PDP Law Flowchart: Is Your Organization Compliant?

    September 11, 2026 / Published by: Editorial

    The 2026 global breach picture points to a clear control problem: attackers are increasingly entering through exploitable software weaknesses, while human error, identity weaknesses, and third-party dependencies remain major contributors. Verizon examined more than 31,000 real-world security incidents, including more than 22,000 confirmed breaches across 145 countries, in its 2026 DBIR. [1]

    We combined that telemetry with the Thales 2026 Data Threat Report and IBM’s Cost of a Data Breach 2026, then mapped the findings to the control duties in Indonesia’s UU 27/2022 (PDP Law). The result is a practical view of where the law’s duties are most likely to fail in operation, and what evidence an organization should be able to produce for each.

    Summary

    Vulnerability exploitation is now the number one entry path in the DBIR: 31% of breaches used it as a known initial-access vector, up from 20% in the 2025 edition (+55%). Verizon states this is the first time in 19 years of the DBIR that exploiting vulnerabilities surpassed stolen credentials as the leading entry point. [1][2] Human error remains the largest reported root cause in the Thales survey, and third parties are involved in 48% of breaches.

    For Indonesian organizations, this means three things. First, patch governance is a privacy control: when vulnerable assets process or expose personal data, remediation speed is evidence of compliance with Article 35. Second, identity controls must be tested against real privileged accounts and logs, not just documented, because Article 39 requires preventing unauthorized access. Third, the 3 x 24-hour notification duty under Article 46 must be pre-wired into incident response, because the window is unworkable if built after a breach starts.

    Four Numbers That Should Shape a PDP Control Test

    Metric Value What It Means
    Vulnerability exploitation 31% #1 initial-access vector
    Third-party involvement 48% Share of breaches involving a third party
    Critical vulnerabilities fully remediated 26% Most were not fully remediated in the observed period
    Median time to full resolution 43 days Up from 32 days in the prior report

    Source: 2026 DBIR. [1][2]

    # Finding What the Data Says
    1 Vulnerability exploitation is now the #1 entry path 31% of breaches, up from 20% in the 2025 DBIR (+55%). [1][2]
    2 “Human error” is still the largest reported root cause In Thales 2026 (~3,120 security/IT professionals, 20 countries), 28% cited misconfiguration or human error as the leading cause; known vulnerabilities were next at 21%. [3]
    3 Third parties are no longer peripheral 48% of breaches involved a third party, up 60% from 30% in the prior DBIR. Processor, SaaS, and supplier oversight is a control issue, not only a procurement issue. [1][2]

    Reading the Numbers Correctly

    “Root cause” and “initial access vector” are not the same thing. A breach can begin with a vulnerability, move through compromised credentials, involve human error, and expose data stored by a third party. Treating one category as the single cause would overstate what the datasets can prove.

    • 31% in the Verizon DBIR means vulnerability exploitation was the known initial-access vector in 31% of the applicable breach dataset. It does not mean 31% of all cyber risk is “patching.” [1]
    • 28% in Thales is a self-reported share from a survey, not a share of all breach events. [3]
    • Classification change: the 2026 DBIR introduced separate tracking for pretexting, so the 13% credential-abuse figure should not be compared mechanically with older credential-abuse percentages. [1][6]
    • Percentage changes use the published source values directly: 31% versus 20% is a 55% relative increase, and 48% versus 30% is a 60% relative increase.

    The Entry Point Has Moved

    Initial-Access Vector Share of Breaches
    Vulnerability exploitation 31%
    Phishing 16%
    Credential abuse 13%
    Pretexting 6%

    Source: 2026 DBIR. [1][6] These categories can overlap in a real attack chain, so the table is best read as a ranking of known access paths rather than a mutually exclusive allocation of every breach.

    Patch Exposure Is the Weak Link Behind the Vector

    Metric 2026 Value Why It Matters
    Critical vulnerabilities fully remediated 26% The majority were not fully remediated in the observed period. [1][2]
    Median time to full resolution 43 days Up from 32 days in the prior report. [1][2]
    Third-party involvement 48% 30% in the prior DBIR: +60% relative. [1][2]
    Mobile-centric social-engineering click success +40% vs email Attackers are shifting toward voice/text vectors as email defenses improve. [1][2]

    Control test: Can you produce a current asset inventory, risk ranking, remediation SLA, exception approvals, and proof of closure for high-risk exposed vulnerabilities?

