Data Controller & Processor Obligations: Mandatory Checklist under PDP Law Articles 20-60
The first PDP audit usually fails not because of a breach, but because you cannot produce a ROPA. Documentation = evidence.
10 Core Data Controller Obligations
- Valid lawful basis — consent, contract, legal obligation, vital / public / legitimate interests
- Transparent information — privacy notice in plain Indonesian, easily accessible
- ROPA — record purposes, data / subject categories, retention periods, security profile (must be available during audits)
- Security (Article 35) — encryption, pseudonymization, access control, logging — security by design
- DPIA — mandatory for high risk: specific data, large scale, systematic profiling
- DPO — appoint if: public agency, core business is large-scale monitoring, or large-scale specific data
- Retention & deletion — do not store longer than the purpose; auto-delete / anonymize
- Processor contracts — written-instruction clauses, confidentiality, assistance with subject rights
- Cross-border transfer — only where the destination country offers adequate protection or safeguards exist
- 72-hour notification — breach notice to subjects + the PDP Authority (more on this later)
Processors Are Not Immune
A processor that exceeds written instructions = becomes a controller — full liability + sanctions.
Mini-ROPA Template (1 row = 1 activity)
| Activity | Data Category | Lawful Basis | Retention | Controls | |—|—|—|—|—| | Mobile customer onboarding | NIK, photo, biometrics | Consent + KYC POJK 12/2023 | 10 years post-closure (OJK) | AES-256, RBAC, audit log |
Download ROPA Excel Template → · Read When DPIA Is Mandatory →