Privacy Law

How does Indonesia's UU PDP classify health data?

Article 4 of Indonesia's UU PDP classifies health data as specific personal data. Controllers must identify an applicable processing basis under Article 20, assess high-risk processing under Article 34, and apply risk-based security under Article 35. Consent is one of six bases, not automatic.

Indonesia's Law No. 27 of 2022 on Personal Data Protection, dated 17 October 2022, lists health data as specific personal data in Article 4. Article 20 requires the controller to identify an applicable processing basis. Explicit consent is one of six listed bases, not a universal prerequisite for every health-data use.

Article 34 requires a Data Protection Impact Assessment when processing has a high-risk potential and expressly includes processing specific personal data. Article 35 requires technical and operational security measures based on the data's nature and risk. For healthcare AI, the institution should confirm its actual role, purpose, and basis with its legal or privacy team, then map access, security, retention, deletion, processors, transfers, and audit evidence for the real deployment.

Related questions

Is patient consent always required to process health data under UU PDP?+
No. Article 20 lists explicit consent alongside five other processing bases. The controller must identify and document the basis that applies to the specific purpose; where consent is used, it must meet the law's requirements.
Does UU PDP require a DPIA for AI on patient data?+
Article 34 requires a Data Protection Impact Assessment when processing has a high-risk potential and expressly includes processing specific personal data, large-scale processing, and certain other listed activities.

Micromeet — AI for governed healthcare. MCU CoPilot, AI Scribe (Voice-to-EMR), AI Front Desk, Care Loop, Claim Readiness and AI Care Command Center — every output doctor-reviewed. AI writes. Doctors decide. See the public benchmark →