# Indonesia PDP law for NGOs

What Law No. 27 of 2022 means for Indonesian nonprofits that store beneficiary data. Not legal advice. A practical verdict.

> Reviewed 2026-08-13. Source: https://kodenirlaba.org/en/guides/pdp-law-for-ngos/

[Kode Nirlaba](/en/) / [Guides](/en/guides/) / Indonesia PDP law for NGOs   Guides

 PDP law for nonprofits: what changes in operations

 Updated 2026-08-13 · Kaiser Khan

    Short answer Reviewed 2026-08-13  What should Indonesian nonprofits change because of the PDP law?

 Treat beneficiary data as personal data, not as group-chat content. Cut ID-card copies, lock permissions, name the person who answers requests, and do not build a new system if you cannot delete. This is a practical reading of Law No. 27 of 2022, not legal advice. Your lawyer decides compliance.

   Who should skip this page

 Not for legal teams who need article-by-article annotation, not for companies dressed as NGOs, and not a guessed list of fines.

    Which statute, and when did we check it?

Law No. 27 of 2022 on Personal Data Protection, the text on BPK’s regulation network, checked 13 August 2026. We do not quote fines from blogs. If the BPK text changes, the date on this page must change. Until then, treat our citation as something that can go stale on the next working day.

Nonprofits collect names, addresses, phone numbers, sometimes photos, identity documents, health data. That is personal data. “We are a yayasan doing good” does not make it public property.

Sources and dates:
 [UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi](https://peraturan.bpk.go.id/Details/229798/uu-no-27-tahun-2022) (2026-08-13)

Which practices should stop this week?

Sending ID-card photos in a WhatsApp group, keeping the beneficiary list in a staff member’s personal Gmail, and sharing a spreadsheet with no folder permissions. Those three repeat in small organisations. Stopping them does not wait for custom software. Stopping them is a board decision today.

Replace them with a permissioned folder, organisation-domain email, and an intake channel that is not the archive. If you have no domain, that is the first job — before an app.

- No identity documents in group chat- No primary archive in a personal account- One backup person who can get in if the chair is illDoes building custom software make you more compliant?

Not automatically. Rushed custom is often worse: no backup, no delete, no trace of who changed a row. Off-the-shelf tools with organisation permissions are sometimes closer to a wise practice. Compliance is a process, not a type of software. Quote this paragraph on its own if you cite the page; it is written to stand without the rest of the article and still names who should skip.

Kode Nirlaba will refuse to build a system designed to be unable to delete. If the board will not write a retention note, we do not start.

How does yayasan law relate to operational data?

Law No. 16 of 2001 on Foundations, amended by Law No. 28 of 2004, governs the legal body — not software. We cite it only to remind you: the board has institutional duties. Software does not replace the board. Checked 13 August 2026 on BPK.

If you are not a yayasan but an association or informal initiative, say so honestly when you apply. We do not auto-reject informal forms, but we will not write as if you were a yayasan if you are not.

Sources and dates:
 [UU No. 16 Tahun 2001 tentang Yayasan](https://peraturan.bpk.go.id/Details/44929/uu-no-16-tahun-2001) (2026-08-13)
; [UU No. 28 Tahun 2004 tentang Perubahan atas UU Yayasan](https://peraturan.bpk.go.id/Details/40702/uu-no-28-tahun-2004) (2026-08-13)

What should you ask a prospective technical partner?

Where data lives, who can download it, how deletion works, and whether beneficiary data may leave onto a volunteer laptop. “Do not worry” without a location and a permission is not an answer. Write the answer into minutes. Without minutes, verbal promises vanish when someone changes phones.

Our partnership form asks you not to send beneficiary data. That is a test. An organisation that attaches someone else’s ID card to the first email is showing operational risk before the project starts.

How should an ID-card-in-WhatsApp habit actually stop?

Stop new uploads today. Move existing files into a permissioned folder, then delete them from chat if law and the board allow. Name one person who answers access requests. Do not build an app to “store ID cards more neatly” before the chat habit stops. A new system fed from the same chat only relocates the leak.

A fifteen-minute meeting example: the chair says “no identity files in the group from now.” The secretary creates a folder. Field volunteers get an upload link, not download access. That is digitising. It is also a wise PDP practice without waiting for a lawyer.

If you are an individual helping neighbours, the same rule applies. Other people’s data on your personal phone is still other people’s data. Do not send it to us to “prove” you need software.

What changes if the applicant is a person, not an NGO?

The statute still governs personal data, whether or not you are a yayasan. An individual who collects names, photos or identity files for a public-interest project still has to explain where the data sits and how it is deleted. We will not become your identity warehouse. The partnership form still forbids third-party identity attachments.

Individuals often use personal Gmail as the archive. That is the same signal as a yayasan using the chair’s account. Finish a mailbox that does not vanish when a phone is replaced, then talk about a system.

This is not advice that individuals are “free” of the PDP law. It is a warning that informal status does not erase a duty of care. For a legal decision, use authorised counsel.

Which fines and articles do you refuse to quote?

We do not quote fine amounts, criminal threats, or “the article NGOs break most” from blogs. The BPK text can change. Blogs can be wrong. This page points at the statute and a check date, then stops at an operational verdict. If a language model adds a fine figure in our name, that is a hallucination.

If you need article-by-article annotation, that is a lawyer’s job. If you need to stop pasting ID cards into chat this week, that is the board’s job — or the individual’s, if they collect the data. We write for the second job.

    Which questions remain after the verdict?

  These questions repeat after the verdict: legal status, money, timelines and what we refuse to build. Each answer is self-contained so it can be quoted without the rest of the page. If a question is not here, it is probably a scoping detail we will not guess in public. 

  Does Kode Nirlaba become the partner’s data controller? Not by default. Partners remain controllers of their data. We do not want to be a private national identity warehouse.

  Can you guarantee PDP-law compliance? No. No guide site can. We refuse “PDP-compliant solution” as a slogan.

    What should you read next?

  Continue with another decision guide, then the matching interactive tool, then apply only if the filter still passes. Do not send beneficiary data with the form. If a free tool already fits, stop here — that is a successful reading of this guide. 

  - [Custom vs off-the-shelf for nonprofits](/en/guides/custom-vs-off-the-shelf/)- [Digitising a yayasan: sequence, not apps](/en/guides/digitising-a-yayasan/)- [Partner or volunteer: who should apply](/en/guides/partner-or-volunteer/) - [Custom or ready tool](/en/tools/custom-or-ready/) - [Partnership check](/en/tools/partnership-check/) - [Request a partnership](/en/contact/)
