Indonesia’s main personal data protection legislation is Law No. 27 of 2022 on Personal Data Protection (the PDP Law). It is described as a comprehensive framework for personal data processing activities and applies across businesses, industries, and organisations, whether private or public. It covers processing in both electronic and non-electronic systems and regulates the full cycle of handling, from collection and analysis through disclosure and eventual deletion or destruction. For consumer research teams, that scope matters because surveys, panels, analytics, and qualitative research all involve repeated processing steps, not just “collection.” If your organisation is planning studies that touch Indonesian consumers, this is the baseline framework to map your research and data collection activities against.
The PDP Law also reshapes responsibilities by distinguishing a Personal Data Controller from a Personal Data Processor. The controller determines the purpose and controls the processing, while processors handle data on the controller’s behalf. In practice, many consumer research programs use vendors for recruitment, data collection platforms, transcription, analytics, or infrastructure. Under the PDP Law, processors must implement strict protection measures, even though controllers carry primary responsibility. The law also has extraterritorial reach, applying to individuals or corporations, public bodies, or international organisations that conduct legal acts as regulated under the PDP Law, regardless of whether they are physically located in Indonesia. This means cross-border research operations can still be pulled into Indonesian compliance expectations when Indonesian personal data is involved.
How Consumer Research Workflows Need to Change Under the PDP Law
Operationally, the PDP Law emphasizes principles and lawful bases for processing, along with data subject rights. In the context of consumer data privacy in Indonesia under the PDP law, research teams should plan for individuals to ask what is being collected, why it is collected, and how it will be used, reflecting the right to be informed described in practical guidance. The law recognizes rights including access, correction, deletion, and withdrawal of consent, and it includes a response mechanism: when a controller receives a request for the exercise of certain rights, it must fulfil the request within 3 × 24 hours, meaning within 72 hours. That timeline is short for research programs, so teams should pre-build request intake, identity verification, and data location processes before fieldwork begins.
Data classification is another immediate impact on research design. Guidance summarising the PDP Law describes two categories: general personal data (for example, full names, gender, citizenship, religion, and combined data that can identify an individual) and specific personal data that requires stricter protection measures. Specific personal data is described as including health data, biometric data, genetic data, criminal records, child data, and personal financial data. Consumer research often drifts into sensitive territory, especially when testing healthcare messaging, collecting age information, or conducting identity verification for incentives. Treat those question sets, recruitment criteria, and storage locations as higher-risk from day one, and align vendor controls to the category of data being processed.
Finally, the PDP Law changes incident planning and governance for research data. When a data breach occurs, both the controller and processor are required to notify affected data subjects and the Indonesian Data Protection Authority within 72 hours. Organisations handling large volumes of sensitive data or engaging in activities that rely heavily on data processing are required to appoint a Data Protection Officer (DPO) to oversee compliance, according to practical summaries. Also note the regulatory landscape is still evolving: although the PDP Law’s two-year transitional period elapsed on 17 October 2024, the government has been drafting an implementing regulation, with a draft last circulated on 31 August 2023 for public discussion. Consumer research leaders should watch for implementing details and remember that sectoral laws and regulations (including within the EIT regulatory framework and sector regulators like OJK and BI) may add requirements so long as they do not contradict the PDP Law.
What is the PDP Law and why does it matter for consumer research in Indonesia?
How fast must a company respond to a consumer request about their personal data?
What kinds of research data may be treated as higher risk under Indonesia’s PDP Law?
What are the breach notification expectations for consumer research datasets?
How does consumer data privacy in Indonesia under the PDP law affect third-party research vendors?