A bank, insurance or multifinance app that uses face verification, matches applicants against Dukcapil (the Home Affairs civil registry) and approves credit from a score meets at least four of the seven data protection impact assessment triggers in Article 34(2) of Law No. 27 of 2022 on Personal Data Protection (UU PDP): letters (a), (b), (d) and (e). The duty has bound since the two-year transition ended on 17 October 2024, and skipping it is on the administrative-sanction list in Article 57(1). Here's the catch. As of 15 September 2026, the body that Article 57(4) says imposes those sanctions hasn't been formed. The regulator that can act today is OJK, the Financial Services Authority, through POJK No. 22 of 2023, in force since 22 December 2023, with fines of up to Rp15 billion under each of Articles 19 and 24.
What follows is material for the decision memo a compliance officer or DPO will have to defend in front of an OJK examiner. It's also for group privacy teams outside Indonesia who expect a GDPR-built DPIA to carry over unchanged. Four parts of it don't.
Article 34(1) requires the Personal Data Controller to run an impact assessment where processing carries "potensi risiko tinggi", a high potential risk. Article 34(2) lists seven situations, introduced by "meliputi" (includes) and joined by "dan/atau" (and/or), so one letter is enough. The official Elucidation of 34(2) says only "Cukup jelas" (sufficiently clear). The law sets no numeric threshold for "large scale", doesn't define "new technology" and doesn't explain "matching".
The seven letters, in our translation. Only the Indonesian text is binding.
The table is our reading of that text against features common in onboarding and credit channels. It's analysis, not regulator guidance.
| Channel feature | Letters triggered by the text | Letters that depend on design | Textual basis |
|---|---|---|---|
| e-KYC with a face photo or fingerprint | (b) specific data | (c) | Article 4(2)(b); its Elucidation names "gambar wajah atau data daktiloskopi" (facial images or fingerprint data) |
| Liveness check and automated face match | (b), (e) | (a) if rejection happens without human review; (f); (g) if there is no alternative route | The face is matched against the ID photo: a "matching" activity under (e) |
| Credit or underwriting decision from a score | (b), (d) | (a) if approval or rejection is issued automatically; (e) if credit-bureau data is combined | (d) names "scoring"; Article 4(2)(f) "personal financial data"; Article 10(1) gives a right to object to automated decisions |
| NIK (national ID number) check against Dukcapil, or data pulled from SLIK, OJK's credit information system | (e); (b) for SLIK | (c) | "matching or combining a group of data" under (e) |
| Segmentation and profiling for push notifications | (d) | (a), (c); (e) if CRM data is combined | "systematic monitoring" under (d) |
| Behavioural analytics SDK inside the app | (d) | (c); (e) if the SDK combines data across apps | "systematic monitoring" under (d) of in-app behaviour |
| Health insurance products or laboratory results | (b) | (c), (d) | Article 4(2)(a) "health data and information" |
An app that combines biometric e-KYC, Dukcapil matching and automated credit decisions meets (a), (b), (d) and (e) without touching (c), (f) or (g). So "do we need a DPIA" doesn't belong in the memo. "Which letters, and what mitigation for each" does.
Article 4(2) puts "personal financial data" alongside health, biometric, genetic, criminal-record and children's data as specific personal data. An account-opening, loan-application or policy-purchase flow that handles balances, income or payment history therefore meets (b) before any biometric feature is added. POJK 22/2023 Article 19(2) also names the NIK and the mother's maiden name among the consumer data that must be protected, and its Elucidation mentions deposit balances and credit card data.
One correction to material in circulation: some Indonesian-language pages ranking for the term say UU PDP doesn't regulate DPIAs. It does. Article 34 calls it "penilaian dampak Pelindungan Data Pribadi".
Foreign-owned banks and insurers often inherit a group DPIA template written against GDPR Article 35. The structure transfers. These four rows don't.
| Point | GDPR (Regulation (EU) 2016/679) | UU PDP (Law No. 27 of 2022) |
|---|---|---|
| Listed triggers | Three cases in Article 35(3), plus lists published by supervisory authorities under Article 35(4) | Seven letters in Article 34(2), any one sufficient; no published list, and the Elucidation adds nothing |
| Financial data | Not a special category under Article 9 | Specific personal data under Article 4(2)(f), so letter (b) applies, with no large-scale qualifier |
| Fine ceiling for skipping the assessment | EUR 10 million or 2% of total worldwide annual turnover, whichever is higher (Article 83(4)) | 2% of annual revenue or receipts "terhadap variabel pelanggaran", measured against the violation variable rather than total revenue (Article 57(3)) |
| Who enforces today | A supervisory authority in each member state | The agency is not yet formed; OJK acts under POJK 22/2023 |
Two WEBARQ case studies show how features from the matrix appear in a real specification. We quote only what the published case studies say. They don't say whether a DPIA was ever carried out, and we don't imply otherwise.
