Digital padlock illustration over documents and data
Back to blog

UU PDP for Businesses: A Personal Data Protection Compliance Guide

A UU PDP compliance guide for Indonesian businesses: legal obligations for data controllers, practical steps to comply, sanctions, and a compliance checklist.

An SME owner in Yogyakarta received an email from a government agency: his business was asked to clarify its collection of customer data, which appeared to lack a clear legal basis. His online registration form collected names, phone numbers, and addresses — but he had never explained what the data would be used for. He never imagined that collecting customer data without consent could now lead to a formal examination.

Since the Personal Data Protection Law (UU PDP) was enacted in October 2022, Indonesia has entered a new era of data management. The two-year transition period has passed; since October 2024, its main provisions are in effect. For businesses — from SMEs to corporations — the UU PDP is no longer a future discussion. It is a legal obligation that applies now, with real sanctions.

This article explains what the UU PDP actually requires of your business, practical steps to comply, what is often misunderstood, and how to get started without becoming a legal expert.

What Is the UU PDP and Why Address It Now

The UU PDP is Indonesia's first comprehensive law governing personal data protection. Previously, data protection was scattered across sectoral regulations — banking, telecommunications, health — with limited scope. The UU PDP unifies these rules into a single national framework and gives the supervisory authority (the Ministry of Communication and Informatics) far stronger oversight and enforcement powers.

Key numbers you should know:

  • Administrative sanctions of up to 2 percent of annual revenue for serious violations.
  • Criminal penalties of up to 5 years in prison and/or fines up to Rp 5 billion for unlawfully collecting personal data — and up to 6 years with fines up to Rp 6 billion when done to benefit oneself or others, or involving data falsification.
  • Criminal penalties of up to 5 years and/or fines up to Rp 5 billion for unlawfully processing specific (sensitive) personal data such as health, biometric, or financial data.

Criminal sanctions apply to the individuals responsible — directors, officers in charge — not only the legal entity. That is what makes the UU PDP serious: it touches personal responsibility.

Beyond sanctions, there is a reputational risk that is no less costly. In the age of social media, a customer data leak becomes news within hours. Businesses proven negligent with customer data pay not only fines but also lose trust built over years.

Who Is Bound by the UU PDP?

The first question people ask: "Does my SME count?" The answer: yes, if you collect or use other people's personal data.

The UU PDP distinguishes two roles:

  • Data controller: the party that determines the purposes and means of data processing. Example: an online store collecting customer data to ship orders.
  • Data processor: the party that processes data on behalf of the controller. Example: a courier service receiving customer addresses to deliver packages, or a software provider storing data on behalf of its clients.

Most businesses are data controllers for their customers' and employees' data. The UU PDP applies to any person, public body, and organization processing personal data within Indonesia's territory, or whose data affects Indonesian citizens — including foreign businesses serving Indonesian customers.

Personal data is not only about customers. Employee data — ID cards, addresses, salary history, health data, even photos — is protected personal data. Many businesses forget that UU PDP compliance starts with their own employees' data.

Basic Obligations of Data Controllers

The core of the UU PDP is a set of obligations every data controller must meet. Here are the basics:

1. A lawful basis for processing

Every collection of personal data must have a legal basis. The most common bases for businesses: consent from the data subject, or fulfillment of a contract (for example, processing an address to deliver an order). Collecting data without a clear basis is a violation from the very first step.

2. Transparency and clear information

When collecting data, you must clearly inform the data subject: what data is collected, for what purpose, how long it will be stored, and how they can exercise their rights. Old habits like pre-checked boxes or privacy policies written in dense legal language no longer suffice.

3. Valid consent

If you use consent as your basis, it must be given explicitly, freely, and be withdrawable at any time. Pre-checked boxes are a violation. Withdrawing consent must be as easy as giving it — this is often forgotten.

4. The minimization principle

Collect only the data genuinely needed for a clear purpose. A form demanding an ID card number when only a name and email are needed violates the minimization principle. Ask yourself: "Do we really need this data?"

5. Data security

Controllers must secure data: encryption, access control, and reasonable technical measures. Data security is not optional; it is a legal obligation. For the technical side, our website security guide covers concrete steps you can implement.

6. Data breach notification

If a data breach occurs, you must report it to the authorities and notify affected data subjects within at most 3x24 hours of learning about it. This is one of the most demanding obligations because it means you must be able to detect breaches early.

7. Data subject rights

Data subjects have the right to access, correct, delete, restrict processing of, and port their data. Businesses must provide mechanisms that allow customers to exercise these rights. Deletion requests must be honored unless a legal basis justifies retention.

8. Records of processing activities

Controllers must record and document their processing activities: what data, where it came from, for what purpose, and where it flows. This documentation is the foundation of any compliance examination.

