Indonesia's PDP Law vs GDPR: What's Actually In Force (2026)

Indonesia's Undang-Undang Pelindungan Data Pribadi (UU PDP, Law No. 27 of 2022) is often described as "not yet in force" or "still years away." That description is wrong, and getting it wrong matters. The two-year transition period built into the Law ended on October 17, 2024. Every substantive obligation in UU PDP, the lawful-basis requirement, the rights catalog, the 72-hour breach-notice duty, the cross-border transfer rules, and both the administrative and criminal penalty provisions, is binding law today, not a future date on a roadmap.
What is missing is not the law itself but the machinery meant to run it. Indonesia has not yet established the independent supervisory authority (Badan Pelindungan Data Pribadi, or Badan PDP) that the Law itself requires, and has not yet issued the implementing government regulation (Peraturan Pemerintah, or PP) that several of the Law's own provisions explicitly defer to. This article works through what that gap actually means, article by article, against the EU's General Data Protection Regulation (GDPR), and closes with the one enforcement path that is not blocked by the missing institution: Indonesia's criminal provisions.
Jurisdiction scope: This article compares the EU's General Data Protection Regulation (GDPR) with Indonesia's Law No. 27 of 2022 on Personal Data Protection (UU PDP), as enacted and currently in force, including its still-pending implementing regulation and supervisory authority. It does not cover Indonesia's separate cybersecurity, electronic-information (ITE), or sector-specific financial-data rules except where they intersect directly with UU PDP. For the full Indonesia privacy picture, see our Indonesia data privacy laws guide.
What Is In Force, and What Is Not
This is the section to read first, because the rest of the comparison only makes sense once this distinction is clear. UU PDP is not a law waiting to take effect. It is a fully enforceable statute with an unbuilt enforcement apparatus sitting on top of it.
What is fully in force today:
- The legal-basis requirement (Pasal 20)
- The data subject rights catalog (Pasal 5-15)
- The sensitive/general data classification (Pasal 4)
- The 72-hour breach notification duty (Pasal 46)
- The cross-border transfer cascade (Pasal 56), at least its contractual-safeguard and consent steps
- The administrative sanction exposure (Pasal 57)
- The criminal provisions (Pasal 67-70) and corporate liability (Pasal 70)
What has not been established:
- Badan PDP, the independent supervisory authority. Pasal 58 requires that the institution ("lembaga") administering the Law be established by the President and be responsible to the President, with further detail set out in a Peraturan Presiden (Perpres). That Perpres has not been issued. The President granted izin prakarsa (initiative approval) to begin drafting it on March 4, 2025; the draft moved through inter-ministerial review from March to September 2025 and has been in Ministry of Law harmonization since October 2025. Komdigi restated a 2026 completion target as of February 4, 2026.
- The implementing Peraturan Pemerintah (PP). UU PDP defers critical operational detail to this regulation at multiple specific points: the final clause of Pasal 56 assigns cross-border transfer procedure to it, and Pasal 57(5) assigns administrative-sanction procedure to it. Neither has been issued. A draft (RPP) reportedly finished its own harmonization process, worked through roughly 1,989 public comments, and was reported sitting at the State Secretariat awaiting presidential signature as of reporting from October 2025. As of this review (July 2026), there is no primary confirmation it has since been signed.
- An adequacy list. Because there is no PP and no Badan PDP, there is no published determination of which countries meet Pasal 56(2)'s "equivalent or higher protection" standard.
- A confirmed Pasal 57 administrative sanction. The sanctioning body Pasal 57(4) assigns this power to is the same not-yet-established institution from Pasal 58; no sanction has been confirmed as issued.
In the interim, Komdigi, the ministry that absorbed PDP oversight when it was restructured from Kominfo in November 2024, handles oversight and complaint intake ad interim, but it is not the independent authority the Law itself calls for.
The precise way to describe this: Indonesia has a GDPR-shaped statute that is fully enforceable text sitting on top of missing enforcement infrastructure. It is not a law that has yet to take effect.

Background and Legislative Context
UU PDP, formally Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi, was enacted and promulgated on October 17, 2022, after years of legislative drafting. It built in a two-year transition period for controllers and processors to reach compliance, which ended October 17, 2024.
