Binding law — in force AI-adjacent law
People can object to decisions based solely on automated processing, including profiling (Indonesia PDP Law Art. 10)
Under Pasal 10(1) of Indonesia's Personal Data Protection Law (UU No. 27 of 2022), a data subject has the right to object to decision-making based solely on automated processing, including profiling, that produces legal effects or significantly affects the data subject; the procedure for objecting is left to a Government Regulation (Pasal 10(2)). Profiling means identifying a person, including from work history, economic condition, health, personal preferences, interests, reliability, behaviour, location or movements, electronically (Elucidation to Pasal 10(1)). The right does not apply for national defence and security, law enforcement, the public interest in running the state, supervision of the financial sector, monetary and payment systems and financial stability, or statistics and scientific research (Pasal 15). The Law binds every person, public body and international organisation, in Indonesia or abroad where there are legal effects in Indonesia or on Indonesian data subjects abroad (Pasal 2), in force on promulgation, 2022-10-17 (Pasal 76), with two years for controllers to adjust their processing, to 2024-10-17 (Pasal 74). Detect a model-driven adverse decision with no objection route that sends the case to a person.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
- Lane
- Binding law — in force In force: applies since 17 Oct 2024
- Official source
- UU No. 27 Tahun 2022, Pasal 10 ayat (1) · captured 2 Oct 2026 · anchor hash (SHA-256)
e636d3975648…· 8 more anchors in the data release - Verification
- Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Adverse status set in a different file from the model call
- Outcomes expressed as numeric codes or enums
- The objection route may live in a separate portal or letters module; a human reviewer who decides before the outcome takes effect means the decision is not solely automated.
Who it applies to
- Duty falls on: controller
- Systems covered: automated decision
- Personal data controllers that make decisions about individuals based solely on automated processing, including profiling, with legal or significant effects on data subjects in Indonesia or Indonesian citizens abroad (Pasal 2, 10); in force 2022-10-17, adjustment period to 2024-10-17 (Pasal 74). The objection procedure is set by PP No. 33 of 2026, not yet captured; whether the two-year adjustment applies to data-subject rights, and what 'solely' automated means, are for counsel (review flag).
- Not covered:
- Processing by individuals in personal or household activities (Pasal 2(2))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Offer an ADMT opt-out (or a qualifying human appeal), store the consumer's choice, and check it before the model runs on any significant-decision path.
Two pieces: an opt-out endpoint linked from the pre-use notice (e.g. POST /privacy/admt-opt-out) that stores a per-consumer admt_opt_out preference, and a check at the top of the server-side decision function that reads that preference and routes opted-out consumers to a human decision-maker without calling the model. Where the business instead relies on a human appeal, the decision response carries an appeal route (POST /decisions/{id}/appeal) to a reviewer who can interpret the model output and overturn the decision. A UI-only toggle that the decision service never reads does not count.
Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Give people a route to object to decisions based solely on automated processing, including profiling, with legal or significant effects, and route objectors to a person (Pasal 10(1)).
Example (FastAPI + OpenAI SDK), before:
def decide_tenancy(applicant):
resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
return approve_or_deny(resp.choices[0].message.content)After:
def decide_tenancy(applicant):
if prefs.get(applicant.consumer_id, 'admt_opt_out'):
return route_to_human(applicant, reason='admt_opt_out') # model never runs
resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
return approve_or_deny(resp.choices[0].message.content)
@app.post('/privacy/admt-opt-out')
def admt_opt_out(user=Depends(current_user)):
prefs.set(user.consumer_id, 'admt_opt_out', True)
return {'opted_out': True}Control: Automated decision tech without opt-out. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- Meta says it will use people's interactions with Meta AI to personalize content and ads (2025-10; disclosed by the operator). On October 1, 2025 Meta announced that from December 16, 2025, in most regions, it would use people's interactions with AI at Meta to personalize the content and ads they see, with notifications to users starting October 7, 2025. Meta says that when people have conversations with Meta AI about topics such as their religious views, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs, or trade union membership, it does not use those topics to show them ads, and it points people to Ads Preferences and feed controls to adjust what they see. The entry records the operator's own description of its practice. Source: Meta Newsroom (2025-10-01) · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
- Microsoft retires Azure Face emotion and identity-attribute inference (2022-06; disclosed by the operator). On June 21, 2022 Microsoft said it would retire Azure Face capabilities that infer emotional states and identity attributes such as gender, age, smile, facial hair, hair, and makeup: unavailable to new customers from that day, with existing customers given until June 30, 2023 to stop using them. Microsoft cited privacy, the lack of consensus on a definition of 'emotions', and the inability to generalize the link between facial expression and emotional state across use cases, regions, and demographics, and said that access to capabilities predicting sensitive attributes opens ways to misuse them, including stereotyping, discrimination, or unfair denial of services. It kept these capabilities for controlled accessibility scenarios such as Seeing AI. Source: Microsoft Azure Blog (2022-06-21) · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
- Hungarian regulator fines a bank for AI analysis of callers' emotions without notice or a way to object (2017-05; confirmed). In decision NAIH-85-3/2022 of 8 February 2022, Hungary's data protection authority found that Budapest Bank's speech-analysis software, which the bank said it introduced on 26 May 2017, automatically analysed recorded customer-service calls for keywords and for the emotional state of the caller and the employee, and that the results were used to rank calls and to select dissatisfied customers to call back. The Authority found that callers were not told at the start of calls about the voice analysis, the automatic evaluation of their emotions, or the resulting possible callback, and could not object; it rejected the bank's statement that the software contained no artificial intelligence. It found infringements of GDPR Articles 5(1)(a)-(b), 6(1), 6(4), 12(1), 13, 21(1)-(2), 24(1) and 25(1), ordered the bank not to analyse emotions in the voice analysis, and imposed a fine of HUF 250 million. The decision also records, from the bank's own technical file, that the emotion was unrecognisable in 91.96% of cases. Source: Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian data protection authority), decision NAIH-85-3/2022, English version · evidence grade: primary · cited by Do not profile people from AI-inferred emotions or sensitive traits without notice and opt-in
Rule id id-pdp-law.automated-decision-objection · review status: primary source derived