CRIVE CRIVE
Privacy Policy Terms of Service UU PDP Compliance

Kepatuhan UU PDP

Regulasi: UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi
Berlaku Efektif: Oktober 2024
Pengendali Data: PT Vintora Teknologi Indonesia
Platform: CRIVE — crive.app

1. Ringkasan UU PDP No. 27 Tahun 2022

Undang-Undang Pelindungan Data Pribadi (UU PDP) No. 27 Tahun 2022 adalah regulasi utama perlindungan data di Indonesia yang berlaku efektif Oktober 2024. Platform CRIVE sebagai pemroses dan pengendali data pribadi wajib mematuhi seluruh ketentuan UU ini.

Sanksi: Denda korporasi maksimal Rp 600 Miliar (Pasal 66) | Pidana maksimal 6 tahun + Rp 60 Miliar (Pasal 65).

2. 8-Item Compliance Checklist

HARD BLOCKER: Seluruh 8 item WAJIB 100% PASS sebelum Sprint 1 dimulai.
NoItem ComplianceReferensi UU PDPStatus
H.1Kebijakan Privasi (Privacy Policy) — Bilingual ID/EN, 13 sectionsPasal 20, 21, 26✅ PASS
H.2Syarat & Ketentuan (Terms of Service) — Bilingual ID/EN, 12 sectionsPasal 22-24, App Store✅ PASS
H.3Data Processing Agreement (DPA) — 20 sub-processors aktifPasal 35-37✅ PASS
H.4Endpoint Penghapusan Data (Right to Erasure) — Cryptographic ErasurePasal 44-46✅ PASS
H.5DPO Designation + Data Residency — CEO as DPO, AWS SingaporePasal 52-54✅ PASS
H.6AI Consent Screen — Default ON, toggle opt-outPasal 20-26✅ PASS
H.77 Kategori Data Sensitif Excluded dari AI TrainingPasal 4(2), 16✅ PASS
H.8Breach Response SOP + Lawyer Sign-OffPasal 46-48⏸️ DEFER

3. Status Keseluruhan

Total ItemPASSDEFERGate Status
8 Item7 / 81 / 8 (H.8 Lawyer)✅ CONDITIONAL GO
Keputusan: H.8 DEFER post-MVP per CEO Decision. Sprint 1 DAPAT dimulai. H.8 WAJIB selesai sebelum M8 Mobile Launch.

4. 5 Privacy Enhancements

CVE-003 v7.0.0 menetapkan 5 Privacy Enhancements yang melampaui persyaratan minimum UU PDP:

IDEnhancementDeskripsiSprint
PV.1Privacy Dashboard GranularDashboard visual data inventory + access log + kontrolSprint 13
PV.2AI Transparency ReportLaporan transparan penggunaan data untuk AI training per userSprint 13
PV.3Poinmate Privacy AddendumZERO browsing data guarantee + kill switchSprint 9
PV.4Breach Notification 3×24 jamStandar internal CRIVE (lebih ketat dari 14 hari UU PDP)Sprint 13
PV.5Granular Consent MatrixConsent terpisah per: profil, konten, AI, analytics, PoinmateSprint 3

5. Referensi Pasal UU PDP No. 27/2022

PasalKetentuanRelevansi CRIVE
Pasal 4-16Kategori data pribadi umum dan sensitifKlasifikasi data user, 7 kategori excluded dari AI
Pasal 20-26Persetujuan (consent) pemrosesan dataAI Consent Screen, Cookie Banner, ToS acceptance
Pasal 35-37Kewajiban pengendali & pemroses dataDPA dengan 20 sub-processors aktif
Pasal 44-46Hak penghapusan data subjekPOST /v1/user/privacy/delete + Cryptographic Erasure
Pasal 46-48Notifikasi pelanggaran dataBreach Response SOP: 3×24 jam (PV.4) / 14 hari kerja
Pasal 52-54Data Protection OfficerCEO sebagai DPO ad interim, privacy@crive.app
Pasal 65Sanksi pidana data sensitifDenda maks Rp 60 Miliar / pidana 6 tahun
Pasal 66Sanksi korporasiDenda maks Rp 600 Miliar untuk badan hukum

