All resources
// Resources

Personal Data Incident Response Requirements in Indonesia

Published August 8, 2026

This is breach-response evidence planning, not legal advice or compliance confirmation. Operator and qualified Indonesian legal review are required for incident characterization, applicable obligations, recipients, public-notification decision, and final notice. Source checked 2026-08-13: official BPK JDIH record and PDF for UU No. 27 Tahun 2022.

Statutory text and planning interpretation

Pasal 46 ayat (1) states that where a failure of personal-data protection occurs, Pengendali Data Pribadi must give written notification no later than 3 x 24 (tiga kali dua puluh empat) jam to data subjects and the institution. Pasal 46 ayat (2) huruf a–c states minimum notice content: personal data exposed; when and how it was exposed; and handling and recovery efforts. Pasal 46 ayat (3) states that, in certain circumstances, controller must notify public.

This text does not say clock always starts on discovery or confirmation. It does not name institution, define certain circumstances in that paragraph, mandate a RACI, or prescribe evidence retention. Timeline, RACI, and decision workflow below are implementation interpretation for preserving facts and routing questions. They do not determine legal outcome.

First hour: preserve facts without speculation

Open incident record with unique ID, reporter, time received, systems, containment actions, and access restrictions. Preserve volatile and durable evidence under approved forensic process: alert IDs, relevant logs, cloud audit records, access histories, system time sources, screenshots, hashes, and custody record. Make working copies; protect originals. Do not collect extra personal data, alter logs, or state data was exposed before evidence supports that conclusion.

Example: at 08:40 a storage alert identifies public access on document bucket. Engineer removes public rule at 08:48 and captures policy export, object access log range, and change ID. Incident lead marks exposure scope as unknown, not “no impact.” Legal reviewer receives factual timeline and exact uncertainty.

Timeline and notification-decision record

RecordCompleted exampleEvidenceOwnerPass/failException or remediation
Event timeline08:40 alert, 08:48 containment, 09:05 log preservationcase record, synchronized timestampsincident leadPasstime source verified
Pasal 46 questionpossible protection failure escalated to legal reviewLEGAL-119, factual brieflegal leadOpenlegal conclusion pending
3 x 24-hour recordstatutory wording recorded; start-point not assumedcounsel note, timelineprivacy ownerPassconfirm trigger with counsel
Notice contentsdata category, when/how, handling/recovery draft fields preparedversioned draftcommunications ownerOpenfacts incomplete
Recipient evidencedelivery method and receipt plan recordedrecipient registerincident coordinatorFailinstitution recipient unresolved

Pass means planning evidence exists and is traceable. It does not mean notification duty is discharged. Open means facts or authorized decision are unresolved. Fail means missing evidence requires named remediation.

RACI for operational routing

ActivityResponsibleAccountableConsultedInformed
Preserve evidence and containment factsincident response leadincident commandersystem owner, securitylegal, privacy
Scope data and affected systemssystem/data ownerincident commandersecurity, vendorprivacy
Determine legal interpretation and notice decisionlegal reviewerauthorized managementprivacy, incident leadcommunications
Draft approved factual noticecommunications ownerauthorized managementlegal, privacysupport team
Send and retain delivery evidenceincident coordinatorauthorized managementlegal, communicationsincident team

Names and delegated authority must be filled before incident. No role label substitutes for authority. When responsible or accountable person is unavailable, record escalation path and elapsed time.

Preservation and decision workflow

  1. Stabilize safety and contain under authorized incident procedures.
  2. Preserve original evidence and build a timestamped fact ledger.
  3. Separate confirmed facts, assumptions, and unanswered questions.
  4. Route factual package to legal and authorized management for Pasal 46 applicability, recipient, timing, and public-notification decisions.
  5. Draft only minimum factual content supported by evidence; version each draft and approval.
  6. Record delivery, recipients, transmission time, failures, and post-notification recovery actions.
  7. Run after-action review, retain decision trail per approved policy, and open remediation items.

Notification-decision closure

Before any notice leaves, coordinator compares approved draft with fact ledger: exact data category, supported event time and mechanism, handling/recovery actions, recipient decision, approval identity, transmission record, and failed-delivery follow-up. Example INC-204 remains Open when bucket logs prove public configuration but cannot prove object access; draft must say only supported facts or wait for authorized decision. Legal reviewer and designated operator retain explicit gate for applicability, timing, recipient, and public statement. Sending a draft or starting a timer does not close this decision record.

Limits

Do not call this workflow legal compliance, an automatic 72-hour-from-discovery rule, or an instruction to notify public for every incident. It helps preserve evidence for authorized decision makers. Consult qualified Indonesian counsel and designated operator before notification or external statements.

Sources

Worked decision record

For suspected exposure from misconfigured object store, preserve discovery time, affected object prefix, access-log availability, containment action, and uncertainty register. Expected behavior: technical team supplies facts while authorized privacy and legal owners decide notification duties from current law and case facts. Edge case: logs incomplete or retention elapsed; document limitation and alternate evidence, never infer affected people. Closure test: validate containment, revocation, evidence custody, decision owner, and follow-up review; do not label legal compliance achieved.

Worked closure check

For suspected object-store exposure, preserve incident ID, discovery and containment times, bucket configuration revision, available log range, privacy owner, and counsel decision reference. Facts in this record support incident handling, not a determination of UU PDP applicability, notification duty, compliance, certification, or legal outcome. New access evidence or altered retention settings require timeline update and authorized reassessment. Independent reviewer follows one notice fact from source log through approved draft and delivery register, while uncertainty and failed delivery remain explicit.

Have a system that needs testing?