The short answer
Not necessarily. Indonesia's Personal Data Protection Law (UU PDP) requires an organisation to appoint a data protection officer, known in the law as a pejabat atau petugas pelindungan data pribadi (PPDP), in three situations only. Most firms of 5 to 50 people do not clearly fall into any of them, because the law puts no number on "large scale". Some firms, though, sit in a grey area, particularly those whose core work involves personal financial data, health data, children's data or criminal matters.
This guide covers when appointment is mandatory, what Government Regulation (PP) 33 of 2026 adds, and how to fill the role without hiring. For the law's obligations as a whole, see the Indonesia PDP law checklist for professional firms.
This guide is general information, not legal advice.
What the law says: Articles 53 and 54
Article 53(1) of Law No. 27 of 2022 requires controllers and processors to appoint a data protection officer where:
- personal data is processed for the purposes of public services;
- the controller's core activities, by their nature, scope or purpose, require regular and systematic monitoring of personal data on a large scale; or
- the controller's core activities consist of large-scale processing of specific personal data and/or personal data relating to criminal offences.
The original text joined points (b) and (c) with "and", which some read as cumulative: all three conditions at once. The Constitutional Court closed off that reading. In Decision No. 151/PUU-XXII/2024, delivered on 30 July 2025, it held that the "and" must be read as "and/or". Meeting any one condition is enough.
Under paragraphs (2) and (3), the officer is chosen for professionalism, legal knowledge, data protection practice and ability to do the job, and may come from inside or outside the organisation.
Article 54(1) sets out the minimum tasks:
- informing and advising the controller or processor so that it complies with the law;
- monitoring and ensuring compliance with the law and with internal policy;
- advising on data protection impact assessments and monitoring the performance of controllers and processors;
- coordinating and acting as the contact point on issues relating to personal data processing.
Article 54(2) asks the officer to weigh risk, given the nature, scope, context and purpose of the processing. And this is not a recommendation: Article 57(1) lists breach of Article 53(1) among the provisions that attract administrative sanctions.
What PP 33/2026 adds
Government Regulation No. 33 of 2026 was enacted and promulgated on 16 July 2026 and takes effect on 16 January 2027 (Kompas, Hukumonline). At the time of review, the official text was not yet on JDIH BPK. What we read is a copy published by Meridian Hukum, a private legal database, and the article numbers below come from that copy. Check them against the official text before you quote them.
According to that copy, the provisions on data protection officers are in Articles 142 to 147:
- Article 142 repeats the three triggers from the law, already worded "and/or" in line with the court's decision, and leaves the detail to a regulation of the supervisory agency (Peraturan Lembaga).
- Article 144 says the appointment must take into account the organisation's structure, size and needs. The role may be held by one person or several, from inside and/or outside.
- Article 146 requires the controller to involve the officer in all processing, give them a reporting line to the highest level of management, let them work objectively and independently, provide adequate resources, seek their advice on impact assessments, and document their work. Paragraph (2) says the officer's tasks must not create a conflict of interest.
- Article 184(1) lists breach of Article 142(1) among the provisions that attract administrative sanctions.
What is missing is a number for "large scale". The only guidance is in the elucidation to Article 120(2)(c), on impact assessments, which lists factors including the volume of data, the number of individuals, the duration of processing, the type of data, the purpose and the geographical area affected. There is no threshold of clients or employees.
Nor is there an agency regulation yet. According to Kompas, the agency itself had not been set up by the end of August 2026.
Does a firm of 5 to 50 people fall in scope?
Public services. Private law firms, tax consultancies, audit firms and agencies are generally not public service providers. Notaries and land deed officials (PPAT) are different: they are public officials. Neither the law nor PP 33/2026 says clearly whether a public official's work counts as processing "for the purposes of public services" under Article 53. If you are a notary, ask your professional body or your own counsel, and keep a note of the answer.
Large-scale systematic monitoring. Law firms and tax consultancies rarely monitor people. An agency that runs behavioural tracking, ad targeting or profiling for its clients should read point (b) more carefully.