The GDPR, adopted in 2016, similarly carried a two-year transition before becoming directly applicable across the EEA on a single date, May 25, 2018. The structural parallel stops there: GDPR's transition ended with a functioning regulator network already in place in every member state. UU PDP's transition ended with the Law binding but its designated regulator not yet built, a genuinely different starting position for enforcement than GDPR had at its own commencement.
Oversight in the interim sits with Komdigi, Kementerian Komunikasi dan Digital, the ministry that replaced Kementerian Komunikasi dan Informatika (Kominfo) under a November 2024 restructuring (Perpres 174/2024), which also created a Ditjen Pengawasan Ruang Digital (Directorate General for Digital Space Oversight) with PDP-related duties.

Scope
UU PDP applies to the processing of personal data by any person, public body, international organization, or corporation, whether located within Indonesia or outside it, where the processing has legal effect within Indonesia or on an Indonesian citizen abroad, an extraterritorial reach broadly similar in spirit to GDPR Article 3's own extraterritorial trigger for organizations targeting individuals in the EEA. For the complete breakdown of what UU PDP covers, see our Indonesia data privacy laws guide.

At a Glance
| Feature | GDPR | Indonesia UU PDP |
|---|---|---|
| Substantive law in force | Yes, since May 25, 2018 | Yes, since October 17, 2024 (transition ended) |
| Supervisory authority | National DPAs + EDPB, operating since 2018 | Badan PDP not yet established; Komdigi handles oversight ad interim |
| Implementing regulation | Directly applicable, no national implementing law required | Peraturan Pemerintah (PP) required by Pasal 56 and Pasal 57(5); not yet issued |
| Adequacy / cross-border list | Published adequacy decisions under Article 45 | None published; the mechanism is deferred to the still-unissued PP |
| Lawful bases | Six under Article 6, including legitimate interests | Six under Pasal 20(2), including a legitimate-interests-style basis (Pasal 20(2)(f)) |
| Data subject rights | Access, rectification, erasure, restriction, portability, objection to automated decisions, and more (Arts. 15-22) | A materially similar list under Pasal 5-15, including portability (Pasal 13) and automated-decision objection (Pasal 10) |
| Sensitive data includes financial data | No (Article 9 excludes it) | Yes (Pasal 4(2)) |
| Sensitive data includes religion | Yes (Article 9) | No, religion sits in the general category (Pasal 4(3)) |
| Breach notification deadline | 72 hours to the regulator; "without undue delay" to individuals | 72 hours (3x24 hours) to both the regulator and the individual, same clock |
| Maximum administrative fine | EUR 20 million or 4% of global annual turnover, two-tier | 2% of annual revenue/receipts, single flat tier (Pasal 57(3)) |
| Criminal penalties | None at the EU level (Article 84 leaves it to member states) | Yes, directly in the statute: up to 5-6 years imprisonment and Rp4-6 billion in fines (Pasal 67-68) |
| Corporate criminal fine cap | Not applicable | Up to 10x the individual maximum: Rp50-60 billion (Pasal 70(3)) |
| Confirmed enforcement to date | Billions of euros in fines since 2018 | None confirmed under either the administrative or criminal track |

Definitions and Sensitive Data: Where Indonesia Diverges from GDPR
UU PDP splits personal data into two categories under Pasal 4: data pribadi yang bersifat spesifik (specific/sensitive personal data) and data pribadi yang bersifat umum (general personal data).
The specific/sensitive category (Pasal 4(2)) covers health data and information, biometric data, genetic data, criminal records, children's data, personal financial data, and any other data further regulation designates. The general category (Pasal 4(3)) covers full name, sex, nationality, religion, marital status, and any personal data combined to identify a person.
