You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 25, 2023

Personal Data Protection and Healthcare Services in Indonesia

One significant development in the health sector in Indonesia is the use of information technology and communication in the implementation of health efforts—particularly digital health services such as telehealth and telemedicine integrated into the country’s National Health Information System.

This development was addressed in a major new piece of legislation for the healthcare sector in Indonesia. Enacted in August 2023, Law No. 17 of 2023 concerning Health (the “Health Law”) provides the updates needed to support the development of healthcare services in Indonesia.

Under the Health Law, health information system (HIS) providers must:

  • Carry out processing of data and health information in the territory of Indonesia, except for certain limited and specific processing activities that may be conducted outside Indonesia when permitted by the relevant authorities and in compliance with relevant regulations.
  • Ensure the reliability of its HIS, including availability, security, maintenance, and integration with Indonesia’s National Health Information System.
  • Provide quality health data and information.
  • Process data and health information, which includes planning, collection, storage, inspection, transfer, utilization, and destruction.
  • Record its data- and information-processing history.
  • Protect every person’s data and health information.
  • Obtain approval from the relevant personal data subject or comply with relevant regulations if the processing of data and health information involves an individual’s health data.
  • Inform the data owner if there is a failure to protect data and individual health information.

The Health Law’s personal data protection requirements listed above appear to be aligned with the provisions in Law No. 27 of 2022 concerning Personal Data Protection (the “PDP Law”). Under this law, data and information relating to health are identified as “specific personal data,” the processing of which carries a high potential risk of impacting the relevant personal data subject.

In the implementation of digital health services, patients’ personal data or medical records must be generated by a health service facility. Health service facilities are responsible for the maintenance of the security, integrity, confidentiality, and availability of the data in Medical Records.

Regulatory Implementation of the PDP Law

In preparation for the implementation of the PDP Law, in September 2023 Indonesia’s Ministry of Communication and Information published the Draft Government Regulation regarding Implementation of PDP Law (the “Draft GR PDP”).

The provisions in the Draft GR PDP most relevant to digital health services and medical records are described below.

Personal Data Subject Rights

According to the Draft GR PDP, personal data subjects have the right to:

  • Terminate processing of personal data about themselves in accordance with relevant laws and regulations.
  • Delete personal data about themselves in accordance with relevant laws and regulations.
  • Destroy personal data about themselves in accordance with relevant laws and regulations.
  • Withdraw their previously given consent to the processing of personal data.
  • Object to decision-making actions based solely on automated processing (including profiling) that have legal consequences or a significant impact on the personal data subject.
  • Suspend or limit the processing of personal data proportionately in accordance with the purpose of processing the personal data.
  • Obtain and use personal data about themselves from the personal data controller in a form that fits a structure or format commonly used or readable by electronic systems.
  • Use and transmit personal data about themselves to other personal data controllers if the systems used can communicate with each other securely in accordance with the personal data protection principles.

Personal Data Controller Obligations

Among personal data controllers’ many obligations related to the protection of personal data in general, there are two related to health. Under the Draft GR PDP, personal data subjects have the right to complete, update, and correct errors or inaccuracies in personal data about them through the means provided by the personal data controller, either independently or by submitting a written request to the personal data controller, who must reject such a request if it:

  • Jeopardizes the security or physical or mental health of the personal data subject or others;
  • Impacts the disclosure of personal data belonging to others; or
  • Is contrary to the interests of national defense and security.

Personal data controllers must assess the impact of their processing of personal data related to health, because processing this type of data carries a high potential risk of impacting the relevant personal data subject.

Other than the obligations mentioned above, personal data controllers are also required to do the following, among others:

  • Have a basis for processing personal data;
  • Present evidence of personal data subjects’ consent to the processing of their personal data;
  • Carry out the processing of personal data in a limited, specific, legally valid, and transparent manner;
  • Carry out the processing of personal data in accordance with the declared purpose for processing the personal data;
  • Ensure the accuracy, completeness, and consistency of personal data in accordance with the provisions of laws and regulations;
  • Update or fix any errors or inaccuracies in personal data under their control;
  • Record all personal data processing activities; and
  • Provide personal data subjects with access to the processed personal data along with a record of processing activities during the period for which the personal data is retained.

