Read Time
Categories
Share
Which bank and insurance channel features legally require a DPIA under UU PDP Article 34, who can sanction a skipped one today, and what to bind the vendor to.

A bank, insurance or multifinance app that uses face verification, matches applicants against Dukcapil (the Home Affairs civil registry) and approves credit from a score meets at least four of the seven data protection impact assessment triggers in Article 34(2) of Law No. 27 of 2022 on Personal Data Protection (UU PDP): letters (a), (b), (d) and (e). The duty has bound since the two-year transition ended on 17 October 2024, and skipping it is on the administrative-sanction list in Article 57(1). Here's the catch. As of 15 September 2026, the body that Article 57(4) says imposes those sanctions hasn't been formed. The regulator that can act today is OJK, the Financial Services Authority, through POJK No. 22 of 2023, in force since 22 December 2023, with fines of up to Rp15 billion under each of Articles 19 and 24.

What follows is material for the decision memo a compliance officer or DPO will have to defend in front of an OJK examiner. It's also for group privacy teams outside Indonesia who expect a GDPR-built DPIA to carry over unchanged. Four parts of it don't.

Article 34(2) DPIA triggers mapped to digital-channel features

Article 34(1) requires the Personal Data Controller to run an impact assessment where processing carries "potensi risiko tinggi", a high potential risk. Article 34(2) lists seven situations, introduced by "meliputi" (includes) and joined by "dan/atau" (and/or), so one letter is enough. The official Elucidation of 34(2) says only "Cukup jelas" (sufficiently clear). The law sets no numeric threshold for "large scale", doesn't define "new technology" and doesn't explain "matching".

The seven letters, in our translation. Only the Indonesian text is binding.

  • (a) automated decision-making with legal consequences or a significant impact on the data subject
  • (b) processing of specific personal data
  • (c) large-scale processing
  • (d) systematic evaluation, scoring or monitoring of data subjects
  • (e) matching or combining groups of data
  • (f) use of new technology in processing
  • (g) processing that restricts the exercise of data subjects' rights

The table is our reading of that text against features common in onboarding and credit channels. It's analysis, not regulator guidance.

Channel featureLetters triggered by the textLetters that depend on designTextual basis
e-KYC with a face photo or fingerprint(b) specific data(c)Article 4(2)(b); its Elucidation names "gambar wajah atau data daktiloskopi" (facial images or fingerprint data)
Liveness check and automated face match(b), (e)(a) if rejection happens without human review; (f); (g) if there is no alternative routeThe face is matched against the ID photo: a "matching" activity under (e)
Credit or underwriting decision from a score(b), (d)(a) if approval or rejection is issued automatically; (e) if credit-bureau data is combined(d) names "scoring"; Article 4(2)(f) "personal financial data"; Article 10(1) gives a right to object to automated decisions
NIK (national ID number) check against Dukcapil, or data pulled from SLIK, OJK's credit information system(e); (b) for SLIK(c)"matching or combining a group of data" under (e)
Segmentation and profiling for push notifications(d)(a), (c); (e) if CRM data is combined"systematic monitoring" under (d)
Behavioural analytics SDK inside the app(d)(c); (e) if the SDK combines data across apps"systematic monitoring" under (d) of in-app behaviour
Health insurance products or laboratory results(b)(c), (d)Article 4(2)(a) "health data and information"

An app that combines biometric e-KYC, Dukcapil matching and automated credit decisions meets (a), (b), (d) and (e) without touching (c), (f) or (g). So "do we need a DPIA" doesn't belong in the memo. "Which letters, and what mitigation for each" does.

Personal financial data already triggers almost every core flow

Article 4(2) puts "personal financial data" alongside health, biometric, genetic, criminal-record and children's data as specific personal data. An account-opening, loan-application or policy-purchase flow that handles balances, income or payment history therefore meets (b) before any biometric feature is added. POJK 22/2023 Article 19(2) also names the NIK and the mother's maiden name among the consumer data that must be protected, and its Elucidation mentions deposit balances and credit card data.

One correction to material in circulation: some Indonesian-language pages ranking for the term say UU PDP doesn't regulate DPIAs. It does. Article 34 calls it "penilaian dampak Pelindungan Data Pribadi".

Where a GDPR-built DPIA template goes wrong in Indonesia

Foreign-owned banks and insurers often inherit a group DPIA template written against GDPR Article 35. The structure transfers. These four rows don't.

PointGDPR (Regulation (EU) 2016/679)UU PDP (Law No. 27 of 2022)
Listed triggersThree cases in Article 35(3), plus lists published by supervisory authorities under Article 35(4)Seven letters in Article 34(2), any one sufficient; no published list, and the Elucidation adds nothing
Financial dataNot a special category under Article 9Specific personal data under Article 4(2)(f), so letter (b) applies, with no large-scale qualifier
Fine ceiling for skipping the assessmentEUR 10 million or 2% of total worldwide annual turnover, whichever is higher (Article 83(4))2% of annual revenue or receipts "terhadap variabel pelanggaran", measured against the violation variable rather than total revenue (Article 57(3))
Who enforces todayA supervisory authority in each member stateThe agency is not yet formed; OJK acts under POJK 22/2023

How the triggers show up in projects we have built

Two WEBARQ case studies show how features from the matrix appear in a real specification. We quote only what the published case studies say. They don't say whether a DPIA was ever carried out, and we don't imply otherwise.

  • CGS International (securities): investor onboarding through a web form "with OCR technology, augmented by video call and self-verification", linked to banks, CGS-CIMB, KSEI (the central securities depository) and DUKCAPIL "for real-time data accuracy". In the matrix, that Dukcapil and KSEI matching is letter (e). The case study doesn't mention face matching, so biometric (b) can't be inferred from it.
  • Prodia (clinical laboratory): dashboards for hospitals and corporate clients, built to "implement advanced analytics for real-time lab data processing", with lab results integrated into billing systems and a courier app carrying "real-time location tracking and scheduling". Lab results are health data under Article 4(2)(a), so (b) is triggered as soon as those results are tied to a patient's identity.

Who can sanction an institution that skips a DPIA today

Under UU PDP, nobody yet. Under POJK 22/2023, OJK, since 22 December 2023. The timeline:

DateEventSource and status
17 October 2022UU PDP enacted and in force (Article 76)State Gazette 2022 No. 196, primary
22 December 2023POJK 22/2023 enacted and in force (Article 125). No deferral of Articles 19 or 24 for banks, insurers or finance companiesPrimary, ojk.go.id
17 October 2024Article 74's two-year transition ends; the Article 34 duty binds in fullCalculated from Article 74 and the enactment date
30 July 2025Constitutional Court Decision No. 151/PUU-XXII/2024 read out: "dan" (and) in Article 53(1)(b) is to be read as "dan/atau" (and/or)Primary, the court's decision
16 July 2026PP 33/2026, the government regulation implementing UU PDP, reportedly enactedSecondary; official text not yet readable
22 July 2026Deputy Minister of Communication and Digital Affairs Nezar Patria: the presidential regulation on personal data protection is targeted for completion in about two monthsPrimary, Komdigi release (our translation)
15 September 2026No signed Perpres (presidential regulation) forming the agency found. The 2026 PP index in BPK's regulation database stops at PP 31/2026Our check; finding nothing is not proof it is unsigned
January 2027PP 33/2026 reportedly takes effect, six months after enactmentSecondary

As of 15 September 2026 the DPIA duty has bound for 698 days with no method set by government regulation, although Article 34(3) delegates the detail to one. If PP 33/2026 takes effect in mid-January 2027 as reported, that gap reaches about 820 days. We don't quote any article of PP 33/2026 here, because we couldn't read an official copy from a government source. Check again once the text appears on peraturan.bpk.go.id or JDIH Setneg, the State Secretariat's legal database.

The UU PDP route: the sanction exists, the body that imposes it doesn't

  • Article 57(1) lists Article 34(1). Skipping a DPIA is a violation subject to administrative sanctions. The law draws no "serious" or "minor" grades for it.
  • Article 57(2): written warning, temporary suspension of processing, erasure or destruction of personal data, and/or an administrative fine.
  • Article 57(3): a fine of at most 2% of annual revenue or annual receipts "terhadap variabel pelanggaran". The cap runs against the violation variable, not the institution's total revenue.
  • Article 57(4): sanctions are "diberikan oleh lembaga", imposed by the agency. Article 58(3) and (5) say the agency is established by the President and governed by presidential regulation, and as of today that regulation hasn't been found.
  • Article 50(1)(d) exempts certain obligations in the interest of financial services sector supervision. Article 34 isn't one of them.

The gap concerns who imposes the sanction, not whether the duty applies. Article 34(1) has bound since 17 October 2024, agency or no agency.

Our view: waiting for the presidential regulation before running a DPIA is a bad bet. OJK isn't waiting for it, and an assessment signed before the channel goes live carries a date that can't be backfilled once an examination has started.

The OJK route: sanctioning the failures a DPIA should have caught

POJK 22/2023 doesn't contain the phrase "penilaian dampak" (impact assessment) anywhere. So the accurate statement isn't "POJK 22 requires a DPIA". It's that OJK can sanction the confidentiality, security or threat-identification failures a DPIA should have caught. That's our inference from these provisions:

  1. Article 19(1): a PUJK, the regulation's term for a financial services business, "wajib menjaga kerahasiaan dan keamanan data dan/atau informasi Konsumen" (must keep consumer data and information confidential and secure). Article 2 names commercial banks, BPRs (rural banks), insurance companies and finance companies as PUJK.
  2. Article 19(3): that duty is carried out by applying the core processing principles of personal data protection law. This clause is how UU PDP's method enters an obligation OJK supervises.
  3. Article 24(1) and (3)(a): the PUJK must ensure information-system security and cyber resilience, at minimum through "identifikasi aset, ancaman, dan kerentanan" (identifying assets, threats and vulnerabilities).
  4. Article 19(6) to (8): sanctions run from written warning, restriction of products or services, freezing, dismissal of management and fines up to revocation of a product licence and of the business licence. Any sanction other than a warning can be imposed without a warning first. The fine for Article 19 is capped at Rp15,000,000,000, and Article 24(8) carries its own separate Rp15 billion cap.

In an examination, a documented DPIA is the shortest proof that the Article 24(3)(a) threat identification was done for that channel.

Clauses to lock into the channel build vendor's contract

A vendor that builds and runs a channel for a bank is a Personal Data Processor when it processes data "on behalf of the Personal Data Controller" (Article 1 point 5). One thing can't be handed over: Article 52 applies Articles 29, 31, 35, 36, 37, 38 and 39 to processors, but not Article 34. The DPIA remains the institution's legal duty as controller, whatever the contract says. What can be bound to the vendor:

  1. Processing only on the controller's written instructions. Article 51(1), which is on the Article 57(1) sanction list. Processing outside those instructions and purposes becomes the processor's responsibility (Article 51(6)).
  2. Written approval before any sub-processor is engaged, including cloud providers, OCR services and SDK vendors. Article 51(5), also on the Article 57(1) list, and Article 60(c) makes the processor directly sanctionable.
  3. The same security and confidentiality duties as the controller: Articles 35 to 39 through Article 52, also on the sanction list.
  4. The duty to keep consumer data confidential and secure under POJK 22/2023 Article 19(4). The duty to ensure it sits with the PUJK, and a fine of up to Rp15 billion lands on the institution, not the vendor.
  5. Incident notice from the vendor carrying the Article 46(2) minimum: the data exposed, when and how it was exposed, and the handling and recovery effort. The vendor's deadline has to be short enough for the institution to notify data subjects and the agency within 3×24 hours (Article 46(1)). UU PDP sets no deadline for processors, so this one exists only if the contract writes it in. A GDPR reader should note that the 72 hours in GDPR Article 33 run to the supervisory authority; Article 46(1) puts the data subjects on the same clock.
  6. A duty to hand over design information for the controller's DPIA: data-flow diagrams, the list of SDKs and sub-processors, storage locations, automated-decision logic. This is our inference from Article 52. Without it, letters (a), (e) and (f) in the matrix can't be assessed.
  7. A data protection officer on the vendor side where the criteria are met. Article 53(1) binds controllers and processors. After Constitutional Court Decision 151/PUU-XXII/2024, the criteria in that article are read with "and/or", so a vendor whose core activity is large-scale processing of specific data may have to appoint its own DPO. Raise it as a due-diligence question, not an assumption.

Due diligence on the vendor's security certificate is covered separately in ISO 27001 certification in Indonesia: the four-field vendor check. That certificate replaces none of the seven clauses above.

What the decision memo should contain before the channel goes live

Until PP 33/2026 takes effect and its text can be read, the only binding guidance on content is the Elucidation of Article 34(1): the impact assessment evaluates the potential risks of the processing and the steps to mitigate them, including risks to data subjects' rights. A memo that holds up in front of an examiner has five lines:

  1. Every channel feature, mapped to the Article 34(2) letters it triggers, with written reasons for each letter declared not triggered. With no official threshold for "large scale", give it an internal number, such as data subjects per year.
  2. For each triggered letter, the mitigation and its owner. For (a), a human-review route that honours the Article 10(1) right to object.
  3. A mapping of those mitigations to POJK 22/2023 Article 24(3)(a) to (d), so the same document answers OJK's questions.
  4. The processors and sub-processors, with the contract clause numbers that bind the seven points above.
  5. The assessment date, the signatory, and a commitment to reassess once PP 33/2026 takes effect in January 2027, because its method and definitions may differ from today's reading.

Lines 1 and 4 are easiest to fill before a vendor is chosen: ask for the SDK list, sub-processors and external integrations together with the technical proposal. A vendor that can't produce them at proposal stage rarely produces them after signing. See also WEBARQ's website development services for regulated institutions.

Method: every statutory provision quoted was checked against the official PDFs of UU PDP (BPK), POJK 22/2023 (OJK) and Constitutional Court Decision 151/PUU-XXII/2024 on 15 September 2026. English renderings of Indonesian legal text are our own translation; only the Indonesian text is binding. The status of PP 33/2026 and of the agency's presidential regulation was checked on the same date. The GDPR comparison cites Regulation (EU) 2016/679 as published on EUR-Lex. Case-study quotes were checked against the case-study text on webarq.com. This article was prepared with AI assistance and is not legal advice.

Back to List