Many companies begin thinking seriously about personal-data protection only after something goes wrong.
A database leaks.
A laptop disappears.
A customer file is sent to the wrong recipient.
A vendor suffers a cyberattack.
Or someone asks:
“Why are you still holding my data?”
Only then do teams begin looking for privacy notices, access lists, vendor contracts, processing records and the person responsible for the response.
Indonesia is now finalising the establishment of an independent personal-data protection authority. In July, the government said the body was expected to operate outside Komdigi's organisational structure, with the final institutional arrangement to be set through a Presidential Regulation.[2]
For businesses, however, one misconception needs to be removed immediately:
data protection obligations do not begin when the new authority is established.
Law No. 27/2022 on Personal Data Protection has been in force since October 2022, and its two-year adjustment period has already expired.[1]
The more useful question is therefore not:
“When should we start preparing?”
It is:
“Could we explain today how personal data moves through our business?”
Nearly every business handles personal data
A company does not need to be a technology platform.
A small retailer may keep customer names and WhatsApp numbers.
HR holds candidate and employee information.
Buildings operate CCTV.
Marketing stores email lists.
Sales uses CRM records.
Customer service can access transaction history.
Digital businesses may also process device, location, behavioural or other information linked to identifiable people.
Indonesia's PDP Law defines personal data broadly as information about an identified or identifiable individual, whether independently or when combined with other information.[1]
Privacy is therefore not confined to IT.
It appears throughout customer journeys and employee lifecycles.
Start with a data inventory
Many organisations have security software but cannot answer a basic question:
What personal data do we actually have?
Map:
what data are collected;
from whom;
through which channel;
where they are stored;
who has access;
why they are processed;
which vendors receive them;
and when the information should be removed.
A data inventory is not merely a compliance document.
It reveals operational dependency and risk exposure.
A company cannot reliably protect information it does not know it possesses.
Consent is not the only legal basis
Privacy compliance is sometimes simplified into one sentence:
“The customer already agreed.”
Indonesia's PDP Law recognises several bases for processing. These include explicit consent for specified purposes, contractual necessity, legal obligations, vital interests, public interest and other legitimate interests as defined by the law.[1]
Businesses therefore need to understand why information is processed.
Adding more checkboxes does not solve a weak processing model.
If the company itself cannot explain the purpose, a long privacy notice will not create clarity.
Purpose limitation is an operating discipline
The law requires personal-data processing to be limited, specific, lawful and transparent, and to remain consistent with the stated purpose.[1]
That produces practical management questions.
A salesperson receives a customer's number to follow up a quotation.
Does that number automatically enter a marketing database?
HR receives a CV during recruitment.
How long is an unsuccessful candidate's file retained?
A customer provides identity documentation for one transaction.
Who still holds copies six months later?
These questions can be more important than another cybersecurity purchase.
Access control is more than a password
The PDP Law requires controllers to preserve confidentiality, prevent unauthorised access and supervise parties involved in processing under their control.[1]
Businesses should therefore examine need-to-know access.
Can every sales employee see every customer?
Do former employees retain accounts?
Can payroll spreadsheets be accessed too widely?
Are shared logins still used by several employees?
Cybersecurity and privacy meet here.
The problem is not always a sophisticated attacker.
Sometimes the problem is simply that too many people retain access they no longer need.
Vendors are part of the data architecture
Modern businesses rarely process all information internally.
They use payroll providers, cloud services, CRM systems, messaging integrations, accounting SaaS, HR platforms, AI tools and call-centre providers.
The PDP Law regulates relationships between controllers and processors. Processors must act under controller instructions, while engagement of additional processors is subject to written controller approval under Article 51.[1]
Vendor risk is therefore not only:
“Is this good software?”
It also includes:
Who processes the information?
Where is it stored?
Are subprocessors involved?
What happens at contract termination?
How quickly will the vendor report an incident?
Technology can be outsourced.
Accountability does not automatically disappear with it.
Retention is often a blind spot
Storage is cheap.
As a result, companies tend to keep information indefinitely.
The PDP Law includes obligations to end processing after retention periods or purposes have been fulfilled, and in specified circumstances to delete or destroy personal data.[1]
Old data has an unusual risk profile.
Its commercial value may decline.
Its security exposure remains.
Inactive customer lists.
Years-old CVs.
Copies of old identity documents.
Exports from campaigns that ended long ago.
The less useful data becomes, the harder it is to justify carrying its risk forever.
Privacy maturity can therefore mean knowing what to delete.
