Overview

Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

PT Divistant Teknologi Indonesia (trading as "Divistant")


Last Updated: February 24, 2026


This document outlines Divistant's standard Data Processing Agreement terms. Specific DPA terms are formalized in individual agreements between Divistant and each client as required by applicable data protection laws.


1. Introduction


This Data Processing Agreement ("DPA") sets out the terms under which PT Divistant Teknologi Indonesia ("Divistant", "Processor") processes personal data on behalf of its clients ("Controller") in connection with the provision of our services. This DPA supplements and is incorporated into the applicable Service Agreement between the parties.


This DPA is designed to ensure compliance with:

  1. UU PDP: Undang-Undang Nomor 27 Tahun 2022 tentang Perlindungan Data Pribadi (Indonesia's Personal Data Protection Law)
  2. GDPR: EU General Data Protection Regulation (Regulation 2016/679)
  3. Other applicable data protection regulations in the jurisdictions where we operate


2. Definitions


  1. Controller (Pengendali Data Pribadi): The Client, who determines the purposes and means of processing personal data
  2. Processor (Prosesor Data Pribadi): Divistant, who processes personal data on behalf of the Controller
  3. Sub-Processor: Any third party engaged by Divistant to process personal data on behalf of the Controller
  4. Data Subject (Subjek Data Pribadi): The individual whose personal data is being processed
  5. Personal Data (Data Pribadi): Any information relating to an identified or identifiable individual, as defined by UU PDP and GDPR
  6. Processing (Pemrosesan): Any operation performed on personal data, including collection, storage, use, transfer, and deletion


3. Scope of Processing


The specific details of processing are defined in each individual DPA and typically include:

  1. Subject Matter: The service(s) being provided under the Service Agreement
  2. Duration: The term of the Service Agreement plus any retention period
  3. Nature & Purpose: Processing necessary to provide the contracted services
  4. Categories of Data Subjects: As determined by the Controller (e.g., employees, customers, end users)
  5. Types of Personal Data: As determined by the Controller based on the services used


4. Processor Obligations


As a Data Processor, Divistant commits to:


a. Lawful Processing

  1. Process personal data only on documented instructions from the Controller
  2. Inform the Controller if any instruction, in Divistant's opinion, infringes data protection laws
  3. Not process personal data for any purpose other than as instructed by the Controller


b. Confidentiality

  1. Ensure that all personnel authorized to process personal data are bound by confidentiality obligations
  2. Limit access to personal data to those employees and contractors who require it to perform the services


c. Security Measures (Article 32 GDPR / Pasal 35 UU PDP)

  1. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
  2. Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)
  3. Role-based access controls and multi-factor authentication
  4. Regular security assessments and vulnerability testing
  5. Continuous monitoring and intrusion detection
  6. Business continuity and disaster recovery procedures


For full details, see our Information Security Policy.


d. Data Breach Notification

  1. Notify the Controller without undue delay upon becoming aware of a personal data breach
  2. Under GDPR: notification within timeframes enabling the Controller to meet its 72-hour obligation (Art. 33)
  3. Under UU PDP: notification within timeframes enabling the Controller to meet its 3x24 hour obligation (Pasal 46)
  4. Provide sufficient information to enable the Controller to fulfill its breach notification obligations


e. Data Subject Rights

  1. Assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection)
  2. Implement technical measures to facilitate the exercise of data subject rights
  3. Redirect any data subject requests received directly to the Controller


5. Sub-Processing


  1. Authorization: Divistant shall not engage a Sub-Processor without prior written authorization from the Controller. We may use general authorization with a list of approved Sub-Processors, subject to the Controller's right to object.
  2. Notification: The Controller will be notified of any intended changes to Sub-Processors at least 30 days in advance, providing an opportunity to object.
  3. Contractual Obligations: All Sub-Processors are bound by data processing agreements with at least the same level of data protection as this DPA.
  4. Liability: Divistant remains fully liable for the performance of its Sub-Processors' obligations.


6. International Data Transfers


When personal data is transferred to countries outside the Controller's jurisdiction:

  1. GDPR Transfers: Transfers outside the EEA are protected by EU Commission-approved Standard Contractual Clauses (SCCs) pursuant to Article 46(2)(c) GDPR, or rely on other approved transfer mechanisms
  2. UU PDP Transfers: International transfers comply with Pasal 56 UU PDP, ensuring the receiving country has adequate data protection or binding contractual protections are in place
  3. Transfer Impact Assessments: Conducted where required to evaluate the data protection regime of the receiving country


For more details, see our GDPR Compliance and UU PDP Compliance pages.


7. Audits & Inspections


  1. Right to Audit: The Controller has the right to conduct audits and inspections to verify Divistant's compliance with this DPA
  2. Cooperation: Divistant will make available all information necessary to demonstrate compliance and allow for audits by the Controller or an authorized third-party auditor
  3. Notice: Audits are conducted with reasonable advance notice (minimum 30 days) during normal business hours
  4. Certifications: Where available, Divistant may provide certifications, audit reports (e.g., SOC 2), or summaries of third-party assessments in lieu of on-site audits


8. Data Retention & Deletion


  1. During the Agreement: Personal data is retained for the duration necessary to provide the contracted services
  2. Upon Termination: At the Controller's choice, Divistant will either return all personal data to the Controller or securely delete/destroy it within 90 days of termination, unless retention is required by law
  3. Certification: Upon request, Divistant will provide written certification confirming the deletion or return of personal data
  4. Backup Copies: Personal data in backup systems will be deleted in accordance with the backup retention schedule


9. DPIA Assistance


Divistant will assist the Controller, taking into account the nature of processing and information available, with:

  1. Data Protection Impact Assessments (DPIAs) as required under Article 35 GDPR
  2. Prior consultation with supervisory authorities as required under Article 36 GDPR
  3. Providing information about Divistant's processing activities, security measures, and Sub-Processors


10. Liability


  1. Each party's liability under this DPA is subject to the limitations set forth in the applicable Service Agreement
  2. Divistant shall be liable for damages caused by processing that does not comply with the Controller's lawful instructions or this DPA
  3. Where both Controller and Processor are involved in the same processing resulting in damages, each party bears responsibility for its share of the damage


11. How to Request a DPA


If you require a Data Processing Agreement with Divistant, please:

  1. Contact us at divistant.com/contacts with the subject "DPA Request"
  2. Include details about the services involved and the types of personal data to be processed
  3. Specify any regulatory requirements applicable to your organization (e.g., GDPR, UU PDP, sector-specific regulations)


Our legal and data protection team will prepare and share the appropriate DPA, typically within 5 business days.


12. Contact Information


For questions about our Data Processing Agreement terms or data protection practices:

  1. Data Protection Officer: divistant.com/contacts
  2. Legal & Partnerships: divistant.com/contacts
  3. Company: PT Divistant Teknologi Indonesia, Jakarta, Indonesia


For more information about our data protection commitments, see our Privacy Policy, GDPR Compliance, and UU PDP Compliance pages.