Indonesia’s PDP Law: Key Takeaways from the New Implementing Rules

UU PDP

Indonesia’s PDP Law: Key Takeaways from the New Implementing Rules

Indonesia has taken a significant step toward operationalizing its data protection framework with the issuance of Government Regulation No. 33 of 2026 on the Implementation of Law No. 27 of 2022 on Personal Data Protection (“PP 33/2026”).
The Regulation provides detailed implementing rules for the obligations of Personal Data Controllers and Processors, Data Subject rights, cross-border transfers, data protection governance, supervision, administrative sanctions and dispute resolution,

Operational Requirements
The key significance of PP 33/2026 is that it transforms many obligations under UU PDP into specific operational and governance requirements. In practice, organizations will need to demonstrate not only that they have adopted privacy policies, but also that they have appropriate procedures, records, contractual arrangements and technical measures to demonstrate compliance.
One of the most significant developments concerns Data Controller and Processor arrangements. Where two or more parties act as joint Controllers, the Regulation requires an agreement addressing, among other matters, each party’s processing basis, purposes, processing methods, responsibilities and contact point, as well as joint and several liability for joint Controllers.
PP 33/2026 also imposes more detailed requirements on Controller-Processor agreements. Such agreements must address the scope and method of processing, data categories, processing period, rights and obligations, audit and inspection mechanisms, dispute resolution, and the appointment of other Processors. The Regulation also requires a Processor to obtain the Controller’s written approval before engaging another Processor.

Accountability and Documentation
PP 33/2026 introduces a stronger accountability framework. Controllers are expected to maintain records of processing activities and data flows. The explanatory provisions describe the required records as including an inventory and mapping of personal-data flows. The regulation also requires Controllers to establish accountability measures, document processing activities, demonstrate compliance and conduct internal and external audits.
These requirements mean that organizations should maintain a comprehensive Record of Processing Activities (“RoPA”), supported by appropriate documentation of processing purposes, legal bases, data categories, recipients, retention periods, security controls and transfers.

Privacy Notices, Consent and Data-Subject Rights
PP 33/2026 significantly elaborates on transparency requirements. Controllers are required to provide information concerning, among other things, the legality and basis of processing, purposes, types of personal data, retention period, processing period and Data Subject rights. The explanatory provisions further indicate that information on processing legality includes the Controller’s identity and contact information, processing basis and relevant DPO/PPDP contact.
Consent requirements are similarly detailed, as the Regulation enforces that consent is to be given freely, consciously, specifically and unambiguously. Controllers are required to maintain evidence of consent as well as a mechanism for withdrawal of consent.
The Regulation also established procedures for exercising Data Subject rights, including request submission, identity verification and response mechanisms. This will require organizations to maintain a formal and documented Data Subject rights request process, rather than relying solely on general service procedures.

High-Risk Processing and Emerging Technologies
A particularly important development is the detailed framework for Personal Data Protection Impact Assessments (“DPIAs”). A DPIA is required where processing presents a high risk to Data Subjects. The specific circumstances include large-scale processing, systematic monitoring, processing of specific/sensitive personal data, profiling or automated decision-making with legal or significant effects, data combination, the use of new technologies, and processing that restricts data-subject rights. The explanatory provisions expressly recognize AI, machine learning, smart technology and Internet of Things as examples of new technology.
The DPIA must be conducted prior to personal data processing begins, addressing the processing purpose, necessity and proportionality, risks to data-subject rights and mitigation measures. The assessment must be documented and reviewed when processing risks change.
This development is particularly relevant to organizations deploying AI, automated decision-making, biometrics, profiling, large-scale analytics or other data-intensive technologies.

Data Breaches and Security
The Regulation provides greater detail on breach-response obligations already established under UU PDP. It requires notification to the data subject and supervisory authority within 3x24 hours after the Controller becomes aware of the breach in a definite and reasonable manner.
The notification must describe the affected data, circumstances of the breach and mitigation measures. Controllers are required to maintain a breach record containing information on the affected data, impact, remediation and notification.

Enforcement
PP 33/2026 was enacted on 16 July 2026 and will take full legal effect, including its legal consequences, on 16 January 2027, thereby providing a six-month grace period for compliance. 
The Regulation also establishes a supervisory authority that is empowered to oversee compliance and issue orders, including orders to stop or restrict data processing.
Administrative sanctions are further operationalized, including procedures for imposing administrative fines and assessing relevant factors such as the impact of the violation, duration, type and volume of data affected, number of data subjects, cooperation and compliance history.