Indonesia · UU 27/2022
UU PDP 27/2022, in plain English
Indonesia's Personal Data Protection Law, what it actually requires of an automated system, and why the most consequential fact about it is which part of its enforcement machinery has never been built.
Covers: UU 27/2022, MK Putusan 151/PUU-XXII/2024, PP 33/2026Published September 26, 2026
It has been in force since 2022, not 2024
Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi was enacted and promulgated in Jakarta on 17 October 2022, recorded at LN 2022/196 and TLN 6820, running to 16 chapters and 76 articles. Pasal 76 provides that it takes effect on promulgation. Note the official spelling is Pelindungan, not the more common Perlindungan.
The date repeated across a great deal of English-language coverage, 17 October 2024, is not a commencement date. It is the end of the two-year window in Pasal 74, within which controllers and processors had to bring existing processing into conformity. The obligations were live throughout that window; what lapsed was the grace period for aligning to them.
Why that makes administrative fines unavailable
This is the point worth carrying away, and it is a structural one rather than a matter of enforcement appetite. Pasal 57(4) provides that administrative sanctions are imposed by the lembaga. If the lembaga has not been constituted, there is no body on which the statute confers the power to impose them.
Pasal 10: an objection right, not Article 22
Pasal 10 gives a data subject the right to submit an objection to a decision based solely on automated processing, including profiling, that produces legal consequences or a significant impact. Pasal 14 provides that the right is exercised by a recorded request to the controller.
Compare that with GDPR Article 22 and the differences matter. The Indonesian provision is a right to object, not a general prohibition on solely automated decisions. It carries no statutory right to human intervention, no right to an explanation, and no right to contest the outcome. And under Pasal 10(2) the procedure for exercising the right was left to the implementing regulation, which means that for the first four years of the law it was a right without a mechanism.
The elucidation defines profiling broadly enough to settle the question most lenders ask: it takes in evaluation of a person’s economic condition, reliability, behaviour and location. Automated credit scoring is profiling for these purposes.
One obligation attached to the same conduct is operable regardless of the objection procedure: Pasal 34(2)(a) makes decision-making based solely on automated processing, including profiling, a trigger for a data protection impact assessment. That duty sits on the controller directly and does not depend on any data subject raising an objection.
The financial-services carve-out, read correctly
Pasal 15(1)(d) disapplies certain data-subject rights, Pasal 10 among them, in the context of supervision of the financial services sector, and its elucidation expressly names financial technology alongside the roles of Bank Indonesia, OJK and LPS.
It is easy, and wrong, to read that as a blanket exemption for lenders. The provision is confined to penyelenggaraan negara, the conduct of state functions, and applies only in the course of implementing statutory provisions. A lender running its own commercial credit-scoring model is not conducting state supervision, and should not treat Pasal 15(1)(d) as removing Pasal 10 from its own obligations.
Lawful bases and specific personal data
Pasal 20(2) sets six lawful bases: explicit consent; performance of a contract; compliance with a legal obligation; protection of vital interests; performance of a public task, public service, or statutory authority; and other legitimate interests, which carries a balancing test.
Pasal 4 distinguishes general from spesifikpersonal data. The specific category covers health data, biometric data, genetic data, criminal records, children’s data, personal financial data, and anything else designated by legislation. The elucidation spells out that personal financial data includes deposits, savings, time deposits, and credit-card data, which places most of a lender’s core records in the heightened category.
Breach notification in 3x24 hours, to two recipients
Pasal 46(1) requires written notification within 3x24 hours to both the affected data subject and the lembaga. Two features distinguish it from the GDPR model: the obligation to notify the individual arises on the same clock as the regulator notification rather than on a separate risk threshold, and the requirement sits in the statute itself rather than in a downstream regulation.
The practical wrinkle follows from the section above: one of the two required recipients does not currently exist as a constituted body.
Sanctions, and the qualifier everyone drops
Pasal 57(2) lists the administrative sanctions: written warning, temporary suspension of processing, erasure or destruction of personal data, and an administrative fine. The fine is capped at no more than 2 per cent of annual revenue or annual receipts terhadap variabel pelanggaran, against the variable of the violation. English summaries almost universally drop that last phrase and render it as a flat 2 per cent of company revenue, which is a materially larger number than the statute describes.
