You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 25, 2023

Personal Data Protection and Healthcare Services in Indonesia

One significant development in the health sector in Indonesia is the use of information technology and communication in the implementation of health efforts—particularly digital health services such as telehealth and telemedicine integrated into the country’s National Health Information System.

This development was addressed in a major new piece of legislation for the healthcare sector in Indonesia. Enacted in August 2023, Law No. 17 of 2023 concerning Health (the “Health Law”) provides the updates needed to support the development of healthcare services in Indonesia.

Under the Health Law, health information system (HIS) providers must:

  • Carry out processing of data and health information in the territory of Indonesia, except for certain limited and specific processing activities that may be conducted outside Indonesia when permitted by the relevant authorities and in compliance with relevant regulations.
  • Ensure the reliability of its HIS, including availability, security, maintenance, and integration with Indonesia’s National Health Information System.
  • Provide quality health data and information.
  • Process data and health information, which includes planning, collection, storage, inspection, transfer, utilization, and destruction.
  • Record its data- and information-processing history.
  • Protect every person’s data and health information.
  • Obtain approval from the relevant personal data subject or comply with relevant regulations if the processing of data and health information involves an individual’s health data.
  • Inform the data owner if there is a failure to protect data and individual health information.

The Health Law’s personal data protection requirements listed above appear to be aligned with the provisions in Law No. 27 of 2022 concerning Personal Data Protection (the “PDP Law”). Under this law, data and information relating to health are identified as “specific personal data,” the processing of which carries a high potential risk of impacting the relevant personal data subject.

In the implementation of digital health services, patients’ personal data or medical records must be generated by a health service facility. Health service facilities are responsible for the maintenance of the security, integrity, confidentiality, and availability of the data in Medical Records.

Regulatory Implementation of the PDP Law

In preparation for the implementation of the PDP Law, in September 2023 Indonesia’s Ministry of Communication and Information published the Draft Government Regulation regarding Implementation of PDP Law (the “Draft GR PDP”).

The provisions in the Draft GR PDP most relevant to digital health services and medical records are described below.

Personal Data Subject Rights

According to the Draft GR PDP, personal data subjects have the right to:

  • Terminate processing of personal data about themselves in accordance with relevant laws and regulations.
  • Delete personal data about themselves in accordance with relevant laws and regulations.
  • Destroy personal data about themselves in accordance with relevant laws and regulations.
  • Withdraw their previously given consent to the processing of personal data.
  • Object to decision-making actions based solely on automated processing (including profiling) that have legal consequences or a significant impact on the personal data subject.
  • Suspend or limit the processing of personal data proportionately in accordance with the purpose of processing the personal data.
  • Obtain and use personal data about themselves from the personal data controller in a form that fits a structure or format commonly used or readable by electronic systems.
  • Use and transmit personal data about themselves to other personal data controllers if the systems used can communicate with each other securely in accordance with the personal data protection principles.

Personal Data Controller Obligations

Among personal data controllers’ many obligations related to the protection of personal data in general, there are two related to health. Under the Draft GR PDP, personal data subjects have the right to complete, update, and correct errors or inaccuracies in personal data about them through the means provided by the personal data controller, either independently or by submitting a written request to the personal data controller, who must reject such a request if it:

  • Jeopardizes the security or physical or mental health of the personal data subject or others;
  • Impacts the disclosure of personal data belonging to others; or
  • Is contrary to the interests of national defense and security.

Personal data controllers must assess the impact of their processing of personal data related to health, because processing this type of data carries a high potential risk of impacting the relevant personal data subject.

Other than the obligations mentioned above, personal data controllers are also required to do the following, among others:

  • Have a basis for processing personal data;
  • Present evidence of personal data subjects’ consent to the processing of their personal data;
  • Carry out the processing of personal data in a limited, specific, legally valid, and transparent manner;
  • Carry out the processing of personal data in accordance with the declared purpose for processing the personal data;
  • Ensure the accuracy, completeness, and consistency of personal data in accordance with the provisions of laws and regulations;
  • Update or fix any errors or inaccuracies in personal data under their control;
  • Record all personal data processing activities; and
  • Provide personal data subjects with access to the processed personal data along with a record of processing activities during the period for which the personal data is retained.

Personal Data Processing

Besides identifying personal data subjects and personal data controllers as relevant parties in the processing of personal data, the Draft GR PDP also details the role of personal data processors. A personal data processor is a party who carries out personal data processing activities, appointed by through an agreement with the personal data controller.

The Draft GR PDP lays out criteria that must be followed in processing personal data. The collection of personal data must be done in a limited, specific, lawful, and transparent manner, and the processing of personal data must be conducted:

  • In accordance with the declared purpose for processing the personal data;
  • In a manner that guarantees the rights of the personal data subject;
  • In a manner that is accurate, complete, not misleading, up-to-date, and reliable.
  • In a manner that protects the security of personal data by preventing unauthorized access, unauthorized disclosure, unauthorized alteration, misuse, destruction, and erasure of the personal data;
  • By informing the personal data subject of its purpose and activities of processing, as well as any failure in protecting the personal data; and
  • Responsibly, as supported by clear evidence of the personal data processing activities.

