GuideMay 26, 20269 min read

UU PDP Readiness: A Practical Guide to Workforce Awareness and Breach Reporting

A working guide to Indonesia's Personal Data Protection Law (UU PDP, Law 27/2022) for security and compliance leaders, focused on the two areas regulators look at first: workforce awareness and breach notification.

What UU PDP actually asks of you

Law 27/2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi, or UU PDP) is Indonesia's first comprehensive data protection statute. It was enacted in October 2022 with a two-year transition period, so its core obligations now apply in full to organizations that process personal data of individuals in Indonesia.

The law sets out lawful bases for processing, rights for data subjects, obligations for data controllers and processors, security and accountability duties, and administrative sanctions for non-compliance. For most security and compliance leaders, the day-to-day pressure lands in two places: proving that your workforce handles personal data correctly, and being ready to report a personal data breach quickly and accurately.

This guide focuses on those two areas. It does not replace legal counsel, and your obligations depend on your sector. Financial institutions also answer to OJK regulations, and incidents touching electronic systems may involve BSSN. Treat UU PDP as the baseline, then layer your sector rules on top.

The breach notification clock: 3x24 hours

UU PDP requires a data controller to notify both the affected data subjects and the relevant authority of a failure to protect personal data no later than 3x24 hours (72 hours) after the breach is known. The notification must, at minimum, describe the personal data that was exposed, when and how the failure occurred, and the steps being taken to handle and recover from it.

Seventy-two hours sounds generous until an incident is live. The clock starts when the breach becomes known, not when your investigation is tidy. That means detection, triage, scoping, and an initial notification draft all have to happen inside a window where facts are still incomplete. Organizations that meet this timeline have rehearsed it: a named incident owner, a decision tree for what counts as a notifiable breach, a contact path to the authority, and a pre-approved notification template in Bahasa Indonesia.

Build the runbook before you need it. Define who declares a breach, who drafts the data subject notice, who signs off, and where the evidence lives. Run a tabletop exercise at least once a year so the 72-hour path is muscle memory rather than a scramble.

Why workforce awareness is a compliance control, not a nice-to-have

Most reportable breaches start with a person, not a firewall. A staff member who clicks a credential-harvesting link, replies to a convincing invoice-redirect request, or sends a spreadsheet of customer data to the wrong address can trigger the same notification duty as a sophisticated intrusion. UU PDP's accountability principle expects controllers to take organizational and technical measures proportionate to the risk, and workforce competence is squarely an organizational measure.

Awareness that satisfies a regulator is specific and evidenced. Generic annual slideshows do not show that staff can recognize the attacks your organization actually faces, such as WhatsApp-based social engineering, vishing calls impersonating internal IT, or localized phishing themed around Indonesian banks and government services. Measured behavior, not attendance, is what demonstrates a working control.

Tie awareness to roles. People who handle large volumes of personal data, such as customer service, HR, and finance teams, carry higher inherent risk and warrant more frequent and more targeted reinforcement.

Building defensible evidence

When a regulator or auditor reviews your program, they ask a simple question: show me. Defensible evidence means records you can produce on demand, not assertions. For awareness, that is a per-employee history of simulations delivered, outcomes, training assigned after a failure, and completion. For breach handling, it is a timestamped record of detection, decisions, notifications sent, and remediation.

Keep the trail continuous. A point-in-time certificate proves someone attended once. A rolling record of simulated phishing results, reporting rates, and risk scores over time proves the control is operating. The second is far more persuasive when you are explaining why an incident happened despite reasonable measures.

Make sure your evidence respects the law it supports. Records about your workforce are themselves personal data, so apply retention limits, access controls, and the same security you expect everywhere else. Encryption at rest and clear retention policies keep your compliance evidence from becoming its own liability.

A 90-day readiness path

Days 1 to 30, establish the baseline. Map where personal data lives and who touches it, identify your highest-risk roles, and run a baseline phishing simulation to see where the workforce actually stands. Draft or update your breach response runbook and confirm the authority contact path.

Days 31 to 60, close the obvious gaps. Assign targeted micro-training to staff who failed the baseline, deploy an easy one-click report button so employees can flag suspicious messages, and run your first tabletop on the 3x24 hour notification path. Translate every employee-facing message and notice into natural Bahasa Indonesia, not a literal rendering.

Days 61 to 90, prove it operates. Run a second simulation to measure improvement, check that reporting rates are rising and repeat-clickers are shrinking, and assemble an evidence pack covering awareness metrics and your breach runbook. The goal is not a perfect score, it is a program you can defend with records.

Where Claro fits

Claro is built for exactly this problem in the Indonesian context. It runs phishing, vishing, and WhatsApp simulations themed for local attack patterns, assigns just-in-time micro-training when someone falls for a lure, and tracks risk scores and reporting rates per employee over time.

Every employee-facing surface ships in English and Bahasa Indonesia from the start, and personal data is encrypted at rest with per-tenant keys. Compliance reporting maps awareness activity and outcomes to UU PDP, OJK, and ISO 27001 expectations, so the evidence pack a regulator asks for is a few clicks away rather than a month of spreadsheet archaeology.

Awareness and breach readiness are programs, not events. The organizations that handle UU PDP well are the ones that make both operational and keep the receipts.

Key takeaways

  • UU PDP (Law 27/2022) requires breach notification to data subjects and the authority within 3x24 hours (72 hours) of the breach becoming known.
  • Workforce awareness is an organizational security measure under the law's accountability principle, not an optional extra.
  • Measured behavior, such as simulation outcomes and reporting rates, demonstrates a working control far better than attendance records.
  • Keep continuous, timestamped evidence of awareness activity and breach handling, and secure that evidence because it is itself personal data.
  • Treat UU PDP as the baseline and layer sector rules such as OJK and BSSN obligations on top.

Build a program that sticks

Claro helps you run simulation, training, and reporting in one place.

Request a demo