Personal Data Processing

Besides identifying personal data subjects and personal data controllers as relevant parties in the processing of personal data, the Draft GR PDP also details the role of personal data processors. A personal data processor is a party who carries out personal data processing activities, appointed by through an agreement with the personal data controller.

The Draft GR PDP lays out criteria that must be followed in processing personal data. The collection of personal data must be done in a limited, specific, lawful, and transparent manner, and the processing of personal data must be conducted:

  • In accordance with the declared purpose for processing the personal data;
  • In a manner that guarantees the rights of the personal data subject;
  • In a manner that is accurate, complete, not misleading, up-to-date, and reliable.
  • In a manner that protects the security of personal data by preventing unauthorized access, unauthorized disclosure, unauthorized alteration, misuse, destruction, and erasure of the personal data;
  • By informing the personal data subject of its purpose and activities of processing, as well as any failure in protecting the personal data; and
  • Responsibly, as supported by clear evidence of the personal data processing activities.

Personal data must be destroyed or erased after the retention period ends or upon the request of the personal data subject, unless otherwise stipulated by laws or regulations.

Cross-Border Transfers of Personal Data

According to the Draft GR PDP, personal data controllers are allowed to transfer personal data to another personal data controller or personal data processor outside of Indonesia only after the personal data controller ensures that the intended receiver of the personal data has an equivalent or higher level of personal data protection. Personal data controllers must also ensure that there are adequate and binding personal data protection mechanisms in the receiver’s country. If the receiver’s country does not meet the requirements mentioned in Indonesia’s data protection laws and regulations, the personal data controller must obtain the personal data subject’s approval to transfer the data.

Next Steps

The publication of the Draft GR PDP suggests that the final implementing regulation will align with the Health Law and its implementing regulation in relation to the storage, processing, and transfer of health and medical data. This alignment is essential in order to enforce the protection of personal data in healthcare services in Indonesia. With these strong protections in place, patients and providers will benefit from greater security and privacy, leading to an overall better standard of care in Indonesia’s rapidly advancing digital and other health services.