6. Kontak

Pertanyaan tentang kepatuhan data?

privacy@crive.app

Jamal NR — CEO & DPO ad interim
PT Vintora Teknologi Indonesia
Respons dalam 14 hari kerja

UU PDP Compliance

Regulation: Law No. 27 of 2022 on Personal Data Protection
Effective: October 2024
Data Controller: PT Vintora Teknologi Indonesia
Platform: CRIVE — crive.app

1. UU PDP Summary

The Personal Data Protection Law (UU PDP) No. 27 of 2022 is Indonesia's primary data protection regulation, effective October 2024. CRIVE as a data processor and controller must comply with all provisions.

Penalties: Corporate fines up to Rp 600 Billion (Article 66) | Criminal penalties up to 6 years + Rp 60 Billion (Article 65).

2. 8-Item Compliance Checklist

HARD BLOCKER: All 8 items must be 100% PASS before Sprint 1 can begin.
NoCompliance ItemUU PDP ReferenceStatus
H.1Privacy Policy — Bilingual ID/EN, 13 sectionsArticles 20, 21, 26✅ PASS
H.2Terms of Service — Bilingual ID/EN, 12 sectionsArticles 22-24, App Store✅ PASS
H.3Data Processing Agreement (DPA) — 20 active sub-processorsArticles 35-37✅ PASS
H.4Data Deletion Endpoint (Right to Erasure) — Cryptographic ErasureArticles 44-46✅ PASS
H.5DPO Designation + Data Residency — CEO as DPO, AWS SingaporeArticles 52-54✅ PASS
H.6AI Consent Screen — Default ON, toggle opt-outArticles 20-26✅ PASS
H.77 Sensitive Data Categories Excluded from AI TrainingArticles 4(2), 16✅ PASS
H.8Breach Response SOP + Lawyer Sign-OffArticles 46-48⏸️ DEFER

3. Overall Status

Total ItemsPASSDEFERGate Status
8 Items7 / 81 / 8 (H.8 Lawyer)✅ CONDITIONAL GO
Decision: H.8 DEFERRED post-MVP per CEO Decision. Sprint 1 may begin. H.8 MUST be completed before M8 Mobile Launch.

4. 5 Privacy Enhancements

CVE-003 v7.0.0 defines 5 Privacy Enhancements exceeding UU PDP minimum requirements:

IDEnhancementDescriptionSprint
PV.1Granular Privacy DashboardVisual data inventory + access log + controlsSprint 13
PV.2AI Transparency ReportPer-user transparent report on AI data usageSprint 13
PV.3Poinmate Privacy AddendumZERO browsing data guarantee + kill switchSprint 9
PV.4Breach Notification 3×24hCRIVE internal standard (stricter than 14-day UU PDP)Sprint 13
PV.5Granular Consent MatrixSeparate consent per: profile, content, AI, analytics, PoinmateSprint 3

5. UU PDP Article References

ArticleProvisionCRIVE Relevance
Articles 4-16General and sensitive personal data categoriesUser data classification, 7 categories excluded from AI
Articles 20-26Consent for data processingAI Consent Screen, Cookie Banner, ToS acceptance
Articles 35-37Controller & processor obligationsDPA with 20 active sub-processors
Articles 44-46Data subject right to erasurePOST /v1/user/privacy/delete + Cryptographic Erasure
Articles 46-48Data breach notificationBreach Response SOP: 3×24h (PV.4) / 14 working days
Articles 52-54Data Protection OfficerCEO as DPO ad interim, privacy@crive.app
Article 65Criminal penalties for sensitive dataFines up to Rp 60 Billion / 6 years imprisonment
Article 66Corporate penaltiesFines up to Rp 600 Billion for legal entities

6. Contact

Questions about data compliance?

privacy@crive.app

Jamal NR — CEO & DPO ad interim
PT Vintora Teknologi Indonesia
Response within 14 working days