Risk Intelligence

Commentary on frameworks,
regulatory change, and risk.

GDPR · Data Protection

What Indonesia's PDP Law Means for Businesses Handling European Data

Indonesia's 2022 Personal Data Protection Law closely mirrors GDPR — creating both compliance obligations and an efficiency opportunity for organizations operating across borders.

June 2026 · Meridian
NIST CSF 2.0

The Govern Function and Why It Matters

May 2026
Hospitality

Guest Data Is a Compliance Asset and a Liability

April 2026
ISO 27001

Why Clients Are Starting to Ask for ISO 27001

March 2026
Vendor Risk

The Vendor You Didn't Vet Is Still Your Risk

February 2026
Maritime

Cybersecurity Governance in Maritime Operations

January 2026
AI Governance

Where AI Governance Meets Existing Compliance Frameworks

December 2025

Risk Intelligence

Ask a Risk Question

Have a question about a framework, regulatory change, or risk scenario? Submit it below. Questions are reviewed before publication and may be answered in a future Meridian Risk Intelligence update. Identifying details are removed before anything is published.

✓ Received. Your question has been submitted for review.

Community

Approved Questions

Selected questions from practitioners, reviewed and answered by the Meridian team.

Data Privacy & GDPR

Does Indonesia's PDP Law require a Data Protection Officer for all organizations?

Not every organization will need the same privacy governance structure. DPO obligations depend on the nature of processing, scale, sensitivity of data, and applicable implementing rules. A focused scoping review is the right first step before assuming an exemption applies.

Answered
Cybersecurity Frameworks

Is NIST CSF 2.0 mandatory for private-sector companies operating in the US?

For many private-sector organizations, NIST CSF 2.0 is not a direct legal mandate. It can still become operationally important through customer expectations, insurance reviews, partner questionnaires, or internal governance goals. The new Govern function is especially useful for clarifying leadership accountability.

Answered
Vendor & Third-Party Risk

How should we handle a critical third-party vendor who refuses to sign a Data Processing Agreement?

This question is under review for a future Risk Intelligence update. It raises practical issues around data processing terms, vendor leverage, documented risk acceptance, and when leadership should revisit the vendor relationship.

Under Review