Joint Control Addendum Template for Indonesia

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Joint Control Addendum?

The Joint Control Addendum is essential when two or more organizations jointly determine the purposes and means of processing personal data under Indonesian law. This document should be used when entities engage in shared data processing activities and need to clearly define their respective roles, responsibilities, and compliance obligations under Indonesia's Personal Data Protection Law (Law No. 27 of 2022). The addendum typically accompanies a main agreement and provides specific provisions for joint control arrangements, including detailed procedures for handling data subject requests, breach notifications, and security measures. It's particularly important given Indonesia's strict data protection requirements and the need for clear accountability in joint processing operations.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Indonesia

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Joint Control Addendum

A Joint Control Addendum is a critical legal document that governs shared data processing arrangements between two or more organizations under Indonesian law. When you're involved in collaborative data processing activities, this addendum ensures compliance with Indonesia's comprehensive Personal Data Protection Law (Law No. 27 of 2022) while clearly defining each party's obligations and responsibilities.

When do you need this document?

You need a Joint Control Addendum when your organization collaborates with other entities in determining both the purposes and means of processing personal data. This commonly occurs in business partnerships, joint ventures, shared marketing campaigns, or collaborative research projects where multiple parties have decision-making authority over data processing activities. The addendum becomes essential when you're sharing customer databases, conducting joint market research, operating shared platforms, or engaging in any activity where you jointly decide what personal data to collect, how to process it, and for what purposes. Under Indonesian law, joint controllers must have clear arrangements in place before beginning any shared processing activities.

Key legal considerations

The most critical aspect of your Joint Control Addendum is the clear allocation of responsibilities between all parties involved. You must define who handles data subject requests, manages consent mechanisms, conducts privacy impact assessments, and responds to data protection authority inquiries. The document should specify breach notification procedures, ensuring compliance with Indonesia's strict 72-hour reporting requirements to authorities and affected individuals. Security measures must be outlined comprehensively, including technical and organizational safeguards that meet Indonesian standards. You'll also need to address data transfer arrangements, particularly if data crosses borders, ensuring compliance with Indonesia's data localization requirements where applicable. The addendum must clearly establish which party serves as the primary contact point for data subjects exercising their rights under the PDP Law.

Legal requirements in Indonesia

Under Indonesia's Personal Data Protection Law (Law No. 27 of 2022), joint controllers must establish transparent arrangements that demonstrate accountability and enable effective data subject rights management. Your addendum must comply with Government Regulation No. 71 of 2019 regarding electronic systems implementation, ensuring proper technical safeguards are in place. The document should reference relevant provisions of MOCI Regulation 20 of 2016 for electronic data protection requirements. You must ensure the addendum aligns with fundamental contract law principles under the Indonesian Civil Code, including proper formation, validity, and enforceability. The arrangement must facilitate compliance with mandatory data protection officer appointment requirements where applicable, and ensure proper legal representation for foreign entities operating in Indonesia. Your addendum should also address potential regulatory changes and provide mechanisms for updating obligations as Indonesian data protection law continues to evolve.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it