    Trend: Vulnerability Exploitation Has Accelerated

    Verizon’s published 2025 report puts vulnerability exploitation at approximately 6%, 5%, 14%, and 20% for the 2022–2025 DBIR editions. The 2026 edition raises the latest point to 31%. [2]

    Year Vulnerability Exploitation Credential Abuse Phishing
    2022 6% 36% 17%
    2023 5% 40% 12%
    2024 14% 31% 14%
    2025 20% 22% 15%
    2026 31% 13% 16%

    Values from Verizon’s published trend series; 2026 classification notes apply. [2][6] Because 2026 separates pretexting, credential abuse is not perfectly comparable with prior editions.

    What changed:

    • Vulnerability exploitation rose from 20% to 31% between the 2025 and 2026 editions, a 55% relative increase. [2]
    • The 2026 report links this environment to faster attacker research and exploitation, including generative-AI assistance that can compress time from months to hours in some scenarios. [1]
    • Credential abuse remains relevant. Separating pretexting changes the classification, which is why a simple “credentials fell from 22% to 13%” story is incomplete. [1][6]

    As remote exploitation rises, asset inventory, exposure management, patch governance, and third-party visibility become direct PDP-risk controls.

    Root Cause: Technology, People, and Governance All Matter

    Thales provides a complementary view. Among ~3,120 security and IT professionals surveyed across 20 countries, misconfiguration or human error was the most commonly cited cause of breach at 28%, followed by known-vulnerability exploitation at 21% and zero-day/novel vulnerability exploitation at 14%. [3]

    Cause (Thales 2026) Share
    Misconfiguration / human error 28%
    Known vulnerability 21%
    Zero-day / novel vulnerability 14%
    No MFA for privileged accounts 12%
    Identity / access control failure 10%
    Improperly configured MFA 9%
    Data classification / handling 7%

    Categories are not mutually exclusive. [3]

    Three Root-Cause Clusters

    Cluster Evidence What an Organization Should Be Able to Prove
    1. Exposure / technology 31% vulnerability exploitation (Verizon); 21% known + 14% novel vulnerability causes (Thales) [1][3] Asset inventory, internet exposure, CVE/KEV prioritization, patch SLAs, compensating controls, exception approvals
    2. Identity / people 16% phishing, 13% credential abuse, 6% pretexting (Verizon); 12% no MFA for privileged accounts, 10% identity/access failure (Thales) [1][3] MFA coverage, privileged-access reviews, access recertification, phishing-resistant authentication where appropriate, joiner/mover/leaver evidence
    3. Governance / process 28% human error/misconfiguration, 7% data classification/handling (Thales); 48% third-party involvement (Verizon) [1][3] Approved procedures, training, data maps, processor register, contract controls, oversight evidence, logging and incident response records

    The entry point and the enabling condition can differ. A mature PDP program tests both the door used and the control that left it open.

    What UU 27/2022 Actually Requires

    UU 27/2022 requires controllers to implement technical and operational measures and set security levels according to the nature and risk of the personal data (Article 35), prevent unauthorized access (Article 39), supervise parties involved in processing (Article 37), perform a DPIA for high-risk processing (Article 34), and notify a personal-data protection failure in writing within 3 x 24 hours (Article 46). [5]

    Breach Signal PDP Law Mapping Evidence Expected in an Audit
    Vulnerability exploitation Art. 35: technical/operational measures; security level based on data nature and risk Current asset register; vulnerability scans; risk ranking; remediation evidence; exceptions; control testing
    Credential abuse / phishing / pretexting Art. 39: prevent unauthorized access MFA coverage; privileged-access controls; access reviews; authentication logs; incident tickets
    Human error / misconfiguration Arts. 35, 36, 38: secure processing, confidentiality, protection from unlawful processing Configuration baselines; change approvals; training; internal rules; monitoring; preventive-control evidence
    Third-party involvement Art. 37: supervision of every party involved in processing under the controller’s control Processor register; due diligence; data-processing terms; security clauses; assurance reports; review cadence
    High-risk processing Art. 34: DPIA when processing is high risk DPIA; risk assessment; mitigation actions; approval; re-assessment triggers
    Failure of personal-data protection Art. 46: written notice to data subjects and the institution within 3 x 24h Breach clock; decision log; affected-data analysis; notification package; dispatch evidence; recovery record

    The law defines duties; breach data helps prioritize where those duties are most likely to fail operationally.

