Indonesia Personal Data Protection Law Compliance: What Your Company Needs Before 16 January 2027

Indonesia personal data protection law compliance comes down to seven duties, and all of them already apply: have a lawful basis before you collect anything, say what it is for, record every processing activity, secure the data, answer requests from the people it belongs to, report a breach within 3x24 hours, and appoint a data protection officer once scale demands one. What changed this year is the detail: Government Regulation No. 33 of 2026 takes effect on 16 January 2027, and fines run up to 2 percent of annual revenue.
Everything below was checked against the official text of Law No. 27 of 2022 and Government Regulation No. 33 of 2026 on 24 September 2026. Rules like these move, so if you read this much later, check the source.
Your company is almost certainly in scope
The law uses two terms. A Personal Data Controller decides what is collected and why — that is you. A Processor handles it on your instructions: system vendor, payroll provider, courier. Article 51 makes a processor’s work the controller’s responsibility. Handing the database to a vendor does not hand over the risk.
There is no small-business carve-out. A distributor in Candi keeping 800 customer numbers on a salesperson’s personal handset, a clinic in Surabaya stacking photocopied ID cards in a drawer — both are controllers. Company size affects how deep compliance goes, not whether the duty applies.
The seven duties under Indonesia’s personal data protection law
The third column is the one companies keep missing. A regulator assesses not intent but what you can put on the table.
Seven core duties and the evidence you must produce
| Duty | Basis in the law | Evidence you need |
|---|---|---|
| Have a lawful basis for processing | Article 20 — consent, contract, legal obligation, vital interests, public task, legitimate interest | A written note of why each data group was collected |
| Inform people before asking consent | Article 21 — purpose, data types, retention period, processing period, the person’s rights | A privacy policy anyone can open |
| Record all processing activity | Article 31 | A data inventory: what, from where, stored where, who opens it |
| Assess impact for high-risk processing | Article 34 — large scale, specific data, scoring, new technology | An assessment written before go-live |
| Secure the data you process | Article 35 | Access limits, encryption, logs, proof it was tested |
| Serve data subject rights | Articles 5 to 13 — access, correction, erasure, withdrawal, objection | A request workflow; PP 33/2026 sets a 3x24-hour limit |
| Report a protection failure | Article 46 — 3x24 hours to the person and the supervisory body | A written procedure, contact list, and notification template |
Article numbers refer to Law No. 27 of 2022; technical detail sits in Government Regulation No. 33 of 2026. Checked 24 September 2026.
Two of those are usually empty, and the cheapest to fix. Plenty of companies bolt a privacy policy onto the website without inventorying the data first. And plenty assume consent is the only valid basis. It is not. Payroll data rests on the employment contract, not a ticked box — asking consent where the law already obliges you weakens your position.
Data the law treats more strictly
Article 4 splits personal data into general and specific. The specific category covers:
- health data, including clinic records
- biometric data, including attendance-machine fingerprints
- genetic data
- criminal records
- children’s data
- personal financial data, including cooperative loan records
Processing that at large scale triggers two more duties: the impact assessment in Article 34 and the data protection officer in Article 53.
Two separate tracks of penalty
Administrative penalties sit in Article 57: written warning, suspension of processing, erasure of data, fines of up to 2 percent of annual revenue. For a company turning over Rp40 billion, that ceiling is Rp800 million.
Criminal exposure is sharper. Unlawfully collecting someone else’s personal data carries up to 5 years and Rp5 billion; falsifying it, up to 6 years and Rp6 billion. A company itself can only be fined, but Article 70 allows ten times the maximum.
What is realistic in the next 30 days
This need not be a project. Almost all of it is in-house work, and the first four steps cost nothing.
- Build the data inventory. One spreadsheet: what data, from where, stored where, who opens it, when it gets deleted. For a single-site business, one day.
- Assign a lawful basis to each row. One extra column: contract, legal obligation, legitimate interest, consent.
- Clean up access. Revoke accounts of leavers, stop copies of the customer database living on personal phones, kill open sharing links.
- Write a privacy policy that matches the inventory, then put it somewhere findable. If the site is neglected and nobody can edit it in-house, that is a job for a web development team, not for legal.
- Prepare a breach procedure. One page: who gets called first, who writes the notification, what it says. Writing it calmly costs far less than in a panic.
- Test it once instead of assuming. Can an intern account open the HR folder? If nobody internally has time, this is the part that most sensibly goes outside, as a regular cybersecurity review.
In our experience the gap at mid-sized companies is not encryption or expensive hardware — it is that inventory. Without it the other six duties are guesswork.
One trade-off is worth stating plainly: a consent form at every touchpoint can work against you. Consent collected under pressure — you cannot proceed unless you tick — is hard to call freely given, so you end up with no valid basis.
Initial mapping needs no vendor. But for a second opinion on what stays in-house, one session with an IT consultant in Sidoarjo usually settles the biggest question.
Does a 10-person company in Indonesia really have to comply?+
When is a data protection officer mandatory?+
What about customer data collected years ago?+
IT consultants helping Indonesian businesses choose and manage cloud infrastructure, develop software, and keep IT operations running smoothly. Based in Sidoarjo, serving clients across East Java and Indonesia.
Related Articles

Office Network Installation Cost in Indonesia: Per-Point Rates, Hardware, and a Worked Example
Office network installation cost in Indonesia: Rp150–250k per point for labour, a worked 20-point build at Rp25 million, plus charges that land later.

How to Register as a Supplier on e-Katalog v6: Three Stages and the Documents You Need
How to register as a supplier on e-Katalog, Indonesia's government procurement catalogue: the three INAPROC stages, documents, and verification times.

How to Digitize a Small Business in Indonesia, Starting From Zero
How to digitize a small business in Indonesia without an expensive app: six steps in order, what each one costs in rupiah, and when custom software pays.