On its face, this is a GDPR-shaped design, a bounded list of categories triggering elevated protection, similar in structure to GDPR Article 9's special-category list. In substance, the two lists diverge in ways worth flagging directly:
| Category | GDPR Article 9 | UU PDP Pasal 4 |
|---|---|---|
| Financial data | Not a special category (regulated elsewhere, e.g. PSD2, PCI DSS) | Sensitive (Pasal 4(2)) |
| Criminal records | Handled separately under Article 10, not Article 9 | Sensitive, inside the same specific-data list (Pasal 4(2)) |
| Children's data | No standalone special category; protected via consent-age rules (Article 8) | Its own listed sensitive category (Pasal 4(2)) |
| Religion | Special category | General category (Pasal 4(3)), the opposite of GDPR |
| Race/ethnicity, political opinions, trade union membership, sex life/orientation | Special categories | No Pasal 4(2) counterpart at all |
The practical read: Indonesia's sensitive-data list protects what its own policymakers judged most locally sensitive, finance, criminal history, and children, rather than reproducing the EU's list, which is built around discrimination-risk categories like race, religion, political opinion, and sexuality. A compliance program built only around GDPR's Article 9 list will both over-protect a category UU PDP treats as ordinary (religion) and under-protect a category UU PDP treats as sensitive that GDPR does not (financial data).
Legal Bases: Pasal 20 vs GDPR Article 6
Pasal 20(1) requires every controller to have a lawful basis for processing personal data. Pasal 20(2) then lists six bases that map onto GDPR Article 6(1) almost one to one:
| Pasal 20(2) | GDPR Art. 6(1) |
|---|---|
| (a) Explicit consent for one or more specified purposes disclosed to the subject | (a) Consent |
| (b) Contract performance, or pre-contract steps at the subject's request | (b) Contract |
| (c) Legal obligation | (c) Legal obligation |
| (d) Protection of the subject's vital interests | (d) Vital interests |
| (e) Public interest, public service, or the controller's official authority | (e) Public task |
| (f) Other legitimate interests, weighed against purpose, necessity, and the balance of interests between controller and subject | (f) Legitimate interests |
Pasal 20(2)(f) deserves particular attention because it is a genuine correspondence rather than a coincidence of translation. Its text explicitly imports a balancing-test standard, weighing the controller's purpose and need against the subject's interests, the same substantive test Article 6(1)(f) applies in practice even though GDPR's own text states it more tersely. Indonesia does have a legitimate-interests basis, contrary to how the law is sometimes described.
Data Subject Rights: Pasal 5-15
UU PDP's rights catalog runs from Pasal 5 through Pasal 15, and it tracks GDPR closely, including two rights sometimes wrongly assumed to be missing from non-EU privacy laws.
| Pasal | Right | GDPR equivalent |
|---|---|---|
| 5 | Information on identity, legal basis, and purpose of processing | Articles 13-14 (transparency) |
| 6 | Complete, update, or correct inaccurate data | Article 16 (rectification) |
| 7 | Access and obtain a copy of one's own data | Article 15 (access) |
| 8 | End processing and delete/destroy one's own data | Article 17 (erasure) |
| 9 | Withdraw previously given consent | Article 7(3) |
| 10 | Object to a decision based solely on automated processing (including profiling) with legal or significant effect | Article 22 (automated decision-making) |
| 11 | Delay or restrict processing proportionate to its purpose | Article 18 (restriction) |
| 12 | Sue for and receive compensation for a processing violation | Articles 79/82 (judicial remedy and compensation) |
| 13 | Obtain data in a structured, commonly-used, machine-readable format, and transmit it to another controller where systems can interoperate securely | Article 20 (portability) |
| 14 | Exercise the Pasal 6-11 rights via a recorded request, electronic or otherwise | Procedural, no single GDPR analogue |
| 15 | Statutory exceptions to specific rights | Article 23 (restrictions) |
Both data portability (Pasal 13) and the right to object to automated decision-making (Pasal 10) are present and substantively scoped close to their GDPR counterparts. Pasal 13 reads almost like a direct translation of Article 20, and Pasal 10 is explicitly limited to profiling and automated decisions with legal or significant effect, mirroring Article 22 rather than functioning as a generic objection right. There is no separately numbered general right to object to processing comparable to GDPR Article 21; Pasal 10 covers only the automated-decision variant.
Pasal 15 carves out exceptions, but narrowly and precisely. They apply only to Pasal 8 (erasure), Pasal 9 (consent withdrawal), Pasal 10(1) (object to automated decisions), Pasal 11 (restriction), and Pasal 13(1)-(2) (portability), for national defense and security, law enforcement, public administration, financial-sector/monetary/payment-system supervision, and statistics/scientific research. They do not reach Pasal 5 (transparency), Pasal 6 (rectification), Pasal 7 (access), or Pasal 12 (compensation), which carry no statutory exception.
