A 12-week PDP Law compliance roadmap for enterprises
Regulators will ask for evidence that you comply with Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, UU PDP). That request could come from the PDP authority (lembaga PDP), or from sector supervisors such as the Financial Services Authority (OJK) or Bank Indonesia (BI). It is far easier to have that evidence ready than to assemble it under pressure.
The plan below spreads the work over twelve weeks in four phases. It suits a large organization that has a named project owner and support from the board. Each phase ends with something you can show.
Weeks 1 and 2: find out what you hold
Start with a data inventory. It records where personal data comes from, whether it is general or specific (the law’s sensitive category), and how it flows from source systems, databases and backups to processors and across borders.
From that inventory, draft an initial record of processing activities (ROPA), the register of every way you use personal data. Expect 30-50 core processing activities. Run a gap analysis against the controller obligations in the PDP Law as you go.
In the same two weeks, audit how you collect consent: banners, consent logs and how granular the choices are. Remove dark patterns, meaning screens designed to push people into agreeing.
Weeks 3 to 6: set the rules and name the owners
This phase turns findings into policy.
- Write the policies and standard operating procedures (SOPs): privacy notice, handling data subject rights requests within the 72-hour deadline, retention, and incident notification within 72 hours (3x24 jam).
- Carry out data protection impact assessments (DPIAs) for two or three high-risk processing activities. In a bank these might be QR code payments (QRIS), BI-FAST real-time transfers and AI-based scoring.
- Appoint a data protection officer (DPO) and form a Privacy Committee.
- Amend processor contracts to include standard contractual clauses (SCCs), which are template data protection terms.
Weeks 7 to 10: close the technical gaps
Policies mean little if the systems leak. This is where the technical team does most of the work.
The controls to put in place include AES-256 encryption, pseudonymization (replacing identifiers with codes), attribute- and role-based access control (ABAC/RBAC), mutual TLS (mTLS) between services, logging, and a key vault. Add data loss prevention (DLP), tools that stop sensitive data leaving the organization. DLP should cover personal data typed into generative AI tools, for example with Nesgate.
Commission penetration testing (an authorized, controlled attack that finds weaknesses before criminals do) and source code review. Close any BOLA/IDOR findings, flaws that let one user read another user’s records. These bear directly on the PDP Law’s data security obligations.
Finally, check your vendors. Audit your processors and run transfer impact assessments (TIAs) for cloud hosting in Singapore.
Weeks 11 and 12, and beyond: prove it works
Run a data breach tabletop exercise, a guided walk-through of a simulated incident. Simulate a breach of 1 million records and ask: who notifies the PDP authority and the people affected within 72 hours?
Then assemble an audit pack for the board. It should hold the ROPA, DPIAs, consent logs, penetration test reports and SOPs.
After that, compliance becomes routine. Track three measures: data subject requests fulfilled within 72 hours, incidents notified within 72 hours, and 100% of data retained in line with your SOPs.
Where Snipeyes fits
Our 10-day assessment produces a risk map and a prioritized view of your sanctions exposure. We then help remediate the findings and retest them, through to an audit pack ready for OJK or BI review. Snipeyes is a CREST-accredited, ISO/IEC 27001:2022-certified penetration testing provider, and all work is carried out under NDA.
Start this week
Send us your draft ROPA and we will review it with you at no cost in a 90-minute session. If you do not have one yet, we will build the inventory with you.