Skip to content
Ambara Digital Nusantara

UU PDP compliance

UU PDP and ISO/IEC 27001 compliance

We translate the requirements of Indonesia’s Personal Data Protection Law (UU No. 27 Tahun 2022) into controls your operations and technology teams can run, reducing regulatory risk and speeding up audit readiness.

Timeline
Set by scope
From
Rp 40 million
Size
SME to group
FrameworksUU No. 27/2022ISO/IEC 27001:2022ISO/IEC 27701NIST CSF 2.0
UU PDPISO 27001NIST CSFStatusPersonal data inventoryA.5.9ID.AMMetConsent and lawful basisA.5.34GV.POGapAccess controlA.5.15PR.AAMetBreach notificationA.5.26RS.COGapProcessor contractsA.5.20GV.SCPartialRoadmap30 days60 days90 days
Illustrative gap assessment: UU PDP obligations mapped to ISO/IEC 27001 and NIST CSF controls.

01

Scope of work

01

Personal data mapping

An inventory of personal data flows and the obligations that apply.

02

Gap assessment

Controls assessed against UU PDP and ISO/IEC 27001.

03

Policies and governance

Policies, SOPs and a governance model that can actually be run.

04

Technical controls

Access control, logging and incident handling.

05

Evidence management

Organised evidence and audit trails for internal and external audits.

06

Awareness and ownership

Awareness training and clear owners across departments.

02

Packages

Compliance Baseline

From Rp 40 million

  • Data flow and regulatory obligation mapping
  • UU PDP and ISO/IEC 27001 gap assessment
  • 30/60/90-day remediation roadmap
Book a consultation →

Compliance Acceleration

From Rp 90 million

  • Policies, SOPs and priority controls implemented
  • Evidence pack and audit trail structure
  • Readiness review support and management report
Book a consultation →

Compliance Enterprise

By proposal

  • Multi-entity governance model and ownership matrix
  • Continuous control programme with a KPI dashboard
  • Pre-audit simulation and continuous improvement plan
Book a consultation →

03

What you receive

  • A compliance roadmap prioritised by risk and business impact
  • Policies and SOPs ready to adopt
  • An evidence checklist for internal and external audits
  • Statement of Applicability (ISO/IEC 27001) and records of processing activities (UU PDP)
  • A continuous improvement plan beyond the first phase

04

Frequently asked questions

What does UU PDP compliance support involve?

Mapping regulatory obligations, assessing control gaps, planning remediation and preparing evidence so the organisation is audit-ready and the risk of sanctions is reduced.

Is it only for large companies?

No. The programme can be tailored for SMEs, growing companies and multi-entity groups, with phased implementation.

How long does the programme take?

It depends on the scope: how complex your personal data processing is, the number of systems, existing documentation and your audit target. We give a time estimate after scoping.

Can ADN issue an ISO/IEC 27001 certificate?

No. Certificates are issued by accredited certification bodies. We prepare your organisation for that audit.

05

Need help with UU PDP compliance?

We support you from the initial assessment through control implementation to audit readiness.

Book a consultation