Data Protection Atlas

Indonesia

Tier 3 Comprehensive law Asia-Pacific

Principal framework: PDP Law 27/2022 (2022). Regulator: Supervisory agency pending. PDP Law 27/2022’s grace period ended Oct 2024, but the implementing regulation and supervisory agency are still pending — enforcement remains transitional.

At a glance

Principal law
Law No. 27 of 2022 on Personal Data Protection
Regulator
No dedicated authority
Breach notification
3×24 hours (72 hours) written notice to subjects and the institution
Maximum penalty
Administrative fines up to 2% of annual revenue; criminal fines to IDR 6bn
DPO required
Required for public services, large-scale monitoring or sensitive data
Digital consent age
Parental consent for children
Extraterritorial reach
Yes — effects on Indonesian data subjects

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
ID

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

Never independently verified — seeded from the prototype.