What UU PDP actually requires of you
Three ideas carry most of the weight. First, you are either a controller — you decide why and how personal data is processed — or a processor acting on somebody else’s instruction, and the obligations differ substantially. Second, you must be able to show what personal data you hold, why, and on what basis; that record is not optional. Third, sanctions are administrative and can reach a share of annual revenue, with criminal provisions for unlawful collection and disclosure.
You may also need a data protection officer. The trigger is not company size but the nature of the processing: large-scale systematic monitoring, or processing sensitive data such as health, biometric, financial, or children’s data as a core activity. A hospital group, a fintech, and an insurance broker all need one. A B2B distributor with an HR database usually does not, though somebody still has to own the topic by name.
Lawful basis: the question you answer per dataset
The law gives six lawful bases, and the practical mistake is reaching for consent every time. Consent must be freely given, specific, informed, and withdrawable — which is exactly why employee data almost never rests on it. An employee cannot meaningfully refuse. Employment data sits on contract performance and legal obligation instead, and framing it as consent creates a withdrawal right you cannot honour without ending the employment.
- Employee HR and payroll data: contract performance plus legal obligation, never consent
- Customer order fulfilment and invoicing: contract performance, with retention set by tax rules
- Marketing and profiling: consent, recorded granularly per channel and withdrawable in one step
- CCTV and access logs: legitimate interest, documented with a balancing assessment kept on file
- Anything involving health, biometrics, or children: sensitive data, with the stricter rules that follow
Data subject rights in practice
Data subjects can ask for information about processing, access to their data, correction, deletion, restriction, withdrawal of consent, an explanation of automated decisions, and portability. The operational implication is unglamorous: an intake channel people can actually find, an identity verification step so you do not hand data to an impostor, a defined internal path to whoever can retrieve the data, and a log of every request and every response.
Test it before somebody real uses it. Have an employee submit an access request under a pseudonym and time the response. In most organisations the first attempt takes eleven days and produces an incomplete answer, because nobody knew which systems to search. That dry run is the cheapest compliance exercise available, and it usually surfaces two systems missing from your inventory.
The breach notification clock
Breach notification runs on a 3x24 hour clock to both the affected individuals and the authority, and the clock starts when you become aware rather than when you finish investigating. Three days is not enough time to invent a process, so the process has to exist beforehand: who declares an incident, who assesses whether personal data was involved, who drafts the notification, and who signs it on a Sunday.
- A single reporting channel staffed in business hours, with a documented out-of-hours escalation
- A pre-drafted notification template containing the required content, approved by legal in advance
- A decision log capturing when you became aware and how the assessment was reached
- An incident register maintained even in quiet years — an empty register is evidence, a missing one is a finding
Vendors, contracts, and cross-border transfer
Every vendor touching personal data on your behalf is a processor and needs an agreement covering purpose limitation, security measures, sub-processor approval, breach notification back to you, audit rights, and deletion at termination. In practice that list includes your payroll provider, cloud host, CRM, email platform, and the agency running your ads. Most companies discover they have thirty such vendors and signed agreements with four of them.
Cross-border transfer needs one of three things: a destination country with equivalent protection, binding safeguards between the parties, or explicit consent. The pragmatic route for most clients is an Indonesian cloud region for anything sensitive plus documented safeguards for the rest. What matters is that the reasoning exists in writing before an inspection, rather than being constructed afterwards under time pressure.
What assessors actually ask to see
Here is what gets requested when an assessment actually happens. None of it is exotic, and all of it takes weeks to assemble if you start the day the letter arrives rather than keeping it current as you go.
- The data inventory and processing record, with owners named and a recent review date
- Consent logs with timestamps and source, for a sample of individuals they choose themselves
- Access review evidence for the last two quarters, showing who has access to what and why
- The incident register, plus the last tabletop exercise or breach simulation you ran
- Signed processor agreements and the list of sub-processors each vendor relies on
- Offboarding evidence proving leavers lost access, and a backup restore you have actually tested
None of that requires a large budget. It requires an owner with authority, a quarterly cadence, and the discipline to write things down as they happen. The companies that struggle here are not the ones with weak technology. They are the ones where six people each own a fragment of the problem and nobody owns the whole of it.
