Newsroom

We are a law firm providing a wide range of high-quality legal services in Indonesia.

IABF’s 60 Seconds: Indonesia Issues Implementing Regulation for the Personal Data Protection Law

Legal News Update

Contributors: Almaida Askandar, S.H., MBA, Nita Damayanti, S.H., and Rania Adhara Safira, S.H.

Published on 12 September 2026 by IABF Law Firm, Jakarta, Indonesia.

Indonesia Issues Implementing Regulation for the Personal Data Protection Law

On 16 July 2026, the Indonesian Government issued Government Regulation No. 33 of 2026 on the Implementing Regulation of the Personal Data Protection Law (“GR 33/2026“), which will take effect on 16 January 2027. The regulation elaborates on the PDP Law across several key areas, including data subject rights, controller obligations, breach notification, DPIAs, DPOs, cross-border transfers, compensation claims, and administrative sanctions. It applies to private entities, public bodies, and international organizations processing personal data in Indonesia or whose activities have legal effects there.

Joint Controllers

Where personal data is processed by joint controllers, they must enter into a joint controller agreement covering the legal basis for processing, the relationship between each party’s purposes, the agreed processing methods, data types, allocation of roles and responsibilities, and a designated point of contact.

Exercise of Data Subject Rights

The regulation sets out a formal process for exercising data subject rights: requests must be submitted through a recorded, accessible channel by the data subject or an authorized representative, and controllers must verify requests and decide whether to fulfil or reject them. Unresolved issues may be reported to the Personal Data Protection Authority, and controllers must maintain internal policies based on the Authority’s guidance. Beyond this general framework, the regulation also provides more detailed rules specific to each right, access, correction, erasure, and portability, meaning obligations may differ depending on which right is exercised, rather than following one uniform procedure.

Legal Bases for Processing

The regulation does not introduce new legal bases but elaborates on the six already recognized under the PDP Law: explicit consent, contractual necessity, legal obligation, protection of vital interests, public interest, and legitimate interests. Processing under any basis must not result in discriminatory treatment. Notably, relying on legitimate interests now requires a documented balancing exercise assessing necessity, proportionality, and risk mitigation, and data subjects have the right to seek explanation, object, and request that the processing be stopped or adjusted, turning this basis into a concrete compliance obligation rather than a one-time justification.

Personal Data Breach Notification

Controllers must notify affected data subjects and the Authority in writing within 3×24 hours of becoming reasonably and definitively aware of a breach, including details on the affected data, circumstances, remediation steps, and relevant contact person. Public notification is required for breaches affecting public services or the public interest. The regulation clarifies that the notification clock starts from the point of awareness (not the breach itself), expands the required notification content, and requires controllers to maintain documented breach records and internal breach-handling policies, embedding breach management as an ongoing governance function.

Compensation Claims

Data subjects may claim compensation for violations related to personal data processing. Controllers must establish procedures for receiving and responding to such claims, and unresolved claims may proceed to further legal remedies.

Data Protection Impact Assessments (DPIA)

A DPIA is required before high-risk processing activities, such as automated decision-making, large-scale processing, systematic monitoring, data matching, or use of new technologies. The assessment must be conducted before processing begins and must describe the activity and purpose, assess necessity and proportionality, evaluate risks to data subjects, and outline protective measures. Controllers must implement these measures, document the process, and review it whenever risks change.

Data Protection Officers (DPO)

A DPO is mandatory for public-service processing, large-scale systematic monitoring, or large-scale processing of sensitive data or criminal offence data. The regulation requires DPOs to be appointed based on professionalism and relevant expertise, with appointment scaled to the organization’s size and needs; a DPO may consist of one or more individuals from inside or outside the organization. Core DPO functions include advising on compliance, monitoring adherence to regulations, supporting DPIAs, and acting as the main contact point for data processing matters.

Cross-Border Data Transfers

Before transferring data abroad, controllers must assess the transfer flow, necessity, applicable mechanism, and risks. Transfers follow a tiered approach: (1) to countries with equal or higher data protection standards; (2) failing that, through binding safeguards such as standard contractual clauses, binding corporate rules, or other approved instruments, preceded by a transfer risk assessment; or (3) as a last resort, through data subject consent, limited to non-recurring transfers with prior notice to both the Authority and the data subject, including relevant purpose, risk, and safeguard information.

Controllers and processors may continue existing processing activities pending further Authority regulations, provided such processing remains consistent with GR 33/2026.

Key Takeaways for Businesses

With GR 33/2026 taking effect on 16 January 2027, businesses should use the transition period to review: controller/joint-controller agreements, data subject request procedures, documentation of legal bases, breach-response protocols, DPIA processes, DPO appointment requirements, cross-border transfer mechanisms, and internal governance policies. Early alignment with these requirements will be key to compliance ahead of the effective date.

***

Disclaimer

This news update is prepared for general informational purposes only. The content does not constitute legal advice, a legal opinion, or counsel from IABF Law Firm. The information contained herein may not reflect the most current developments. Any quotation, distribution, or use of this information for any purpose is solely at the user’s own risk.

Contact Us for Legal Assistance

Scroll to Top