You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 25, 2023

Personal Data Protection and Healthcare Services in Indonesia

One significant development in the health sector in Indonesia is the use of information technology and communication in the implementation of health efforts—particularly digital health services such as telehealth and telemedicine integrated into the country’s National Health Information System.

This development was addressed in a major new piece of legislation for the healthcare sector in Indonesia. Enacted in August 2023, Law No. 17 of 2023 concerning Health (the “Health Law”) provides the updates needed to support the development of healthcare services in Indonesia.

Under the Health Law, health information system (HIS) providers must:

  • Carry out processing of data and health information in the territory of Indonesia, except for certain limited and specific processing activities that may be conducted outside Indonesia when permitted by the relevant authorities and in compliance with relevant regulations.
  • Ensure the reliability of its HIS, including availability, security, maintenance, and integration with Indonesia’s National Health Information System.
  • Provide quality health data and information.
  • Process data and health information, which includes planning, collection, storage, inspection, transfer, utilization, and destruction.
  • Record its data- and information-processing history.
  • Protect every person’s data and health information.
  • Obtain approval from the relevant personal data subject or comply with relevant regulations if the processing of data and health information involves an individual’s health data.
  • Inform the data owner if there is a failure to protect data and individual health information.

The Health Law’s personal data protection requirements listed above appear to be aligned with the provisions in Law No. 27 of 2022 concerning Personal Data Protection (the “PDP Law”). Under this law, data and information relating to health are identified as “specific personal data,” the processing of which carries a high potential risk of impacting the relevant personal data subject.

In the implementation of digital health services, patients’ personal data or medical records must be generated by a health service facility. Health service facilities are responsible for the maintenance of the security, integrity, confidentiality, and availability of the data in Medical Records.

Regulatory Implementation of the PDP Law

In preparation for the implementation of the PDP Law, in September 2023 Indonesia’s Ministry of Communication and Information published the Draft Government Regulation regarding Implementation of PDP Law (the “Draft GR PDP”).

The provisions in the Draft GR PDP most relevant to digital health services and medical records are described below.

Personal Data Subject Rights

According to the Draft GR PDP, personal data subjects have the right to:

  • Terminate processing of personal data about themselves in accordance with relevant laws and regulations.
  • Delete personal data about themselves in accordance with relevant laws and regulations.
  • Destroy personal data about themselves in accordance with relevant laws and regulations.
  • Withdraw their previously given consent to the processing of personal data.
  • Object to decision-making actions based solely on automated processing (including profiling) that have legal consequences or a significant impact on the personal data subject.
  • Suspend or limit the processing of personal data proportionately in accordance with the purpose of processing the personal data.
  • Obtain and use personal data about themselves from the personal data controller in a form that fits a structure or format commonly used or readable by electronic systems.
  • Use and transmit personal data about themselves to other personal data controllers if the systems used can communicate with each other securely in accordance with the personal data protection principles.

Personal Data Controller Obligations

Among personal data controllers’ many obligations related to the protection of personal data in general, there are two related to health. Under the Draft GR PDP, personal data subjects have the right to complete, update, and correct errors or inaccuracies in personal data about them through the means provided by the personal data controller, either independently or by submitting a written request to the personal data controller, who must reject such a request if it:

  • Jeopardizes the security or physical or mental health of the personal data subject or others;
  • Impacts the disclosure of personal data belonging to others; or
  • Is contrary to the interests of national defense and security.

Personal data controllers must assess the impact of their processing of personal data related to health, because processing this type of data carries a high potential risk of impacting the relevant personal data subject.

Other than the obligations mentioned above, personal data controllers are also required to do the following, among others:

  • Have a basis for processing personal data;
  • Present evidence of personal data subjects’ consent to the processing of their personal data;
  • Carry out the processing of personal data in a limited, specific, legally valid, and transparent manner;
  • Carry out the processing of personal data in accordance with the declared purpose for processing the personal data;
  • Ensure the accuracy, completeness, and consistency of personal data in accordance with the provisions of laws and regulations;
  • Update or fix any errors or inaccuracies in personal data under their control;
  • Record all personal data processing activities; and
  • Provide personal data subjects with access to the processed personal data along with a record of processing activities during the period for which the personal data is retained.

