On 2 October 2026, Indonesia's Ministry of Communication and Digital Affairs said it was investigating alleged illegal trading of personal data that had resurfaced online. According to a BSSN explanation relayed by the ministry, the information attracting renewed attention consisted of older data that had resurfaced. Authorities nevertheless continued investigating and taking action against sites suspected of trading personal information.
For businesses, cases like this raise a question that differs from the usual cybersecurity discussion. It is not only: how well are we protecting today's database? It is also: how much old data do we still hold, where do all its copies exist, and do we still have a clear reason for retaining it?
Information can stop being commercially useful without stopping being risky.
Data Does Not End When the Customer Becomes Inactive
The beginning of a data lifecycle is usually easy to identify. A customer fills out a form, creates an account, completes a transaction, makes a claim, joins a mailing list or provides documents for a particular process.
The ending is often much less visible.
Once the original purpose has finished, the record may remain inside the CRM. Marketing may have exported it into a spreadsheet. Customer service may retain an attachment. Backups can contain earlier database versions. A vendor may have received a copy to provide a service. Test environments may even contain information originally drawn from production systems.
Operationally, one customer record can become many copies.
Indonesia's Personal Data Protection Law treats processing as an entire lifecycle, including collection, storage and eventually deletion or destruction. It also requires controllers to end processing once the retention period or processing purpose has been fulfilled and, in specified circumstances, to delete data that is no longer required for its processing purpose.
Retention is therefore not merely a storage-capacity decision. It is a governance decision.
The Problem Is Larger Than Deleting the Main Database Record
Suppose a company removes an inactive customer from its primary application.
Does that mean the information no longer exists?
Not necessarily.
There may still be a CSV exported six months ago, an email attachment, shared folders, backups, snapshots, retired equipment or copies previously sent to service providers.
GATICORP therefore uses deletion debt as an editorial framework: the accumulation of information that should have reached an end-of-life review but remains across the organisation because there is no consistent mechanism for closing its lifecycle.
It is not a legal term under Indonesia's PDP Law.
The idea resembles technical debt. Deferring the decision may appear inexpensive today, but complexity grows as the number of systems, vendors and duplicated datasets increases.
NIST treats data processing as a full lifecycle that includes collection, retention, sharing and disposal. Its Cybersecurity Framework also includes managing information through destruction, while its privacy guidance recognises deletion and retention management as part of organisational data-control capabilities.
Not All Old Data Should Simply Be Deleted
Data minimisation does not mean indiscriminately erasing every old record.
Some information may remain necessary for contracts, transactions, audits, disputes, recordkeeping obligations or sector-specific regulation. Indonesia's PDP Law itself places ending processing, deletion and destruction within the wider requirements of applicable law.
The better retention question is therefore not:
“How many years have we kept this?”
It is:
“What purpose still justifies keeping it, and what rule requires us to do so?”
If the answer is no longer clear, the information deserves review.
International privacy principles point in a similar direction. OECD guidance includes collection limitation, purpose specification and use limitation, while NIST defines minimisation around restricting the creation, collection, processing and retention of personal information to what is relevant and necessary for an authorised purpose.
Deletion Needs to Become a Workflow
A mature organisation does not wait for someone to remember that a folder has existed for too long.
Retention needs triggers.
A customer relationship may end. A recruitment process closes. A campaign finishes. A vendor contract terminates. A statutory or contractual retention obligation expires.
The organisation then needs to know which systems are affected, who owns the process, whether a legal hold applies, which vendors hold copies, how backups are governed and how completion is recorded.
Backups are a particularly important example. They are essential for resilience and recovery; managing them is not the same as deleting an active database record one by one. Organisations nevertheless need to decide how retention rules interact with backup lifecycles and what happens when older information re-enters production through a restoration process. NIST treats backup, retention and secure disposal as related lifecycle-management concerns.
Privacy therefore requires more than security controls.
It also needs end-of-life controls.
Data You No Longer Hold Does Not Need Protecting
Businesses often measure their data capabilities by how much information they can collect.
A mature organisation can also explain what information it intentionally no longer keeps.
Removing unnecessary records does not eliminate cybersecurity risk. Active databases still require access control, encryption, monitoring, vendor governance and other technical safeguards. Indonesia's PDP Law explicitly requires controllers to apply technical and operational protection measures and determine security levels according to the nature and risk of the personal data being processed.
But there is a meaningful difference between protecting one million records that the business genuinely needs and protecting those records plus several million old copies whose business purpose is no longer understood.
That is where data retention stops being housekeeping and becomes a management decision.
The increasingly useful question is not only:
“Is our data secure?”
It is also:
“Do we still need to possess this data at all?”
- Indonesia Ministry of Communication and Digital Affairs, 2 October 2026 — “Old Data Breach Resurfaces, Komdigi Investigates Illegal Personal-Data Traders.” Used as current context. Komdigi relayed BSSN's explanation that the data attracting renewed attention consisted of older information. This article does not infer the original source of the breach, ownership of the dataset, authenticity of every record or dataset scale because those matters were not confirmed by the official source.
- Law No. 27 of 2022 on Personal Data Protection. Article 16 is used for the processing lifecycle; Article 35 for security obligations; and Articles 42–45 for termination of processing, deletion and destruction. These provisions are not interpreted as a requirement to erase all historical information regardless of other applicable legal obligations.
- NIST Privacy Framework and Cybersecurity Framework. Used as international references for data lifecycle management, retention management, deletion and secure disposal. NIST frameworks are voluntary guidance and are not Indonesian law.
- NIST Glossary — Data Processing and Minimization. Used to clarify that the data lifecycle includes retention and disposal and that minimisation limits processing and retention to information that is necessary.
- OECD Privacy Guidelines. Used for the principles of collection limitation, purpose specification and use limitation.
- “Deletion debt” is a GATICORP editorial framework, not an official term used by Indonesia's PDP Law, NIST or the OECD.
- This article does not prescribe a universal retention period. Retention requirements can differ according to processing purpose, record type, contractual requirements and applicable sectoral regulation.
- The article does not suggest that deletion replaces cybersecurity. Data minimisation, access control, security engineering, vendor governance and incident response remain complementary controls.
Published: October 7, 2026




