70% of Indonesia PDP Law you already have
NIST Cybersecurity Framework 2.0 already covers about 70% of Indonesia PDP Law, leaving
3 of 10 controls as genuinely new work.
Already covered 0
Likely covered 7
New work 3
No control in NIST Cybersecurity Framework 2.0
maps directly to one in Indonesia PDP Law. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.
IDPdp-Processor-Contracts-DPA-Vendor-Art51-Subprocessor-Audit-Confidentiality-EndOfContractIndonesia PDP Articles 47-56 + Personal Data Processor + DPA Contracts + Subprocessor Approval + Cross-Border Transfer Adequacy/BCR/Consent + Indonesian Representative
IDPdp-Scope-UU27-2022-Joko-Widodo-17Oct2022-Effective-17Oct2024-MoCom-DPA-ExtraterritorialIndonesia PDP Law Scope + UU No. 27 of 2022 (UU PDP) + President Joko Widodo 17 October 2022 + 2-Year Transition + Effective 17 October 2024 + MoCom DPA + Extraterritorial Applicat
IDPdp-Security-BreachNotification-72Hour-Art39-Art46-Encryption-Pseudonymisation-Records-IRIndonesia PDP Article 39 + Article 46 + Reasonable Security + Encryption + Pseudonymisation + Personal Data Breach Notification 3x24 Hours (72 Hours) to DPA + Data Subjects + IR Pl
Show the 7 you already have
IDPdp-Controller-DPO-ROPA-DPIA-PrivacyByDesign-Art20to46-Accuracy-AccountabilityIndonesia PDP Articles 20-46 + Controller Obligations + DPO Appointment + ROPA + DPIA + Privacy by Design + Accuracy + Accountability + Risk Assessment + Documentation
IDPdp-DataSubjectRights-Art5to15-Access-Correction-Erasure-Portability-Object-Withdraw-AutomatedIndonesia PDP Articles 5-15 + Data Subject Rights + Access + Correction + Erasure + Portability + Object + Withdraw Consent + Automated Decision-Making + Damages Claim + Identity V
IDPdp-Enforcement-Sanctions-Administrative-Criminal-Art56to69-DPAgency-Fine-Imprisonment-IDR6bnIndonesia PDP Articles 57-73 + Enforcement + Administrative Sanctions + Criminal Sanctions + Fines IDR Up to 6 Billion + Imprisonment Up to 6 Years + DPA Investigation + Damages Cl
IDPdp-LawfulBasis-Notice-Consent-PurposeLimitation-DataMinimisation-Art16to19-ExplicitConsentIndonesia PDP Articles 16-19 + Lawful Basis + Notice + Explicit Consent + Purpose Limitation + Data Minimisation + 6 Lawful Bases + Withdrawal + Transparency
IDPdp-Marketing-Profiling-DirectCommunication-Art18-OptOut-PreferenceCenter-CookiesIndonesia PDP Marketing + Profiling + Direct Communication + Article 18 Marketing Consent + Opt-Out + Preference Center + Cookies + Tracking Technologies + Behavioural Advertising
IDPdp-SpecificData-SensitiveData-Children-Art4-Art25-Consent-COPPA-VerifiableParentalIndonesia PDP Article 4 + Article 25 + Specific Personal Data (Sensitive) + Health + Biometric + Genetic + Crime + Financial + Child + Verifiable Parental Consent + Best Interests
IDPdp-Training-Awareness-Coord-ASEAN-SingaporePDPA-APEC-CBPR-GDPR-Art70to76-MoCom-TransitionIndonesia PDP Training + Awareness + Indonesian Representative + Lembaga PDP Transition + Coordination ASEAN/Singapore PDPA/APEC CBPR/GDPR/India DPDP/Cross-Sectoral OJK/BI/BSSN
How this is calculated
Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition