You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 25, 2023

Personal Data Protection and Healthcare Services in Indonesia

One significant development in the health sector in Indonesia is the use of information technology and communication in the implementation of health efforts—particularly digital health services such as telehealth and telemedicine integrated into the country’s National Health Information System.

This development was addressed in a major new piece of legislation for the healthcare sector in Indonesia. Enacted in August 2023, Law No. 17 of 2023 concerning Health (the “Health Law”) provides the updates needed to support the development of healthcare services in Indonesia.

Under the Health Law, health information system (HIS) providers must:

  • Carry out processing of data and health information in the territory of Indonesia, except for certain limited and specific processing activities that may be conducted outside Indonesia when permitted by the relevant authorities and in compliance with relevant regulations.
  • Ensure the reliability of its HIS, including availability, security, maintenance, and integration with Indonesia’s National Health Information System.
  • Provide quality health data and information.
  • Process data and health information, which includes planning, collection, storage, inspection, transfer, utilization, and destruction.
  • Record its data- and information-processing history.
  • Protect every person’s data and health information.
  • Obtain approval from the relevant personal data subject or comply with relevant regulations if the processing of data and health information involves an individual’s health data.
  • Inform the data owner if there is a failure to protect data and individual health information.

The Health Law’s personal data protection requirements listed above appear to be aligned with the provisions in Law No. 27 of 2022 concerning Personal Data Protection (the “PDP Law”). Under this law, data and information relating to health are identified as “specific personal data,” the processing of which carries a high potential risk of impacting the relevant personal data subject.

In the implementation of digital health services, patients’ personal data or medical records must be generated by a health service facility. Health service facilities are responsible for the maintenance of the security, integrity, confidentiality, and availability of the data in Medical Records.

Regulatory Implementation of the PDP Law

In preparation for the implementation of the PDP Law, in September 2023 Indonesia’s Ministry of Communication and Information published the Draft Government Regulation regarding Implementation of PDP Law (the “Draft GR PDP”).

The provisions in the Draft GR PDP most relevant to digital health services and medical records are described below.

Personal Data Subject Rights

According to the Draft GR PDP, personal data subjects have the right to:

  • Terminate processing of personal data about themselves in accordance with relevant laws and regulations.
  • Delete personal data about themselves in accordance with relevant laws and regulations.
  • Destroy personal data about themselves in accordance with relevant laws and regulations.
  • Withdraw their previously given consent to the processing of personal data.
  • Object to decision-making actions based solely on automated processing (including profiling) that have legal consequences or a significant impact on the personal data subject.
  • Suspend or limit the processing of personal data proportionately in accordance with the purpose of processing the personal data.
  • Obtain and use personal data about themselves from the personal data controller in a form that fits a structure or format commonly used or readable by electronic systems.
  • Use and transmit personal data about themselves to other personal data controllers if the systems used can communicate with each other securely in accordance with the personal data protection principles.

Personal Data Controller Obligations

Among personal data controllers’ many obligations related to the protection of personal data in general, there are two related to health. Under the Draft GR PDP, personal data subjects have the right to complete, update, and correct errors or inaccuracies in personal data about them through the means provided by the personal data controller, either independently or by submitting a written request to the personal data controller, who must reject such a request if it:

  • Jeopardizes the security or physical or mental health of the personal data subject or others;
  • Impacts the disclosure of personal data belonging to others; or
  • Is contrary to the interests of national defense and security.

Personal data controllers must assess the impact of their processing of personal data related to health, because processing this type of data carries a high potential risk of impacting the relevant personal data subject.

Other than the obligations mentioned above, personal data controllers are also required to do the following, among others:

  • Have a basis for processing personal data;
  • Present evidence of personal data subjects’ consent to the processing of their personal data;
  • Carry out the processing of personal data in a limited, specific, legally valid, and transparent manner;
  • Carry out the processing of personal data in accordance with the declared purpose for processing the personal data;
  • Ensure the accuracy, completeness, and consistency of personal data in accordance with the provisions of laws and regulations;
  • Update or fix any errors or inaccuracies in personal data under their control;
  • Record all personal data processing activities; and
  • Provide personal data subjects with access to the processed personal data along with a record of processing activities during the period for which the personal data is retained.

Personal Data Processing

Besides identifying personal data subjects and personal data controllers as relevant parties in the processing of personal data, the Draft GR PDP also details the role of personal data processors. A personal data processor is a party who carries out personal data processing activities, appointed by through an agreement with the personal data controller.

The Draft GR PDP lays out criteria that must be followed in processing personal data. The collection of personal data must be done in a limited, specific, lawful, and transparent manner, and the processing of personal data must be conducted:

  • In accordance with the declared purpose for processing the personal data;
  • In a manner that guarantees the rights of the personal data subject;
  • In a manner that is accurate, complete, not misleading, up-to-date, and reliable.
  • In a manner that protects the security of personal data by preventing unauthorized access, unauthorized disclosure, unauthorized alteration, misuse, destruction, and erasure of the personal data;
  • By informing the personal data subject of its purpose and activities of processing, as well as any failure in protecting the personal data; and
  • Responsibly, as supported by clear evidence of the personal data processing activities.

Personal data must be destroyed or erased after the retention period ends or upon the request of the personal data subject, unless otherwise stipulated by laws or regulations.

Cross-Border Transfers of Personal Data

According to the Draft GR PDP, personal data controllers are allowed to transfer personal data to another personal data controller or personal data processor outside of Indonesia only after the personal data controller ensures that the intended receiver of the personal data has an equivalent or higher level of personal data protection. Personal data controllers must also ensure that there are adequate and binding personal data protection mechanisms in the receiver’s country. If the receiver’s country does not meet the requirements mentioned in Indonesia’s data protection laws and regulations, the personal data controller must obtain the personal data subject’s approval to transfer the data.

Next Steps

The publication of the Draft GR PDP suggests that the final implementing regulation will align with the Health Law and its implementing regulation in relation to the storage, processing, and transfer of health and medical data. This alignment is essential in order to enforce the protection of personal data in healthcare services in Indonesia. With these strong protections in place, patients and providers will benefit from greater security and privacy, leading to an overall better standard of care in Indonesia’s rapidly advancing digital and other health services.

