Law / Indonesia

Law on Personal Data Protection, cross-border transfer

Law No. 27 of 2022 on Personal Data Protection, Article 56

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 17 October 2022.

A cross border transfer rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app transferring the personal data of an individual in Indonesia, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside Indonesia must ensure the recipient's country of domicile provides a level of personal data protection equal to or higher than this Law's standard.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 56 permits a Personal Data Controller to transfer personal data to a controller or processor outside Indonesia's legal territory, provided the recipient's country of domicile has a level of personal data protection equal to or higher than the Act's own standard. Later paragraphs of Article 56, which provide fallback mechanisms such as binding instruments or consent where the adequacy standard is not met, are not reproduced here. No data-localization mandate was found in the paragraphs read.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_voice
  • processes_biometrics

Read the law

government (.go.id) legal-documentation network mirror

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app