Articles 47-56 of UU PDP govern relationships with processors and cross-border transfers. Article 47-50 Personal Data Processor: Processor (Prosesor Data Pribadi) shall (a) process personal data based on instructions from Personal Data Controller; (b) implement TOMs equivalent to Controller; (c) not engage subprocessors without Controller written authorisation; (d) ensure persons processing personal data are bound by confidentiality obligations; (e) assist Controller in fulfilling Data Subject rights; (f) return or delete personal data at end of services; (g) maintain ROPA per Article 46. Article 51 Data Processing Agreement: contract between Controller and Processor shall be in writing + Bahasa Indonesia + cover (a) subject matter + duration + nature + purpose of processing; (b) types of personal data + categories of Data Subjects; (c) obligations + rights of Controller + Processor; (d) instructions for processing; (e) confidentiality requirements; (f) TOMs requirements; (g) sub-processor restrictions; (h) Data Subject rights assistance; (i) breach notification; (j) data return/deletion at end of contract; (k) audit rights for Controller; (l) governing law (Indonesian law preferred). Articles 55-56 Cross-Border Transfer: transfer of personal data outside Indonesian territory shall comply with one of the following: (a) Data Subject explicit consent for the transfer + after being informed of risks; (b) adequacy determination - the receiving country has equivalent or higher personal data protection (Lembaga PDP to issue adequacy determinations); (c) appropriate safeguards including Standard Contractual Clauses (SCCs) similar to ASEAN MCCs + EU SCCs + Binding Corporate Rules (BCRs) approved by Lembaga PDP + Privacy Codes of Conduct + Certification; (d) necessary for contract performance with Data Subject; (e) public interest; (f) protection of vital interests; (g) legal claims; (h) compelling legitimate interests with safeguards. Government Access requests: handled through international cooperation channels per ICAO/MLAT process not direct compelled access. Data Localisation: certain categories require local processing including (a) electronic transaction data per OJK regulations for financial services; (b) public service data per Government Regulation 71/2019; (c) sectoral data per BSSN + Bank Indonesia. Article 38 Indonesian Representative: foreign Controllers/Processors processing personal data of Indonesian residents must appoint Indonesian Representative based in Indonesia who is accountable + responsive to DPA + Data Subjects. Coordinates with GDPR Arts 28 + 44-50 + India DPDP Sec 16-17 + Singapore PDPA cross-border + ASEAN Model Contractual Clauses + APEC CBPR + Bank Indonesia + OJK + BSSN cyber regulations. Indonesia PDP Art 47-56 Processor + Cross-Border applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.