You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 25, 2023

Personal Data Protection and Healthcare Services in Indonesia

One significant development in the health sector in Indonesia is the use of information technology and communication in the implementation of health efforts—particularly digital health services such as telehealth and telemedicine integrated into the country’s National Health Information System.

This development was addressed in a major new piece of legislation for the healthcare sector in Indonesia. Enacted in August 2023, Law No. 17 of 2023 concerning Health (the “Health Law”) provides the updates needed to support the development of healthcare services in Indonesia.

Under the Health Law, health information system (HIS) providers must:

  • Carry out processing of data and health information in the territory of Indonesia, except for certain limited and specific processing activities that may be conducted outside Indonesia when permitted by the relevant authorities and in compliance with relevant regulations.
  • Ensure the reliability of its HIS, including availability, security, maintenance, and integration with Indonesia’s National Health Information System.
  • Provide quality health data and information.
  • Process data and health information, which includes planning, collection, storage, inspection, transfer, utilization, and destruction.
  • Record its data- and information-processing history.
  • Protect every person’s data and health information.
  • Obtain approval from the relevant personal data subject or comply with relevant regulations if the processing of data and health information involves an individual’s health data.
  • Inform the data owner if there is a failure to protect data and individual health information.

The Health Law’s personal data protection requirements listed above appear to be aligned with the provisions in Law No. 27 of 2022 concerning Personal Data Protection (the “PDP Law”). Under this law, data and information relating to health are identified as “specific personal data,” the processing of which carries a high potential risk of impacting the relevant personal data subject.

In the implementation of digital health services, patients’ personal data or medical records must be generated by a health service facility. Health service facilities are responsible for the maintenance of the security, integrity, confidentiality, and availability of the data in Medical Records.

Regulatory Implementation of the PDP Law

In preparation for the implementation of the PDP Law, in September 2023 Indonesia’s Ministry of Communication and Information published the Draft Government Regulation regarding Implementation of PDP Law (the “Draft GR PDP”).

The provisions in the Draft GR PDP most relevant to digital health services and medical records are described below.

Personal Data Subject Rights

According to the Draft GR PDP, personal data subjects have the right to:

  • Terminate processing of personal data about themselves in accordance with relevant laws and regulations.
  • Delete personal data about themselves in accordance with relevant laws and regulations.
  • Destroy personal data about themselves in accordance with relevant laws and regulations.
  • Withdraw their previously given consent to the processing of personal data.
  • Object to decision-making actions based solely on automated processing (including profiling) that have legal consequences or a significant impact on the personal data subject.
  • Suspend or limit the processing of personal data proportionately in accordance with the purpose of processing the personal data.
  • Obtain and use personal data about themselves from the personal data controller in a form that fits a structure or format commonly used or readable by electronic systems.
  • Use and transmit personal data about themselves to other personal data controllers if the systems used can communicate with each other securely in accordance with the personal data protection principles.

Personal Data Controller Obligations

Among personal data controllers’ many obligations related to the protection of personal data in general, there are two related to health. Under the Draft GR PDP, personal data subjects have the right to complete, update, and correct errors or inaccuracies in personal data about them through the means provided by the personal data controller, either independently or by submitting a written request to the personal data controller, who must reject such a request if it:

  • Jeopardizes the security or physical or mental health of the personal data subject or others;
  • Impacts the disclosure of personal data belonging to others; or
  • Is contrary to the interests of national defense and security.

Personal data controllers must assess the impact of their processing of personal data related to health, because processing this type of data carries a high potential risk of impacting the relevant personal data subject.

Other than the obligations mentioned above, personal data controllers are also required to do the following, among others:

  • Have a basis for processing personal data;
  • Present evidence of personal data subjects’ consent to the processing of their personal data;
  • Carry out the processing of personal data in a limited, specific, legally valid, and transparent manner;
  • Carry out the processing of personal data in accordance with the declared purpose for processing the personal data;
  • Ensure the accuracy, completeness, and consistency of personal data in accordance with the provisions of laws and regulations;
  • Update or fix any errors or inaccuracies in personal data under their control;
  • Record all personal data processing activities; and
  • Provide personal data subjects with access to the processed personal data along with a record of processing activities during the period for which the personal data is retained.

