what we do

Practice Areas

Data Protection & Cybersecurity

Data Protection & Cybersecurity

Practice Area

Indonesia's Personal Data Protection Law (Law No. 27 of 2022 / UU PDP) came into full legal effect in October 2024, establishing a comprehensive data protection regime that applies to all entities, domestic and foreign, that process the personal data of Indonesian data subjects. HWMA's data protection practice advises companies across all industries on building and implementing legally compliant personal data governance frameworks, including data inventories, lawful basis analysis, consent mechanisms, privacy policies, internal data protection procedures, and vendor data processing agreements. We assist clients with cross-border data transfer assessments, data localization obligations, and compliance with sector-specific data regulations issued by OJK, BI, and the Ministry of Communication and Digital Affairs (Komdigi). Our team advises on data subject rights implementation, data protection officer (DPO) roles, data breach notification procedures, and regulatory reporting obligations. We also conduct data protection compliance audits and gap analyses for organizations transitioning from legacy practices to full UU PDP compliance. On the cybersecurity side, we advise on legal obligations arising from Indonesia's Electronic Information and Transactions Law (UU ITE), Government Regulation No. 71/2019 (PP PDPSE), and sector-specific cybersecurity regulations. We assist clients in responding to cybersecurity incidents, managing regulatory investigations, and structuring contractual cyber risk allocations in technology and outsourcing agreements.

 

Lead Partners