We hold customer data but are not ready if it leaks
Short answer
Indonesia’s data protection law allows administrative sanctions of up to 2% of annual revenue, and breaches must be reported within 72 hours. What decides the outcome is not how advanced your security is, but whether the data map, access trail, and reporting procedure existed before the incident. A readiness review takes three weeks.
Typical duration: 3 weeks
$4,200
What this looks like
- Nobody can say with certainty where all customer data is held
- There is no record of who accessed what and when
- No written procedure for the first 72 hours after a breach
- Old customer data is never deleted because nobody knows whether it may be
- Third-party vendors hold your data without an agreement covering their obligations
Why this happens
Almost every obligation under the law demands something that must already exist before the incident, not something assembled afterwards. An access audit trail cannot be created retroactively. A data map cannot be built in three days while everyone is handling a breach. And the 72-hour clock starts when the breach is discovered — not when you finish investigating it.
That is why companies with good security still get sanctioned: what is examined is not whether you can be breached, but whether you carried out the written obligations. Those are different things, and the second is far easier for an examiner to prove.
How we solve it
- 01
Data map
We trace where personal data actually flows — systems, spreadsheets, third-party vendors, and forgotten export files. One week.
- 02
Gap analysis
Each obligation is compared against reality, and the gaps are ordered by sanction risk rather than by ease. One week.
- 03
Breach procedure
We build a 72-hour path that can be run as written: who decides, what is reported, who signs. Then we test it with a tabletop exercise.
- 04
Ordered remediation
You receive a fix list with effort estimates per item, so it can be worked through in stages against your budget.
Numbers from our own work
Every breach procedure we hand over is tested with a tabletop exercise, not just written
The fix list is ordered by sanction risk, so a limited budget still closes the heaviest gaps first
Mistakes we keep seeing
- Assuming the obligation is met by buying a security product — what is examined is the procedure, not the product
- Writing the breach procedure during the breach; the deadline passes before the first meeting ends
- Forgetting third-party vendors, even though data they hold remains your responsibility
Questions we are asked most
Can we still be sanctioned if we already bought expensive security tools?
Yes. What is examined is whether the written obligations are carried out — data map, access trail, retention limits, and reporting procedure. Security tools produce none of those on their own.
How long until we are considered compliant?
The review and procedure work takes three weeks. The fixes found are usually worked through over one to three months, depending on how many systems hold personal data.
Is this the same as ISO 27001 certification?
No. ISO 27001 is a management system certification audited by a certification body. The data protection law is a legal obligation that applies whether you are certified or not. They reinforce each other but do not substitute.
Updated 30 July 2026 · Neuraltan
If this is happening to you
Tell us the situation. We will say plainly whether this is worth doing now, and how long it takes.