A 3×24-hour breach clock moves quickly
If personal-data protection fails, the law requires written notification within 3×24 hours to affected data subjects and the institution. The notice must at least explain what information was exposed, when and how the exposure occurred, and what response and recovery actions are being taken.[1]
Three days can sound generous until a real incident occurs.
Day one may disappear into investigation.
Technology teams need to determine whether the incident is genuine.
Legal needs scope.
Management wants certainty.
A vendor responds slowly.
Customer service has no approved communication.
This is why incident response should be designed before an incident.
Who leads?
Who contacts legal?
Who communicates externally?
Where are logs located?
Who determines the affected population?
The exact response will vary by incident.
The organisational structure should not have to be invented while the clock is already running.
Not every company automatically needs a dedicated DPO
This distinction matters.
The PDP Law requires appointment of a data-protection officer or responsible function in specified circumstances, including public-service processing; core activities involving regular and systematic monitoring at large scale; or large-scale processing of specific-category personal data or data relating to criminal offences.[1]
It is therefore inaccurate to say:
“Every Indonesian company and MSME must employ a DPO.”
Companies outside those criteria still need accountability.
Who verifies privacy notices?
Who handles data-subject requests?
Who reviews vendors?
Who coordinates incident response?
The job title may vary.
Responsibility cannot simply disappear.
An independent authority could increase enforcement visibility
The PDP Law already gives the future institution broad functions: policy-making, supervision, administrative enforcement, complaint handling, investigations, requests for information and documents, inspection, and assessment of certain cross-border data-transfer requirements.[1]
The law also provides administrative measures ranging from written warnings and temporary suspension of processing to deletion or destruction orders and administrative fines of up to 2% of annual revenue or receipts, subject to applicable variables and further implementing mechanisms.[1]
A dedicated independent authority may make regulatory supervision more visible.
It would be premature, however, to predict its enforcement style.
The final Presidential Regulation establishing the institution has not yet been located as an enacted regulation in this research.
The GATICORP Data Readiness Test
Businesses can simplify preparation into six questions:
Know it — What information do we hold?
Justify it — Why are we processing it?
Limit it — Who actually needs access?
Protect it — What technical and organisational controls apply?
Delete it — When is the information no longer needed?
Respond — What happens when protection fails?
This is a GATICORP editorial framework, not a regulator's checklist.
But inability to answer even one of those questions can reveal a significant visibility gap.
Privacy is more than a compliance cost
Personal-data protection is often framed as legal cost, cybersecurity spending and administration.
There is another way to view it.
Customers disclose information because they expect it to be used reasonably.
Employees provide sensitive information because it is necessary for employment.
Vendors gain access because the business requires their services.
Each relationship contains trust.
When a company knows its data, limits access, uses information for clear purposes and can respond quickly when something fails, privacy becomes part of digital operating quality.
Do not wait for the authority before cleaning up the data
Indonesia is finalising an independent PDP authority.[2]
That is an important institutional development.
Businesses do not need to wait for it before acting.
The law is already in force.
Its transition period has passed.
Core controller and processor obligations already exist.
The useful question is not:
“When will the new regulator start working?”
It is:
“If a customer, auditor, management team or regulator asked tomorrow how personal data is processed, could we answer with evidence?”
If not, the new authority is not creating the underlying problem.
It may simply make an existing gap easier to see.
Sources:
- [1] Republik Indonesia / JDIH Kemkomdigi. Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi. 17 October 2022.
- [2] Kementerian Komunikasi dan Digital RI. Wamen Nezar Patria: Indonesia Siapkan Otoritas Pelindungan Data Pribadi yang Independen. 22 July 2026.
- [3] JDIH Kemkomdigi. Pengharmonisasian Rancangan Peraturan Pemerintah tentang Pelaksanaan UU No. 27/2022. 21 May 2025.
- Editorial Notes
- Artikel tidak mengatakan otoritas PDP independen sudah resmi terbentuk.
- UU PDP sendiri sudah berlaku dan masa penyesuaian dua tahun telah berakhir.
- Kewajiban DPO tidak diperlakukan sebagai kewajiban universal semua perusahaan.
- Batas 3×24 jam berasal langsung dari UU PDP.
- Denda administratif maksimum 2% disebut sebagai batas dalam UU, bukan prediksi sanksi otomatis untuk setiap insiden.
- Artikel bukan legal advice dan tidak menggantikan assessment berdasarkan jenis data, sektor, serta kegiatan pemrosesan masing-masing perusahaan.
Published: August 12, 2026
Source and editorial notes are managed through GATICORP CMS.