Personal Data Processing

Besides identifying personal data subjects and personal data controllers as relevant parties in the processing of personal data, the Draft GR PDP also details the role of personal data processors. A personal data processor is a party who carries out personal data processing activities, appointed by through an agreement with the personal data controller.

The Draft GR PDP lays out criteria that must be followed in processing personal data. The collection of personal data must be done in a limited, specific, lawful, and transparent manner, and the processing of personal data must be conducted:

  • In accordance with the declared purpose for processing the personal data;
  • In a manner that guarantees the rights of the personal data subject;
  • In a manner that is accurate, complete, not misleading, up-to-date, and reliable.
  • In a manner that protects the security of personal data by preventing unauthorized access, unauthorized disclosure, unauthorized alteration, misuse, destruction, and erasure of the personal data;
  • By informing the personal data subject of its purpose and activities of processing, as well as any failure in protecting the personal data; and
  • Responsibly, as supported by clear evidence of the personal data processing activities.

Personal data must be destroyed or erased after the retention period ends or upon the request of the personal data subject, unless otherwise stipulated by laws or regulations.

Cross-Border Transfers of Personal Data

According to the Draft GR PDP, personal data controllers are allowed to transfer personal data to another personal data controller or personal data processor outside of Indonesia only after the personal data controller ensures that the intended receiver of the personal data has an equivalent or higher level of personal data protection. Personal data controllers must also ensure that there are adequate and binding personal data protection mechanisms in the receiver’s country. If the receiver’s country does not meet the requirements mentioned in Indonesia’s data protection laws and regulations, the personal data controller must obtain the personal data subject’s approval to transfer the data.

Next Steps

The publication of the Draft GR PDP suggests that the final implementing regulation will align with the Health Law and its implementing regulation in relation to the storage, processing, and transfer of health and medical data. This alignment is essential in order to enforce the protection of personal data in healthcare services in Indonesia. With these strong protections in place, patients and providers will benefit from greater security and privacy, leading to an overall better standard of care in Indonesia’s rapidly advancing digital and other health services.