Specific Personal Data: Special Treatment

The UU PDP gives special treatment to specific (sensitive) personal data:

  • Health data and physical/mental conditions
  • Biometric data (fingerprints, faces, irises)
  • Personal financial data (loan history, balances)
  • Children's data
  • Data related to sexual orientation, political views, religion, and beliefs
  • Genetic and criminal data

Processing specific data is only allowed with stricter explicit consent or another clear legal basis. Employee data from biometric attendance systems — very common in Indonesia — falls into this category. That means a fingerprint attendance system installed without explicit employee consent and without explaining the purpose can be a point of violation. Read our digital attendance and HRIS guide for the practical side of this issue.

The Transition Period and Indonesia's Readiness

The UU PDP was enacted with a two-year transition period; its main provisions have been in effect since October 2024. However, readiness among Indonesian businesses remains uneven. Surveys and industry reports in 2025-2026 consistently show that most SMEs have no written privacy policy, have not appointed a data-responsible officer, and do not understand their basic obligations.

This is not entirely bad news. It means businesses that start organizing compliance now will be ahead of the curve. Conversely, businesses waiting "until enforcement begins" take a risk: when enforcement starts rolling — and all indications point that way — the unprepared will be scrambling.

Enforcement does not have to wait for sanctions to be felt. Corporate and government clients are now starting to include UU PDP compliance requirements in vendor contracts. Large companies are beginning to refuse working with vendors that lack clear privacy policies. UU PDP compliance is slowly becoming a condition for entering larger business supply chains.

Practical Steps Toward Compliance: A Realistic Roadmap

Compliance does not have to be perfect overnight, but it must begin. Here is a realistic roadmap for small and medium businesses:

Months 1-2: Mapping and foundations

  1. Data inventory: list all personal data you collect: customers, employees, suppliers, prospects. Where does it come from, where is it stored, who can access it.
  2. Determine the processing basis: for each data type, write its legal basis: consent, contract, legal obligation, or legitimate interest.
  3. Fix collection points: registration forms, checkout, website — make sure every collection point includes clear information and explicit consent (no pre-checked boxes).

Months 3-4: Policies and rights

  1. Write a privacy policy: clear, simple Indonesian, not a copy of an English template. Explain what data is collected, for what, and how long it is stored.
  2. Set up a mechanism for data subject rights: an email address or form for access, correction, and deletion requests. Train staff to handle these requests.
  3. Update vendor contracts: make sure contracts with software providers, hosting, and other services include data protection clauses matching each party's role.

Months 5-6: Security and incident readiness

  1. Strengthen technical security: encrypt sensitive data, role-based access control, two-factor authentication for all data access.
  2. Prepare a breach response procedure: who decides, how to detect, how to report within 3x24 hours, how to communicate with data subjects.
  3. Train employees: basic rules for handling customer data, recognizing phishing, and reporting procedures. Employees are the first line of defense and the weakest point at once.

Ongoing: Documentation and audits

  1. Record all processing activities: documentation is a continuous process, not a one-off project.
  2. Audit regularly: once a year, review the data inventory, update policies, and fix gaps.

The Role of Technology in Compliance

UU PDP compliance is not just documents; it depends heavily on the technology you use daily. Several points to examine:

Website and forms

Forms collecting data must include a privacy policy and a correct consent mechanism. CMS and contact form plugins that store data indefinitely are a problem: set retention periods and delete data automatically afterward. Websites left unmaintained for years often become sources of silent leaks — our website development guide covers healthy website management standards.

Databases and storage

Personal data must be stored with encryption, restricted access, and secure backups. A database accessible to anyone in the company — with one shared password — is a common access-control violation.

Attendance and HR systems

Employee data, including biometrics, is specific data. Fingerprint or facial attendance systems require explicit consent, documented purposes, and clear retention policies. If your system was installed without these, now is the time to fix it.

Legacy data

If you have collected customer data for years without clear policies, you hold "historical obligations": old data still falls under the UU PDP. At minimum, inform your existing customers through available channels (email, WhatsApp, social media) about your new privacy policy, and offer an opt-out.

Everyday Scenarios: Risk Points Often Overlooked

UU PDP compliance often feels abstract until you look at it through daily operations. Here are some common scenarios that unknowingly bring businesses into violation:

Customer WhatsApp groups

Many businesses create WhatsApp groups for customer service: "New Product Info Group" or "Loyal Customer Community." Customer phone numbers are added without explicit consent, and those numbers are visible to every other member. Collecting customer numbers into a group without a clear processing basis, then exposing them to dozens of strangers, is two violations at once: collection without legal basis and disclosure without consent. The solution is not to abolish groups but to redesign them: use official broadcast channels, request consent at registration, and never add members without confirmation.

Spreadsheets sent back and forth

Sales teams emailing customer lists as spreadsheets to colleagues, to personal WhatsApp, or to personal laptops is a common sight. Every copy scattered around is an unmonitored leak point: a lost laptop, a misdirected email, or a hacked WhatsApp account, and customer data goes out with it. This is not about bad intentions; it is about control. Customer data should only be accessible through official systems with role-based access, not sent as attachments.