Breach Notification: Pasal 46
Pasal 46(1) requires a controller to notify a personal data protection failure in writing no later than 3x24 hours (72 hours) to both the data subject and the "lembaga" (currently Komdigi, ad interim). Pasal 46(2) requires the notice to state what data was exposed, when and how it was exposed, and what remediation steps the controller has taken. Pasal 46(3) requires public notification in certain circumstances.
This is a structurally different design from GDPR, which runs two separate clocks: a hard 72-hour deadline to the supervisory authority under Article 33, and a "without undue delay" standard, not a fixed number, for notifying affected individuals under Article 34 (triggered only where the breach poses a high risk to the individual). UU PDP instead runs a single 72-hour clock to both recipients at the same time, with no separate, softer standard for the individual leg. Indonesia and the Philippines are unusual in this respect among APAC jurisdictions, most of which follow GDPR's pattern of a single hard regulator clock paired with a separate or no individual-notice clock. For how Indonesia's timeline compares against the rest of the world, see our data breach notification deadlines by country guide.
Pasal 46 sets no numeric severity or headcount threshold; the trigger is simply "kegagalan Pelindungan Data Pribadi" (a personal data protection failure), whatever its scale.
Cross-Border Data Transfers: Pasal 56 and the Missing Regulation
Pasal 56 sets out a four-step cascade for transferring personal data outside Indonesia, and it maps closely onto GDPR's Chapter V structure:
- Pasal 56(2): the controller must ensure the receiving country has a level of personal data protection "equivalent to or higher than" UU PDP itself, similar to a GDPR Article 45 adequacy decision.
- Pasal 56(3): if step (2) is not met, the controller must ensure adequate and binding protection exists, similar to GDPR Article 46's appropriate safeguards, such as Standard Contractual Clauses or Binding Corporate Rules.
- Pasal 56(4): if neither (2) nor (3) is met, the controller must obtain the data subject's consent, functioning the same way GDPR Article 49's consent derogation does, as a last resort rather than a primary basis.
- Pasal 56's final clause defers further provisions on transfer procedure to a Peraturan Pemerintah.
The structural match to GDPR is genuinely close. What breaks down is the mechanism that would make step (2) usable: nobody has been designated to assess and publish which countries meet the "equivalent or higher" standard, because that assessment procedure is exactly what the still-unissued PP was supposed to define. No adequacy list exists. In practice, this pushes controllers transferring data out of Indonesia toward step (3) contractual safeguards or step (4) consent, even though the Law's own cascade nominally starts at step (2). It is a direct, concrete instance of the text-versus-machinery gap this whole comparison turns on, not just an abstract point about the missing Badan PDP.
Penalties: Administrative Sanctions vs Criminal Prosecution
This is where UU PDP diverges from GDPR most sharply, and it is the page's most useful practitioner takeaway: Indonesia is not toothless. Its teeth are criminal, not administrative.
Administrative sanctions (Pasal 57)
Pasal 57(1) lists specific violations subject to administrative sanction, including breach of the legal-basis requirement (Pasal 20(1)), the breach-notification duty (Pasal 46(1) and (3)), and the cross-border cascade (Pasal 56(2)-(4)). Pasal 57(2) sets out four escalating sanction types: written warning, temporary suspension of processing activity, deletion or destruction of the data, and an administrative fine. Pasal 57(3) caps the fine at 2% of annual revenue or annual receipts relative to the violation.
That single flat 2% ceiling is structurally similar to GDPR's percentage-of-turnover concept under Article 83, but simpler: GDPR splits violations into a lower tier (2% of global turnover or EUR 10 million) and a higher tier (4% of global turnover or EUR 20 million), while UU PDP applies one flat rate with no two-tier split. In magnitude, Indonesia's cap sits closer to GDPR's lower tier than its headline 4% figure.
Both the body empowered to impose these sanctions (Pasal 57(4), the "lembaga") and the procedural detail for imposing them (Pasal 57(5)) are assigned to the missing PP and the not-yet-established Badan PDP. No Pasal 57 sanction has been confirmed as issued.
