Law / Indonesia

Law on Personal Data Protection, breach notification

Law No. 27 of 2022 on Personal Data Protection, Article 46

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 17 October 2022.

A breach notification rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app that suffers a failure of personal data protection affecting an individual in Indonesia must give written notification within 72 hours to the affected individual and to the supervisory institution, describing the data disclosed and the remedial measures taken.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 46(1) requires a Personal Data Controller to give written notification no later than 3 times 24 hours (72 hours) to the personal data subject and to the supervisory institution on a failure of personal data protection. The notification must at minimum describe the data disclosed, when and how it was disclosed, and the controller's handling and recovery efforts; in certain cases the controller must also notify the public.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web

Read the law

government (.go.id) legal-documentation network mirror

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app