Using customer data for promotions

Email addresses and phone numbers collected for order delivery get used to send promotions without separate consent. This is a very common violation: a transactional processing basis does not automatically become a marketing basis. If you want to use customer data for promotions, ask for separate consent — or offer a clear opt-in at registration.

Archives that are never deleted

Prospect data from 2019 registrations that never converted to transactions still sits in the database, never used. Storage without time limits and without purpose violates the minimization and retention principles. Set a policy: prospects with no transaction within 12 months are deleted automatically, unless another legal basis justifies retention.

These four scenarios share the same pattern: UU PDP violations rarely come from malicious intent, but from habits that are never reviewed. The good news is that all of them can be fixed with the right process and technology.

Common Compliance Mistakes

Copying privacy policies from the internet

A privacy policy is not a ceremonial document. Copying a template from abroad — one referencing the GDPR, or naming a company that is not yours — is not only useless; it can become evidence of negligence during an examination. The policy must reflect your business's actual practices.

Treating compliance as purely legal

UU PDP compliance stands on three legs: law, process, and technology. Legal documents without supporting technology — encryption, access control, breach detection — are just paper. The reverse is equally true.

Ignoring employee data

Many businesses focus on customer data and forget that employee data is also protected. Yet employee data is usually more complete and more sensitive than customer data: ID cards, addresses, health history, biometrics.

No breach response plan

Most businesses have no procedure when a breach occurs. Yet the 3x24-hour reporting obligation cannot be met by improvising mid-crisis. The procedure must be written, rehearsed, and known by everyone relevant before a breach happens.

Waiting for enforcement

The "later" strategy works until it doesn't. Legal risk, contract risk, and reputational risk accumulate every day data is managed without a clear basis.

How Much Does UU PDP Compliance Cost

Compliance costs depend heavily on your starting point. Here are realistic estimates for the Indonesian market:

ItemEstimated cost
Privacy policy and basic documents (with guidance)Rp 5-25 million
Data audit and processing mappingRp 10-50 million
Technical fixes (encryption, access control, forms)Rp 10-100 million, depending on systems
Incident response procedure and trainingRp 5-20 million
Ongoing compliance supportRp 2-10 million/month

Compare that with the cost of non-compliance: administrative fines of up to 2 percent of annual revenue, criminal penalties up to Rp 6 billion, lost contracts from clients requiring compliance, and reputational damage whose value is hard to calculate. For small businesses, start with the free steps — a data inventory and a simple policy — then move up gradually according to risk.

The UU PDP and Digital Transformation

UU PDP compliance actually aligns with healthy digital transformation. Businesses that organize their data well — knowing what data they hold, why, and where it flows — will find it easier to use data for business decisions. Messy data is not only a legal risk; it is also unusable for analysis and good decision-making.

Businesses undergoing digital transformation should build in data compliance from the start, not bolt it on at the end. Fixing running systems is far more expensive than building correctly from the beginning. Read our SME digital transformation guide to see how data compliance fits into a complete digital journey.

A Practical Compliance Checklist

Use this checklist to gauge where your business stands:

  1. An inventory of held personal data exists (customers, employees, prospects).
  2. Every data type has a valid, documented processing basis.
  3. Every data collection point includes clear information and explicit consent.
  4. A privacy policy in easy-to-understand Indonesian exists, matching actual practices.
  5. A mechanism exists for access, correction, and deletion requests.
  6. Sensitive data (biometric, health, financial) receives special treatment.
  7. Encryption is active for sensitive data; access is role-based and restricted.
  8. A written breach response procedure exists, including the 3x24-hour reporting obligation.
  9. Employees have been trained in basic data handling.
  10. Vendor contracts include data protection clauses.
  11. Processing documentation is maintained and reviewed periodically.

The more "yes" answers, the more solid your position. The more "no" answers, the higher the priority.

Start Now, Not Later

The UU PDP is not a sudden burden; it is a consequence of how the business world has changed. Customers are increasingly aware that their data is valuable, and the state has finally provided a legal framework to protect it. Businesses that take customer data seriously are building a competitive advantage, not just meeting an obligation.

Start with the simplest steps: list the data you hold, write an honest privacy policy, and fix your data collection forms. Then build from there, step by step.

The Kartech. team in Bandar Lampung helps businesses meet the technical obligations of the UU PDP: data audits, system fixes, encryption and access control, incident response procedures, and ongoing support. We work alongside your legal counsel to ensure the technical and documentary sides move in sync. Discuss your needs through our contact page, or explore our services to see how we work.

Your customers' data is trust entrusted to you. Protecting it is not only a legal obligation — it is the foundation of a sustainable business.

Foto: Unsplash

Bring us the hard part.

Tell us what is blocked, what must be built, or where your current technology is falling short. We will start with the problem.

Talk to us