Criminal provisions (Pasal 67-70)
GDPR has no criminal penalty regime of its own. Article 84 leaves criminal sanctions entirely to individual EU member states' discretion, and the Regulation itself imposes none. UU PDP does, directly, in the statute:
| Provision | Conduct | Maximum penalty |
|---|---|---|
| Pasal 67(1) | Unlawful, intentional acquisition or collection of another's personal data, for one's own or another's benefit, causing harm to the subject | Up to 5 years imprisonment and/or a fine up to Rp5,000,000,000 |
| Pasal 67(2) | Unlawful, intentional disclosure of another's personal data | Up to 4 years imprisonment and/or a fine up to Rp4,000,000,000 |
| Pasal 67(3) | Unlawful, intentional use of another's personal data | Up to 5 years imprisonment and/or a fine up to Rp5,000,000,000 |
| Pasal 68 | Intentionally fabricating or falsifying personal data for one's own or another's benefit, causing harm | Up to 6 years imprisonment and/or a fine up to Rp6,000,000,000 |
| Pasal 69 | Additional penalty on top of a Pasal 67/68 sentence | Confiscation of profits and/or assets obtained from the crime |
At an approximate mid-2025/2026 exchange rate of roughly Rp15,600-15,900 per US dollar, Rp5 billion is in the neighborhood of USD 320,000 and Rp6 billion roughly USD 385,000; treat any USD figure here as a dated, approximate conversion, not a fixed equivalence.
The critical distinction for compliance planning: these provisions target intentional misuse by a bad actor, unlawful acquisition, disclosure, use, or falsification of someone else's data, not mere non-compliance by a controller. A controller that mishandles data through negligence faces the administrative track (Pasal 57); someone who deliberately misuses another person's data faces prosecution through Indonesia's ordinary criminal courts, running alongside, not instead of, the administrative exposure.
And critically, the criminal track does not depend on the missing Badan PDP. It runs through the ordinary courts, not the still-unbuilt regulator, making it the one enforcement path UU PDP creates that is not blocked by the institutional gap described above. No confirmed prosecution under Pasal 67-70 has been identified as of this review; this point concerns the track's legal availability, not a track record.
Corporate Liability: Pasal 70
Pasal 70 extends the Pasal 67 and 68 criminal provisions to corporations. Punishment may fall on the corporation's management, controlling parties, those who ordered the act, beneficial owners, and/or the corporation itself (Pasal 70(1)). A corporation itself can only be fined, not imprisoned, for obvious reasons (Pasal 70(2)).
The fine ceiling for a corporation is up to 10 times the maximum fine otherwise threatened under Pasal 67 or 68 (Pasal 70(3)): Rp50 billion (10x Rp5 billion, for Pasal 67(1)/(3) conduct) or Rp60 billion (10x Rp6 billion, for Pasal 68 conduct), roughly USD 3.2-3.9 million at the approximate exchange rate above. Pasal 70(4) allows additional penalties beyond the fine, including confiscation of profits or assets, freezing all or part of the corporation's business, permanent prohibition from certain acts, closure of all or part of its business premises, and fulfilling any neglected obligation.
That produces a genuinely interesting asymmetry: for any company with roughly under USD 160-195 million in annual revenue, the criminal corporate-fine ceiling can exceed what a 2%-of-revenue administrative fine under Pasal 57 would produce. For most companies operating in Indonesia, criminal exposure is not the secondary risk behind administrative fines; it can be the larger one.
Recent Developments
October 17, 2024. UU PDP's two-year transition period ended; every substantive obligation became fully binding.
November 5, 2024. Perpres 174/2024 restructured the overseeing ministry, renaming Kominfo to Komdigi and creating a new Ditjen Pengawasan Ruang Digital with PDP-related duties.
March-September 2025. The President granted izin prakarsa (initiative approval) on March 4 to begin drafting the Badan PDP Perpres, which then moved through inter-ministerial review.
Since October 2025. The draft Perpres has been in Ministry of Law harmonization. Separately, a draft implementing PP (RPP) reportedly finished harmonization and roughly 1,989 rounds of public comment, and was reported sitting at the State Secretariat (Setneg) awaiting presidential signature as of that same period.
February 4, 2026. Komdigi publicly restated a target of completing Badan PDP in 2026, confirming the authority remained unestablished as of that date.