Under UU PDP, nobody yet. Under POJK 22/2023, OJK, since 22 December 2023. The timeline:
| Date | Event | Source and status |
|---|---|---|
| 17 October 2022 | UU PDP enacted and in force (Article 76) | State Gazette 2022 No. 196, primary |
| 22 December 2023 | POJK 22/2023 enacted and in force (Article 125). No deferral of Articles 19 or 24 for banks, insurers or finance companies | Primary, ojk.go.id |
| 17 October 2024 | Article 74's two-year transition ends; the Article 34 duty binds in full | Calculated from Article 74 and the enactment date |
| 30 July 2025 | Constitutional Court Decision No. 151/PUU-XXII/2024 read out: "dan" (and) in Article 53(1)(b) is to be read as "dan/atau" (and/or) | Primary, the court's decision |
| 16 July 2026 | PP 33/2026, the government regulation implementing UU PDP, reportedly enacted | Secondary; official text not yet readable |
| 22 July 2026 | Deputy Minister of Communication and Digital Affairs Nezar Patria: the presidential regulation on personal data protection is targeted for completion in about two months | Primary, Komdigi release (our translation) |
| 15 September 2026 | No signed Perpres (presidential regulation) forming the agency found. The 2026 PP index in BPK's regulation database stops at PP 31/2026 | Our check; finding nothing is not proof it is unsigned |
| January 2027 | PP 33/2026 reportedly takes effect, six months after enactment | Secondary |
As of 15 September 2026 the DPIA duty has bound for 698 days with no method set by government regulation, although Article 34(3) delegates the detail to one. If PP 33/2026 takes effect in mid-January 2027 as reported, that gap reaches about 820 days. We don't quote any article of PP 33/2026 here, because we couldn't read an official copy from a government source. Check again once the text appears on peraturan.bpk.go.id or JDIH Setneg, the State Secretariat's legal database.
The gap concerns who imposes the sanction, not whether the duty applies. Article 34(1) has bound since 17 October 2024, agency or no agency.
Our view: waiting for the presidential regulation before running a DPIA is a bad bet. OJK isn't waiting for it, and an assessment signed before the channel goes live carries a date that can't be backfilled once an examination has started.
POJK 22/2023 doesn't contain the phrase "penilaian dampak" (impact assessment) anywhere. So the accurate statement isn't "POJK 22 requires a DPIA". It's that OJK can sanction the confidentiality, security or threat-identification failures a DPIA should have caught. That's our inference from these provisions:
In an examination, a documented DPIA is the shortest proof that the Article 24(3)(a) threat identification was done for that channel.
A vendor that builds and runs a channel for a bank is a Personal Data Processor when it processes data "on behalf of the Personal Data Controller" (Article 1 point 5). One thing can't be handed over: Article 52 applies Articles 29, 31, 35, 36, 37, 38 and 39 to processors, but not Article 34. The DPIA remains the institution's legal duty as controller, whatever the contract says. What can be bound to the vendor:
Due diligence on the vendor's security certificate is covered separately in ISO 27001 certification in Indonesia: the four-field vendor check. That certificate replaces none of the seven clauses above.
Until PP 33/2026 takes effect and its text can be read, the only binding guidance on content is the Elucidation of Article 34(1): the impact assessment evaluates the potential risks of the processing and the steps to mitigate them, including risks to data subjects' rights. A memo that holds up in front of an examiner has five lines:
Lines 1 and 4 are easiest to fill before a vendor is chosen: ask for the SDK list, sub-processors and external integrations together with the technical proposal. A vendor that can't produce them at proposal stage rarely produces them after signing. See also WEBARQ's website development services for regulated institutions.
Method: every statutory provision quoted was checked against the official PDFs of UU PDP (BPK), POJK 22/2023 (OJK) and Constitutional Court Decision 151/PUU-XXII/2024 on 15 September 2026. English renderings of Indonesian legal text are our own translation; only the Indonesian text is binding. The status of PP 33/2026 and of the agency's presidential regulation was checked on the same date. The GDPR comparison cites Regulation (EU) 2016/679 as published on EUR-Lex. Case-study quotes were checked against the case-study text on webarq.com. This article was prepared with AI assistance and is not legal advice.