Indonesia
Tier 3 Comprehensive law Asia-PacificPrincipal framework: PDP Law 27/2022 (2022). Regulator: Supervisory agency pending. PDP Law 27/2022’s grace period ended Oct 2024, but the implementing regulation and supervisory agency are still pending — enforcement remains transitional.
At a glance
- Principal law
- Law No. 27 of 2022 on Personal Data Protection
- Regulator
- No dedicated authority
- Breach notification
- 3×24 hours (72 hours) written notice to subjects and the institution
- Maximum penalty
- Administrative fines up to 2% of annual revenue; criminal fines to IDR 6bn
- DPO required
- Required for public services, large-scale monitoring or sensitive data
- Digital consent age
- Parental consent for children
- Extraterritorial reach
- Yes — effects on Indonesian data subjects
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- ID
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
Instruments
No instrument profiled yet.
Sources
- Regulator No dedicated authority
Never independently verified — seeded from the prototype.