Joint Controller Data Processing Agreement Template for Indonesia
Generate a bespoke document
What is a Joint Controller Data Processing Agreement?
This Joint Controller Data Processing Agreement is essential when two or more organizations jointly determine the purposes and means of processing personal data in Indonesia. It is specifically designed to comply with Indonesia's Personal Data Protection Law (UU No. 27/2022) and related regulations, including Government Regulation No. 71 of 2019 on Electronic Systems and Transactions. The agreement becomes necessary in scenarios such as joint ventures, shared services arrangements, or collaborative projects where multiple parties have control over data processing decisions. It establishes clear protocols for data protection, defines respective responsibilities, ensures proper handling of data subject rights, and sets out liability arrangements between the controllers. This document is particularly important given Indonesia's strengthened data protection framework and the increasing scrutiny of joint processing arrangements by regulatory authorities.
About the Joint Controller Data Processing Agreement
A Joint Controller Data Processing Agreement is a crucial legal document that defines the relationship between two or more organizations that jointly determine the purposes and means of processing personal data. Under Indonesia's Personal Data Protection Law (UU No. 27/2022), when multiple entities share control over data processing decisions, they must establish clear agreements outlining their respective responsibilities and obligations.
When do you need this document?
You need this agreement when your organization collaborates with other entities in ways that involve shared control over personal data processing. Common scenarios include joint ventures where partners combine customer databases, shared services arrangements between parent and subsidiary companies, collaborative research projects involving multiple institutions, and strategic partnerships where organizations exchange customer information for mutual benefit. The agreement is also essential when establishing data sharing arrangements with affiliated companies, creating joint marketing campaigns that involve customer data, or participating in industry consortiums that process member data collectively.
Key legal considerations
The agreement must clearly define each party's role and responsibilities under Indonesian data protection law. Key provisions include designating a primary contact point for data subject inquiries, establishing procedures for handling data subject rights requests such as access, rectification, and deletion, and defining how each party will implement appropriate technical and organizational security measures. The document should specify liability allocation between joint controllers, outline data breach notification procedures, and establish protocols for third-party data processor management. Additionally, it must address data transfer mechanisms, retention periods, and termination procedures that ensure continued compliance with Indonesian regulations.
Legal requirements in Indonesia
Under UU No. 27/2022, joint controllers must ensure their agreement complies with Indonesia's comprehensive data protection framework. The agreement must demonstrate adherence to lawful processing principles, including obtaining proper consent where required and ensuring data processing serves legitimate purposes. Government Regulation No. 71 of 2019 requires electronic system operators to implement adequate security measures, making technical safeguards a mandatory component of joint controller arrangements. The document must also comply with Minister of Communication and Informatics Regulation No. 20 of 2016, which mandates specific data protection mechanisms in electronic systems. Joint controllers must establish clear procedures for cross-border data transfers, ensure compliance with data localization requirements where applicable, and maintain proper documentation of processing activities as required by Indonesian authorities.
GOVERNING LAW
Applicable law
This Joint Controller Data Processing Agreement is drafted to comply with Indonesia law. Key legislation includes:
Government Regulation No. 71 of 2019 on Electronic Systems and Transactions: Regulates the implementation of electronic systems and transactions, including requirements for electronic system operators and data processing activities.
Minister of Communication and Informatics Regulation No. 20 of 2016: Specific regulation on personal data protection in electronic systems, providing detailed requirements for data protection mechanisms and data processing activities.
Indonesian Civil Code (Kitab Undang-Undang Hukum Perdata): Provides the basic framework for contract law in Indonesia, including requirements for valid agreements, which applies to the formation and enforcement of the joint controller agreement.
Law No. 11 of 2008 on Electronic Information and Transactions (ITE Law): Governs electronic transactions and information, including provisions relevant to electronic documentation and signatures that may be used in the agreement.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it