TwinEthos homeRequest access

Law

Indonesia Personal Data Protection Law (UU No. 27/2022)

Government of Indonesia (Ministry of Communication and Digital Affairs; the personal data protection institution under Pasal 58) · ID · 1 provision encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: jdih.komdigi.go.id.

Trust and provenance 1 official source · last verified 3 Oct 2026 · not reviewed by a lawyer · 1 of 1 provision audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 1
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 1 provision has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 provision audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 1 provision added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

People can object to decisions based solely on automated processing, including profiling (Indonesia PDP Law Art. 10)

UU No. 27 Tahun 2022, Pasal 10 ayat (1) · official text · In force: applies since 17 Oct 2024 · ID

Under Pasal 10(1) of Indonesia's Personal Data Protection Law (UU No. 27 of 2022), a data subject has the right to object to decision-making based solely on automated processing, including profiling, that produces legal effects or significantly affects the data subject; the procedure for objecting is left to a Government Regulation (Pasal 10(2)). Profiling means identifying a person, including from work history, economic condition, health, personal preferences, interests, reliability, behaviour, location or movements, electronically (Elucidation to Pasal 10(1)). The right does not apply for national defence and security, law enforcement, the public interest in running the state, supervision of the financial sector, monetary and payment systems and financial stability, or statistics and scientific research (Pasal 15). The Law binds every person, public body and international organisation, in Indonesia or abroad where there are legal effects in Indonesia or on Indonesian data subjects abroad (Pasal 2), in force on promulgation, 2022-10-17 (Pasal 76), with two years for controllers to adjust their processing, to 2024-10-17 (Pasal 74). Detect a model-driven adverse decision with no objection route that sends the case to a person.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 17 Oct 2024
Official source
UU No. 27 Tahun 2022, Pasal 10 ayat (1) · captured 2 Oct 2026 · anchor hash (SHA-256) e636d3975648… · 8 more anchors in the data release
Verification
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Adverse status set in a different file from the model call
  • Outcomes expressed as numeric codes or enums
  • The objection route may live in a separate portal or letters module; a human reviewer who decides before the outcome takes effect means the decision is not solely automated.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision
  • Personal data controllers that make decisions about individuals based solely on automated processing, including profiling, with legal or significant effects on data subjects in Indonesia or Indonesian citizens abroad (Pasal 2, 10); in force 2022-10-17, adjustment period to 2024-10-17 (Pasal 74). The objection procedure is set by PP No. 33 of 2026, not yet captured; whether the two-year adjustment applies to data-subject rights, and what 'solely' automated means, are for counsel (review flag).
  • Not covered:
    • Processing by individuals in personal or household activities (Pasal 2(2))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Offer an ADMT opt-out (or a qualifying human appeal), store the consumer's choice, and check it before the model runs on any significant-decision path.

Two pieces: an opt-out endpoint linked from the pre-use notice (e.g. POST /privacy/admt-opt-out) that stores a per-consumer admt_opt_out preference, and a check at the top of the server-side decision function that reads that preference and routes opted-out consumers to a human decision-maker without calling the model. Where the business instead relies on a human appeal, the decision response carries an appeal route (POST /decisions/{id}/appeal) to a reviewer who can interpret the model output and overturn the decision. A UI-only toggle that the decision service never reads does not count.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Give people a route to object to decisions based solely on automated processing, including profiling, with legal or significant effects, and route objectors to a person (Pasal 10(1)).

Example (FastAPI + OpenAI SDK), before:

def decide_tenancy(applicant):
    resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
    return approve_or_deny(resp.choices[0].message.content)

After:

def decide_tenancy(applicant):
    if prefs.get(applicant.consumer_id, 'admt_opt_out'):
        return route_to_human(applicant, reason='admt_opt_out')   # model never runs
    resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
    return approve_or_deny(resp.choices[0].message.content)

@app.post('/privacy/admt-opt-out')
def admt_opt_out(user=Depends(current_user)):
    prefs.set(user.consumer_id, 'admt_opt_out', True)
    return {'opted_out': True}

Control: Automated decision tech without opt-out. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Meta says it will use people's interactions with Meta AI to personalize content and ads (2025-10; disclosed by the operator). On October 1, 2025 Meta announced that from December 16, 2025, in most regions, it would use people's interactions with AI at Meta to personalize the content and ads they see, with notifications to users starting October 7, 2025. Meta says that when people have conversations with Meta AI about topics such as their religious views, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs, or trade union membership, it does not use those topics to show them ads, and it points people to Ads Preferences and feed controls to adjust what they see. The entry records the operator's own description of its practice. Source: Meta Newsroom (2025-10-01) · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
  • Microsoft retires Azure Face emotion and identity-attribute inference (2022-06; disclosed by the operator). On June 21, 2022 Microsoft said it would retire Azure Face capabilities that infer emotional states and identity attributes such as gender, age, smile, facial hair, hair, and makeup: unavailable to new customers from that day, with existing customers given until June 30, 2023 to stop using them. Microsoft cited privacy, the lack of consensus on a definition of 'emotions', and the inability to generalize the link between facial expression and emotional state across use cases, regions, and demographics, and said that access to capabilities predicting sensitive attributes opens ways to misuse them, including stereotyping, discrimination, or unfair denial of services. It kept these capabilities for controlled accessibility scenarios such as Seeing AI. Source: Microsoft Azure Blog (2022-06-21) · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
  • Hungarian regulator fines a bank for AI analysis of callers' emotions without notice or a way to object (2017-05; confirmed). In decision NAIH-85-3/2022 of 8 February 2022, Hungary's data protection authority found that Budapest Bank's speech-analysis software, which the bank said it introduced on 26 May 2017, automatically analysed recorded customer-service calls for keywords and for the emotional state of the caller and the employee, and that the results were used to rank calls and to select dissatisfied customers to call back. The Authority found that callers were not told at the start of calls about the voice analysis, the automatic evaluation of their emotions, or the resulting possible callback, and could not object; it rejected the bank's statement that the software contained no artificial intelligence. It found infringements of GDPR Articles 5(1)(a)-(b), 6(1), 6(4), 12(1), 13, 21(1)-(2), 24(1) and 25(1), ordered the bank not to analyse emotions in the voice analysis, and imposed a fine of HUF 250 million. The decision also records, from the bank's own technical file, that the emotion was unrecognisable in 91.96% of cases. Source: Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian data protection authority), decision NAIH-85-3/2022, English version · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in

Rule id id-pdp-law.automated-decision-objection · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.