Indonesia Personal Data Protection Law: Security-Control Workbook
This workbook supports evidence planning for organizations processing personal data in Indonesia. It is not legal advice, a compliance assessment, or a guarantee of compliance. Operator and qualified Indonesian legal review are required to decide applicability, roles, lawful basis, current implementing rules, and sufficiency of controls. Source checked 2026-08-13: UU No. 27 Tahun 2022 on the official BPK JDIH record and PDF.
Statutory text, not implementation claim
Pasal 20 ayat (1) says a Pengendali Data Pribadi must have a basis for processing personal data; ayat (2) lists bases. Pasal 35 huruf a–b says a controller must protect and ensure security of processed data by preparing and applying technical operational measures against processing interference contrary to law, and determining security level with regard to data characteristics and risks. Pasal 39 ayat (1)–(3) says a controller must prevent unauthorized access, using security systems for processed data and/or reliable, secure, responsible electronic systems, subject to applicable legislation.
Those are statutory provisions. They do not prescribe a workbook, control framework, technology, evidence retention period, or a single lawful basis. Tables below are implementation interpretation: a way to make facts, owners, evidence, gaps, and legal questions reviewable.
Start with processing boundary
For each activity, identify data categories, data subjects, purpose, system path, controller/processor role question, recipients, transfer question, and accountable operational owner. Do not assume title or vendor contract resolves role. Ask legal reviewer to determine legal characterization. Record unknowns as gaps.
Example: recruitment portal receives name, email, CV, and application metadata; applicant submits through web form; HR reviews in SaaS workflow; vendor stores encrypted backups. Evidence planner records purpose, data path, access groups, configuration owner, and legal-review question about roles and processing basis. Planner does not state activity is lawful or compliant.
Obligation-to-control evidence workbook
| Provision / planning question | Completed example | Evidence | Owner | Pass/fail | Exception or remediation |
|---|---|---|---|---|---|
| Pasal 20: basis recorded? | recruitment activity has basis field and counsel-review ticket | register v4, LEGAL-112 | privacy owner | Open | legal conclusion pending |
| Pasal 35(a): measures linked to path? | HR SaaS MFA, role groups, encrypted transport mapped | configuration export, access review | HR systems owner | Pass | backup setting review due |
| Pasal 35(b): risk considered? | CV classified as personal data; access risk documented | risk record R-77 | risk owner | Pass | retention risk open |
| Pasal 39: unauthorized access prevention tested? | terminated test account denied after deprovisioning | test log, timestamp | identity owner | Pass | quarterly repetition scheduled |
| Evidence freshness | access export dated 2026-08-01 and reviewer named | repository link | control owner | Fail | replace expired export |
Pass means stated planning criterion has current, attributable evidence. It does not mean statutory compliance. Fail means evidence missing, stale, contradictory, or does not relate to stated boundary. Open means legal, operational, or risk decision awaits authorized review.
Evidence quality
Prefer evidence that shows effective state: export from target, change approval, access-review result, test result, incident record, and signed decision. A policy can show intent but not operation. Preserve source, collection date, system version, collector, redactions, and access restrictions. Avoid placing credentials, full personal-data samples, or security secrets in broad repositories.
Map controls to specific threat and boundary. MFA for administrator access may support an access-control objective but says nothing about an uncontrolled export job. Encryption at transport may not address overbroad internal access. Record control limitation, compensating measure, exception owner, review date, remediation action, and retest evidence.
Review workflow
Operational owner updates evidence; security reviewer tests claims against target boundary; risk owner accepts or rejects residual risk; legal reviewer decides legal interpretation and applicable obligations. Keep their decisions distinct. If system changes, evidence changes, or authority changes, reopen relevant rows. Do not convert an old pass to enduring assurance.
Practical completion check
Before marking a workbook row pass, verify evidence comes from correct target, has collection date, identifies responsible owner, and maps to stated processing boundary. When evidence is vendor-provided, record what was independently verified and what remains vendor assertion. Escalate discrepancies to security, risk, and legal reviewers without changing statutory text.
Publication gate and worked review output
Do not publish a PDP mapping until named legal reviewer and designated operator approve applicability statement, quoted provision, and boundary. Example output: PDP-REC-04 records recruitment portal, CV access group, evidence hash, security test date, unresolved controller/processor question, legal reviewer, and next review date. If vendor backup evidence cannot identify storage or access boundary, row stays Open; it cannot be converted into a legal conclusion. This gate preserves operational facts for review and makes no compliance determination.
Sources
Worked closure check
For account-registration flow, record processing boundary, data categories, tested control state, collection date, configuration owner, and legal-review ticket. This workbook organizes operational evidence; it does not determine UU PDP compliance, lawful basis, certification, or legal effect. Reopen row after a processor, retention rule, identity path, or data destination changes. A reviewer samples one access-control claim from target export to test result and risk decision, marking unsupported vendor assertions and residual gaps as open rather than passing them.