UU PDP
Personal-data rights, controller responsibilities, security, breach notification, and cross-border transfer governance apply across sectors.
UU PDP technical guideSeparate UU PDP, OJK banking supervision, and Bank Indonesia payment-system obligations while preserving one traceable control and evidence path.
Indonesia starts as one substantive page because the same financial-services workflow may simultaneously process personal data, sit inside an OJK-supervised bank, and interact with a Bank Indonesia-regulated payment service. The legal sources remain distinct even when the runtime evidence overlaps.
Personal-data rights, controller responsibilities, security, breach notification, and cross-border transfer governance apply across sectors.
UU PDP technical guideBinding IT and consumer-protection rules combine with OJK's 2025 AI governance guidance for banking supervision.
OJK technical guidePayment service providers and payment-system infrastructure firms operate under PBI governance, security, risk, audit, and reporting expectations.
Bank Indonesia technical guide| Control area | UU PDP lens | OJK / BI lens | AxonFlow contribution |
|---|---|---|---|
| Personal data | Purpose, rights, safeguards, breach response, and transfers. | Customer protection, banking secrecy, security, and operational risk. | Configured NIK, NPWP, phone, and bank-account detection with policy and audit records. |
| System accountability | Controller and processor responsibilities. | Responsible owner, governance, reliability, and supervised operation. | Tenant, system, actor, policy, and execution context linked to framework workflows. |
| Human intervention | Organizational safeguard for material processing decisions. | Human oversight and accountable action in banking and payments. | HITL approval records and licensed emergency controls. |
| Incident evidence | Discovery, affected data, notification content, timing, and remediation. | Operational incident reporting, containment, recovery, and audit evidence. | Incident-oriented records and Enterprise breach-notification workflow support. |
| Cross-border processing | Transfer basis and destination governance. | Outsourcing, infrastructure, data, and operational risk controls. | Enterprise transfer-basis and data-residency evidence fields; legal basis remains yours. |
| Auditability | Demonstrate processing and safeguards. | IS audit, readiness, retention, and regulator-facing evidence. | Governed request records and OJK / BI / UU PDP-oriented exports. |
Identify where data enters, which model or tool receives it, the transfer location, and the downstream system of record.
Test allow, redact, block, and approval behavior before information reaches a model, connector, or payment action.
Connect AxonFlow decisions with banking, payment, customer-case, and infrastructure logs.
Capture discovery time, data categories, affected subjects, remediation, approvals, and downstream correction.
Verify that routing and evidence match the organization's approved cross-border processing decision.
Confirm retention, ownership, reviewer authority, missing metadata, and export completeness before audit or supervisory engagement.
Separate technical pages already preserve the implementation detail. On the landing site, one country page gives a buyer or platform team a coherent map without repeating the same policy, PII, approval, and audit story three times.
Use the Evaluation license to assess policy enforcement, human review, evidence records, and deployment boundaries before a regulated rollout.