At two in the morning, the IT team of a Jakarta based e-commerce platform noticed an unusual alert from their monitoring system. Thousands of rows of customer data, ranging from phone numbers to shipping addresses, had been accessed by an unknown party for several hours before anyone caught it.
The first question raised in the emergency meeting was not “how do we close the gap,” but “who do we need to inform, and within how many hours?” This kind of scenario has become a real concern for many data controllers in Indonesia, no longer just a hypothetical exercise on paper.
According to the IBM Cost of a Data Breach Report 2026, the global average cost of a single data breach incident reached 4.99 million US dollars, a 12 percent increase from the previous year and the highest figure recorded in the report’s history. That number does not even include the administrative fines or civil lawsuits that can follow when a company is late in reporting an incident.
This is where data breach notification becomes a critical element, not merely an administrative formality drafted once the dust settles. Indonesia’s Personal Data Protection Law (UU PDP) regulates this obligation in detail, complete with strict deadlines, minimum content requirements, and sanctions for those who fail to comply.
What Is Data Breach Notification?
In simple terms, data breach notification is the obligation of a personal data controller to inform relevant parties as soon as a personal data protection failure occurs. That simple definition often leads to a common misunderstanding, as if sending a single apology email to affected customers is enough to satisfy the requirement.
In reality, under the framework of the PDP Law, this obligation consists of three interlinked elements: who must be notified, what the deadline is, and what information must be included. All three are explicitly regulated under Article 46, not left open to each company’s own interpretation.
Imagine a private hospital losing control of a server storing the medical records of five thousand patients due to a ransomware attack. The moment management discovers the incident, the clock starts running, and the hospital is obligated to prepare and send a written notification before the 3×24 hour deadline expires.
The purpose of this obligation is not to publicly shame a company that has fallen victim to a cyberattack. A prompt notification gives affected data subjects room to take further preventive action, such as changing their passwords or blocking a payment card whose data was exposed.
Legal Basis of Data Breach Notification Under the PDP Law
The obligation to notify a data breach does not come from a single article. It is spread across several provisions that work together, and the four key articles below are worth understanding before an incident actually happens.
Article 46 Paragraph (1): The 3×24 Hour Deadline
This paragraph requires a personal data controller to deliver a written notification no later than 3×24 hours after becoming aware of a personal data protection failure. There are two recipients of this notification: the affected data subjects, and the supervisory authority, whose function is currently carried out by the Directorate General of Digital Space Supervision under the Ministry of Communication and Digital Affairs.
For illustration, a fintech startup discovers on Monday at ten in the morning that its lending database has been breached. The deadline for sending the notification falls on Thursday at ten in the morning, with no extension even if it lands on a weekend.
Article 46 Paragraph (2): Minimum Content of the Notification
The second paragraph makes clear that a written notification cannot simply be a generic apology without substance. There are three pieces of information that must be included:
- The personal data that was exposed
- When and how the data was exposed
- The remediation and recovery measures already taken by the data controller
A notification that meets this standard would specifically state, for example, that customer names, national ID numbers, and transaction histories from January through March were exposed through a vulnerability in a third party API. The document should also describe the concrete steps taken, such as temporarily disabling that API access and rotating all affected system credentials.
Article 46 Paragraph (3): Notification to the Public
Under certain conditions, the notification obligation does not stop at the data subjects and the supervisory authority. If the breach disrupts public services or seriously affects the broader public interest, the data controller is required to make a public announcement.
Data breaches at regional government services usually fall into this category because they involve large volumes of citizen data. Private companies with millions of users, such as ride hailing apps or digital wallets, could face a similar obligation if the impact is considered significant to the public.
Article 47: Accountability of the Data Controller
Beyond the notification obligation, Article 47 states that a personal data controller is fully responsible for the entire personal data processing activity, not only at the moment an incident occurs. This means a company must be able to demonstrate that data protection principles were already in place from the start, not hastily assembled after a breach becomes public.
Who Is Required to Carry Out the Notification?
This obligation does not automatically apply to every party that comes into contact with personal data. The PDP Law distinguishes between two roles with different levels of responsibility.
- Personal data controller: the party that determines the purpose and means of processing personal data, such as an e-commerce company collecting customer data for transactions and marketing.
- Personal data processor: the party that processes data on behalf of the controller, such as a cloud storage vendor or a delivery service provider.
The obligation to notify data subjects and the supervisory authority rests with the controller, not the processor. However, if a breach occurs on a cloud vendor’s side, the controller is still required to report it because the controller bears legal responsibility for that data, which is why a clear notification clause from vendor to controller should be written into the service agreement from the outset.
Who Must Receive the Notification?
