Indonesia’s PDP Law Enters a New Phase: Enforcement Moves Forward under GR 33/2026
The Indonesian Government has finally enacted Government Regulation No. 33 of 2026 on the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”) on 16 July 2026. GR 33/2026 is the long-awaited implementing regulation of Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”), issued nearly four years after the PDP Law’s enactment in October 2022 (its two-year transition lapsed in October 2024 with no implementing rules in force). The regulation spans 225 articles across 12 chapters, translating the PDP Law’s high-level principles into detailed operational obligations for data controllers and processors.
GR 33/2026 covers the full lifecycle of personal data processing, from lawful bases (including consent), transparency and data-subject rights, data security and breach notification, the data protection officer function, cross-border transfers, international cooperation, supervision, administrative sanctions, and dispute resolution. It also regulates additional matters considered necessary to operationalize the PDP Law, including joint controllership, controller-processor contracts, and records of processing. The key features of GR 33/2026 are summarized below.
Scope and Household Exemption
Consistent with the PDP Law, GR 33/2026 applies extraterritorially to processing carried out outside Indonesia that has legal consequences within Indonesia or that affects Indonesian data subjects. However, it provides more detail on the personal or household activity exemption. Processing by an individual is excluded where it is: (i) for personal or household needs; (ii) not professional or commercial; and/or (iii) not intended for the public (namely, where it does not cause personal data to become accessible to parties outside the individual data subject’s control).
Salient Provisions
Categories of personal data
GR 33/2026 retains the PDP Law’s existing data categories, but permits sectoral authorities, in coordination with the Data Protection Authority (DPA), to designate additional specific personal data based on its potential impact. It also clarifies that general personal data includes data that can identify an individual when combined with other information, including publicly available data.
Data subject rights request procedures
Controllers must provide accessible electronic and/or non-electronic channels for data subject requests, verify each request proportionately, and accept requests submitted by data subjects, parents or guardians of children, guardians of persons with disabilities, or authorized representatives. Requests must identify the applicant, the relevant right or interest, and the action requested in relation to the personal data. Further, GR 33/2026 operationalizes the PDP Law’s 3x24-hour period response for several rights, namely: right to rectification, right to access, right to withdraw consent, and right to restrict or suspend processing. These periods generally run from receipt and, where applicable, verification of the request.
Lawful bases for processing
GR 33/2026 retains the six lawful bases under the PDP Law, but prescribes additional conditions for their use. Most notably, the regulation effectively requires a documented legitimate interests assessment.
Mandatory RoPA
GR 33/2026 emphasizes the obligation to establish and maintain detailed records of processing activities (RoPA), including prescribing mandatory items that must be included in a RoPA.
Enhanced protection for children and people with disabilities
In the context of personal data protection, a child is now clearly defined as any person under 18 and unmarried. Controllers must actively identify children, verify parental consent using available technology, and provide a transition mechanism when a child reaches adulthood. Similar accessibility mechanisms are required for persons with disabilities.
Personal data breaches
The PDP Law’s 3x24-hour breach notification requirement is further operationalized. It starts from when the controller definitively, properly, and reasonably knows of the breach, based on the conclusion of the controller’s incident documentation. GR 33/2026, as it stands, re-affirms the stricter mandatory notification requirement, in which the notification must be made regardless of the characteristics or the magnitude and severity of the incident.
Security and privacy by design and default
Controllers must implement risk-based technical and organizational measures from the system-planning stage onward, including as appropriate pseudonymization, encryption, resilience, restoration capabilities, and periodic security testing. Systems must, by default, process only personal data necessary for the relevant purpose, taking into account technology, implementation costs, context, scope, and risks.
Data Protection Officer (DPO)
GR 33/2026 confirms, consistently with Constitutional Court Decision No. 151/PUU-XXII/2024, that a controller or processor must appoint a DPO if any one or more of the prescribed triggers applies, namely processing for public-service purposes, core activities requiring regular and systematic large-scale monitoring, or core activities involving large-scale processing of specific personal data or criminal-offence data. The use of “and/or” makes these triggers alternative rather than cumulative. The regulation goes on to set out the DPO’s qualifying criteria, functions, resourcing, and independence.
Cross-border data transfers
The regulation operationalizes the PDP Law’s three-tier framework for cross-border transfers: (i) transfer to a jurisdiction on the DPA’s "adequacy" list; (ii) reliance on adequate and binding safeguards, including DPA-issued Standard Contractual Clauses (SCCs), or DPA-approved Binding Corporate Rules (BCRs); or (iii) data subject consent, subject to limited conditions. Before a transfer, the controller must map and assess the transfer, ensure data minimization, evaluate the applicable transfer instruments and risks, implement supplementary safeguards where necessary, and notify data subjects. Further details remain subject to DPA regulations.