Personal Data Processing

Besides identifying personal data subjects and personal data controllers as relevant parties in the processing of personal data, the Draft GR PDP also details the role of personal data processors. A personal data processor is a party who carries out personal data processing activities, appointed by through an agreement with the personal data controller.

The Draft GR PDP lays out criteria that must be followed in processing personal data. The collection of personal data must be done in a limited, specific, lawful, and transparent manner, and the processing of personal data must be conducted:

  • In accordance with the declared purpose for processing the personal data;
  • In a manner that guarantees the rights of the personal data subject;
  • In a manner that is accurate, complete, not misleading, up-to-date, and reliable.
  • In a manner that protects the security of personal data by preventing unauthorized access, unauthorized disclosure, unauthorized alteration, misuse, destruction, and erasure of the personal data;
  • By informing the personal data subject of its purpose and activities of processing, as well as any failure in protecting the personal data; and
  • Responsibly, as supported by clear evidence of the personal data processing activities.

Personal data must be destroyed or erased after the retention period ends or upon the request of the personal data subject, unless otherwise stipulated by laws or regulations.

Cross-Border Transfers of Personal Data

According to the Draft GR PDP, personal data controllers are allowed to transfer personal data to another personal data controller or personal data processor outside of Indonesia only after the personal data controller ensures that the intended receiver of the personal data has an equivalent or higher level of personal data protection. Personal data controllers must also ensure that there are adequate and binding personal data protection mechanisms in the receiver’s country. If the receiver’s country does not meet the requirements mentioned in Indonesia’s data protection laws and regulations, the personal data controller must obtain the personal data subject’s approval to transfer the data.

Next Steps

The publication of the Draft GR PDP suggests that the final implementing regulation will align with the Health Law and its implementing regulation in relation to the storage, processing, and transfer of health and medical data. This alignment is essential in order to enforce the protection of personal data in healthcare services in Indonesia. With these strong protections in place, patients and providers will benefit from greater security and privacy, leading to an overall better standard of care in Indonesia’s rapidly advancing digital and other health services.