As of this review (July 2026). No primary source confirms either the Badan PDP Perpres or the implementing PP has since been signed. Treat both as still pending, not issued, absent a specific dated primary confirmation.
Dual-Compliance Guidance
Organizations subject to both frameworks face a compliance posture with no GDPR precedent: a statute that is fully binding on paper, but whose enforcement infrastructure, and its own cross-border cascade's top step, is not yet functional.
| Issue | GDPR | UU PDP | Approach |
|---|---|---|---|
| Marketing/analytics basis | Legitimate interests or consent | Pasal 20(2)(f) is a real, usable legitimate-interests basis with the same balancing test | Document one balancing analysis for both regimes |
| Financial data | Not a special category | Sensitive (Pasal 4(2)) | Apply UU PDP's stricter handling even where GDPR does not require it |
| Religion | Special category | General, non-sensitive (Pasal 4(3)) | Keep GDPR's stricter standard globally; do not relax it for Indonesia |
| Cross-border transfer | Adequacy, SCCs, BCRs | Pasal 56(2) adequacy pathway unusable (no PP, no list); fall back to 56(3)/56(4) | Build on contractual safeguards or consent now, not a future adequacy list |
| Breach response | 72h to regulator; "without undue delay" to individuals | 72h to both, same clock | Build one 72-hour internal deadline covering both recipients for Indonesia |
| Enforcement risk | Administrative fines, established track record | Administrative exposure plus live criminal-prosecution risk for intentional misuse; no confirmed cases either way | Do not treat Indonesia as low-risk because Badan PDP is unstaffed; criminal courts still function |
| Corporate liability | Capped at EUR 20M / 4% of turnover | Criminal fines to Rp50-60 billion can exceed the 2% administrative cap | Model the criminal ceiling, not just the administrative cap |
For the EU side of this comparison, see our what is GDPR guide. For Indonesia's complete privacy picture, see our Indonesia data privacy laws guide.
Disclaimer
This article presents general legal information about Indonesia's Law No. 27 of 2022 on Personal Data Protection (UU PDP) and the EU's General Data Protection Regulation. It does not constitute legal advice. UU PDP's implementing regulation and supervisory authority are both still in process, and their status may change at any time following further government action. Organizations subject to either framework should consult a lawyer licensed in the relevant jurisdiction for advice specific to their situation. This article reflects information available as of July 23, 2026.
Authorities Cited
- Kementerian Komunikasi dan Digital (Komdigi), JDIH portal: Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (UU PDP), full article text. https://jdih.komdigi.go.id/produk_hukum/view/id/832/t/undangundang+nomor+27+tahun+2022
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 6, 8-10, 15-23, 33-35, 45-49, 83-84. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
- Hukumonline. "Menanti Disahkannya Aturan Turunan UU PDP" (Awaiting the Enactment of UU PDP's Implementing Regulations). https://www.hukumonline.com/berita/a/menanti-disahkannya-aturan-turunan-uu-pdp-lt68fae7fbe057d/
- Antara News Jatim. Komdigi statement on the Badan PDP 2026 completion target. https://jatim.antaranews.com/berita/1031282
Last updated: July 23, 2026. Indonesia's implementing regulation and supervisory authority are both in active process; readers should confirm current status against Komdigi's official notifications before relying on any date in this article for compliance purposes.
Frequently Asked Questions
Is Indonesia's UU PDP actually in force?
Yes, fully. The Law's two-year transition period ended October 17, 2024, and every substantive obligation, legal-basis requirements, rights, the 72-hour breach notice duty, cross-border rules, and both administrative and criminal penalties, is currently binding. What has not been established is the enforcement machinery: the independent supervisory authority (Badan PDP) has not been set up, and the implementing government regulation (PP) several provisions defer to has not been issued.
Does Indonesia have a data protection authority like the EU's DPAs?
Not yet, operationally. Pasal 58 requires an independent authority, Badan Pelindungan Data Pribadi (Badan PDP), established by the President via a Peraturan Presiden. That Perpres has not been issued; drafting received presidential initiative approval on March 4, 2025 and has been in Ministry of Law harmonization since October 2025, with Komdigi restating a 2026 completion target as of February 2026. Until it exists, Komdigi handles oversight and complaint intake on an interim basis.
Does UU PDP have a legitimate-interests lawful basis like GDPR?