Enforcement and Dispute Resolution Framework
GR 33/2026 operationalizes the PDP Law's enforcement framework and dispute-resolution framework by detailing the DPA’s supervisory, sanctioning, and mediation powers:
Supervision: the DPA may monitor and investigate compliance, issue written remedial orders, require action plans and progress reports, and publish its supervisory findings.
Administrative sanctions: Available sanctions include written warnings; temporary suspension of processing activities; erasure or destruction of personal data; and administrative fines. Sanctions may be imposed cumulatively and without a prior warning.
Administrative fines: fines are capped at 2% of annual revenue or income, and assessed by reference to specified factors, including the impact and duration of the violation, affected data and data subjects, cooperation, business scale, ability to pay, and compliance history. Sanction decisions must generally be implemented within 30 business days of their announcement.
Enforcement procedure: GR 33/2026 prescribes procedures and timelines for complaints, investigations, sanction decisions, and objections. An objection must be filed within 14 business days and does not suspend enforcement; a rejected objection may be challenged before the administrative court.
Dispute resolution: disputes may be resolved through the courts, arbitration, or other alternative dispute resolution. DPA-facilitated mediation generally runs for 30 business days, and may be extended once for up to a further 30 business days.
Implementation Timeline and the Pending Establishment of the DPA
GR 33/2026 will enter into force six (6) months after its promulgation, providing data controllers and data processors with a transition period to prepare for compliance. A savings provision preserves existing personal data protection rules to the extent they are not inconsistent with the regulation, while controllers and processors are permitted to continue processing personal data during the interim period, provided such processing does not contravene the regulation, until the relevant implementing DPA regulations are issued.
While the regulation establishes a comprehensive implementation framework for the PDP Law, many of its provisions will require further guidance from the DPA. Approximately 30 provisions (including rules on legitimate interests, Data Protection Impact Assessment (DPIA), automated decision-making, data subject requests, cross-border data transfer mechanisms, sanctions, and mediation) contemplate implementing regulations to be issued by the DPA, which will also be responsible for key functions such as supervision, enforcement, and dispute resolution. The DPA is to be established by the President through a Presidential Regulation, which has not been issued as of the date of this update. Pending its establishment, personal data protection matters continue to be administered by the Directorate General of Digital Space Supervision under the Ministry of Communication and Digital Affairs (KOMDIGI).
ABNR Commentary
GR 33/2026 moves Indonesia's data protection regime from principle to practice. While the core obligations were already established under the PDP Law, the regulation introduces firm timelines, more detailed accountability requirements (including RoPA, retention policies, DPIAs, and legitimate-interest assessments), and a clearer enforcement framework (including supervisory investigations and administrative fines of up to 2% of annual revenue or income).
However, the framework remains incomplete. Numerous operational matters are reserved for further DPA regulations, including cross-border transfer instruments, automated decision-making, DPO requirements and administrative sanctions. More fundamentally, the DPA itself has yet to be established, meaning that regulatory notification channels and the practical exercise of its supervisory and enforcement powers cannot yet be fully operationalized. Articles 223-224 bridge this institutional gap by permitting processing to continue insofar as it complies with GR 33/2026 and preserving existing regulations that do not conflict with it.
Two points stand out. First, the compliance framework will continue to evolve as the DPA is established and further regulations are issued. Second, the six-month implementation period is short relative to the remediation required. Organizations should therefore prioritize matters already capable of implementation, including data mapping, accountability documentation, contractual arrangements, data subject rights request procedures, data breach response, high-risk processing and cross-border transfers, rather than defer compliance pending further DPA regulations. Those that use this period to implement the new requirements will be better prepared when the regulation takes effect.
By partners Agus Ahadi Deradjat (aderadjat@abnrlaw.com), Mahiswara Timur (mtimur@abnrlaw.com), senior associates Nina Santoso (nsantoso@abnrlaw.com), Natasya Amalia (namalia@abnrlaw.com), associates Sonia Dhan Kaur (dkaur@abnrlaw.com), and Beverly Laza (blaza@abnrlaw.com).
This ABNR client alert is intended solely to provide a general overview, for informational purposes, of selected recent developments in Indonesian law. It does not constitute legal advice and should not be relied upon as such. ABNR accepts no liability of any kind in respect of any statement, opinion, view, error or omission that may be contained in this update. You are strongly advised to consult a licensed Indonesian legal practitioner before taking any action that could affect your rights and obligations under Indonesian law.
