Roadmap Kepatuhan UU PDP untuk Enterprise: Checklist 12 Minggu dari ROPA hingga Audit

Jangan tunggu Lembaga PDP mengetuk — kejar audit PDP sebelum OJK/BI menanyakan bukti.

Fase 1 — Discover (Minggu 1-2)

  • Inventaris data: sumber, kategori (umum/spesifik), aliran (source → DB → backup → prosesor → lintas negara)
  • ROPA awal: 30-50 aktivitas utama, gap vs Pasal 20-35
  • Consent audit: banner, log, granular — hilangkan dark pattern

Fase 2 — Design (Minggu 3-6)

  • Kebijakan & SOP: privacy notice, hak subjek (SOP 14 hari), retensi, breach 72 jam
  • DPIA untuk 2-3 risiko tinggi (QRIS, BI-FAST, scoring AI)
  • Tunjuk DPO + Privacy Committee, kontrak prosesor amendemen SCC

Fase 3 — Harden (Minggu 7-10)

  • Teknis: enkripsi AES-256, pseudonimisasi, ABAC/RBAC, mTLS, logging, DLP, key vault
  • Penetration test & code review — tutup temuan BOLA/IDOR yang langsung jadi pasal PDP
  • Vendor assurance: audit prosesor, TIA untuk cloud Singapore

Fase 4 — Prove & Sustain (Minggu 11-12 + kontinu)

  • Tabletop breach 72 jam: simulasi kebocoran 1 juta record — siapa lapor ke Lembaga PDP dalam 3x24 jam?
  • Paket audit: ROPA, DPIA, log consent, laporan pen-tes, SOP — board pack 10 hari ala Snipeyes, retest termasuk
  • KPI: SAR ≤14 hari, breach notify ≤72 jam, retensi 100% sesuai SOP

Deliverable Snipeyes (CREST + ISO 27001:2022)

Assessment 10 hari → peta risiko + prioritas sanksi → tutup temuan + retest → paket audit OJK/BI ready. NDA, per-module pricing, follow-the-sun.

Mulai minggu ini: Kirim ROPA draft Anda — kami review gratis 90 menit. Jika belum ada, kami inventariskan bareng.

Request PDP Enterprise Roadmap → · Template ROPA/DPIA — Download →