Skip to content

Regulatory Pulse

Indonesia issues PDP Law implementing regulation: operational duties from January 2027

Government Regulation No. 33 of 2026 adds operational rules for Indonesia’s PDP Law and is scheduled to take effect on 16 January 2027.

Indonesia
PDP Law implementation, privacy operations and international transfers
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Government Regulation No. 33 of 2026 — implementing regulation · Reviewed 5 September 2026 · 9 min read

The 60-second summary

Government Regulation No. 33 of 2026 supplies operational rules for Indonesia’s Law No. 27 of 2022 on Personal Data Protection. Promulgated on 16 July 2026 and publicly circulating from late August, it is scheduled to take effect on 16 January 2027. The regulation details lawful-basis and consent evidence, data-subject request procedures, processing records, retention policies, breach notification and documentation, high-risk impact assessments, data-protection officer arrangements, processor and joint-controller contracts, cross-border transfers and administrative sanctions. Some mechanisms still depend on the future supervisory authority and further authority regulations, so organisations should prepare against the enacted text while tracking institutional implementation.

Timeline that matters

  1. 17 October 2022

    PDP Law enacted

    Law No. 27 of 2022 established the national personal-data protection framework.

  2. 17 October 2024

    Statutory transition ended

    The PDP Law’s two-year conformity period expired.

  3. 16 July 2026

    GR 33/2026 promulgated

    The implementing regulation was enacted and placed in the State Gazette.

  4. Late August 2026

    Text became widely available

    The certified regulation text began circulating publicly ahead of a formal government announcement.

  5. 5 September 2026

    PrivacyBuilt review

    The regulation record, parent law and available certified text were checked.

  6. 16 January 2027

    Scheduled effective date

    GR 33/2026 is due to take effect six months after promulgation.

  7. 19 September 2026

    Next editorial review

    Check the official databases, creation of the supervisory authority and any implementing instruments.

What changed

The PDP Law’s high-level duties now have a detailed operational layer. GR 33/2026 prescribes documentation and process expectations across the personal-data lifecycle, including accessible and recorded rights-request channels; evidence for lawful bases; controller and processor processing records; written retention rules; pre-processing impact assessments for specified high-risk activities; incident policies and breach records; governance for processors, subprocessors and joint controllers; and staged safeguards for international transfers. The regulation also describes how administrative fines of up to 2% of annual revenue or receipts may be assessed. It does not mean every organisation faces the maximum fine, and several authority-dependent instruments are not yet available.

Who should pay attention?

Privacy and legal teams

Map each processing purpose to a documented legal basis, update notices and rights procedures, and resolve authority-dependent questions with specialists.

Security and incident-response teams

Integrate the 3 x 24-hour notification framework, evidence requirements and public-notification triggers into tested response playbooks.

Product and data teams

Identify high-risk processing, automated decisions, new technologies, large-scale activity and other DPIA triggers before deployment.

Procurement and vendor-risk teams

Update controller-processor, subprocessor and joint-controller arrangements, audit rights and incident escalation terms.

Transfer and enterprise architecture teams

Map international data flows, minimise transfers and document the selected transfer basis, risks and supplementary measures.

What the guidance clarifies

It is an enacted regulation, not consultation material
GR 33/2026 was promulgated on 16 July 2026 and is scheduled to take effect six months after promulgation.
The preparation window is time-limited
The operative date is 16 January 2027, so affected organisations should use the remaining period for gap assessment, remediation and evidence collection.
Operational records are central
The regulation adds prescribed content for processing records, retention rules, impact assessments, incident documentation, rights handling and transfer analysis.
Cross-border mechanisms are staged
Adequacy, adequate and binding safeguards, and limited consent pathways are described, but some instruments depend on the future authority.
The maximum fine is not automatic
Administrative fines can reach 2% of annual revenue or receipts, with the amount depending on statutory assessment factors and the circumstances of the infringement.