RELATED INSIGHTS​ 

August 25, 2026
Thailand’s Electronic Transactions Development Agency (ETDA) is studying potential new regulatory measures for digital platform services that could significantly expand the country’s digital platform governance framework. The ETDA has already conducted one public consultation session on the proposed measures and will hold additional sessions on August 25 and September 2, 2026, covering five types of platform services under the Royal Decree on Digital Platform Services B.E. 2565 (2022). The measures under study are preliminary and may be changed based on consultation outcomes. Foundational Measures Applicable to All Platform Types Seven baseline obligations would apply across all digital platform categories: Transparency reports. Platforms must prepare and publish statistical reports on platform governance activities, including the number of content items removed or restricted and appeal outcomes, in a comparable format. Notice and action mechanism. Platforms must establish minimum standards for channels to report potentially illegal content or goods, conduct case-by-case review, provide explanations when content is removed or restricted, and maintain an internal appeals channel. Rights over automated decision-making. Users significantly affected by automated decisions are granted rights to request an explanation, request human review, and contest the decision. Service level agreements (SLAs). Platforms must publish minimum standards for response times, processing timelines, progress notifications, and remedies for incidents on the platform. Labeling of AI-generated content. Content generated or modified by AI must carry visible labels and machine-readable metadata, with exceptions for creative works that disclose AI use in a nonmisleading manner. Prohibition of dark patterns. User interface designs that deceive, coerce, or distort user decision-making are prohibited, including hiding critical information, creating false urgency, or making service cancellation unreasonably difficult. Business user fairness. Platforms must meet minimum standards for the treatment of sellers, workers, and content creators, including advance notice of term changes, explanation of account suspensions or visibility reductions,
August 20, 2026
Thailand has established a new cross-ministerial committee to oversee data center operations nationwide. On August 5, 2026, the Thai cabinet approved the Prime Minister’s Office Regulation on the Data Center Business Policy Committee, which was published in the Government Gazette on August 13, 2026, and is now in effect. The regulation reflects the government’s policy to elevate Thailand’s digital economy and promote investment in digital infrastructure and AI. The key features of the new committee are outlined below. Definition of “Data Center” Under the regulation, “data center” is defined as a building, premises, or structure that uses electronic equipment to provide services related to the collection, storage, processing, hosting, or transmission of data by electronic means to third parties that are not affiliates, as further determined by the Data Center Business Policy Committee. Committee Composition The committee will be chaired by a deputy prime minister designated by the prime minister, and will have three vice-chairs comprising the ministers of digital economy and society, interior, and energy. The committee also includes 12 ex-officio members: the permanent secretaries of finance, agriculture, natural resources, energy, interior, digital economy, industry, and commerce; the secretaries-general of the Board of Investment (BOI), Energy Regulatory Commission, National Broadcasting and Telecommunications Commission (NBTC), and National Water Resources Office; and the director of the Energy Policy and Planning Office. Up to three expert members may be appointed by the prime minister for two-year terms, renewable once. The secretary-general of the National Economic and Social Development Council (NESDC) serves as member and secretary, with up to two NESDC officials serving as assistant secretaries. Powers and Duties The committee is empowered to: Propose policies, standards, and operational frameworks for government agencies in approving, licensing, issuing investment promotion certificates, or providing services to data center operators in Thailand; Study, analyze, and
August 20, 2026
As part of its membership in Lex Mundi, Tilleke & Gibbins has released the latest edition of its Guide to Doing Business in Thailand, providing an overview of the legal, regulatory, and commercial considerations for companies establishing or expanding operations in Thailand. The 2026 edition offers practical insight into the country’s business environment, investment framework, and operational requirements. The guide covers a wide range of topics relevant to foreign and domestic investors, including: Investment incentives and promotion schemes Financial facilities and banking regulations Exchange controls and money transfers Import and export regulations Business structures and incorporation options Requirements for establishing a business Operational and compliance considerations Business cessation and insolvency procedures Employment and labor laws Taxation Immigration and visa requirements Prepared by Tilleke & Gibbins lawyers across multiple practice areas, the publication outlines key aspects of doing business in Thailand, including foreign investment restrictions, regulatory compliance obligations, corporate structures, employment requirements, and recent legal and economic developments affecting investors. The publication forms part of Lex Mundi’s Country Guides series, a global collection of jurisdiction-specific reference materials prepared by member firms around the world. Together, these guides help companies evaluate opportunities, compare regulatory environments, and plan international business activities across multiple markets. The full Guide to Doing Business in Thailand 2026 is available through the button below.
August 14, 2026
Thailand’s Office of the Insurance Commission (OIC) has issued guidelines clarifying the boundaries between permissible and prohibited activities for unlicensed individuals—including influencers, bloggers, and content creators—when communicating about insurance products on social media. The Good Practice Guidelines for Persons Not Licensed as Insurance Agents or Brokers Regarding the Dissemination of Insurance Content Through Digital Media B.E. 2569 (2026) took effect on July 24, 2026. Activities Requiring a License The guidelines reserve the following activities for licensed agents and brokers: Soliciting or facilitating insurance contracts. Providing personalized advice on product suitability. Recommending policy cancellation to purchase promoted products. Creating links that facilitate contract formation. Receiving performance-based compensation tied to policies or premiums generated. Importantly, boilerplate disclaimers such as “this is not a recommendation to buy insurance” will not shield individuals from liability if the OIC views the content as personalized advice or solicitation. Permitted Activities Unlicensed persons may present general educational content about insurance—such as explaining terminology, sharing industry statistics, reporting news, or sharing personal experiences—provided the content does not target specific individuals to purchase from specific companies. The guidelines also set out best practices for communication, including presenting information in a fair and balanced manner that covers both benefits and limitations, encouraging consumers to read policy terms and consult licensed professionals, verifying information from credible sources before dissemination, and exercising special care when the audience may include vulnerable groups such as persons aged 60 and older. Prohibited Practices Prohibited practices include fear-based marketing, creating artificial urgency, omitting material limitations, making exaggerated claims, falsely claiming professional credentials, using fake engagement mechanisms, and sharing false or misleading content. The guidelines also reinforce the prohibitions under section 83 of the Life Insurance Act B.E. 2535 and section 78 of the Non-Life Insurance Act B.E. 2535 against soliciting insurance contracts with foreign operators