RELATED INSIGHTS​ 

September 11, 2026
Thailand’s National Broadcasting and Telecommunications Commission (NBTC) has published a new five-year master plan that will bring significant regulatory changes to the broadcasting and digital media sectors, including formal licensing requirements for internet-based audiovisual services. The Master Plan for Broadcasting and Television, 3rd Edition (B.E. 2569–2573/2026–2030) was published in the Government Gazette on September 1, 2026, and will affect OTT platforms, internet-based audiovisual service providers, and traditional broadcasters. Licensing Reform The NBTC will develop new licensing frameworks ahead of existing digital television license expirations, which are slated to occur between 2028 and 2030. This creates both uncertainty and opportunity for incumbents and new market entrants. New licensing criteria will also be developed for audiovisual services delivered over the internet, meaning previously unregulated internet-based providers may face licensing, fee, and content obligations for the first time. The plan also calls for a new law to govern converged communications services. OTT Regulation and Content Oversight The plan explicitly acknowledges and aims to lessen the regulatory asymmetry between traditional broadcasters—which are subject to licensing, fees, and content regulation—and internet-based services that currently face fewer obligations. The NBTC intends to develop regulatory frameworks to bring internet-based audiovisual services, including OTT platforms, streaming services, and user-generated content platforms, under content, consumer protection, and licensing requirements. Consumer Protection and Digital Rights The NBTC will strengthen its oversight of broadcasting, television, and telecommunications operators to ensure compliance with consumer protection and personal data protection requirements. This includes updating relevant notifications and orders and more strictly enforcing rules against practices that unfairly exploit consumers. These measures may layer NBTC-specific requirements on top of Thailand’s existing Personal Data Protection Act obligations. Stricter enforcement against practices that exploit consumers is a priority, with particular scrutiny on advertising practices. The NBTC will modernize complaint resolution processes, meaning service providers should
September 9, 2026
On August 5, 2026, the Consumer Case Division of Thailand’s Civil Court rendered a judgment in a case involving a beauty clinic that advertised acne scar treatments using claims that the clinic was operated by a specialist physician and that the treatment, allegedly involving stem cell technology, could permanently remove acne scars. The plaintiff brought a claim against both the physician-owner and the clinic company, alleging that the advertisements were false and induced her to purchase the treatment. The court found that the clinic was liable for the false representations and that the physician-owner, as both the authorized director of the company and the medical practitioner who provided treatment, was jointly responsible. Although the plaintiff could not fully prove all damages claimed, the court awarded compensation of THB 20,000, together with interest. While the judgment arose from a consumer protection dispute, it serves as a valuable reminder that medical facility advertisements in Thailand are regulated and may expose clinics and healthcare providers not only to regulatory enforcement but also to civil liability from patients who rely on misleading promotional claims. Regulatory Framework Governing Medical Facility Advertisements Medical facility advertising in Thailand is governed by the Medical Facility Act B.E. 2541 (1998), as amended by the Medical Facility Act (No. 4) B.E. 2559 (2016). The principal secondary legislation is the Department of Health Service Support (DoHSS) Notification Re: Rules, Procedures, Conditions, and Fees for an Advertisement or Publication Concerning a Medical Facility, which came into force on November 25, 2019. Under this notification, “advertising” includes any act, by any means, that causes members of the public to see, hear, or otherwise become aware of a message, sound, or image for the commercial benefit of a medical facility. This broad definition covers not only traditional media but also clinic websites, social
September 9, 2026
On June 30, 2026, Indonesia’s National Agency of Drug and Food Control (BPOM) issued BPOM Regulation No. 11 of 2026 on Food Packaging, which expands the list of approved food-contact substances and recognizes a broader range of permissible functions for those substances. The new regulation, which revokes BPOM Regulation No. 20 of 2019, reflects developments in packaging technology and materials science. Although the new regulation provides more advantages to business actors by adding more food contact substances to the approved list for use in food packaging, there are more stringent rules and restrictions for testing. One of the most significant changes is a comprehensive migration-testing framework that sets out requirements for packaging materials, testing conditions, food simulants, and specific migration limits. Overall and Specific Migration Under BPOM Regulation No. 20 of 2019, migration requirements were primarily set out within the lists of approved food-contact substances and packaging materials. BPOM Regulation No. 11 of 2026 instead expressly requires packaging materials that come into direct contact with food to meet both overall and specific migration limits. These are defined as follows: Overall migration: The total quantity of all substances that migrate from the packaging, regardless of whether the substances are hazardous or nonhazardous to health. Specific migration: The quantity of a particular identified substance known to be hazardous to health that migrates from the packaging. Stricter Limits on Heavy Metals The overall migration limit for plastic packaging remains unchanged under both regulations at 60 mg/kg or 10 mg/dm². However, the new regulation introduces significant changes to the regulation of heavy metals. Under the 2019 regulation, four heavy metals—lead, cadmium, chromium VI, and mercury—were subject to a single combined limit of 1 mg/kg. The 2026 regulation, however, requires each heavy metal to meet its own individual specific migration limit, adds arsenic as
September 7, 2026
On September 4, 2026, Thailand’s prime minister convened the first meeting of the Data Center Business Policy Committee. The committee endorsed a draft policy framework for the data center industry and tasked four subcommittees with developing the standards that would sit beneath it, shifting away from fragmented, agency-by-agency approvals toward a unified national strategy aiming to maximize economic value while managing environmental and infrastructure concerns. Proposed Scope and Pillars of the National Data Center Policy Framework The proposed framework would cover all types of data centers, including internal or captive facilities operated within a company or its affiliates, rather than only commercial third-party providers. If adopted in this form, companies running private data centers purely for internal purposes would also become subject to regulatory oversight. Minimum safety and operational standards would be established, with uniform enforcement across all categories. The committee endorsed a draft policy framework with four key pillars: Industrial classification: Data centers exceeding 2 MW would be classified as industrial operations, which may require factory licenses and environmental impact assessments under the Factory Act. Resource pricing: Utility rates would be structured to reflect both direct and indirect costs, supporting green energy and green data center standards. Centralized screening: A centralized review would evaluate project suitability and resource allocation. Operators may be required to submit proposals through periodic “pitching” rounds, where projects are competitively assessed on their potential economic and strategic benefits to Thailand. Digital ecosystem: The framework would prioritize data sovereignty, tax incentives, and conditions promoting domestic digital businesses, AI, and cloud infrastructure. Multidimensional Evaluation Criteria and Subcommittees Four subcommittees will be established to develop standards responsible for the following dimensions: Economic: Criteria for assessing the economic viability of data center projects, for use in prioritizing data centers based on infrastructure readiness, demand type (including AI factories),