Consent Management Implementation: A Practical Guide Amid PDP Law Enforcement

July 27, 2026 / Published by: Editorial

Imagine the marketing team of a retail company in Jakarta sending WhatsApp promotions to thousands of old customer numbers. Some of those customers had already withdrawn their consent six months earlier, but the company’s CRM system never recorded that change.

This kind of incident isn’t a minor oversight. It’s a real violation of the consent principle set out in Law No. 27 of 2022 on Personal Data Protection (PDP Law), which has been fully in effect since October 2024.

More than a year in, the pattern keeps repeating. Throughout 2025 and into 2026, many organizations have simply relabeled their privacy policies as “PDP Law compliant” while the systems behind them have barely changed, according to notes from compliance practitioners in the financial sector.

This fact points to something often overlooked. Consent management implementation, the thorough deployment of a data consent management system, isn’t a seasonal IT project. It’s an urgent operational need for every organization that handles customer data in Indonesia.

What Is Consent Management?

Before getting into the technical steps, it’s worth aligning on the term itself. Consent management is often equated simply with a “cookie pop-up” on a website, when in fact its scope is far broader than that.

Consent management is the systematic process of requesting, recording, storing, and enforcing a person’s consent over the use of their personal data. Three things set it apart from a simple permission form: consent must be granular per purpose of use, it can be withdrawn by the data owner at any time, and every status change must be logged with a verifiable audit trail.

Take the example of a bank customer. They might agree to have their data used for identity verification, but refuse to have the same data used for additional insurance product offers.

A good consent management system will automatically separate those two preferences. It won’t treat them as a single “accept all or reject all” package.

Without this kind of granular separation, a company doesn’t really have consent at all. What it has is an illusion of compliance, and regulators are now increasingly sharp at telling the two apart during audits or when investigating public complaints.

Another example can be seen with website consent cookies. A visitor might allow analytics cookies to help the company understand browsing behavior, but refuse third-party advertising cookies that track their activity on other sites.

These two types of permission must be managed separately, not merged into a single “Accept All” button that actually hides the real choice. The more specifically this separation is designed, the stronger the company’s legal position when it eventually needs to prove the validity of the consent it holds.

Why Consent Management Implementation Is Now a Priority

This urgency didn’t appear out of nowhere. There are at least three pressures that have pushed this topic onto the board’s agenda this year.

Enforcement Is Already Underway, but the Institution Isn’t Fully Formed

The PDP Law has been fully in effect since October 17, 2024, with tiered administrative sanctions ranging from written warnings up to a maximum fine of 2 percent of a company’s annual revenue for a single violation, as set out in Article 57. For more serious cases, criminal liability can extend to the individuals directly responsible.

Interestingly, the PDP Supervisory Agency mandated by this law has still not been fully established. Enforcement is currently carried out through Komdigi (the Ministry of Communication and Digital Affairs) and sector-specific ministries, so the absence of a dedicated agency shouldn’t be mistaken for the rules having “no teeth.”

Consumers Are More Aware and More Selective

Consumers no longer passively accept privacy policies. A recent global survey found that 75 percent of consumers are reluctant to do business with a company they don’t trust to handle their personal data, as reported in a 2026 compilation of data privacy statistics.

When an e-commerce platform is caught sharing customer data with third parties without clear permission, the fallout rarely stays confined to the technical realm. The resulting loss of trust usually lasts far longer than the financial impact of the administrative fine itself.

A Gap Between Compliance Claims and System Reality

Many companies claim to be compliant on paper, even though their consent systems are fragile. Only 26 percent of companies actually have a centralized consent management platform, with the rest still relying on scattered records, according to this 2026 privacy data.

The same customer data can end up spread across five different systems: CRM, mobile app, email marketing, call center, and an internal data warehouse. None of these systems stay in sync on the customer’s latest consent status.

Common Challenges in Implementing Consent Management

Recognizing the importance of consent management is one thing. Executing it in practice, with legacy systems and teams that have different interests, is a far more complicated challenge.

Data Scattered Across Many Legacy Systems

Most mid-size to large companies have been operating for decades. Their data has piled up in old systems that were never designed to record consent granularly, such as 2010s-era ERP systems that typically only have a single “okay to contact: yes/no” field, with no separation by channel or purpose of use.

Preference Changes Not Synced in Real Time

When a customer withdraws consent through one channel, say, a call center, that change often isn’t immediately picked up by other systems like email marketing. As a result, the marketing team keeps sending promotions to someone who already opted out, exactly the scenario described at the start of this article.