On the criminal side, Pasal 65 and 66 define the prohibited conduct and Pasal 67 to 69 attach the penalties: unlawfully obtaining or collecting personal data, five years and a fine up to five billion rupiah; unlawful disclosure, four years and four billion; unlawful use, five years and five billion; falsifying personal data, six years and six billion under Pasal 68, with confiscation and compensation under Pasal 69.
PP 33/2026, the implementing regulation
The implementing regulation contemplated by the statute has been issued as Peraturan Pemerintah No. 33 Tahun 2026 on the implementing rules for UU 27/2022, recorded at LN 2026/88 and TLN 7190, running to 12 chapters and 225 articles. It takes effect six months after promulgation, in January 2027.
Two cautions on citing it. Sources differ by a day on the promulgation date, mid-July 2026, which in turn shifts the commencement date by a day; the discrepancy most likely reflects the difference between the signing and the formal promulgation, and it is better to note the ambiguity than to state a single date confidently. And at the time of writing the full text is not yet published in the national legal databases, so article-level claims about its contents, including how it operationalises the Pasal 10 objection procedure, should be treated as provisional until the official text is available.
How Nova AIS lines up against it
The obligations that actually bind an automated system here are about provenance, categorisation, and the ability to respond to a recorded request. Nova AIS puts a permission model and an immutable audit trail under the systems built on it, so which data fed a decision, and under which lawful basis it was held, is answerable from the record. Where a system touches deposits, savings, or card data, the Pasal 4 specific-data classification needs to be visible in the model itself rather than inferred later.
On Pasal 10, the pragmatic position is to build the objection pathway regardless of the enforcement gap. The right exists in the statute today, the implementing regulation lands in January 2027, and a system designed to keep a human in the decision path is outside the “solely automated” trigger in the first place.
Common questions.
- When did Indonesia's Personal Data Protection Law take effect?
- 17 October 2022, the date it was promulgated, under Pasal 76. The widely repeated date of 17 October 2024 is not the date it took effect; it is the end of the two-year conformity period in Pasal 74, during which controllers and processors had to bring existing processing into line with the law. The Act itself was never suspended during that window.
- Does Indonesia have a data protection authority?
- Not yet. The law refers only to a “lembaga,” an institution left undefined in Pasal 1, to be established by the President under Pasal 58(3) and regulated by a Peraturan Presiden under Pasal 58(5). That presidential regulation has not been issued. Interim functions sit with Komdigi, through its directorate general for digital space supervision.
- Can Indonesian regulators fine a company under UU PDP today?
- Administrative fines are structurally unavailable, because Pasal 57(4) provides that administrative sanctions are imposed by the lembaga, and the lembaga does not exist. This is a gap in the enforcement machinery, not merely a dormant regulator. The criminal provisions in Pasal 67 to 70 are unaffected and run through the ordinary criminal process.
- Does UU PDP give a right against automated decision-making like GDPR Article 22?
- It is narrower. Pasal 10 gives a data subject the right to object to a decision based solely on automated processing, including profiling, that produces legal effects or a significant impact. That is an objection right rather than a prohibition, and the law grants no accompanying right to human intervention, to an explanation, or to contest the outcome. The procedure for exercising it was deferred to the implementing regulation, so it was not operable before PP 33/2026.
- Is credit scoring covered by the profiling provision?
- Yes. The elucidation to Pasal 10 defines profiling to include evaluation of a person's economic condition, reliability, behaviour, and location. An automated credit-scoring or risk-tiering model sits squarely inside that definition.
- What is the maximum administrative fine under UU PDP?
- Pasal 57(2) sets it at no more than 2 per cent of annual revenue or annual receipts “terhadap variabel pelanggaran,” meaning against the variable of the violation rather than against total company revenue. English summaries routinely drop that qualifier and present it as a flat 2 per cent of annual revenue, which overstates it.