Skip to main content

Support & Maintenance

Security Audit & Data Protection Readiness

A review that ends in a prioritised action list, not a hundred-page report.

A consultant points at a data map on screen while a data officer takes notes on a laptop, a printed action list on the table

Indonesia's data protection law is in force, and most of its duties are not about technology but about being able to answer simple questions: what personal data do you hold, who can open it, and how long is it kept.

A security consultant and the client database administrator review where personal data is stored, with an exports folder on a laptop, an old backup drive marked for purge, and a prioritised action list

Our review traces all three down to the database, then checks what is most often missed: forms collecting more than is used, exports landing on personal laptops, and old backups that never get purged along with everything else.

The result is a prioritised action list with an effort estimate per item — not a report so long that none of its items ever get done.

What is included

  • Personal data inventory

    What is stored, where, on what basis, and until when.

  • Access review

    Who can open personal data today, and whether that access is logged.

  • Prioritised action list

    Findings ordered by risk, each with an effort estimate attached.

Start with a review, not with a large project

The review stands on its own. The follow-up may well be done by your own team, and some of it should be.