    How to Use the Compliance Flow Operationally

    1. Start with data inventory and processing context. Confirm what personal data is processed, where it sits, who can access it, and which third parties touch it.
    2. Trigger the high-risk branch. Use Article 34 criteria to decide when a DPIA is required, and preserve the assessment and mitigations as evidence.
    3. Test technical safeguards against actual breach pathways. Vulnerability exploitation and identity-related access remain high-value attack paths, so test patching, MFA, and access control rather than merely checking that a policy exists.
    4. Test third-party governance. With 48% of breaches involving third parties, processor and supplier oversight should be a core security control.
    5. Run the 3 x 24-hour breach clock. The incident process must support rapid identification of affected data, timing and manner of the incident, and response and recovery actions, so the statutory notice can be prepared and sent within the window. [5]

    Expert Commentary

    Verizon DBIR team: fundamentals still win. The 2026 report frames the response around visibility into assets and third parties, disciplined patch management, practiced response plans, and secure organizational behavior. [1] These are the control layers needed to prevent unauthorized access and to demonstrate that security measures are actually operating.

    CIS: prioritize the attack paths attackers repeatedly use. Phyllis Lee, Vice President of CIS Security Best Practices Content Development, drew the same lesson: prioritize proven controls, timely remediation, and the most common attack paths rather than assuming more technology automatically reduces risk. [6]

    IBM: AI compresses the window between exposure and impact. IBM’s Limor Kessem describes 2026 as an inflection point in attack speed. IBM reports a 56% increase in AI-driven attacks, a global average breach cost of USD 4.99 million, and a control gap: 50% of breached organizations deployed AI agents for threat hunting, response, and containment, but only 18% used them for vulnerability scanning and management. [4][7]

    Expert consensus: strong compliance is demonstrable control over the attack paths most likely to expose personal data.

    Our Take

    The common assumption, that having a PDP policy and a privacy officer means the organization is compliant, does not survive contact with the breach data. The law’s duties are technical and operational: Articles 35 and 39 are tested by whether patches were applied and MFA was enforced, not by whether a document says so. With vulnerability exploitation now the leading entry path, only 26% of critical vulnerabilities fully remediated, and 48% of breaches touching a third party, the gap between policy and practice is where personal data is exposed. The fix is not more documentation. It is evidence: current inventories, measured remediation, tested identity controls, supervised processors, and a breach clock that can actually meet 3 x 24 hours.

    What You Should Do

    Five priorities, ordered by breach prevalence, exposure potential, and direct PDP control relevance.

    1. Reduce Exploitable Exposure on Internet-Facing Assets (P0)

    31% of breaches begin with vulnerability exploitation, and only 26% of critical vulnerabilities were fully remediated. [1][2] Owner: CISO / Infrastructure / AppSec. Evidence of completion: validated asset inventory, KEV/CVE backlog, SLA dashboard, exception register.

    2. Close Privileged Identity Gaps (P0)

    Thales cites 12% failure to use MFA for privileged accounts and 10% identity/access-control failure. [3] Owner: IAM / Security. Evidence: MFA coverage, privileged access review, stale-account removal, log coverage.

    3. Institutionalize the 3 x 24-Hour Breach Workflow (P0)

    Article 46 requires written notification within 3 x 24 hours. [5] Owner: DPO / Legal / IR / SOC. Evidence: playbook, timer, notification template, tabletop exercises, contact matrix.

    4. Quantify Third-Party Risk and Use the DPIA as a Design Control (P1)

    48% of breaches involved third parties, and Article 34 requires a DPIA for high-risk processing. [1][2][5] Owner: Procurement / DPO / Security / Product / Data. Evidence: processor register, contract controls, risk tiering, assurance reviews, DPIA library, risk decisions, re-assessment triggers.

    5. Reduce Human-Error and Configuration Risk, then Add Continuous Monitoring (P1–P2)

    28% of Thales respondents named human error or misconfiguration as a cause, and AI is accelerating exploitation and response windows. [3][7] Owner: Engineering / Operations / Security Engineering / Risk. Evidence: baseline configs, change approval, training completion, exception metrics, control health dashboard, breach simulations.