Lack of Defensible Audit Evidence

When a regulator requests proof of consent for specific data, many companies can only show a “yes” or “no” status with no timestamp or context. Yet valid record-keeping should be able to reconstruct exactly when consent was given, for what specific purpose, and through which channel.

Internal Resistance to Process Change

Marketing teams often see consent management as a campaign blocker rather than a business safeguard. Yet campaigns sent to a contact list without valid consent actually risk triggering customer complaints, reports to authorities, or even damage claims down the line.

Steps for Effective Consent Management Implementation

Once the challenges are understood, the next question is where to start. The following framework can be adapted by organizations of any scale, from startups to corporations with dozens of legacy systems.

Conduct a Data Audit and Inventory

The first step is to map every data collection point, from website forms and mobile apps to call center interactions. An insurance company, for example, only realized its data was coming in through at least seven different channels after actually carrying out an audit like this.

Determine the Legal Basis and Purpose of Data Use

Every piece of data collected must have a clear legal basis, whether that’s consent, a contract, or another legal obligation. ID card data used for account verification, for instance, has a different legal basis than shopping preference data used for marketing purposes.

Build an Auditable Consent Recording Mechanism

The system built must be able to record who gave consent, when, for what purpose, and through which channel, then store it in a format that can’t be unilaterally altered. Think of every consent change like a timestamp in a ledger: once recorded, the history remains even if the current status later changes.

Integrate the Consent System Across All Data Touchpoints

A consent status recorded in one system must automatically propagate to every other system using the same data. When a customer withdraws consent through a mobile app, ideally the email marketing and call center systems receive that update within minutes, not weeks.

Establish Governance and Change Control

Who has the authority to change consent policy? Who monitors day-to-day compliance, and through what approval process? All of this needs to be defined from the start so that different teams don’t end up applying conflicting consent rules.

Conduct Regular Monitoring and Review

Regulations change, and so do the vendors and tracking tags a company uses over time. Regular review ensures the consent system continues to reflect what’s actually happening on the ground, not just a policy neatly filed away on paper.

Key Principles for Sustainable Implementation

Successful implementation isn’t a project that gets finished once and then abandoned. The following principles help keep a consent system relevant over the long term, well after the initial project wraps up.

Treat consent as living data, not a static status. Every change in customer preference should be reflected across all related systems immediately, not wait for the next manual sync. Involve legal, IT, and marketing teams from the design stage, not after the system is already built. Operational needs and legal compliance need to move in parallel from the outset, not get patched in later. Measure success with concrete metrics, such as the percentage of data deletion requests completed on time. Simply having a cookie banner on the website isn’t meaningful proof of compliance. Keep compliance evidence ready to produce at any time. Regulators and internal auditors alike can request a reconstruction of consent history without much advance notice.

Closing the Consent Gap Before It Leads to Sanctions

Consent management implementation is fundamentally about trust maintained systematically, not just administrative compliance that’s considered done once the policy document is updated. Companies that can prove every piece of data consent is properly recorded will be far better prepared to face PDP Law audits and increasingly high consumer expectations.

By contrast, organizations still relying on manual record-keeping or fragmented systems face two risks at once: administrative sanctions of up to 2 percent of annual revenue, and a loss of customer trust that’s far harder to restore. Enforcement of the PDP Law has been underway since 2024, so delaying a consent system overhaul is really just delaying a risk that’s already real and present, not one that’s still far off in the future.

The question is no longer whether consent management needs to be implemented, but how quickly an organization can build a system that’s genuinely auditable. The longer this process is put off, the wider the gap grows between compliance claims on paper and the reality in production systems.

For organizations looking to speed up this process without building everything from scratch, Accelist Adaptist Consulting offers Adaptist PRIVE, a product category designed specifically to help companies implement consent management in a structured way, from data audits and auditable consent recording to cross-system integration. The Adaptist team is ready to support this process so that PDP Law compliance moves in step with day-to-day business operations, rather than becoming a separate, additional burden.

Ready to Manage Privacy Compliance as a Business Risk?

See how GRC helps map personal data risks, monitor compliance with the PDP Law, and prepare companies for audits without complicated manual processes.

FAQ

1. What exactly is consent management? 

The systematic process of recording, storing, and enforcing customer data consent, not just a cookie banner.

2. Why implement it now? 

The PDP Law has been fully in force since October 2024, with fines of up to 2% of annual revenue.

3. What’s the biggest challenge?

Data scattered across legacy systems and preference changes that aren’t synced in real time.

Profil Adaptist Consulting

Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.

Read Related Post