The next common question is exactly who this notification needs to be sent to. The PDP Law identifies three possible recipients, depending on the scale and impact of the incident.
- The affected data subjects, whose personal data was directly compromised
- The supervisory authority, currently under the Ministry of Communication and Digital Affairs
- The general public, if the incident disrupts public services or has a wide reaching impact
A digital health app that suffers a breach only needs to notify the data subjects and the authority if the impact is limited to a few hundred users. But once the incident involves millions of medical records and risks disrupting public healthcare services, the obligation to notify the public also kicks in.
Procedure and Steps for Reporting Within 3×24 Hours
A three day deadline sounds generous on paper, but in practice it is extremely tight for a company without an established procedure. Below are the steps typically required from the moment an incident is detected until the notification is actually sent.
- Detect and confirm the incident, making sure the event is genuinely a personal data protection failure and not just a routine system error.
- Conduct an initial investigation, determining which data was affected and since when the vulnerability had been exploited.
- Draft the notification, preparing a written document that meets the minimum content requirements under Article 46 paragraph (2).
- Send it to data subjects and the supervisory authority, completed before the 3×24 hour deadline expires.
- Assess the need for public notification, evaluating whether the impact is broad enough to fall under Article 46 paragraph (3).
Companies that already have an incident response team in place can usually complete the first four steps in under twenty four hours. Companies without a standard procedure, on the other hand, often only realize the true scale of a breach after more than half the deadline has already passed, since the investigation stage tends to take far longer than expected.
Consequences of Failing to Notify
Failing to meet the notification obligation is not a minor administrative slip that can be resolved with a simple warning letter. Article 57 of the PDP Law sets out a range of sanctions that can be imposed either progressively or all at once against a negligent data controller.
- A written warning from the supervisory authority
- Temporary suspension of personal data processing activities
- Deletion or destruction of personal data
- An administrative fine of up to two percent of the company’s annual revenue
To put that into perspective, a company with annual revenue of one hundred billion rupiah found negligent in reporting a data breach could face a fine of up to two billion rupiah, not counting the cost of reputational recovery or potential lawsuits from affected customers. This figure does not even include the criminal liability that applies in certain cases, such as intentionally and unlawfully disclosing personal data, which is regulated separately under the PDP Law.
Why Notification Readiness Is Becoming More Urgent
The pressure to respond within a matter of hours is not solely about legal compliance in Indonesia. Global cybersecurity trends show that the window of time available for companies to react is shrinking year after year.
IBM’s report also found that one in four malicious breaches now involves artificial intelligence, a 56 percent increase from the previous year, with an average cost of 6 million US dollars per incident. AI assisted attacks tend to move far faster, shrinking the window between the initial unauthorized access and full exploitation compared to just a few years ago.
The Verizon 2026 Data Breach Investigations Report offers a similar picture from the angle of root causes. The report found that the human element was involved in 62 percent of data breaches worldwide, ranging from misconfigurations to credentials stolen through phishing.
This combination of faster moving attacks and persistently wide human error gaps makes the 3×24 hour deadline under the PDP Law more demanding than it appears on paper. Companies still relying on manual processes to detect and draft notifications risk running out of time before they can fulfill their obligation to the regulator.
Notification Readiness Is an Investment, Not a Burden
Data breach notification under the PDP Law is not an administrative procedure that can be rushed together once an incident occurs. This obligation demands comprehensive readiness, from early detection systems and an incident response team, to notification templates prepared well before a breach ever happens.
Failing to meet the 3×24 hour deadline can lead to administrative sanctions, fines of up to two percent of annual revenue, and, just as damaging, a loss of customer trust. Amid cyber threats that are moving faster than ever, as shown by the IBM and Verizon data above, waiting for an incident to happen before building a procedure is no longer an option for companies that take their users’ data seriously.
For companies that want to be genuinely ready to meet their obligations under the PDP Law without having to build everything from scratch, Adaptist PRIVE from Accelist Adaptist Consulting serves as a personal data protection compliance partner, covering risk assessment, incident response procedure development, and guided drafting of data breach notifications in line with Article 46 of the PDP Law. With an approach tailored to your business needs, Adaptist PRIVE helps companies respond to incidents on time while minimizing the risk of legal sanctions down the road.
Ready to Manage Privacy Compliance as a Business Risk?
See how GRC helps map personal data risks, monitor compliance with the PDP Law, and prepare companies for audits without complicated manual processes.
FAQ
It is the obligation to notify affected parties after a personal data breach occurs.
Data controllers must provide notification within 3×24 hours after discovering the breach.
Penalties may include warnings, processing suspension, data deletion, and administrative fines.




