Meet UU PDP awareness and breach-readiness expectations
Indonesia's Personal Data Protection Law asks organizations to protect personal data with real technical and organizational measures. Claro strengthens the human layer that most breaches begin with.
- Regulator
- Republic of Indonesia
- Applies to
- All personal data controllers and processors in Indonesia
Overview
Undang-Undang Pelindungan Data Pribadi, Law No. 27 of 2022, is Indonesia's first comprehensive personal data protection statute. Enacted in October 2022 with a two-year transition period that ended in October 2024, it now applies in full to any organization that processes the personal data of Indonesian individuals, whether acting as a data controller or a data processor. The law reaches domestic and, in defined circumstances, foreign entities whose processing affects people in Indonesia. It reflects a wider regional movement toward accountable, rights-based handling of personal data.
At its core the law requires organizations to implement appropriate technical and organizational measures to keep personal data secure and to demonstrate that those safeguards actually operate. Accountability is central: it is not enough to have a policy on paper, you must be able to show that controls are applied and effective in practice. Data subjects are given defined rights over their information, and organizations are expected to process data lawfully, transparently, and for legitimate purposes. Governance, documentation, and evidence sit at the heart of the regime.
Breach response is a specific and time-bound obligation. When a personal data breach occurs, organizations are required to notify affected data subjects and the supervisory authority within 3 x 24 hours, which is 72 hours. Meeting that window depends on fast detection, clear internal escalation, and a workforce that recognizes and reports suspicious activity quickly. Because phishing and social engineering are among the most common triggers of a reportable incident, the ability of employees to spot and report an attack directly shortens detection time and supports the notification duty.
Non-compliance can attract administrative sanctions, with exposure reported to reach up to 2 percent of annual revenue, alongside additional consequences for the most serious violations; the precise exposure for any organization should be confirmed with qualified counsel. This page is general information and not legal advice, and consulting counsel is recommended before relying on any interpretation. Claro supports the human-layer controls the law expects, including awareness, simulation, and breach-reporting readiness, but Claro alone does not make an organization compliant. Compliance depends on the full set of legal, technical, and organizational measures you put in place.
What the rule expects
Technical and organizational security measures
Organizations must protect personal data with security measures that are appropriate to the risk. This includes both technical safeguards and organizational practices such as staff training and clear internal responsibilities.
Accountability and demonstrable safeguards
It is not enough to hold a policy; you must be able to demonstrate that controls operate in practice. Evidence of awareness activity, testing, and remediation supports the accountability principle at the center of the law.
Breach notification within 3 x 24 hours
A personal data breach must be reported to affected data subjects and the supervisory authority within 3 x 24 hours, that is 72 hours. Fast detection and clear escalation are essential to meeting this window.
Workforce awareness of personal data risks
Because people handle personal data every day, the workforce needs to understand how it can be exposed and how to protect it. Regular, role-relevant awareness reduces the chance of accidental or attacker-driven disclosure.
Detection and rapid incident reporting
The 72-hour notification duty is only achievable if incidents are detected quickly. Employees who can recognize and report suspicious emails act as an early-warning layer that shortens time to detection.
Lawful, purpose-bound processing
Personal data must be processed lawfully, transparently, and only for legitimate, defined purposes. Staff who understand these limits are less likely to mishandle data or fall for pretexts that seek to extract it.
Data governance and record-keeping
Organizations are expected to maintain governance over how personal data is processed and to keep records that show safeguards are in place. Structured evidence of controls supports both internal governance and any supervisory inquiry.
How Claro helps you comply
Bilingual phishing simulation
Claro runs localized phishing simulations in English and Bahasa Indonesia, so awareness reflects the threats your people actually face. Per-recipient tracking of opens, clicks, submissions, and reports shows where personal-data exposure risk is concentrated.
Just-in-time awareness and training
When a user falls for a simulation, Claro shows an instant awareness page and auto-enrolls them in role-relevant micro-modules. This turns a mistake into a targeted teaching moment that lowers the chance of a real data breach.
Phish-report button as a human sensor
The Claro reporting button, available as an Outlook add-in and a Gmail extension, lets employees report suspicious mail in one click. This early-warning signal shortens detection time and supports the 3 x 24 hour notification duty.
Risk scoring by user and department
Claro scores human risk at the user and department level so you can see where personal-data handling is most exposed. Leaders can direct awareness effort to the groups that need it, which supports a risk-appropriate security posture.
Evidence packages and audit logs
Claro produces evidence packages, Claro-style PDF reports, and detailed audit logs that document awareness activity and results. This gives you material to demonstrate the accountability the law expects.
On-premise deployment for data residency
Claro can be deployed on-premise, which helps organizations keep personal data within Indonesia when residency matters to them. PII is encrypted at rest with AES-256-GCM and isolated per tenant.
Frequently asked questions
The law does not name phishing simulation as a specific technique. It requires appropriate technical and organizational measures and demonstrable safeguards, and awareness training and simulation are widely accepted ways to reduce human risk and evidence that effort.
This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.
Related pages
OJK POJK 11/2022
OJK's IT and cyber-resilience rule for banks. Evidence the awareness and testing it calls for.
Learn moreBSSN Guidance
Indonesia's national cyber agency guidance. Strengthen the human layer it emphasizes.
Learn morePP 71/2019 (PSTE)
Indonesia's core rule for operating electronic systems: registration, security, and personal data protection obligations for PSE.
Learn moreBuild defensible security awareness evidence
Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.
Request a demo