All resources
// Resources

Indonesia Personal Data Protection Law: Security-Control Workbook

Published August 7, 2026

This workbook supports evidence planning for organizations processing personal data in Indonesia. It is not legal advice, a compliance assessment, or a guarantee of compliance. Operator and qualified Indonesian legal review are required to decide applicability, roles, lawful basis, current implementing rules, and sufficiency of controls. Source checked 2026-08-13: UU No. 27 Tahun 2022 on the official BPK JDIH record and PDF.

Statutory text, not implementation claim

Pasal 20 ayat (1) says a Pengendali Data Pribadi must have a basis for processing personal data; ayat (2) lists bases. Pasal 35 huruf a–b says a controller must protect and ensure security of processed data by preparing and applying technical operational measures against processing interference contrary to law, and determining security level with regard to data characteristics and risks. Pasal 39 ayat (1)–(3) says a controller must prevent unauthorized access, using security systems for processed data and/or reliable, secure, responsible electronic systems, subject to applicable legislation.

Those are statutory provisions. They do not prescribe a workbook, control framework, technology, evidence retention period, or a single lawful basis. Tables below are implementation interpretation: a way to make facts, owners, evidence, gaps, and legal questions reviewable.

Start with processing boundary

For each activity, identify data categories, data subjects, purpose, system path, controller/processor role question, recipients, transfer question, and accountable operational owner. Do not assume title or vendor contract resolves role. Ask legal reviewer to determine legal characterization. Record unknowns as gaps.

Example: recruitment portal receives name, email, CV, and application metadata; applicant submits through web form; HR reviews in SaaS workflow; vendor stores encrypted backups. Evidence planner records purpose, data path, access groups, configuration owner, and legal-review question about roles and processing basis. Planner does not state activity is lawful or compliant.

Obligation-to-control evidence workbook

Provision / planning questionCompleted exampleEvidenceOwnerPass/failException or remediation
Pasal 20: basis recorded?recruitment activity has basis field and counsel-review ticketregister v4, LEGAL-112privacy ownerOpenlegal conclusion pending
Pasal 35(a): measures linked to path?HR SaaS MFA, role groups, encrypted transport mappedconfiguration export, access reviewHR systems ownerPassbackup setting review due
Pasal 35(b): risk considered?CV classified as personal data; access risk documentedrisk record R-77risk ownerPassretention risk open
Pasal 39: unauthorized access prevention tested?terminated test account denied after deprovisioningtest log, timestampidentity ownerPassquarterly repetition scheduled
Evidence freshnessaccess export dated 2026-08-01 and reviewer namedrepository linkcontrol ownerFailreplace expired export

Pass means stated planning criterion has current, attributable evidence. It does not mean statutory compliance. Fail means evidence missing, stale, contradictory, or does not relate to stated boundary. Open means legal, operational, or risk decision awaits authorized review.

Evidence quality

Prefer evidence that shows effective state: export from target, change approval, access-review result, test result, incident record, and signed decision. A policy can show intent but not operation. Preserve source, collection date, system version, collector, redactions, and access restrictions. Avoid placing credentials, full personal-data samples, or security secrets in broad repositories.

Map controls to specific threat and boundary. MFA for administrator access may support an access-control objective but says nothing about an uncontrolled export job. Encryption at transport may not address overbroad internal access. Record control limitation, compensating measure, exception owner, review date, remediation action, and retest evidence.

Review workflow

Operational owner updates evidence; security reviewer tests claims against target boundary; risk owner accepts or rejects residual risk; legal reviewer decides legal interpretation and applicable obligations. Keep their decisions distinct. If system changes, evidence changes, or authority changes, reopen relevant rows. Do not convert an old pass to enduring assurance.

Practical completion check

Before marking a workbook row pass, verify evidence comes from correct target, has collection date, identifies responsible owner, and maps to stated processing boundary. When evidence is vendor-provided, record what was independently verified and what remains vendor assertion. Escalate discrepancies to security, risk, and legal reviewers without changing statutory text.

Publication gate and worked review output

Do not publish a PDP mapping until named legal reviewer and designated operator approve applicability statement, quoted provision, and boundary. Example output: PDP-REC-04 records recruitment portal, CV access group, evidence hash, security test date, unresolved controller/processor question, legal reviewer, and next review date. If vendor backup evidence cannot identify storage or access boundary, row stays Open; it cannot be converted into a legal conclusion. This gate preserves operational facts for review and makes no compliance determination.

Sources

Worked closure check

For account-registration flow, record processing boundary, data categories, tested control state, collection date, configuration owner, and legal-review ticket. This workbook organizes operational evidence; it does not determine UU PDP compliance, lawful basis, certification, or legal effect. Reopen row after a processor, retention rule, identity path, or data destination changes. A reviewer samples one access-control claim from target export to test result and risk decision, marking unsupported vendor assertions and residual gaps as open rather than passing them.

Have a system that needs testing?