Yes. Pasal 20(2)(f) provides a basis for 'other legitimate interests,' explicitly qualified by weighing purpose, necessity, and the balance of interests between the controller and the data subject, the same substantive test GDPR Article 6(1)(f) applies in practice. This is a genuine correspondence, not a gap some descriptions of Indonesian law suggest.
How does Indonesia's sensitive-data category differ from GDPR's special categories?
Pasal 4(2) treats financial data and criminal records as sensitive; GDPR's Article 9 excludes financial data entirely and handles criminal-conviction data separately under Article 10. Conversely, religion sits in Indonesia's general, non-sensitive category (Pasal 4(3)), the opposite of GDPR, where religious belief is textbook Article 9 data. Race, political opinion, union membership, and sexual orientation, all GDPR Article 9 categories, have no Pasal 4(2) counterpart at all.
What happens to cross-border data transfers without a functioning Badan PDP?
Pasal 56 sets out a four-step cascade similar to GDPR's Chapter V: an adequacy-style equivalence test, then contractual safeguards, then consent as a last resort. In practice, only the contractual-safeguard and consent steps work today, because the assessment procedure and adequacy list for the first step were assigned to the still-unissued implementing regulation.
Can someone be criminally prosecuted under Indonesia's data protection law?
Yes, and this is UU PDP's sharpest divergence from GDPR, which imposes no criminal penalties at the EU level at all. Pasal 67 and 68 criminalize unlawful, intentional acquisition, disclosure, use, or falsification of another person's data, carrying up to 4-6 years imprisonment and fines of Rp4-6 billion, plus confiscation of criminal proceeds under Pasal 69. Because prosecution runs through Indonesia's ordinary courts, it is not blocked by the still-unestablished Badan PDP.
What is the maximum penalty a company can face under UU PDP?
Two tracks run alongside each other. The administrative track (Pasal 57) caps fines at 2% of annual revenue or receipts. The criminal track (Pasal 70) can fine a corporation up to 10 times the individual maximum under Pasal 67 or 68, up to Rp50 billion or Rp60 billion, which can exceed the administrative cap for many companies. No confirmed sanction or prosecution under either track has been identified as of this review.
Does UU PDP give Indonesians a right to data portability?
Yes. Pasal 13 grants a right to obtain one's own data in a structured, machine-readable format and transmit it to another controller, closely mirroring GDPR Article 20. Indonesia also grants a right to object to fully automated decisions with legal or significant effect under Pasal 10, mirroring GDPR Article 22. Both rights are sometimes wrongly assumed missing from non-EU privacy laws; UU PDP has both.
Updates
Komdigi publicly restated a target of completing Badan PDP (the independent supervisory authority) in 2026, confirming the authority remains unestablished and that the ministry continues to handle oversight ad interim.
The draft Peraturan Presiden (Perpres) establishing Badan PDP entered harmonization at the Ministry of Law. Separately, the draft implementing Peraturan Pemerintah (RPP) reportedly finished its own harmonization process and roughly 1,989 rounds of public comment, and was reported sitting at the State Secretariat (Setneg) awaiting presidential signature as of that reporting.
The President granted izin prakarsa (initiative approval) to begin drafting the Perpres that will establish Badan PDP.
Perpres 174/2024 restructured the ministry overseeing UU PDP ad interim, renaming Kementerian Komunikasi dan Informatika (Kominfo) to Kementerian Komunikasi dan Digital (Komdigi), with a new Ditjen Pengawasan Ruang Digital handling PDP-related oversight duties.
UU PDP's two-year transition period ended. Every substantive obligation in the Law, legal-basis requirements, data subject rights, breach notification, cross-border transfer rules, and administrative and criminal penalties, became fully binding.
Article published. As of this review, no primary source confirms the implementing PP or the Badan PDP Perpres has been signed; both remain in process.
Sources and References
- Komdigi JDIH: Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (UU PDP), full text(jdih.komdigi.go.id).gov
- Regulation (EU) 2016/679 (GDPR) Full Text(eur-lex.europa.eu).gov
- Hukumonline: Menanti Disahkannya Aturan Turunan UU PDP(hukumonline.com)
- Antara News Jatim: Komdigi restates Badan PDP 2026 completion target(jatim.antaranews.com)