Risk Intelligence
What Indonesia's PDP Law Means for Businesses Handling European Data
Indonesia's 2022 Personal Data Protection Law closely mirrors GDPR — creating both compliance obligations and an efficiency opportunity for organizations operating across borders.
June 2026 · MeridianThe Govern Function and Why It Matters
Guest Data Is a Compliance Asset and a Liability
Why Clients Are Starting to Ask for ISO 27001
The Vendor You Didn't Vet Is Still Your Risk
Cybersecurity Governance in Maritime Operations
Where AI Governance Meets Existing Compliance Frameworks
Risk Intelligence
Have a question about a framework, regulatory change, or risk scenario? Submit it below. Questions are reviewed before publication and may be answered in a future Meridian Risk Intelligence update. Identifying details are removed before anything is published.
Community
Selected questions from practitioners, reviewed and answered by the Meridian team.
Does Indonesia's PDP Law require a Data Protection Officer for all organizations?
Not every organization will need the same privacy governance structure. DPO obligations depend on the nature of processing, scale, sensitivity of data, and applicable implementing rules. A focused scoping review is the right first step before assuming an exemption applies.
Is NIST CSF 2.0 mandatory for private-sector companies operating in the US?
For many private-sector organizations, NIST CSF 2.0 is not a direct legal mandate. It can still become operationally important through customer expectations, insurance reviews, partner questionnaires, or internal governance goals. The new Govern function is especially useful for clarifying leadership accountability.
How should we handle a critical third-party vendor who refuses to sign a Data Processing Agreement?
This question is under review for a future Risk Intelligence update. It raises practical issues around data processing terms, vendor leverage, documented risk acceptance, and when leadership should revisit the vendor relationship.