Framework overlap

Does BSI IT-Grundschutz cover Indonesia PDP Law?

You hold BSI IT-Grundschutz and have been told to do Indonesia PDP Law. Here is how much overlaps, control by control.

70% of Indonesia PDP Law you already have

BSI IT-Grundschutz already covers about 70% of Indonesia PDP Law, leaving 3 of 10 controls as genuinely new work.

Already covered 5 Likely covered 2 New work 3

What is genuinely new work

Nothing in BSI IT-Grundschutz reaches these. This is the list to scope.

IDPdp-Processor-Contracts-DPA-Vendor-Art51-Subprocessor-Audit-Confidentiality-EndOfContract
Indonesia PDP Articles 47-56 + Personal Data Processor + DPA Contracts + Subprocessor Approval + Cross-Border Transfer Adequacy/BCR/Consent + Indonesian Representative
IDPdp-Scope-UU27-2022-Joko-Widodo-17Oct2022-Effective-17Oct2024-MoCom-DPA-Extraterritorial
Indonesia PDP Law Scope + UU No. 27 of 2022 (UU PDP) + President Joko Widodo 17 October 2022 + 2-Year Transition + Effective 17 October 2024 + MoCom DPA + Extraterritorial Applicat
IDPdp-Security-BreachNotification-72Hour-Art39-Art46-Encryption-Pseudonymisation-Records-IR
Indonesia PDP Article 39 + Article 46 + Reasonable Security + Encryption + Pseudonymisation + Personal Data Breach Notification 3x24 Hours (72 Hours) to DPA + Data Subjects + IR Pl
Show the 7 you already have
IDPdp-Controller-DPO-ROPA-DPIA-PrivacyByDesign-Art20to46-Accuracy-Accountability
Indonesia PDP Articles 20-46 + Controller Obligations + DPO Appointment + ROPA + DPIA + Privacy by Design + Accuracy + Accountability + Risk Assessment + Documentation
IDPdp-Enforcement-Sanctions-Administrative-Criminal-Art56to69-DPAgency-Fine-Imprisonment-IDR6bn
Indonesia PDP Articles 57-73 + Enforcement + Administrative Sanctions + Criminal Sanctions + Fines IDR Up to 6 Billion + Imprisonment Up to 6 Years + DPA Investigation + Damages Cl
IDPdp-LawfulBasis-Notice-Consent-PurposeLimitation-DataMinimisation-Art16to19-ExplicitConsent
Indonesia PDP Articles 16-19 + Lawful Basis + Notice + Explicit Consent + Purpose Limitation + Data Minimisation + 6 Lawful Bases + Withdrawal + Transparency
IDPdp-Marketing-Profiling-DirectCommunication-Art18-OptOut-PreferenceCenter-Cookies
Indonesia PDP Marketing + Profiling + Direct Communication + Article 18 Marketing Consent + Opt-Out + Preference Center + Cookies + Tracking Technologies + Behavioural Advertising
IDPdp-SpecificData-SensitiveData-Children-Art4-Art25-Consent-COPPA-VerifiableParental
Indonesia PDP Article 4 + Article 25 + Specific Personal Data (Sensitive) + Health + Biometric + Genetic + Crime + Financial + Child + Verifiable Parental Consent + Best Interests
IDPdp-DataSubjectRights-Art5to15-Access-Correction-Erasure-Portability-Object-Withdraw-Automated
Indonesia PDP Articles 5-15 + Data Subject Rights + Access + Correction + Erasure + Portability + Object + Withdraw Consent + Automated Decision-Making + Damages Claim + Identity V
IDPdp-Training-Awareness-Coord-ASEAN-SingaporePDPA-APEC-CBPR-GDPR-Art70to76-MoCom-Transition
Indonesia PDP Training + Awareness + Indonesian Representative + Lembaga PDP Transition + Coordination ASEAN/Singapore PDPA/APEC CBPR/GDPR/India DPDP/Cross-Sectoral OJK/BI/BSSN

How this is calculated

Already covered means a mapping runs from a control in BSI IT-Grundschutz to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition