Indonesia PDP Law
Indonesia PDP Sensitive + Children

Indonesia PDP Law IDPdp-SpecificData-SensitiveData-Children-Art4-Art25-Consent-COPPA-VerifiableParental: Indonesia PDP Article 4 + Article 25 + Specific Personal Data (Sensitive) + Health + Biometric + Genetic + Crime + Financial + Child + Verifiable Parental Consent + Best Interests of Child

Article 4 of UU PDP categorises personal data into General Personal Data and Specific Personal Data. Specific Personal Data (Sensitive) per Article 4(2) includes: (a) health data and information; (b) biometric data; (c) genetic data; (d) personal data related to crimes; (e) child data (under 17 years per Indonesian Children Protection Law); (f) personal financial data; (g) other data per legislation. Processing of Specific Personal Data requires elevated protections per Article 25 and Implementing Regulations including: (1) explicit consent of Data Subject or legal guardian for children; (2) heightened security safeguards including encryption + access controls + audit trails; (3) reduced retention period; (4) DPIA mandatory; (5) Data Protection Officer (DPO) involvement; (6) restricted further processing; (7) impact assessment for transfer. Article 25 Children Data: processing of personal data of children under 17 years of age (Indonesian definition) requires verifiable consent of parent or legal guardian + processing must serve the best interests of the child + Child Subject of personal data has all Data Subject rights with rights exercised by parent or legal guardian until child reaches age of majority + age verification at registration mandatory. No Tracking + No Targeted Advertising to children except as authorised by guardian. Health Data: special obligations apply per Indonesia Health Law (UU No. 17 of 2023) + Hospital Law + Medical Practice Law (UU Praktik Kedokteran) + electronic health record requirements + medical confidentiality + clinical research consent. Biometric + Genetic: face recognition + fingerprint + iris + DNA - elevated consent + restrictions on use + data minimisation principles + no automated bulk collection. Crime/Criminal Conviction Data: restricted processing + only by authorised parties + linked to criminal justice system + judicial oversight. Financial Data: coordinated with Otoritas Jasa Keuangan (OJK Financial Services Authority) regulations + Bank Indonesia (BI) regulations + Payment System Provider (PSP) requirements + Anti-Money Laundering (AML) + Counter-Terrorism Financing (CTF). Coordinates with GDPR Art 9 + DPDP Sec 9 + COPPA + Singapore PDPA + Malaysia PDPA + ASEAN Children Online Protection + UN CRC + Indonesia Child Protection Law (UU No. 35 of 2014) + Indonesia Health Law + OJK + Bank Indonesia + Indonesia Anti-Corruption + KPI Broadcasting Commission. Indonesia PDP Art 4 + Art 25 Sensitive + Children applies.

What else in your programme already covers this

This control maps to 61 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 31000:2018 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO 20000-1 · 1 control

  • 9.1 Risk communication and consultation

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

MITRE D3FEND · 1 control

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.