Article 4 of UU PDP categorises personal data into General Personal Data and Specific Personal Data. Specific Personal Data (Sensitive) per Article 4(2) includes: (a) health data and information; (b) biometric data; (c) genetic data; (d) personal data related to crimes; (e) child data (under 17 years per Indonesian Children Protection Law); (f) personal financial data; (g) other data per legislation. Processing of Specific Personal Data requires elevated protections per Article 25 and Implementing Regulations including: (1) explicit consent of Data Subject or legal guardian for children; (2) heightened security safeguards including encryption + access controls + audit trails; (3) reduced retention period; (4) DPIA mandatory; (5) Data Protection Officer (DPO) involvement; (6) restricted further processing; (7) impact assessment for transfer. Article 25 Children Data: processing of personal data of children under 17 years of age (Indonesian definition) requires verifiable consent of parent or legal guardian + processing must serve the best interests of the child + Child Subject of personal data has all Data Subject rights with rights exercised by parent or legal guardian until child reaches age of majority + age verification at registration mandatory. No Tracking + No Targeted Advertising to children except as authorised by guardian. Health Data: special obligations apply per Indonesia Health Law (UU No. 17 of 2023) + Hospital Law + Medical Practice Law (UU Praktik Kedokteran) + electronic health record requirements + medical confidentiality + clinical research consent. Biometric + Genetic: face recognition + fingerprint + iris + DNA - elevated consent + restrictions on use + data minimisation principles + no automated bulk collection. Crime/Criminal Conviction Data: restricted processing + only by authorised parties + linked to criminal justice system + judicial oversight. Financial Data: coordinated with Otoritas Jasa Keuangan (OJK Financial Services Authority) regulations + Bank Indonesia (BI) regulations + Payment System Provider (PSP) requirements + Anti-Money Laundering (AML) + Counter-Terrorism Financing (CTF). Coordinates with GDPR Art 9 + DPDP Sec 9 + COPPA + Singapore PDPA + Malaysia PDPA + ASEAN Children Online Protection + UN CRC + Indonesia Child Protection Law (UU No. 35 of 2014) + Indonesia Health Law + OJK + Bank Indonesia + Indonesia Anti-Corruption + KPI Broadcasting Commission. Indonesia PDP Art 4 + Art 25 Sensitive + Children applies.
This control maps to 61 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.