Many companies claim to comply with Law Number 27 of 2022 concerning Personal Data Protection. However, when asked for proof, the answer often stops at “we have a privacy policy on our website.” In fact, the privacy policy is merely a showcase. The real compliance burden lies in two documents that are rarely seen by the public: RoPA and DPIA.
Both are not as popular as the privacy policy due to their internal nature. This is where their value lies. When regulators or auditors come, these two documents are usually the first ones to be asked about.
RoPA, The Record Required by Article 31
The PDP Law through Article 31 requires data controllers to record all personal data processing activities. The law does not literally mention the term Record of Processing Activities, but in practice, it points in that direction. The record must include the types of data processed, categories of data subjects, parties receiving the data, legal basis for processing, and security measures implemented. Without RoPA, companies do not truly know what data they hold. This is a bigger issue than it seems.
DPIA, Assessing Risks Before It's Too Late
DPIA or Data Protection Impact Assessment is an analysis to map risks to personal data before processing begins. This document becomes mandatory, or at least highly recommended, when processing is high-risk. For example, involving sensitive data on a large scale or invasive new technologies. The logic is simple. Fixing gaps in the design phase is much cheaper than addressing them after they become auditor findings or leakage incidents.
Why Both Are Often Overlooked
RoPA and DPIA require cross-divisional work and do not produce anything visible on the surface. There are no pretty pages to showcase to customers. Therefore, they are often postponed until there is a trigger, usually an audit or a request from business partners. The administrative sanctions of the PDP Law, which can reach two percent of annual revenue, make such delays a costly gamble.
Proven Compliance
Personal data compliance is not about having a policy that is easy to read, but rather about being able to show a neat trail when requested. Companies that treat RoPA and DPIA as an administrative burden usually change their minds only after an incident. And when that happens, the cost is already much higher than preparing it from the start.
References:
- BPK Regulation – Law No. 27 of 2022 concerning Personal Data Protection → peraturan.bpk.go.id
- Hukumonline – Provisions of Record of Processing Activities in the PDP Law → hukumonline.com
- Faculty of Law, Tarumanagara University – Implementation of Law No. 27 of 2022 and Enforcement Challenges → fh.untar.ac.id