RELATED INSIGHTS​ 

July 9, 2025
On June 16, 2025, the National Assembly of Vietnam adopted Law No. 75/2025/QH15 amending and supplementing a number of articles of the 2012 Advertising Law, with an effective date of January 1, 2026. The amended Advertising Law was enacted to further refine the legal framework for advertising activities in the modern era. Online Advertising Under the amended Advertising Law, “online advertising” is defined to encompass not only advertising on electronic newspapers and electronic information pages (as provided under the 2012 Advertising Law) but also advertising on other electronic venues, including social media, online applications, and digital platforms with internet connection. The amended Advertising Law also imposes new requirements for online advertising, including: Identification signs: Advertisements must have clear identifiable signs in numbers, letters, symbols, images, or sounds to distinguish them from non-advertising content. Control features: For advertisements not in fixed areas, there must be easily recognizable features and icons that allow recipients to turn off the advertisement, notify the service provider of violating advertising content, and refuse to view inappropriate advertising content. Linked content: Content in the links embedded in advertisements must comply with the law. Advertising service providers and publishers must have measures to check and monitor the linked content. Advertising on social media: Organizations and enterprises providing social media services must offer users features to distinguish advertising content from other content. Signage for sponsored content: When advertising, users of social media services must use signs to differentiate advertising or sponsored content from other content they provide. In response to the above requirements for online advertising, the amended Advertising Law sets out obligations of advertisers, advertising service providers, advertising publishers, and advertising conveyors in relation to online advertising. Among these, it is notably the responsibility of individuals and organizations engaging in online advertising to prevent and remove violating
July 8, 2025
On July 3, 2025, Vietnam’s Ministry of Health (MOH) issued Circular No. 34/2025/TT-BYT amending some articles of Circular No. 06/2011/TT-BYT on the management of cosmetics products (Circular 34), which provides the current regulations on the product notification process for cosmetics (cosmetic notification). Circular 34 will come into effect on August 18, 2025. Changes to Cosmetic Notification Some of the key stipulations of Circular 34 are outlined below. Addition of submission route for notification Circular 34 officially adds online submission via the National Public Service Portal as an accepted type of cosmetic notification, in addition to direct submission and submission via post. Clearer regulations on preparing cosmetic notification form Circular 34 provides clarification on the signing requirements for cosmetic notification forms. For online submissions, both e-signatures and digital signatures are accepted. For offline submissions, the circular explicitly states that stamped/generated signatures are not acceptable. There are no substantive changes to existing requirements regarding grouping of products in a single declaration, ingredient listing, or language used in the notification form. Circular 34 only introduces formatting adjustments to these provisions. Updated administrative procedures Circular 34 updates requirements on digital procedures and authentication for online submission with references to new government decrees. In addition, processing timelines for cosmetic notification are further clarified, in particular, five working days for feedback on incomplete dossiers and five working days for approval after receiving complete supplemental dossiers. Revised requirements for import of samples for testing and research An updated Appendix 14-MP form is introduced with Circular 34, in which the receiving authority is updated from the Drug Administration of Vietnam to the specialized health agency under the provincial People’s Committee. Both online and direct submission of the request are allowed. The approval timeline is three working days from the date of reviewing the request. Transition clause Notifications
July 8, 2025
On June 29, 2025, the government of Vietnam issued Decree No. 163/2025/ND-CP providing detailed guidance on the implementation of the amended Law on Pharmacy (Decree 163). Decree 163, like the amended Law on Pharmacy, took effect on July 1, 2025, officially replacing Decree No. 54/2017/ND-CP (Decree 54). The new decree introduces comprehensive regulations across key areas of pharmaceutical management such as pharmacy practice certificates, certificates of eligibility for pharmaceutical business, import and export of drugs and drug materials, GMP inspection of foreign manufacturers, drug and drug material recall, certificates of drug advertising content, and drug price management. Key Changes in Decree 163 Some outstanding changes and additions in Decree 163 are presented below. Destruction of Specially Controlled Drugs It is no longer required to obtain approval from the competent authority before the destruction of narcotic, psychotropic, and precursor drugs, and pharmaceutical ingredients that are narcotic or psychotropic substances, or precursors used in drugs. Instead, notification must be provided at least seven working days in advance, including the proposed destruction date and a detailed list of items to be destroyed. E-commerce in Pharmaceuticals Pharmaceutical businesses operating via e-commerce platforms must publicly disclose the following information to ensure transparency and consumer safety: (i) certificate of eligibility for pharmaceutical business, (ii) pharmacy practice certificate of the person responsible for pharmaceutical expertise, and (iii) drug information. Shelf-Life Requirements for Imported Products For drugs and ingredients with a total shelf life of nine months or less, at least one-third of the shelf life must remain at the time of customs clearance. Drugs with a shelf life of 30 days or less must still be within their shelf life at the time of clearance. Control of Imported Products Drugs subject to import control include all drugs with marketing authorization (MA), except for (i) drugs that
July 1, 2025
Now halfway through 2025, Thailand continues to advance in the realm of data privacy, with the ambitious goal of achieving zero data breaches. The Personal Data Protection Committee (PDPC), an independent government body established by the Personal Data Protection Act (PDPA), is taking a more proactive approach, having published several rulings and orders to enhance data protection measures and clarify compliance expectations for businesses. Here is a look back at Thailand’s data privacy developments in the first half of the year. Strengthening Law Enforcement and New Guidance for Compliance Enforcement of existing data protection laws and regulations has taken a step forward this year. Some of the specific initiatives include: Increased enforcement by the PDPC. A key trend to watch from the first half of 2025 is the PDPC’s active enforcement of the PDPA as it intensifies oversight through compliance orders and public warnings against noncompliant organizations while ramping up efforts to prevent and halt the illegal trading of personal data by actively monitoring emerging societal issues. Call center scams and cyber fraud control. Thailand published an amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Orders from the Expert Committee. Several orders issued by the Expert Committee under the PDPA were announced in the first half of this year. These include directives for data controllers to take corrective actions to comply with the PDPA, as well as initiatives to raise awareness of data privacy within organizations, reflecting the regulator’s focus on promoting organizational awareness and compliance. A guideline report summarizing the Expert Committee’s decisions and orders was also published to serve as a reference for compliance. Public issue monitoring. The PDPC has been taking a more proactive approach