Personal data must be destroyed or erased after the retention period ends or upon the request of the personal data subject, unless otherwise stipulated by laws or regulations.

Cross-Border Transfers of Personal Data

According to the Draft GR PDP, personal data controllers are allowed to transfer personal data to another personal data controller or personal data processor outside of Indonesia only after the personal data controller ensures that the intended receiver of the personal data has an equivalent or higher level of personal data protection. Personal data controllers must also ensure that there are adequate and binding personal data protection mechanisms in the receiver’s country. If the receiver’s country does not meet the requirements mentioned in Indonesia’s data protection laws and regulations, the personal data controller must obtain the personal data subject’s approval to transfer the data.

Next Steps

The publication of the Draft GR PDP suggests that the final implementing regulation will align with the Health Law and its implementing regulation in relation to the storage, processing, and transfer of health and medical data. This alignment is essential in order to enforce the protection of personal data in healthcare services in Indonesia. With these strong protections in place, patients and providers will benefit from greater security and privacy, leading to an overall better standard of care in Indonesia’s rapidly advancing digital and other health services.

RELATED INSIGHTS​ 

June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal
May 28, 2025
Tilleke & Gibbins attorneys in Vietnam have contributed the 2025 edition of Doing Business in Vietnam, a comprehensive Q&A-style resource from Thomson Reuters Practical Law that provides essential insights for companies navigating business operations in Vietnam. The guide presents a detailed overview of the country’s legal framework and regulatory environment, reflecting recent updates in Vietnamese legislation and practice. This annually updated guide offers key information on the following areas: Legal system: Structure of the Vietnamese judiciary and the role of codified law. Foreign investment: Conditions for market access, licensing requirements, foreign ownership restrictions, and investment incentives. Business vehicles: Formation and operation of legal entities, including limited liability companies, joint-stock companies, and representative offices. Employment: Employment contracts, social insurance, labor rights, and procedures for hiring foreign nationals. Tax: Overview of corporate income tax, personal income tax, value-added tax, and other tax obligations. Intellectual property: Procedures for protecting and enforcing patents, trademarks, copyrights, and other IP rights. Data protection: Compliance requirements under Vietnam’s data privacy laws, including the Personal Data Protection Decree. Competition law: Antitrust rules and regulatory oversight under the Law on Competition. Anti-bribery and corruption: Legal framework and enforcement practices aimed at curbing corrupt activities. E-commerce and digital business: Regulations governing online platforms, digital content, and cross-border services. Marketing and advertising: Laws and guidelines on advertising standards and consumer protection. Product regulation and liability: Safety requirements, product liability issues, and roles of relevant authorities. Doing Business in Vietnam is part of Practical Law’s global series of legal guides designed to support international practitioners and businesses. To access the most recent edition of the Vietnam guide, visit the Practical Law website and sign up for a free trial.
May 28, 2025
Thailand’s Food and Drug Administration (FDA) has launched a strategic collaboration with leading e-commerce platforms Lazada and Shopee to strengthen regulatory oversight of health-related products sold online. This partnership is part of a broader initiative to enhance consumer protection, enforce compliance with Thai health regulations, and foster a safer digital marketplace for health products. As part of this initiative, the Thai FDA is urging all sellers—particularly cross-border vendors—to secure proper FDA registration for their products before market entry. The objective is to ensure that only legally authorized, safe, and quality-assured healthcare products are available to Thai consumers. In pursuit of this goal, the FDA has been working closely with Lazada and Shopee to implement proactive surveillance mechanisms aimed at identifying and removing noncompliant, substandard, or unregistered products. This collaboration has already yielded measurable results. Between September 2023 and 2024, Lazada supported regulatory enforcement by removing 9,454 noncompliant listings and delisting 30 vendors. In addition, 134 sellers were subjected to legal proceedings for regulatory violations. Shopee has taken a similarly rigorous stance, committing to the immediate removal of products found to be in breach of FDA regulations. The platform has also provided educational materials for merchants and implemented consumer complaint mechanisms to enhance accountability. Looking ahead, the Thai FDA plans to roll out a data integration system utilizing API technology, enabling seamless and secure exchange of regulatory data between the agency and e-commerce platforms. This system will be supported by comprehensive training for both Thai FDA officials and e-commerce staff, with a particular focus on the use of the Thai government’s Law Enforcement Request Portal, a secure communication channel for coordinating enforcement actions between government agencies and platform operators. Additionally, a joint product inspection framework is currently under development in partnership with Lazada and Shopee. This framework will incorporate strict