Indonesia PDP Law Compliance Roadmap for Enterprise: 12-Week Checklist from ROPA to Audit

Don’t wait for the PDP Authority to knock — chase your PDP audit before OJK/BI asks for evidence.

Phase 1 — Discover (Weeks 1-2)

  • Data inventory: sources, categories (general / specific), flows (source → DB → backup → processor → cross-border)
  • Initial ROPA: 30-50 key activities, gap vs Articles 20-35
  • Consent audit: banners, logs, granularity — remove dark patterns

Phase 2 — Design (Weeks 3-6)

  • Policies & SOPs: privacy notice, subject rights (14-day SOP), retention, 72-hour breach
  • DPIA for 2-3 high risks (QRIS, BI-FAST, AI scoring)
  • Appoint DPO + Privacy Committee, amend processor contracts with SCCs

Phase 3 — Harden (Weeks 7-10)

  • Technical: AES-256 encryption, pseudonymization, ABAC/RBAC, mTLS, logging, DLP, key vault
  • Penetration test & code review — close BOLA/IDOR findings that map directly to PDP articles
  • Vendor assurance: processor audits, TIA for Singapore cloud

Phase 4 — Prove & Sustain (Weeks 11-12 + continuous)

  • 72-hour breach tabletop: simulate a 1-million-record leak — who reports to the PDP Authority within 3x24 hours?
  • Audit pack: ROPA, DPIA, consent logs, pen-test reports, SOPs — Snipeyes-style 10-day board pack, retest included
  • KPIs: SAR ≤14 days, breach notify ≤72 hours, 100% retention per SOP

Snipeyes Deliverables (CREST + ISO 27001:2022)

10-day assessment → risk map + sanctions priority → remediate findings + retest → OJK/BI-ready audit pack. NDA, per-module pricing, follow-the-sun.

Start this week: Send your draft ROPA — we review it free in 90 minutes. If you don’t have one yet, we will inventory it together.

Request PDP Enterprise Roadmap → · ROPA/DPIA Templates — Download →