Where the rules stand in September 2026
Law No. 27 of 2022 on Personal Data Protection (UU PDP) was promulgated on 17 October 2022. Article 74 gave organisations two years to adjust, so the law has applied in full since October 2024, to anyone who processes personal data, professional firms included.
Its implementing regulation, Government Regulation (PP) No. 33 of 2026, was promulgated in July 2026. According to Kompas and Hukumonline, it takes effect on 16 January 2027. When this guide was reviewed, we could not yet find the official text in the JDIH BPK database, so the checklist below rests on the articles of the law itself. Check the regulation's technical details against its official text.
The law already says which parts the regulation will fill in: impact assessments (Article 34(3)), data protection officers (Article 54(3)), transfers abroad (Article 56(5)) and the procedure for administrative sanctions (Article 57(5)). The obligations exist in the statute; the regulation sets out how to meet them.
The supervisory agency required by Article 58 had, according to Kompas, still not been set up at the end of August 2026. That is not a reason to wait. The obligations apply regardless, and your corporate clients are probably already asking about them.
This guide is general information, not legal advice.
Why law firms, notaries, tax consultants and audit firms are in scope
The law applies to every person and organisation processing personal data in Indonesia (Article 2). The only exemption is processing for purely personal or household purposes, which a firm's work is not.
Consider what crosses your desk in a week: copies of ID cards (KTP) and family cards, tax IDs (NPWP), land certificates, bank statements, tax returns, clients' payroll, medical records in litigation, children's details in inheritance or guardianship matters. Several of these are specific personal data under Article 4(2), which covers health data, children's data, criminal records and personal financial data, among others. Specific data carries heavier obligations.
For most of its work, a firm is the personal data controller: it decides why and how client data is processed. The vendors it uses (cloud storage, email, AI services) are usually processors. In some engagements, such as auditing a company's employee records, your role may differ. Decide per type of service and write it down.
Checklist 1: Map the personal data you hold
You cannot protect data you cannot locate.
- List the personal data involved in each service: property conveyancing, company formation, civil litigation, annual tax returns, statutory audits.
- Mark which of it is specific personal data.
- Record where it lives, including the unofficial places: staff members' personal Google Drives, WhatsApp groups, email attachments, laptops, USB sticks and personal AI accounts.
- Record who can open it.
- Set how long each type is kept and how it is destroyed. Your professional rules may require longer retention; note the basis.
Checklist 2: Record a lawful basis for each activity
Article 20 requires a basis for all processing. There are six, and consent is only one of them. For professional firms the usual bases are performance of a contract with the client and compliance with a legal obligation.
- Write down the basis for each type of service.
- If you rely on consent, Article 22 requires it to be written or recorded, and Article 21 lists what you must tell the person first.
- Consent can be withdrawn (Article 9), so do not rely on it for data you are obliged to keep.
Checklist 3: Keep a record of all processing
Article 31 is short and demanding: the controller must record all personal data processing activities. Article 47 adds that you must be able to demonstrate accountability.
- Keep a processing register: data types, purpose, basis, location, recipients, retention.
- Make sure your systems log who opened, downloaded or shared each client file.
- Write a short internal policy on handling client data and have every member of staff read it.
Checklist 4: Control access and keep data confidential
Articles 35 to 39 require technical and operational safeguards, confidentiality, oversight of everyone involved in processing, and prevention of unauthorised access.
- Grant access per client or per matter, not one shared drive for the whole office.
- Turn on two-step sign-in for email and file storage.
- Forbid client files in personal accounts.
- Send documents to clients through links with a password and an expiry date rather than open email attachments.
- Remove access on a leaver's last day.
Checklist 5: Manage vendors and third parties
Under Article 51, a processor may only act on your instructions, and responsibility stays with you as controller. A processor also needs your written approval before bringing in another processor (Article 51(5)).
- List every vendor that touches client data: cloud storage, email, e-signature, accounting software, AI services.
- Obtain a data processing agreement and a list of sub-processors.
- Ask where data is stored and processed. If it is outside Indonesia, Article 56 applies.
Checklist 6: Handle data subject requests
Individuals have rights to access, correction, ending processing and erasure (Articles 5 to 9). Some deadlines are tight: access and correction must be provided within 3 x 24 hours (Articles 30 and 32).
- Name one address and one person to receive requests.
- Log the date each request arrives and the date it is closed.
- Make sure you can find every file relating to one person quickly.
Checklist 7: Assess high-risk processing
Article 34 requires a data protection impact assessment where processing is high-risk, including processing specific data, large-scale processing, combining datasets and using new technology. Tax consultants and audit firms handling personal financial data at volume will almost certainly need one. A firm starting to use AI on client documents should consider one too.
Checklist 8: Appoint someone responsible
Article 53 requires a data protection officer in certain cases, for example where your core activity involves large-scale processing of specific data. The role can be filled internally or externally. A small firm may not be obliged to appoint one, but it still needs one named person who owns the subject.
Checklist 9: Prepare for a breach
After a personal data protection failure, Article 46 requires written notice to the individuals affected and to the agency within 3 x 24 hours, stating at minimum what data was exposed, when and how, and what is being done about it.
- Prepare a notice template and a contact list.
- Decide who makes the call and who drafts.
- Make sure your access records are detailed enough to answer "which files were exposed?".
The checklist on one page
| Obligation | Basis in UU PDP | Evidence worth having |
|---|---|---|
| Lawful basis | Art. 20 | Table of services and their bases |
| Record of processing | Art. 31 | Processing register and access logs |
| Security and confidentiality | Arts. 35 to 39 | Per-client access, internal policy |
| Oversight of processors | Arts. 37, 51, 52 | Vendor agreements, sub-processor list |
| Transfers abroad | Art. 56 | Processing location for each vendor |
| Data subject rights | Arts. 5 to 13, 30, 32 | Request log with closing dates |
| Impact assessment | Art. 34 | Assessment for each high-risk activity |
| Data protection officer | Arts. 53 and 54 | Letter of appointment |
| Breach notification | Art. 46 | Template and 3 x 24 hour procedure |
Penalties
Breaching these obligations can lead to administrative sanctions under Article 57: a written warning, temporary suspension of processing, erasure or destruction of data, and an administrative fine of up to 2 per cent of annual revenue or receipts relative to the breach.
There are criminal offences too. Under Article 67, unlawfully disclosing personal data belonging to someone else carries up to four years' imprisonment and/or a fine of up to Rp4 billion. For corporations, Article 70 allows fines of up to ten times that maximum. For a professional firm, though, the heavier cost is usually the client who does not come back.
Where folders.id can help
Much of this checklist is policy and contracts, and that remains your work. Some of it is tooling, and there folders.id can help:
- Client files organised by folder, with per-folder permissions for your team.
- Client portals for sending and collecting documents, with a password, an expiry date, download controls and a log of who opened what.
- If your team uses AI, you choose which folders it may read. Every AI request is recorded, refusals included.
- NIK, NPWP, passport and bank account numbers are masked before they reach an AI. This is on by default.
- Uploaded files are stored with an Indonesian object-storage provider.
Start with checklist 1. Once the map is clear, the other eight get much easier.