Understanding Personal Data Risk at Vendors in Indonesia

September 11, 2026 / Published by: Admin

Personal data risk at vendors is the potential harm that arises when a vendor, partner, or service provider processing your customers’ personal data mishandles, leaks, or retains that data without adequate oversight. That risk doesn’t stay contained to the vendor, since the consequences flow back to the company that hired them in the first place.

The scale of this problem is well documented. Verizon’s own 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled to 30% in a single year, based on an analysis of more than 22,000 security incidents worldwide.

The trouble is that personal data risk at vendors is often treated as settled the moment a contract is signed. Legally, that’s not how responsibility actually works, and this article breaks down why, along with what to do about it.

Why This Risk Stays Your Responsibility, Even When Outsourced

Legally, this relationship is governed by Articles 51 to 54 of Indonesia’s Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”), which treats a vendor as a data processor required to process personal data strictly on the controller’s instructions. As with the PDP Law’s other obligations, this applies extraterritorially, so a foreign company can be in scope simply because a vendor processes the personal data of people in Indonesia on its behalf.

In practice, this means that when a payment vendor or cloud provider you use suffers a data breach, your company as the controller can still be held legally accountable. That principle is exactly why managing personal data risk at vendors can’t just be handed off without further oversight.

That said, responsibility isn’t entirely one-sided. The table below breaks down how it splits between controller and processor under the PDP Law.

PartyMain Responsibility
Controller (Your Company)Establishing a lawful basis for processing, selecting and overseeing vendors, and answering to data subjects and regulators for the processing as a whole
Processor (Vendor)Processing data only on the controller’s written instructions, keeping data confidential and secure, reporting incidents, and never engaging a subprocessor without written consent

A vendor only becomes legally liable in its own right once it’s shown to have processed data outside the controller’s instructions. As long as the vendor sticks to those instructions, primary responsibility stays with the company that appointed them.

Types of Personal Data Risk at Third-Party Vendors

Personal data risk at vendors generally falls into 5 categories, depending on how the data is mishandled once it leaves your direct control. The table below summarises each category with an example.

Type of RiskDescriptionExample
Data Security RiskThe vendor suffers a cyber incident that exposes the personal data it holds for youAn email marketing provider is breached, exposing the customer contact database
Processing Beyond InstructionsThe vendor uses personal data for purposes beyond what the contract agreedA vendor uses your customer data to market its own products
Subprocessor Chain RiskPersonal data is passed to another subprocessor without your knowledge or consentA hosting vendor quietly hands data management to another cloud provider
Data Retention RiskThe vendor keeps personal data after the contract ends or the data is no longer neededFormer customers’ data sits in a vendor’s old system for years after termination
Excess Access RiskThe vendor grants more of its own staff access to personal data than the work requiresA former vendor employee can still open your customer records after resigning

These 5 categories rarely occur in isolation, since one poor vendor practice usually triggers more than one at once. A vendor careless about data retention is typically just as careless about controlling who can still access that data.

5 Steps to Manage Personal Data Risk at Vendors

Managing personal data risk at vendors follows 5 steps in order: classify vendors, run due diligence, build required clauses into the contract, monitor regularly, and prepare an exit process. Each step is explained below.

1. Classify Vendors by the Type and Volume of Personal Data They Access

Not every vendor processes personal data with the same intensity, so oversight shouldn’t be one-size-fits-all. A vendor handling sensitive data or large volumes of customer data belongs in a critical tier, while a vendor supplying office stationery doesn’t need that level of scrutiny.

2. Run Due Diligence on the Vendor’s Data Protection Practices

Before signing, ask the vendor to show how it stores, restricts access to, and secures the personal data it will process for you. This step is the one most often skipped, usually because procurement is in a rush to close the deal.

3. Build Required Clauses Into the Vendor Contract

A vendor contract needs clear terms on processing instructions, confidentiality obligations, security standards, and your right to audit. The UK’s ICO takes a similar approach: contracts should state that the vendor may only process data on documented instructions, must report incidents, and can’t bring in a subprocessor without prior written consent.

4. Monitor How Vendors Handle Personal Data on an Ongoing Basis

An assessment done only at onboarding loses relevance fast once a vendor’s data practices change. Schedule a review at least annually for critical vendors, and sooner if there’s any change in how they store or access your customers’ data.

5. Make Sure Personal Data Is Deleted or Returned When the Contract Ends

Contracts should require the vendor to delete or return all personal data once the relationship ends, with proof of deletion. Without that clause, customer data can quietly sit in a former vendor’s systems without your knowledge.

Infographics of 5 Steps to Manage Personal Data Risk at Vendors

Common Mistakes Companies Make Managing Vendor Data Risk

There are at least 5 mistakes that most often undermine how companies manage personal data risk at vendors. Recognising the pattern helps avoid repeating it.

  1. Assessing a vendor once at the start of the contract, without ever reviewing how they handle personal data afterward.
  2. Leaving legal out of the contract negotiation, resulting in weak or missing data protection clauses.
  3. Granting a vendor broader access to personal data than its work actually requires.
  4. Having no complete list of every vendor with access to personal data, which lets unmonitored “shadow vendors” slip through.
  5. Failing to require deletion of personal data once a contract ends or the data is no longer needed.

Conclusion

Personal data risk at vendors doesn’t end the moment a contract is signed, because legal responsibility stays with the company that appointed the vendor in the first place. Classifying vendors, running due diligence early, writing clear contract clauses, and monitoring continuously are what decide whether this risk is genuinely managed or just waiting to become a problem.

The more business functions get handed to third parties, the larger the risk surface a company has to watch. Managing this by hand in a spreadsheet might work for the first handful of vendors, but it stops scaling once the vendor list keeps growing.

Ready to Manage Privacy Compliance as a Business Risk?

See how GRC helps map personal data risks, monitor compliance with the PDP Law, and prepare companies for audits without complicated manual processes.

FAQ

Does the PDP Law require due diligence on vendors?

The PDP Law doesn’t use the term “due diligence” explicitly, but the duty to ensure a processor follows instructions and the law effectively requires that kind of review. Without it, a controller would struggle to demonstrate its own compliance.

Who’s responsible if a vendor has a data breach?

Your company as the controller can still be held legally accountable. The vendor, as processor, can also be held liable if it’s shown to have processed data outside the instructions given.

Do subprocessors need oversight too?

Yes, since a subprocessor appointed by your main vendor still has access to the same data. Contracts with the main vendor should require written consent before any subprocessor is brought in.

How often should vendors be reassessed?

At least once a year for vendors with access to critical data, and sooner if there’s a meaningful change in their service. Lower-risk vendors can go on a longer review cycle.

Does this apply if our vendor, or our company, is based outside Indonesia?

Yes. The PDP Law applies extraterritorially, so processing the personal data of people in Indonesia can bring both parties into scope regardless of where either company is based.

Profil Adaptist Consulting

Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.

Read Related Post