More Legal Updates
- 09 Sep 2026 ABNR partners named to Hukumonline's Golden Alumni 2026
- 21 Aug 2026 ABNR partners and of counsel recognized across six Lexology Index 2026 reports
- 12 Aug 2026 Indonesia's New SOE Rulebook: How the Draft Regulation Could Reshape SOE Transactions
- 12 Aug 2026 ABNR Advises on USD 82 Million Data Center Financing
- 07 Aug 2026 What’s Changing for E-Commerce in Indonesia? Key Takeaways from Minister of Trade Regulation No. 19 of 2026
- 22 Jul 2026 Implementation of BI Reg 5/2026 on the Natural-Resource Export Proceeds Framework
NEWS DETAIL
15 Sep 2026
Indonesia’s PDP Law Enters a New Phase: Enforcement Moves Forward under GR 33/2026
The Indonesian Government has finally enacted Government Regulation No. 33 of 2026 on the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”) on 16 July 2026. GR 33/2026 is the long-awaited implementing regulation of Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”), issued nearly four years after the PDP Law’s enactment in October 2022 (its two-year transition lapsed in October 2024 with no implementing rules in force). The regulation spans 225 articles across 12 chapters, translating the PDP Law’s high-level principles into detailed operational obligations for data controllers and processors.
GR 33/2026 covers the full lifecycle of personal data processing, from lawful bases (including consent), transparency and data-subject rights, data security and breach notification, the data protection officer function, cross-border transfers, international cooperation, supervision, administrative sanctions, and dispute resolution. It also regulates additional matters considered necessary to operationalize the PDP Law, including joint controllership, controller-processor contracts, and records of processing. The key features of GR 33/2026 are summarized below.
Scope and Household Exemption
Consistent with the PDP Law, GR 33/2026 applies extraterritorially to processing carried out outside Indonesia that has legal consequences within Indonesia or that affects Indonesian data subjects. However, it provides more detail on the personal or household activity exemption. Processing by an individual is excluded where it is: (i) for personal or household needs; (ii) not professional or commercial; and/or (iii) not intended for the public (namely, where it does not cause personal data to become accessible to parties outside the individual data subject’s control).
Salient Provisions
Categories of personal data
GR 33/2026 retains the PDP Law’s existing data categories, but permits sectoral authorities, in coordination with the Data Protection Authority (DPA), to designate additional specific personal data based on its potential impact. It also clarifies that general personal data includes data that can identify an individual when combined with other information, including publicly available data.
Data subject rights request procedures
Controllers must provide accessible electronic and/or non-electronic channels for data subject requests, verify each request proportionately, and accept requests submitted by data subjects, parents or guardians of children, guardians of persons with disabilities, or authorized representatives. Requests must identify the applicant, the relevant right or interest, and the action requested in relation to the personal data. Further, GR 33/2026 operationalizes the PDP Law’s 3x24-hour period response for several rights, namely: right to rectification, right to access, right to withdraw consent, and right to restrict or suspend processing. These periods generally run from receipt and, where applicable, verification of the request.
Lawful bases for processing
GR 33/2026 retains the six lawful bases under the PDP Law, but prescribes additional conditions for their use. Most notably, the regulation effectively requires a documented legitimate interests assessment.
Mandatory RoPA
GR 33/2026 emphasizes the obligation to establish and maintain detailed records of processing activities (RoPA), including prescribing mandatory items that must be included in a RoPA.
Enhanced protection for children and people with disabilities
In the context of personal data protection, a child is now clearly defined as any person under 18 and unmarried. Controllers must actively identify children, verify parental consent using available technology, and provide a transition mechanism when a child reaches adulthood. Similar accessibility mechanisms are required for persons with disabilities.
Personal data breaches
The PDP Law’s 3x24-hour breach notification requirement is further operationalized. It starts from when the controller definitively, properly, and reasonably knows of the breach, based on the conclusion of the controller’s incident documentation. GR 33/2026, as it stands, re-affirms the stricter mandatory notification requirement, in which the notification must be made regardless of the characteristics or the magnitude and severity of the incident.
Security and privacy by design and default
Controllers must implement risk-based technical and organizational measures from the system-planning stage onward, including as appropriate pseudonymization, encryption, resilience, restoration capabilities, and periodic security testing. Systems must, by default, process only personal data necessary for the relevant purpose, taking into account technology, implementation costs, context, scope, and risks.
Data Protection Officer (DPO)
GR 33/2026 confirms, consistently with Constitutional Court Decision No. 151/PUU-XXII/2024, that a controller or processor must appoint a DPO if any one or more of the prescribed triggers applies, namely processing for public-service purposes, core activities requiring regular and systematic large-scale monitoring, or core activities involving large-scale processing of specific personal data or criminal-offence data. The use of “and/or” makes these triggers alternative rather than cumulative. The regulation goes on to set out the DPO’s qualifying criteria, functions, resourcing, and independence.
