Data Controller & Processor Obligations: Mandatory Checklist under PDP Law Articles 20-60

The first PDP audit usually fails not because of a breach, but because you cannot produce a ROPA. Documentation = evidence.

10 Core Data Controller Obligations

  1. Valid lawful basis — consent, contract, legal obligation, vital / public / legitimate interests
  2. Transparent information — privacy notice in plain Indonesian, easily accessible
  3. ROPA — record purposes, data / subject categories, retention periods, security profile (must be available during audits)
  4. Security (Article 35) — encryption, pseudonymization, access control, logging — security by design
  5. DPIA — mandatory for high risk: specific data, large scale, systematic profiling
  6. DPO — appoint if: public agency, core business is large-scale monitoring, or large-scale specific data
  7. Retention & deletion — do not store longer than the purpose; auto-delete / anonymize
  8. Processor contracts — written-instruction clauses, confidentiality, assistance with subject rights
  9. Cross-border transfer — only where the destination country offers adequate protection or safeguards exist
  10. 72-hour notification — breach notice to subjects + the PDP Authority (more on this later)

Processors Are Not Immune

A processor that exceeds written instructions = becomes a controller — full liability + sanctions.

Mini-ROPA Template (1 row = 1 activity)

| Activity | Data Category | Lawful Basis | Retention | Controls | |—|—|—|—|—| | Mobile customer onboarding | NIK, photo, biometrics | Consent + KYC POJK 12/2023 | 10 years post-closure (OJK) | AES-256, RBAC, audit log |

Download ROPA Excel Template → · Read When DPIA Is Mandatory →