RELATED INSIGHTS​ 

May 15, 2025
Vietnam’s Ministry of Health (MOH) has published for public consultation a draft amendment of the Law on Donation, Recovery, and Transplantation of Human Tissues and Organs and Donation and Retrieval of Cadavers, a law which has been in effect since 2007. Among its changes, the draft amendment notably includes new provisions on stem cells, a hot-button topic with social, legal, and ethical ramifications extending beyond the medical field. There are currently no specific regulations on stem cells under Vietnamese law—only the MOH’s technical guidance—leaving many controversial issues unsettled. Key points related to stem cells that may impact the activities of researchers and institutions in Vietnam and abroad are highlighted below. Requirements for Stem Cells Under the draft amendment, stem cells are defined as cells naturally occurring in the body, having the ability to divide and differentiate into various types of cells. The draft amendment outlines conditions for stem cell donation, establishes requirements for medical facilities authorized to receive stem cell donations, and specifies the rights of stem cell donors. Under the draft amendment, it is prohibited to receive, screen, or produce stem cells at facilities that do not satisfy conditions. Establishment of Private Stem Cell Banks In addition to state-owned stem cell banks, the draft amendment also addresses independent stem cell banks established by private investors. In general, the stem cell banks (whether public or private) must obtain an operation license by meeting various conditions on personnel, equipment, facilities, and management systems to be further guided by the government. Notably, stem cell banks will have the right to cooperate with foreign entities in exchanging stem cells for treatment, education, and research purposes. Prohibition on Creating Embryos for Stem Cell Research or Therapy Considering the ethical concerns over the use and destruction of embryos, the draft amendment expressly prohibits the
May 14, 2025
Following the amendment to the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes in mid-April 2025, new measures were introduced by the Electronic Transactions Development Agency (ETDA) in a hearing session held on May 13, 2025, to establish shared liability between online social media platform operators and other in-scope operators for damages arising from technological crimes. Stakeholders are being invited to submit their comments on the proposed new provisions directly to the ETDA by May 20, 2025. The concept of the new measures for social media platform operators is that to be released from liability for damages arising from technological crimes, social media platform operators must demonstrate compliance with the relevant technological crime prevention standards and measures prescribed by their respective regulators (“safe harbor rules”). Safe Harbor Rules Under the principles of the proposed safe harbor rules, social media platform operators and the relevant service providers would be required to comply with the following obligations: Immediate takedown and suspension of dissemination: Disable access, remove the content from the system, or suspend the relevant service within 24 hours of receiving an official notification from the Cyber Crime Investigation Bureau’s Anti-Online Scam Operation Center (AOC) that a service or social media platform is disseminating content that is or may be used to commit or support technological crimes. Establishment of notification channels: Establish a system or channel to receive notifications from the AOC. User registration and identity verification: Require user registration (including identity verification and authentication) before allowing content to be posted, with sufficient information to identify the user. Suspending dissemination of suspect advertisements: Disable access to advertisements reasonably suspected of involving or potentially involving the commission of technology-related crimes. Reporting: Report on actions taken, including details like account owner information, IP address, email, or phone number used for account
May 5, 2025
On April 29, 2025, the government of Vietnam promulgated Decree No. 94/2025/ND-CP with regulations on a controlled “sandbox” for innovative fintech solutions in the banking sector (Decree 94). The decree aims to promote innovation, modernize banking, and enhance financial inclusion while assessing risks and benefits of fintech solutions in a controlled testing environment. Fintech Sandbox Currently, the fintech sandbox focuses on three specific areas: Credit scoring Open API data sharing Peer-to-peer (P2P) lending Eligible participants for the fintech sandbox include: Credit institutions and foreign bank branches (except for P2P lending) Fintech companies operating in Vietnam Cross-border supply by foreign providers is not included in the sandbox framework. Eligible participants are permitted to provide fintech solutions only within the scope specified in the Certificate of Sandbox Participation issued by the State Bank of Vietnam in consultation with other ministries. P2P lending companies face specific restrictions within the fintech sandbox, including prohibitions against: Providing security for customer loans Operating as a customer (i.e., P2P lender or borrower) Providing P2P lending solutions to pawn shops The maximum sandbox period is two years, with the possibility of extension as permitted by law. The outcomes of the fintech sandbox will serve as a practical basis for authorities to develop and refine future fintech regulations. It is worth noting that participation in the sandbox does not guarantee that participants will meet relevant business and investment conditions that may be stipulated in future regulations. Decree 94 will take effect on July 1, 2025, signaling that the Vietnamese government intends to take a proactive approach to fostering fintech development. Implications Parties interested in participating in the fintech sandbox should begin preparing now to be ready to apply for a Certificate of Sandbox Participation when the decree takes effect.
May 2, 2025
Attorneys from Tilleke & Gibbins have updated the latest edition of Doing Business in Thailand, a Q&A-style guide from Thomson Reuters Practical Law that offers an overview of key legal considerations for companies operating in jurisdictions worldwide. The contribution outlines the country’s legal and regulatory framework for foreign investment and business operations and reflects the latest legislative developments. The chapter addresses the following core topics: Legal system: Structure of the courts and the codified nature of Thai law. Foreign investment: Business restrictions under the Foreign Business Act, sector-specific regulations, exchange control rules, and investment incentives. Business vehicles: Overview of partnerships, private and public limited companies, and other legal entities. Employment: Labor protections, employment contracts, foreign worker requirements, and termination procedures. Tax: Corporate and personal income tax, indirect taxes, and tax obligations for residents and non-residents. Intellectual property: Registration and enforcement of patents, trademarks, designs, and copyrights. Data protection: Key provisions of the Personal Data Protection Act and related compliance obligations. Competition law: Regulatory framework under the Trade Competition Act. Anti-bribery and corruption: Relevant legislation and enforcement mechanisms. E-commerce and digital business: Legal regime for online transactions and digital platforms. Marketing and advertising: Consumer protection laws and regulations affecting advertising and marketing practices. Product regulation and liability: Safety standards, liability regimes, and roles of enforcement authorities. Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.