Portal ROPA is an internal governance application developed to support PT. Bank Rakyat Indonesia (Persero) Tbk’s compliance with Indonesian Personal Data Protection regulation (UU No. 27 Tahun 2022 – PDP Law). The system enables structured documentation, monitoring, and governance of all activities involving personal data processing within BRI.
Background & Objectives
Ensure compliance with UU No. 27 Tahun 2022 regarding the obligations of Data Controllers and Data Processors.
Provide centralized documentation for all personal data processing activities (ROPA) across BRI.
Improve visibility, traceability, and monitoring of personal data usage.
Establish stronger personal data governance and accountability within the organization.
Scope & Key Contributions
Designed and developed the ROPA application from scratch to support self-service data entry by users.
Designed database schema to record processing purposes, data categories, legal basis, data subjects, retention, and security controls.
Built secure web forms enabling business units to input and manage ROPA data independently.
Implemented access control and role-based authorization for compliance and operational users.
Enabled monitoring and reporting capabilities for personal data processing activities.
Supported audit readiness by providing structured and traceable ROPA documentation.
Business Impact
Enabled BRI to comply with PDP Law (UU No. 27 Tahun 2022).
Improved visibility and monitoring of personal data processing across business units.
Established a formal system of record for personal data governance and compliance.