Sep 03, 2026
After a much-anticipated three and a half years, the Implementing Regulation of Indonesia's umbrella legislation Law No. 27 of 2022 on Personal Data Protection ("PDP Law") has finally taken its concrete form as Government Regulation No. 33 of 2026 on the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection ("GR PDP"), promulgated on 16 July 2026. Importantly, the GR PDP does not take effect immediately, as it enters into force six months after promulgation, giving organisations until approximately 16 January 2027 to prepare for compliance. The regulation marks the start of a more robust and comprehensive governance of personal data protection by translating the previously high-level provisions in the PDP Law into actionable obligations. Its significance makes early understanding of its key provisions essential, not only to allow organisations to begin adjusting their compliance frameworks, but also to identify the key legal risks surrounding the processing of personal data in Indonesia.
The key provisions of the GR PDP are summarised below, together with how they further articulate the data protection obligations set out in the PDP Law.
The GR PDP outlines each legal basis in the PDP Law. Consent must be distinguishable from other matters, presented in an easily comprehensible, accessible format in simple, clear language, preceded by the privacy notice, and evidenced by proof retained by the controller, with consent for children and persons with disabilities obtained from parents or guardians. When relying on contractual necessity, the GR PDP requires data controllers to have a written agreement with data subjects that includes prescribed clauses. As for the other legal bases:
The GR PDP elaborates on data subject rights, establishing detailed procedures and strict timelines. Controllers must provide accessible channels for requests, which must be verified before fulfilment. The prescriptive 3 x 24 hours timeline is applied for (i) data subject access rights, (ii) termination of processing, deletion, and/or destruction, and (iii) restriction of processing.
The GR PDP turns the ROPA from a general obligation into a prescribed template, listing twelve minimum elements for controllers and a shorter four-element record for processors.
For DPIAs, the GR PDP requires that the assessment be conducted and documented before processing begins, covering (i) the processing and its purpose, necessity, and proportionality, (ii) risks to data subjects' rights and mitigating safeguards, and (iii) recording the DPO's advice, with the assessment revisited when the risk profile changes.
The GR PDP requires written data breach notification to be sent to both the data subject and the DPA within 3 x 24 hours, now calculated from the point at which the failure becomes known with certainty and on reasonable grounds, and require the controller's DPO or other contact details to be included.
The GR PDP also added obligations that are enforceable before any incident occurs: (i) data breach documentation reportable to the DPA, and (ii) a written data breach prevention and handling policy covering roles and responsibilities, triage and resolution, documentation and reporting, and periodic review.
On the DPO role, the GR PDP requires involvement in all processing activities, direct reporting to the highest level of management, sufficient resources and access, objectivity and independence, and the absence of any conflict of interest.
The GR PDP expands the bases for cross-border transfers:
Before transferring personal data abroad, the controller is expected to map the transfer cycle, confirm the data is adequate, relevant and limited to the purpose, identify and assess the effectiveness of the instrument relied upon, apply supplementary measures where required, re-evaluate the arrangement periodically, and inform the data subject in advance of the purpose, the protection instrument, their rights, the risks and the mitigation adopted.
The GR PDP adopts the same administrative sanctions for non-compliance as the PDP Law, including written warnings, temporary suspension of personal data processing, deletion or destruction of personal data, and administrative fines of up to 2% of the annual revenue or receipts of the data controller and/or processor. That ceiling is a maximum rather than a fixed rate, and the GR PDP explains how the DPA can apply sanctions: enforcement may be flexible and case-specific, with the applicable sanction and any fine depending on the overall circumstances of the violation. The GR PDP also identifies which obligations carry administrative sanctions, including the data breach notification, DPIA, DPO appointment and cross-border transfer requirements described above.
The effective enforcement of both the PDP Law and the GR PDP ultimately hinges on the establishment of a dedicated supervisory and adjudicatory body, referred to in the legislation as the Data Protection Authority. That said, the GR PDP has been issued ahead of the Authority's formal creation.
A draft Presidential Regulation on the establishment of the Authority has been circulated since 2025, suggesting that the institutional architecture of Indonesia's data protection regime may soon take clearer shape. For now, however, de facto supervisory and enforcement functions for personal data protection matters are carried out by the Directorate General of Digital Space Supervision within the Ministry of Communication and Digital Affairs ("Komdigi"), pending the issuance of the Presidential Regulation, although our understanding is that they are limited to data breach violations conducted by electronic systems operators, pursuant to relevant electronic information and transactions regulations such as Government Regulation No. 71 of 2019 on the Operations of Electronic Information and Transaction.
While the institutional enforcement architecture is still evolving, the regulation nonetheless signals the direction of Indonesia's data governance regime. With the regulation taking effect six months after promulgation, organisations have a limited period to prepare. Areas likely to require particular attention include:
Reviewing internal governance structures, legal documentations, and vendor and intra-group contracts during this period is likely to be less costly than addressing these matters after the regulation takes effect.
Should you have any questions or require assistance in assessing how this regulation impacts your organisation, please do not hesitate to reach out to Danny Kobrata, Emil Zanadi Sasongko, and Gilang Sephia Alfarisi.