Detailed rules turn privacy principles into evidence requirements

Why this matters for global organisations

A mature privacy programme must connect policy statements to repeatable controls, records and accountable owners. The regulation is another signal that inventories, lawful-basis decisions, retention, incident response, impact assessments, vendor oversight and transfer governance need verifiable operational evidence.

  • Use one control framework, then map local requirements without losing traceability.
  • Treat processing records, retention schedules and transfer registers as maintained operational assets.
  • Make incident escalation and rights handling measurable, tested and evidenced.
  • Track authority-dependent mechanisms separately from duties that can be implemented now.

14 actions to start now

  1. Confirm which entities, services and processing activities fall within the PDP Law’s territorial and extraterritorial scope.
  2. Create a requirement-to-control matrix for GR 33/2026 with named legal, privacy, security, product and procurement owners.
  3. Validate every processing purpose and legal basis; document legitimate-interest assessments and consent evidence where used.
  4. Update privacy notices and consent capture so required information is clear, specific, accessible and connected to the user action.
  5. Create accessible, recorded and proportionate data-subject request channels with identity-verification, decision and deadline controls.
  6. Bring controller and processor records of processing up to the regulation’s prescribed content and reconcile them with live systems.
  7. Approve a written retention policy covering periods, de-identification, deletion or destruction methods, exceptions and ownership.
  8. Screen proposed and existing processing for DPIA triggers; complete assessments before new high-risk processing begins.
  9. Review whether a data-protection officer function is required and document independence, management access, resources and conflicts controls.
  10. Update controller-processor, subprocessor and joint-controller contracts, including instructions, allocation of duties, audit rights and breach escalation.
  11. Map international transfers, minimise exported data, assess the available transfer basis and document risks and supplementary safeguards.
  12. Test the 3 x 24-hour breach-notification workflow, evidence capture, processor escalation and public-communication decision process.
  13. Prepare a dependency register for authority-issued adequacy findings, standard clauses, binding corporate rules and other future instruments.
  14. Run an executive readiness review before 16 January 2027 and retain remediation evidence.

Suggested next steps

  • Start with scope, processing records, retention, impact assessments, incident response, vendor terms and international transfers. Track the supervisory authority and additional instruments separately. Validate legal interpretation and applicability with qualified specialists.

Evidence worth retaining

  • Entity and territorial-scope analysis approved by counsel or a qualified specialist.
  • GR 33/2026 requirement-to-control matrix with owners and completion status.
  • Processing inventory, controller and processor ROPAs, system maps and data-flow records.
  • Lawful-basis decisions, legitimate-interest assessments, notices and consent records.
  • Rights-request procedures, request logs, verification decisions, response evidence and exception rationales.
  • Retention schedule, written retention policy, deletion or destruction records and legal-hold exceptions.
  • DPIA screening criteria, completed assessments, DPO advice and risk acceptance decisions.
  • DPO appointment, reporting line, resources, independence and conflict assessments.
  • Controller-processor, subprocessor and joint-controller agreements and approval records.
  • International transfer register, minimisation decisions, transfer-risk assessments and safeguards.
  • Incident policy, breach register, notification decision log, message templates and simulation results.
  • Training, control testing, remediation tickets, executive approvals and authority-dependency register.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Which entities and remote activities fall within the regulation’s extraterritorial scope?
  • Which legal bases need new documentation, notices or contractual wording?
  • How should the 3 x 24-hour timeframes be calculated for rights requests and breach notification in each scenario?
  • Which existing activities meet the high-risk DPIA triggers, including automated decisions, large-scale processing or new technologies?
  • Does each entity need a data-protection officer function, and how should independence and conflicts be structured?
  • Which processor, subprocessor or joint-controller contracts need amendment before the effective date?
  • What transfer mechanism is available while authority-issued adequacy and safeguard instruments remain pending?
  • How should legacy transfers and ongoing processing be treated under the transitional provision?
  • Which revenue or receipts base could apply to administrative-fine calculations?
  • What further authority regulations or institutional steps could change the implementation plan?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.