
Support & Maintenance
Security Audit & Data Protection Readiness
A review that ends in a prioritised action list, not a hundred-page report.

Indonesia's data protection law is in force, and most of its duties are not about technology but about being able to answer simple questions: what personal data do you hold, who can open it, and how long is it kept.

Our review traces all three down to the database, then checks what is most often missed: forms collecting more than is used, exports landing on personal laptops, and old backups that never get purged along with everything else.
The result is a prioritised action list with an effort estimate per item — not a report so long that none of its items ever get done.
What is included
Personal data inventory
What is stored, where, on what basis, and until when.
Access review
Who can open personal data today, and whether that access is logged.
Prioritised action list
Findings ordered by risk, each with an effort estimate attached.
Start with a review, not with a large project
The review stands on its own. The follow-up may well be done by your own team, and some of it should be.

