Indonesia’s Personal Data Protection Law No. 27 of 2022 takes full effect today, following a two-year transition period since its enactment in October 2022.
Key points
- Security measures are required.
- A DPO is required for large-scale or sensitive processing.
- Breaches must be notified within 3 × 24 hours.
- Fines of up to 2% of annual revenue and criminal sanctions apply.
The law applies extraterritorially, so UK organisations processing Indonesian citizens’ data, including through offshore service providers, should review their compliance and breach procedures.
Source: Law No. 27 of 2022 on Personal Data Protection (JDIH BPK)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.