ブログ
[Indonesia Legal News] Personal Data Protection Law – Issuance of the Implementing Regulation for Personal Data Protection Law
2026.09.29
The Government of Indonesia has officially issued the implementing regulation for the Law No. 27 of 2022 on Personal Data Protection (“PDP Law”) by issuing the Government Regulation No. 33 of 2026 on the Implementation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”). This regulation will be effective from 16 January 2027.
GR 33/2026 is the principal implementing regulation contemplated by the PDP Law, and provides detailed operational requirements, covering the classification and processing of personal data, legal bases, data-subject request procedure, processor and joint-controller arrangements, records of processing, retention, breach response, data-protection impact assessments, data-protection officers, corporate transactions, cross-border transfers, regulatory supervision, administrative sanctions and dispute resolution. The introduction of GR 33/2026 also reflects Indonesia’s growing commitment to aligning its data protection framework with international standards.
This regulation itself does not operate fully in executing and requires several technical and procedural further regulations to be issued by the institution responsible for personal data protection under the PDP Law (PDP Institution). Businesses should therefore treat GR 33/2026 as the core operational framework while monitoring the establishment and operation of the PDP Institution and the issuance of further implementing regulations.
Containing total of 255 articles, several key highlights from GR 33/2026 that are important to note are:
(1) Data Breach Notification Requirements: GR 33/2026 clarifies that the 72-hour breach notification period begins to run only when a personal data protection failure has been established with certainty and on reasonable grounds based on relevant supporting documentation. GR 33/2026 helpfully clarifies that the 72-hour notification clock does not commence until a data controller has completed a reasonable assessment and concluded, based on documented evidence, that a personal data protection failure has in fact occurred.
(2) Cross-border transfers: GR 33/2026 provides more detail on the implementation of cross-border transfer requirements. The PDP Law previously referred to jurisdictions with an equivalent or higher level of protection but did not specify who would be responsible for making that determination. GR 33/2026 now confirms that adequacy assessments will be conducted by the data protection authority (“DPA”), which will maintain of adequate jurisdictions.
(3) Data-subject rights: GR 33/2026 reaffirms this 72-hour deadline across each of the data subject’s rights under the PDP Law (i.e. right to request for information, right to rectification, right of access and copies, right of erasure and destruction, right to withdraw consent, right to object to automated decision making, right to restrict or suspend processing, right to data portability), and requires data controllers to verify both the requesting party’s identity and their entitlement to exercise the relevant right by using a mechanism appropriate to the purpose, the technology available, and the time reasonably required. GR 33/2026 provide an obligation for data controllers to fulfil data subject’s requests related to the relevant rights (such as rectification, withdrawal of consent, or restriction of processing) within 3 x 24 hours (72 hours) as of receiving the formal request, and must provide accessible electronic and/or non-electronic request channels, verify requests in a reasonable manner .
(4) Lawful Processing: Data controllers must document legal bases before processing, maintain internal processing rules, provide accessible notices, record processing activities, adopt retention policies, implement security measures and be able to demonstrate accountability.
(5) High-risk processing: A data-protection impact assessment must be completed before high-risk processing, including certain automated decisions, large-scale or specific-data processing, systematic monitoring, data matching and use of new technology.
(6) Data Protection Officer (“DPO”): GR 33/2026 details the functions of a DPO, which include advising on compliance, monitoring compliance, advising on and being consulted during data protection impact assessments (“DPIA”), and acting as a point of contact. The DPO must be involved in all processing activities, have direct access to senior management, operate free from intervention, receive adequate resources and access, and remain free from conflicts of interest, with its activities documented as part of the DPIA.
(7) Administrative Sanctions: GR 33/2026 provides that administrative sanctions that are categorized into four main stages, i.e. (1) written warnings – preliminary sanction issued upon initial discovery of violation or failure of compliance; (2) temporary suspension of processing – ordering data controller or processor to suspend personal data processing; (3) erasure (deletion) or destruction – ordering the permanent removal or destruction of improper processed personal data; and (4) administrative fines of up to 2% of annual revenue or receipts to be calculated against specified violation variables. The Elucidation to GR 33/2026 also clarifies that revenue means gross economic inflows, not net profit. The fine amounts may also take into account the categories and number of data subjects affected.
(8) Privacy Notices: GR 33/2026 extends notice obligations to personal data collected indirectly (e.g., from affiliates, vendors, public sources, or corporate transactions). Data controllers must notify the data subject within 30 business days of collection. Notices must contain the data controller’s identity, lawful basis, processing purposes, data categories, retention periods, sources, recipients/transfers, security measures, processing lifecycle, and data subject rights. This notice must be accessible and updated. GR 33/2026 prohibits exoneration clauses, i.e., provisions that reduce, limit, or exclude a data controller’s obligations.
We recommend that all companies conduct a comprehensive compliance review to identify gaps between their current practices and the obligations imposed under the PDP Law and GR 33/2026. Furthermore, companies and organizations should review existing privacy notices.
Member
PROFILE
PROFILE

