Data Processing Agreement Overview

Published by:Binari Legal & CompliancePublished at:July 18, 2020Last Updated:January 17, 2023Read time:8 min read

An overview of Binari's Data Processing Agreement (DPA): when it applies, our core responsibilities, and how your procurement or legal team can request it.

Overview

On certain engagements, Binari processes personal data on behalf of a client rather than for our own purposes. For those engagements, we make available a standard Data Processing Agreement (DPA) that supplements the applicable service agreement and sets out how that personal data is handled. This page summarizes what our DPA covers at a high level. It is not the contractual document itself, and not every Binari project automatically requires one.

What Is the Binari DPA?

The DPA is a contractual document that supplements the relevant service agreement whenever Binari processes personal data on a client’s behalf. It helps clarify who is responsible for what in connection with the personal data processed within a given project, covering matters such as processing instructions, confidentiality, security, and incident handling. The DPA does not replace the service agreement; it adds to it for the portion of the work that touches a client’s personal data.

When Does the DPA Apply?

A DPA may be relevant for engagements where Binari processes personal data that a client controls, for example:

  • software or application development;
  • website or application maintenance;
  • managed hosting;
  • system integration;
  • technical support involving access to client data;
  • cloud-related services; and
  • other work where Binari processes personal data on documented, written instructions from the client.

Not every project involves personal data processing. Most SEO or website audit work, for instance, is technical in nature and never touches a client’s personal data at all, while an application build that stores end-user data almost always calls for one. Whether a DPA is needed comes down to the actual nature of the work, not the service category in general.

Roles and Responsibilities

On engagements involving a DPA, the client generally acts as the party determining the purpose of processing, while Binari acts as the party processing personal data according to the client’s documented instructions. Each party remains responsible for the obligations that attach to its own role.

Separately from this, Binari may also process business contact or administrative information for our own corporate purposes, for example when communicating with prospective clients through our website. That kind of processing is governed by our Privacy Policy, not by a client DPA.

What the DPA Covers

Binari’s standard DPA generally addresses:

  • documented, written processing instructions;
  • confidentiality obligations for personnel who handle the data;
  • technical and organizational safeguards appropriate to the processing risk;
  • access limited to authorized personnel;
  • use of subprocessors, including the client’s written consent before a new one is engaged;
  • international data processing or transfers, where relevant;
  • assistance to the client in responding to data subject requests;
  • handling of personal data breaches;
  • data retention;
  • return or deletion of client data once a project ends; and
  • cooperation on compliance or audit needs, to the extent reasonable and relevant to the project’s scope.

This page only summarizes these areas at a high level. The full contractual clauses live in the DPA document itself.

Security and Confidentiality

Our DPA requires safeguards appropriate to the nature of the service, the data involved, the systems in play, and the level of processing risk. Depending on the project, this can include access controls, secure authentication, infrastructure protection, monitoring, vulnerability management, backup and recovery, incident handling, secure development practices, and confidentiality obligations for our personnel.

The specific controls applied are not identical across every project, since they are tailored to the needs and risk profile of each engagement. For a broader look at Binari’s approach to security and compliance, visit our Security & Compliance page.

Subprocessors

To deliver certain services, Binari may rely on third-party providers, for example in areas such as cloud infrastructure, hosting, system monitoring, communication services, security, or other technical platforms. We do not publish a specific vendor list on this page, since the mix of subprocessors can vary from project to project.

Relevant subprocessor arrangements are addressed through appropriate contractual and data protection safeguards, including the client consent step referenced under What the DPA Covers above. Project-specific subprocessor information can be shared during contracting or due diligence, where needed.

International Data Processing

Some of the technology and infrastructure providers Binari relies on may operate across multiple jurisdictions. Where personal data is processed or transferred internationally as part of a project, Binari and the client will address the applicable data protection requirements through appropriate contractual and operational safeguards, consistent with the PDP Law’s provisions on transferring personal data outside Indonesia.

Data Breach and Incident Management

Our standard DPA sets out responsibilities for identifying, investigating, mitigating, and communicating personal data breaches affecting client data. As the party processing data on the client’s instructions, Binari will notify the client without undue delay once an incident of this kind is identified, so the client can meet its own notification obligations under the PDP Law, including notifying the relevant authority and affected data subjects within the timeframe set by applicable law.

Any specific contractual notification periods are set out in the DPA document itself and are not published in detail on this page.

Data Retention, Return, and Deletion

The DPA can define how a client’s personal data is handled once processing is no longer needed, a project ends, a service is terminated, or the client requests return or deletion where applicable. The actual procedure can depend on the project’s architecture, backup practices, applicable legal requirements, contractual terms, and technical feasibility at the time. We do not promise instant deletion from every system or backup, since that depends heavily on the technical context of each project.

Project-Specific Terms

The full DPA may include schedules or annexes containing project-specific detail, such as the purpose of processing, categories of data subjects, categories of personal data, processing duration, systems involved, security arrangements, subprocessors, and retention and deletion requirements. These details are agreed as part of the relevant client engagement and are not published on this page.

Privacy Policy
Covers personal data Binari processes for its own website and corporate purposes.

Cookie Policy
Covers cookies and similar technologies used on the Binari website.

Security & Compliance
Gives a broader overview of Binari’s security and compliance practices.

Service Agreements / Contracts
Govern commercial scope, deliverables, fees, timelines, and project-specific obligations.

Request the Binari DPA

Prospective and existing clients can request a copy of Binari’s standard DPA for procurement review, legal review, compliance assessment, security due diligence, or contracting. Want your procurement, legal, or security team to review our standard DPA before contracting? Reach out and we’ll send it over.

PT Binary Cipta Solusindo (Binari)
Email: [email protected]

Updates

We may update our standard DPA or this public overview from time to time to reflect legal developments, service changes, operational changes, or improvements to our data protection practices. The date of the most recent update will always appear at the top of this page.