Cross-border data transfers
The regulation operationalizes the PDP Law’s three-tier framework for cross-border transfers: (i) transfer to a jurisdiction on the DPA’s "adequacy" list; (ii) reliance on adequate and binding safeguards, including DPA-issued Standard Contractual Clauses (SCCs), or DPA-approved Binding Corporate Rules (BCRs); or (iii) data subject consent, subject to limited conditions. Before a transfer, the controller must map and assess the transfer, ensure data minimization, evaluate the applicable transfer instruments and risks, implement supplementary safeguards where necessary, and notify data subjects. Further details remain subject to DPA regulations.
Enforcement and Dispute Resolution Framework
GR 33/2026 operationalizes the PDP Law's enforcement framework and dispute-resolution framework by detailing the DPA’s supervisory, sanctioning, and mediation powers:
Supervision: the DPA may monitor and investigate compliance, issue written remedial orders, require action plans and progress reports, and publish its supervisory findings.
Administrative sanctions: Available sanctions include written warnings; temporary suspension of processing activities; erasure or destruction of personal data; and administrative fines. Sanctions may be imposed cumulatively and without a prior warning.
Administrative fines: fines are capped at 2% of annual revenue or income, and assessed by reference to specified factors, including the impact and duration of the violation, affected data and data subjects, cooperation, business scale, ability to pay, and compliance history. Sanction decisions must generally be implemented within 30 business days of their announcement.
Enforcement procedure: GR 33/2026 prescribes procedures and timelines for complaints, investigations, sanction decisions, and objections. An objection must be filed within 14 business days and does not suspend enforcement; a rejected objection may be challenged before the administrative court.
Dispute resolution: disputes may be resolved through the courts, arbitration, or other alternative dispute resolution. DPA-facilitated mediation generally runs for 30 business days, and may be extended once for up to a further 30 business days.
Implementation Timeline and the Pending Establishment of the DPA
GR 33/2026 will enter into force six (6) months after its promulgation, providing data controllers and data processors with a transition period to prepare for compliance. A savings provision preserves existing personal data protection rules to the extent they are not inconsistent with the regulation, while controllers and processors are permitted to continue processing personal data during the interim period, provided such processing does not contravene the regulation, until the relevant implementing DPA regulations are issued.
While the regulation establishes a comprehensive implementation framework for the PDP Law, many of its provisions will require further guidance from the DPA. Approximately 30 provisions (including rules on legitimate interests, Data Protection Impact Assessment (DPIA), automated decision-making, data subject requests, cross-border data transfer mechanisms, sanctions, and mediation) contemplate implementing regulations to be issued by the DPA, which will also be responsible for key functions such as supervision, enforcement, and dispute resolution. The DPA is to be established by the President through a Presidential Regulation, which has not been issued as of the date of this update. Pending its establishment, personal data protection matters continue to be administered by the Directorate General of Digital Space Supervision under the Ministry of Communication and Digital Affairs (KOMDIGI).
ABNR Commentary
GR 33/2026 moves Indonesia's data protection regime from principle to practice. While the core obligations were already established under the PDP Law, the regulation introduces firm timelines, more detailed accountability requirements (including RoPA, retention policies, DPIAs, and legitimate-interest assessments), and a clearer enforcement framework (including supervisory investigations and administrative fines of up to 2% of annual revenue or income).
However, the framework remains incomplete. Numerous operational matters are reserved for further DPA regulations, including cross-border transfer instruments, automated decision-making, DPO requirements and administrative sanctions. More fundamentally, the DPA itself has yet to be established, meaning that regulatory notification channels and the practical exercise of its supervisory and enforcement powers cannot yet be fully operationalized. Articles 223-224 bridge this institutional gap by permitting processing to continue insofar as it complies with GR 33/2026 and preserving existing regulations that do not conflict with it.
Two points stand out. First, the compliance framework will continue to evolve as the DPA is established and further regulations are issued. Second, the six-month implementation period is short relative to the remediation required. Organizations should therefore prioritize matters already capable of implementation, including data mapping, accountability documentation, contractual arrangements, data subject rights request procedures, data breach response, high-risk processing and cross-border transfers, rather than defer compliance pending further DPA regulations. Those that use this period to implement the new requirements will be better prepared when the regulation takes effect.
By partners Agus Ahadi Deradjat (aderadjat@abnrlaw.com), Mahiswara Timur (mtimur@abnrlaw.com), senior associates Nina Santoso (nsantoso@abnrlaw.com), Natasya Amalia (namalia@abnrlaw.com), associates Sonia Dhan Kaur (dkaur@abnrlaw.com), and Beverly Laza (blaza@abnrlaw.com).
This ABNR client alert is intended solely to provide a general overview, for informational purposes, of selected recent developments in Indonesian law. It does not constitute legal advice and should not be relied upon as such. ABNR accepts no liability of any kind in respect of any statement, opinion, view, error or omission that may be contained in this update. You are strongly advised to consult a licensed Indonesian legal practitioner before taking any action that could affect your rights and obligations under Indonesian law.