Large-scale processing of specific data as a core activity. This is where professional firms come closest. Article 4(2) classes health data, children's data, criminal records and personal financial data as specific personal data. The elucidation says personal financial data includes, among other things, the amount held in bank accounts, including savings and deposits, and credit card data. Compare that with your own work:
- Tax consultants complete the list of assets in individual tax returns, including bank balances.
- Audit and accounting firms handle clients' payroll and employee records.
- Notaries hold children's details in inheritance, gift and guardianship matters, and sometimes receive the parties' bank statements.
- Law firms with a criminal practice handle data relating to criminal offences, and employment and insurance cases often come with medical records.
For many firms this is the core activity, not a side line. That leaves scale. On a reasonable reading, a tax consultant with 150 individual clients is probably not processing "on a large scale". A firm with thousands of clients, or one running payroll for dozens of companies, will find that argument harder to make. With no number in the law, both are judgements, not certainties.
Our suggestion: write your assessment down. One page setting out the types of data, the rough number of individuals and your reasoning is far stronger, if the agency ever asks, than "we didn't think we needed one".
Whatever you conclude, the law's other obligations still apply: a lawful basis, a record of processing, security, and breach notification within 3 x 24 hours. Someone in the firm still has to own them.
The options: staff, partner or outside help
| Option | Strengths | Watch for |
|---|---|---|
| A member of staff, such as the office manager or a senior associate | Knows how the firm works, low cost | Needs time and training. Make sure they have a direct line to the managing partner |
| One of the partners | Has authority, decides quickly | The regulation forbids conflicts of interest without giving examples. A partner who also decides why data is processed could be seen as conflicted |
| An outside adviser, such as a part-time data protection consultant | Expertise on day one, easier to show independence | Still needs an internal contact. Cover confidentiality and access in the contract |
For a small firm a combination often works best: a member of staff as the day-to-day officer, with an outside consultant for impact assessments and an annual review. Article 144 of PP 33/2026 allows the role to be shared in this way.
A job description you can adapt
Role: Data Protection Officer (PPDP)
Reports to: the managing partner or head of the firm
Time: for example 10 to 20 per cent, reviewed every six months
Responsibilities:
- Advise the partners and staff on their obligations under the PDP Law and PP 33/2026.
- Maintain the record of processing and update it whenever a new service, vendor or system is introduced.
- Monitor compliance with internal policy, including regular access reviews.
- Advise on data protection impact assessments and keep the documentation.
- Receive and log requests from individuals and make sure deadlines are met.
- Coordinate the response to a data protection failure, including notice within 3 x 24 hours.
- Act as the contact point for clients, individuals and the agency on personal data matters.
- Report to the firm's leadership at least once a quarter.
Authority: access to information about all processing, the right to ask staff and vendors for information, and an assurance of no internal penalty for carrying out these duties in good faith.
Qualifications: a working knowledge of the PDP Law, familiarity with how the firm operates, and willingness to train. A certificate helps, but the law does not require one.
The first 90 days
Days 1 to 30: know what you hold.
- Issue a letter of appointment signed by the managing partner and tell the whole firm.
- Put the officer's contact details in your privacy notice and on your website.
- Map the data for each service: what it is, where it is kept and who can open it.
- Write down whether the firm is obliged to appoint an officer, as discussed above.
Days 31 to 60: fix the riskiest things first.
- Draw up or update the record of processing.
- Run a first access review: who can open which client folders, and do they still need to?
- List every vendor that touches client data and ask each for a data processing agreement.
- Decide which processing needs an impact assessment, such as using AI on client documents.
Days 61 to 90: prepare for a bad day.
- Write a breach procedure and a 3 x 24 hour notice template, then test them with a short exercise.
- Set up a process for requests from individuals, including a way to find every file relating to one person.
- Run a one-hour training session for everyone.
- Give the partners a first report: what is done, what is not, and what needs a budget.
After that, set a rhythm: update the record of processing every quarter, review access every six months, and revisit whether an officer is mandatory as soon as the agency regulation is issued.
Evidence the officer can point to
Most of the job is policy and habit; some of it is evidence. If your client files are in folders.id, the activity record keeps every search and read an AI made, refusals included. Access reviews record who decided to keep or remove each piece of access. The record of processing is built from your live settings and exports to CSV. Uploaded files are stored with an Indonesian object-storage provider.