The New GR PDP: Indonesia’s Data Protection Regime Enters a New Phase

Sep 03, 2026

A. A New Phase in Indonesia's Data Protection Framework

After a much-anticipated three and a half years, the Implementing Regulation of Indonesia's umbrella legislation Law No. 27 of 2022 on Personal Data Protection ("PDP Law") has finally taken its concrete form as Government Regulation No. 33 of 2026 on the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection ("GR PDP"), promulgated on 16 July 2026. Importantly, the GR PDP does not take effect immediately, as it enters into force six months after promulgation, giving organisations until approximately 16 January 2027 to prepare for compliance. The regulation marks the start of a more robust and comprehensive governance of personal data protection by translating the previously high-level provisions in the PDP Law into actionable obligations. Its significance makes early understanding of its key provisions essential, not only to allow organisations to begin adjusting their compliance frameworks, but also to identify the key legal risks surrounding the processing of personal data in Indonesia.

B. Key Compliance Obligations Introduced Under the Regulation

The key provisions of the GR PDP are summarised below, together with how they further articulate the data protection obligations set out in the PDP Law.

1. Legal Basis

The GR PDP outlines each legal basis in the PDP Law. Consent must be distinguishable from other matters, presented in an easily comprehensible, accessible format in simple, clear language, preceded by the privacy notice, and evidenced by proof retained by the controller, with consent for children and persons with disabilities obtained from parents or guardians. When relying on contractual necessity, the GR PDP requires data controllers to have a written agreement with data subjects that includes prescribed clauses. As for the other legal bases:

  • legitimate interest now requires a documented legitimate interest assessment before processing;
  • public task requires a policy defining its scope; and
  • vital interest and legal obligation are similarly delineated.

2. Data Subject Rights

The GR PDP elaborates on data subject rights, establishing detailed procedures and strict timelines. Controllers must provide accessible channels for requests, which must be verified before fulfilment. The prescriptive 3 x 24 hours timeline is applied for (i) data subject access rights, (ii) termination of processing, deletion, and/or destruction, and (iii) restriction of processing.

3. Record of Processing Activities ("ROPA")

The GR PDP turns the ROPA from a general obligation into a prescribed template, listing twelve minimum elements for controllers and a shorter four-element record for processors.

4. Data Protection Impact Assessment ("DPIA")

For DPIAs, the GR PDP requires that the assessment be conducted and documented before processing begins, covering (i) the processing and its purpose, necessity, and proportionality, (ii) risks to data subjects' rights and mitigating safeguards, and (iii) recording the DPO's advice, with the assessment revisited when the risk profile changes.

5. Data Breach

The GR PDP requires written data breach notification to be sent to both the data subject and the DPA within 3 x 24 hours, now calculated from the point at which the failure becomes known with certainty and on reasonable grounds, and require the controller's DPO or other contact details to be included.

The GR PDP also added obligations that are enforceable before any incident occurs: (i) data breach documentation reportable to the DPA, and (ii) a written data breach prevention and handling policy covering roles and responsibilities, triage and resolution, documentation and reporting, and periodic review.

6. Data Protection Officer ("DPO")

On the DPO role, the GR PDP requires involvement in all processing activities, direct reporting to the highest level of management, sufficient resources and access, objectivity and independence, and the absence of any conflict of interest.

7. Cross-Border Transfer

The GR PDP expands the bases for cross-border transfers:

  • adequacy of the recipient jurisdiction's personal data protection regulations is determined by the DPA;
  • adequate and binding protection may take the form of legally binding and enforceable instruments, standard contractual clauses set by the DPA, binding corporate rules approved by the DPA, or other recognised instruments; and
  • consent is available only in limited circumstances, such as non-repeated transfers involving a limited number of data subjects.

Before transferring personal data abroad, the controller is expected to map the transfer cycle, confirm the data is adequate, relevant and limited to the purpose, identify and assess the effectiveness of the instrument relied upon, apply supplementary measures where required, re-evaluate the arrangement periodically, and inform the data subject in advance of the purpose, the protection instrument, their rights, the risks and the mitigation adopted.

C. Sanctions and Liability for Non-Compliance

The GR PDP adopts the same administrative sanctions for non-compliance as the PDP Law, including written warnings, temporary suspension of personal data processing, deletion or destruction of personal data, and administrative fines of up to 2% of the annual revenue or receipts of the data controller and/or processor. That ceiling is a maximum rather than a fixed rate, and the GR PDP explains how the DPA can apply sanctions: enforcement may be flexible and case-specific, with the applicable sanction and any fine depending on the overall circumstances of the violation. The GR PDP also identifies which obligations carry administrative sanctions, including the data breach notification, DPIA, DPO appointment and cross-border transfer requirements described above.

D. Enforcement Landscape and Institutional Challenges

The effective enforcement of both the PDP Law and the GR PDP ultimately hinges on the establishment of a dedicated supervisory and adjudicatory body, referred to in the legislation as the Data Protection Authority. That said, the GR PDP has been issued ahead of the Authority's formal creation.

A draft Presidential Regulation on the establishment of the Authority has been circulated since 2025, suggesting that the institutional architecture of Indonesia's data protection regime may soon take clearer shape. For now, however, de facto supervisory and enforcement functions for personal data protection matters are carried out by the Directorate General of Digital Space Supervision within the Ministry of Communication and Digital Affairs ("Komdigi"), pending the issuance of the Presidential Regulation, although our understanding is that they are limited to data breach violations conducted by electronic systems operators, pursuant to relevant electronic information and transactions regulations such as Government Regulation No. 71 of 2019 on the Operations of Electronic Information and Transaction.

E. Preparing for a Maturing Data Protection Regime

While the institutional enforcement architecture is still evolving, the regulation nonetheless signals the direction of Indonesia's data governance regime. With the regulation taking effect six months after promulgation, organisations have a limited period to prepare. Areas likely to require particular attention include:

  • reviewing legal bases relied upon for processing and the procedures for handling data subject requests;
  • reviewing core privacy governance and documentation;
  • improving incident responses readiness;
  • reviewing risk assessment process;
  • appointing a DPO in accordance with the requirements under the GR PDP; and
  • preparing documentation of cross-border transfers as well as updating existing data transfer instruments.

Reviewing internal governance structures, legal documentations, and vendor and intra-group contracts during this period is likely to be less costly than addressing these matters after the regulation takes effect.

Should you have any questions or require assistance in assessing how this regulation impacts your organisation, please do not hesitate to reach out to Danny Kobrata, Emil Zanadi Sasongko, and Gilang Sephia Alfarisi.

Avatar
Danny Kobrata
Avatar
Emil Zanadi Sasongko
Avatar
Gilang Sephia Alfarisi