The Subsidiary Silo: Navigating Data Governance in Tripartite Corporate Structures
In large-scale conglomerates, the lines between "sister companies" and "service providers" often blur. A common assumption is that if a parent group owns the entities involved, data can flow freely for oversight. However, under the Indonesian UU PDP, these internal handshakes are being replaced by rigorous legal requirements—especially when a third-party intermediary is involved.
The Challenge: A Financial Audit with a Governance Gap
We recently resolved a complex data-sharing hurdle for a regional infrastructure leader. The conglomerate needed to conduct a multi-year audit of its employee benefit expenditures to verify rising costs.
The structure of the service was layered:
The Client: The infrastructure conglomerate (Parent Group).
The Provider: An external private insurance company that managed the policy.
The Handler: A specialized health-services subsidiary—wholly owned by the same parent group as the client—acting as the subcontractor for the insurance company.
The challenge was a legal paradox. The conglomerate wanted to audit its own expenditures, but the data was held by its own sister company under a subcontract from an external insurer. Because there was no direct contract between the two sister companies, and because the PDP Law mandates strict safeguards for sensitive health data, the health-services provider could not legally release the audit data. The "good faith" commitment to privacy created a barrier to financial transparency.
Our Intervention: The Two-Phase Governance Bridge
To resolve the impasse without triggering a regulatory breach or a contractual dispute with the external insurer, we implemented a two-phase solution:
Phase 1: Financial Verification via Aggregation We mapped the data requirements to deliver aggregated, non-identifiable summaries. By stripping away "Personally Identifiable Information" (PII), the health-services provider could fulfill the audit request immediately. This allowed the conglomerate to verify its costs without accessing sensitive individual records, maintaining operational momentum.
Phase 2: Formalizing the Tripartite Framework To provide a long-term solution, we facilitated the design of a tripartite contractual framework. This established a formal "Primary Source" for data sharing that included the external insurance company and the two sister entities. By aligning these contracts with PDP Law standards, we ensured that future audits for identifiable data would be handled within a clear, governed protocol.
Analysis Result: Strategic Lessons for Executive Leadership
This case highlights why "proximity" does not equal "permission" in 2026:
The Subcontractor Trap: Even if you own the company handling your data, if they are subcontracted by a third party (the insurer), the legal path for data return must be explicitly paved in the contract.
Sister Companies are Separate Legal Personalities: Under the PDP Law, being in the same "family" does not grant automatic access to sensitive records. Each entity must have a documented legal basis for processing.
Transparency Requires Privacy by Design: Effective financial oversight in a multi-entity group depends on having Data Processing Agreements (DPAs) in place before the audit begins.
The Outcome
By implementing this phased approach, the conglomerate successfully verified its expenditures, the insurance provider maintained its contractual integrity, and the health-services subsidiary remained fully compliant with the PDP Law. This standardized protocol has since been adopted group-wide, ensuring that financial oversight never creates legal liability.
English