William Chandra, IT GRC and Data Protection

From The Beginning: An IT GRC and Data Protection Career

IT GRC and Data Protection - William Chandra

IT GRC and Data Protection - William Chandra

I grew up thinking technology was about building things. Today, that same systems-thinking shapes how I approach IT GRC and data protection across Indonesia’s regulated markets.

I studied Computer Science at Universitas Indonesia, then went to Taiwan for a Master of Information Management at National Taiwan University of Science and Technology. Those years gave me something I did not fully appreciate until much later: the habit of thinking in systems. How components interact. Where dependencies hide. What breaks first under stress.

I did not know then that I would spend my career applying that thinking not to code or infrastructure, but to governance.

The Beginning: Learning What IT GRC Controls Actually Mean

My first professional role in the field was at KPMG Indonesia as an IT Assurance Consultant. I conducted IT General Controls and IT Application Controls audits, SOX assessments, and Internal Control over Financial Reporting evaluations across banking, insurance, and oil and gas.

What KPMG taught me was not just how to audit. It taught me how organizations rationalize risk to themselves. I learned that the gap between how an organization describes its controls and how those controls actually operate is where the real risk lives.

That lesson has stayed with me through every role since and has shaped my IT GRC and data protection mindset.

Four Years Inside a Transformation: ByteDance, GoTo, and TikTok Shop Indonesia

In 2021 I joined Tokopedia, which was in the middle of one of the most complex corporate transitions in Indonesian tech history. The GoTo merger. The ByteDance acquisition. The emergence of TikTok Shop as a commerce platform operating across e-commerce and fintech simultaneously.

I was there for all of it, first under GoTo on a formal secondment arrangement, then under ByteDance as the acquisition completed, with my full tenure recognized across the transition.

Over four years I moved from IT Security Assurance to IT Security and Privacy Leader. The work spanned vulnerability management, security hardening, KPI/KRI dashboards for CISO and executive leadership, third-party risk assessment across payment processors, logistics partners, and SaaS vendors, and ultimately leading the simultaneous certification of ISO 27001, ISO 27701, and PCI-DSS across TikTok Shop Indonesia’s e-commerce and fintech operations.

Zero findings across all three certifications.

I am proud of that outcome. But what that period really taught me was something harder to put on a certification: how to communicate risk to people who have every reason not to want to hear it. How to build a governance program that the business treats as an asset rather than a constraint. How to represent a technical compliance position in front of leadership in a way that leads to a decision rather than a deferral.

Those skills do not appear in any framework. They are built through repetition, through getting it wrong, and through understanding that governance is fundamentally a question of trust.

The DPO Chapter: Personal Accountability at Scale

In April 2025 I joined SPayLater at PT Commerce Finance, part of Monee Group, as Head of IT GRC and Data Protection Officer.

This was a different kind of data protection responsibility. Not the scale of a hypergrowth platform, but the precision required by an OJK-supervised consumer financing entity operating under Indonesia’s Personal Data Protection Law. I was the sole DPO. My name was on the regulatory submissions. I reported directly to the SPayLater board on IT risk posture, compliance maturity, and third-party exposure.

I built the privacy framework from the ground up. Record of Processing Activities. Data Protection Impact Assessments. Consent management. Data subject rights processes. PSE registration compliance. Breach response architecture. Vendor data processing agreements across IT and Operations third-party relationships simultaneously.

I also led the ISO 27001:2022 recertification for the entity, again with zero major and zero minor findings.

What this role clarified for me is the difference between being professionally responsible for governance and being personally accountable for it. When your name is registered with the regulator, when OJK examiners direct their questions to you specifically, governance stops being an organizational function and becomes a personal commitment.

That shift in mindset changed how I approach the work.

What I Have Learned Across These Years

A few things I believe now about IT GRC and data protection that I did not when I started:

Governance that the business cannot operate within is not governance. It is friction with documentation attached. The best frameworks are the ones people follow because they make sense, not because they are required.

Regulators remember people who engage honestly. Indonesia’s regulatory landscape for digital financial services is maturing quickly. OJK’s approach to supervision is becoming more entity-specific and more technically rigorous. In that environment, the practitioners who build long-term credibility are the ones who do not try to manage the regulator. They inform them.

Certifications prove you can learn. What they cannot prove is judgment. CISA, CISM, CRISC, and ISO 27001:2022 Lead Auditor are on my credentials because they represent genuine knowledge I use. But every senior decision I have made came down to judgment, reading a situation correctly, understanding whose interests were at stake, and choosing the position I could defend honestly.

The riskiest moment in any governance role is not the audit. It is the quiet decision nobody is watching.

What Comes Next

I’m at the start of a new chapter, one that will take this seven-year arc from OJK-regulated fintech into a broader corner of Indonesia’s regulated digital-asset space. I’ll share more as that unfolds.

I’m building this website as a place to think out loud about technology risk, data protection, and regulated digital markets in Indonesia. Not as a platform, but as a discipline. Writing forces clarity. And clarity is what this field needs more of.

If you work in GRC, privacy, cybersecurity governance, or regulated fintech in Indonesia or the broader SEA region, I hope something here is useful to you.

This is the first post. There will be more.


About Me

William Chandra is an IT GRC and data protection professional with years across Big 4 assurance, hypergrowth e-commerce, and OJK-licensed financial services. He holds CISA, CISM, CRISC, and ISO 27001:2022 Lead Auditor certifications and serves on the executive team of ISACA Indonesia’s Certification Office.

Connect with me on Linkedin.

William Chandra, IT GRC and Data Protection Officer, CISO, Indonesia

Exit mobile version