia PDPL?
Indonesia PDPL is a compliance framework from Indonesia with 22 domains and 39 controls. Indonesia Personal Data Protection Law (Law No. 27 of 2022, full enforcement Oct 2024). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Indonesia PDPL have?
Indonesia PDPL has 39 controls organised across 22 domains. The largest domains are Data subject rights (9 controls), Penalties (4 controls), Governance (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Indonesia PDPL map to?
Indonesia PDPL does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with Indonesia PDPL compliance?
Start your Indonesia PDPL compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Indonesia PDPL requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required