Keamanan & Data

Indonesia Personal Data Protection Law Compliance: What Your Company Needs Before 16 January 2027

TAB
Tim Editorial TAB
··4 min read
Stacks of paper files and customer records on an office desk, illustrating Indonesia personal data protection law compliance and the duty to map and secure personal data

Indonesia personal data protection law compliance comes down to seven duties, and all of them already apply: have a lawful basis before you collect anything, say what it is for, record every processing activity, secure the data, answer requests from the people it belongs to, report a breach within 3x24 hours, and appoint a data protection officer once scale demands one. What changed this year is the detail: Government Regulation No. 33 of 2026 takes effect on 16 January 2027, and fines run up to 2 percent of annual revenue.

Everything below was checked against the official text of Law No. 27 of 2022 and Government Regulation No. 33 of 2026 on 24 September 2026. Rules like these move, so if you read this much later, check the source.

Your company is almost certainly in scope

The law uses two terms. A Personal Data Controller decides what is collected and why — that is you. A Processor handles it on your instructions: system vendor, payroll provider, courier. Article 51 makes a processor’s work the controller’s responsibility. Handing the database to a vendor does not hand over the risk.

There is no small-business carve-out. A distributor in Candi keeping 800 customer numbers on a salesperson’s personal handset, a clinic in Surabaya stacking photocopied ID cards in a drawer — both are controllers. Company size affects how deep compliance goes, not whether the duty applies.

The seven duties under Indonesia’s personal data protection law

The third column is the one companies keep missing. A regulator assesses not intent but what you can put on the table.

Seven core duties and the evidence you must produce

DutyBasis in the lawEvidence you need
Have a lawful basis for processingArticle 20 — consent, contract, legal obligation, vital interests, public task, legitimate interestA written note of why each data group was collected
Inform people before asking consentArticle 21 — purpose, data types, retention period, processing period, the person’s rightsA privacy policy anyone can open
Record all processing activityArticle 31A data inventory: what, from where, stored where, who opens it
Assess impact for high-risk processingArticle 34 — large scale, specific data, scoring, new technologyAn assessment written before go-live
Secure the data you processArticle 35Access limits, encryption, logs, proof it was tested
Serve data subject rightsArticles 5 to 13 — access, correction, erasure, withdrawal, objectionA request workflow; PP 33/2026 sets a 3x24-hour limit
Report a protection failureArticle 46 — 3x24 hours to the person and the supervisory bodyA written procedure, contact list, and notification template

Article numbers refer to Law No. 27 of 2022; technical detail sits in Government Regulation No. 33 of 2026. Checked 24 September 2026.

Two of those are usually empty, and the cheapest to fix. Plenty of companies bolt a privacy policy onto the website without inventorying the data first. And plenty assume consent is the only valid basis. It is not. Payroll data rests on the employment contract, not a ticked box — asking consent where the law already obliges you weakens your position.

Data the law treats more strictly

Article 4 splits personal data into general and specific. The specific category covers:

  • health data, including clinic records
  • biometric data, including attendance-machine fingerprints
  • genetic data
  • criminal records
  • children’s data
  • personal financial data, including cooperative loan records

Processing that at large scale triggers two more duties: the impact assessment in Article 34 and the data protection officer in Article 53.

The 3x24-hour clock is literal
If data leaks, Article 46 requires written notice within 3x24 hours to the people affected and to the supervisory body: what was exposed, when and how, and what you are doing. As of September 2026 the Personal Data Protection Authority still does not exist, and Komdigi supervises in the interim. That is no reason to wait — the duty to tell the people whose data it is runs regardless, and a record showing you told them on time is the best defence you can prepare now.

Two separate tracks of penalty

Administrative penalties sit in Article 57: written warning, suspension of processing, erasure of data, fines of up to 2 percent of annual revenue. For a company turning over Rp40 billion, that ceiling is Rp800 million.

Criminal exposure is sharper. Unlawfully collecting someone else’s personal data carries up to 5 years and Rp5 billion; falsifying it, up to 6 years and Rp6 billion. A company itself can only be fined, but Article 70 allows ten times the maximum.

What is realistic in the next 30 days

This need not be a project. Almost all of it is in-house work, and the first four steps cost nothing.

  1. Build the data inventory. One spreadsheet: what data, from where, stored where, who opens it, when it gets deleted. For a single-site business, one day.
  2. Assign a lawful basis to each row. One extra column: contract, legal obligation, legitimate interest, consent.
  3. Clean up access. Revoke accounts of leavers, stop copies of the customer database living on personal phones, kill open sharing links.
  4. Write a privacy policy that matches the inventory, then put it somewhere findable. If the site is neglected and nobody can edit it in-house, that is a job for a web development team, not for legal.
  5. Prepare a breach procedure. One page: who gets called first, who writes the notification, what it says. Writing it calmly costs far less than in a panic.
  6. Test it once instead of assuming. Can an intern account open the HR folder? If nobody internally has time, this is the part that most sensibly goes outside, as a regular cybersecurity review.

In our experience the gap at mid-sized companies is not encryption or expensive hardware — it is that inventory. Without it the other six duties are guesswork.

One trade-off is worth stating plainly: a consent form at every touchpoint can work against you. Consent collected under pressure — you cannot proceed unless you tick — is hard to call freely given, so you end up with no valid basis.

Initial mapping needs no vendor. But for a second opinion on what stays in-house, one session with an IT consultant in Sidoarjo usually settles the biggest question.

Does a 10-person company in Indonesia really have to comply?+
Yes. Law No. 27 of 2022 has no exemption for micro or small enterprises. Only depth differs: a ten-person company needs no full-time data protection officer, but must know what data it holds, on what basis, and who opens it.
When is a data protection officer mandatory?+
Article 53 names three situations: processing data for public services; core activities requiring regular, systematic monitoring of personal data at large scale; or large-scale processing of specific data or criminal-offence data. The officer may come from outside, so this need not mean a hire.
What about customer data collected years ago?+
The two-year adjustment window in Article 74 closed on 17 October 2024, so legacy data is already held to the same standard. In practice: assign a lawful basis to each legacy set, delete what has no basis and is unused, stop keeping ID photocopies you never needed.
TAB
Tim Editorial TAB - CV Trengginas Alfath Berkarya

IT consultants helping Indonesian businesses choose and manage cloud infrastructure, develop software, and keep IT operations running smoothly. Based in Sidoarjo, serving clients across East Java and Indonesia.