ElendiLabs
Data Residency: For "Strategic Public Data" , the data must reside on servers located within Indonesia. For private health data, while cross-border transfer is permitted, you must appoint a Data Protection Officer (DPO) in Indonesia and conduct a Data Protection Impact Assessment (DPIA). • Cybersecurity Evaluation: During the Regalkes technical review, you are now required to submit a Vulnerability Assessment and Penetration Testing (VAPT) report. The MoH's cybersecurity team will specifically check for compliance with ISO/IEC 27001 or the local BSSN (National Cyber and Crypto Agency) standards for any device with internet connectivity
Anonymous
Our Software as a Medical Device (SaMD) uses a cloud-based server hosted on AWS Singapore. With Indonesia's PDP Law (Personal Data Protection) coming into full enforcement in 2026, does the MoH require our clinical data servers to be physically located in Indonesia? Furthermore, what specific 'Cybersecurity Maturity Level' certificate must we provide during the technical evaluation of the CSDT?