    Suggested Executive Dashboard

    Metric Target Direction Frequency
    Critical exposed vulnerabilities beyond SLA Down Weekly
    Critical vulnerabilities fully remediated Up from 26% baseline Monthly
    Median time to remediation Down from 43-day baseline Monthly
    Privileged accounts with strong MFA Up toward 100% where applicable Monthly
    Third-party processors with current assurance Up toward 100% of risk-tiered population Quarterly
    High-risk processing with current DPIA Up toward 100% Monthly
    Breach notification readiness tested within 3 x 24h 100% tabletop coverage Quarterly

    Methodology & Sources

    This report uses a two-lens methodology: an incident-telemetry lens (how breaches begin) and an organizational lens (what people report as root cause), then maps both to UU 27/2022 control gates.

    Dataset / Source What It Measures Why It Is Used Limitation
    Verizon 2026 DBIR [1][2] Observed incidents and confirmed breaches; initial-access vectors; third-party involvement; vulnerability remediation Best global telemetry on how real-world breaches begin Data largely reflects the preceding reporting window; vector categories can co-occur and are not a simple pie chart of all causes
    Thales 2026 Data Threat Report [3] Global survey of ~3,120 security and IT professionals across 20 countries, fielded by S&P Global 451 Research Adds an organizational root-cause lens, especially human error and misconfiguration Self-reported; categories are not mutually exclusive; the published breakdown does not isolate a breached-only sample, so it is a whole-sample view rather than a breach-only census
    IBM Cost of a Data Breach 2026 [4][7] 602 breached organizations; breach economics and AI-related risk Quantifies business impact and complements technical evidence A cost study, not designed as a prevalence database for attack vectors
    UU 27/2022 [5] Legal duties of Indonesian personal-data controllers Maps observed risks to concrete compliance control gates The mapping is an analytical control framework, not legal advice

    Sources:

    1. Verizon, “2026 Data Breach Investigations Report (DBIR),” May 2026. Global dataset: >31,000 incidents; >22,000 confirmed breaches; 145 countries. Key figures: 31% vulnerability exploitation; 48% third-party involvement; remediation metrics. https://www.verizon.com/business/resources/reports/dbir/
    2. Verizon, “2026 DBIR & 2026 Breach Impact Study – Key insights” infographic, 2026. Key figures: 31%, +55%; 48%, +60%; 43 days; +40% mobile social engineering. https://www.verizon.com/business/resources/infographics/2026-dbir-bis-cyber-insurance-losses.pdf
    3. Thales, “2026 Data Threat Report,” 2026 (fielded by S&P Global 451 Research). Survey base: ~3,120 security and IT professionals across 20 countries. Cause figures: human error 28%; known vulnerability 21%; zero-day/novel vulnerability 14%; privileged MFA failure 12%; identity/access failure 10%; MFA misconfiguration 9%; data classification/handling 7%. https://cpl.thalesgroup.com/data-threat-report
    4. IBM, “Cost of a Data Breach Report 2026,” 2026. Key figures: USD 4.99M global average cost; +12%; AI-driven attacks +56%. https://www.ibm.com/reports/data-breach
    5. Kementerian Komunikasi dan Digital, JDIH, “Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi.” Key provisions: Arts. 31, 34-39, 46. https://jdih.komdigi.go.id/produk_hukum/view/id/832/t/crc32/
    6. Center for Internet Security, “CIS Controls and MS-ISAC Insights Featured in Verizon’s 2026 DBIR,” 2026. Commentary from Phyllis Lee on patching and proven controls. https://www.cisecurity.org/about-us/media/press-release/cis-controls-and-ms-isac-insights-featured-in-verizons-2026-data-breach-investigations-report
    7. Limor Kessem, IBM X-Force, “AI-powered adversaries and the enterprise risk challenge: Preparing for the new reality,” 29 July 2026. AI-driven attacks +56%; 18% vulnerability-management AI adoption vs 50% threat hunting/response. https://www.ibm.com/think/x-force/2026-cost-of-a-data-breach-ai-adversaries-enterprise-risk
    8. Verizon RISK Team, VERIS / VCDB repository. Note on public data-sharing limitations and VERIS schema. https://github.com/vz-risk/VCDB

    Profil Adaptist Consulting

    Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.

    ✕