PT Novatama Solusi Teknologi
Book a schedule
Home/Insights/Digital Strategy
Digital Strategy

A CIO’s Plain-Language UU PDP Readiness Checklist

UU 27/2022 has been enforceable since October 2024, and most Indonesian companies are still somewhere between a policy PDF and a plan. This is the checklist I use with clients: what the law asks of you in plain language, and what evidence you will eventually be asked to produce.

What UU PDP actually requires of you

Three ideas carry most of the weight. First, you are either a controller — you decide why and how personal data is processed — or a processor acting on somebody else’s instruction, and the obligations differ substantially. Second, you must be able to show what personal data you hold, why, and on what basis; that record is not optional. Third, sanctions are administrative and can reach a share of annual revenue, with criminal provisions for unlawful collection and disclosure.

You may also need a data protection officer. The trigger is not company size but the nature of the processing: large-scale systematic monitoring, or processing sensitive data such as health, biometric, financial, or children’s data as a core activity. A hospital group, a fintech, and an insurance broker all need one. A B2B distributor with an HR database usually does not, though somebody still has to own the topic by name.

Lawful basis: the question you answer per dataset

The law gives six lawful bases, and the practical mistake is reaching for consent every time. Consent must be freely given, specific, informed, and withdrawable — which is exactly why employee data almost never rests on it. An employee cannot meaningfully refuse. Employment data sits on contract performance and legal obligation instead, and framing it as consent creates a withdrawal right you cannot honour without ending the employment.

  • Employee HR and payroll data: contract performance plus legal obligation, never consent
  • Customer order fulfilment and invoicing: contract performance, with retention set by tax rules
  • Marketing and profiling: consent, recorded granularly per channel and withdrawable in one step
  • CCTV and access logs: legitimate interest, documented with a balancing assessment kept on file
  • Anything involving health, biometrics, or children: sensitive data, with the stricter rules that follow

Data subject rights in practice

Data subjects can ask for information about processing, access to their data, correction, deletion, restriction, withdrawal of consent, an explanation of automated decisions, and portability. The operational implication is unglamorous: an intake channel people can actually find, an identity verification step so you do not hand data to an impostor, a defined internal path to whoever can retrieve the data, and a log of every request and every response.

Test it before somebody real uses it. Have an employee submit an access request under a pseudonym and time the response. In most organisations the first attempt takes eleven days and produces an incomplete answer, because nobody knew which systems to search. That dry run is the cheapest compliance exercise available, and it usually surfaces two systems missing from your inventory.

The breach notification clock

Breach notification runs on a 3x24 hour clock to both the affected individuals and the authority, and the clock starts when you become aware rather than when you finish investigating. Three days is not enough time to invent a process, so the process has to exist beforehand: who declares an incident, who assesses whether personal data was involved, who drafts the notification, and who signs it on a Sunday.

  • A single reporting channel staffed in business hours, with a documented out-of-hours escalation
  • A pre-drafted notification template containing the required content, approved by legal in advance
  • A decision log capturing when you became aware and how the assessment was reached
  • An incident register maintained even in quiet years — an empty register is evidence, a missing one is a finding

Vendors, contracts, and cross-border transfer

Every vendor touching personal data on your behalf is a processor and needs an agreement covering purpose limitation, security measures, sub-processor approval, breach notification back to you, audit rights, and deletion at termination. In practice that list includes your payroll provider, cloud host, CRM, email platform, and the agency running your ads. Most companies discover they have thirty such vendors and signed agreements with four of them.

Cross-border transfer needs one of three things: a destination country with equivalent protection, binding safeguards between the parties, or explicit consent. The pragmatic route for most clients is an Indonesian cloud region for anything sensitive plus documented safeguards for the rest. What matters is that the reasoning exists in writing before an inspection, rather than being constructed afterwards under time pressure.

What assessors actually ask to see

Here is what gets requested when an assessment actually happens. None of it is exotic, and all of it takes weeks to assemble if you start the day the letter arrives rather than keeping it current as you go.

  • The data inventory and processing record, with owners named and a recent review date
  • Consent logs with timestamps and source, for a sample of individuals they choose themselves
  • Access review evidence for the last two quarters, showing who has access to what and why
  • The incident register, plus the last tabletop exercise or breach simulation you ran
  • Signed processor agreements and the list of sub-processors each vendor relies on
  • Offboarding evidence proving leavers lost access, and a backup restore you have actually tested

None of that requires a large budget. It requires an owner with authority, a quarterly cadence, and the discipline to write things down as they happen. The companies that struggle here are not the ones with weak technology. They are the ones where six people each own a fragment of the problem and nobody owns the whole of it.

Key takeaways
Build the data inventory before the policy; most findings come from systems nobody remembered existed.
Employee data rests on contract and legal obligation — consent creates a withdrawal right you cannot honour.
Breach notification runs 3x24 hours from awareness, so the process must exist before the incident does.
Assessors ask for evidence — inventories, consent logs, access reviews, processor agreements — not policies.
Back to insights

Want this applied to your business?

Book a free 45-minute consultation. We’ll look at your actual process and tell you honestly what is worth doing first.