Technical Regulation on Personal Data Protection and the Obligations of Controllers and Processors Finally Issued through Government Regulation No. 33 of 2026
Introduction
On 16 July 2026, the Government enacted Government Regulation No. 33 of 2026 on the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”). Although it has been promulgated, GR 33/2026 will only come into force on 16 January 2027, namely 6 (six) months from the date of promulgation. GR 33/2026 strengthens the implementing provisions of Law No. 27 of 2022 on Personal Data Protection (“PDP Law”), including provisions concerning objections to automated processing, procedures for the payment of compensation, Personal Data Protection impact assessments, the appointment of Officers or Personnel Performing Personal Data Protection Functions (“PPDP”), cross-border transfers of Personal Data, and the imposition of administrative sanctions by the Personal Data Protection Authority (“Authority”).
GR 33/2026 was issued to provide technical regulations for a number of provisions of the PDP Law that were previously general in nature and required further regulation through a Government Regulation. Such regulations cover mechanisms for exercising the rights of Personal Data Subjects, including the right to object and the right to receive compensation, as well as the obligations of Personal Data Controllers and Processors, including the implementation of impact assessments, appointment of PPDPs, and notification of Personal Data Protection Failures. Accordingly, GR 33/2026 provides certainty regarding the procedures for exercising rights and fulfilling obligations under the PDP Law, while also establishing a more operational Personal Data protection framework for business entities, public bodies, and international organizations that process Personal Data in Indonesia or whose activities give rise to legal consequences in Indonesia.
Key Provisions
- Joint Controllers and Appointment of Personal Data Processors
Referring to Articles 10 through 12, the parties involved in the processing of Personal Data consist of:
-
-
Personal Data Subjects,
-
Personal Data Controllers, and/or
-
Personal Data Processors.
-
Personal Data processing may be carried out by Joint Personal Data Controllers subject to the requirements of an agreement governing the roles, responsibilities, and relationship among the Personal Data Controllers, interrelated purposes and jointly determined means of processing, as well as a jointly appointed contact person. Such agreement must at least contain the legal basis and purposes of processing, the types of Personal Data processed, the allocation of roles and responsibilities for fulfilling legal obligations, and a joint contact person. Referring to Article 12, Joint Personal Data Controllers shall be jointly and severally liable for the processing of Personal Data.
Referring to Articles 13 through 16, a Personal Data Controller may appoint a Personal Data Processor based on an agreement that at least regulates the scope and means of processing, the types and purposes of processing, the categories of Personal Data Subjects, the processing period, the rights and obligations of the parties, and the supervision and audit mechanisms. The processing of Personal Data by a Personal Data Processor shall remain the responsibility of the Personal Data Controller. A Personal Data Processor may also engage another Personal Data Processor upon first obtaining the written approval of the Personal Data Controller and must ensure that the processing is carried out in accordance with the applicable provisions. The provisions concerning the appointment of Personal Data Processors shall also apply to Joint Personal Data Controllers.
- Procedures for Exercising the Rights of Personal Data Subjects
Referring to Articles 20 through 27, the exercise of the rights of Personal Data Subjects shall be submitted through a recorded request to the Personal Data Controller, either electronically or non-electronically. The Personal Data Controller must provide an easily accessible request channel and, where the processing of Personal Data is carried out electronically, the request shall be submitted electronically. Such request may be submitted by the Personal Data Subject, the parent or guardian of a Child, the guardian of a Person with Disabilities, or an authorized party, and must at least contain the applicant’s identity, an explanation of the rights and interests of the Personal Data Subject, and a description of the request concerning the Personal Data being processed. Referring to Article 25, the Personal Data Controller must verify the request through a proportionate mechanism and determine whether to fulfill and/or reject the request in accordance with the provisions of laws and regulations. If the Personal Data Controller fails to perform its obligations, the Personal Data Subject may report such failure to the Authority as provided in Article 27.
Furthermore, referring to Articles 28 and 29, the Personal Data Controller must prepare and establish internal provisions governing the processing of Personal Data by referring to guidelines established by the Authority. The Personal Data Controller may consult with the Authority in preparing such provisions. In addition, the Personal Data Controller and/or Personal Data Processor must implement orders issued by the Authority in connection with the administration of Personal Data Protection in accordance with the provisions of laws and regulations.
- Legal Basis for Personal Data Processing
Referring to Article 30, every Personal Data Controller must have a legal basis for Personal Data processing prior to carrying out the processing. The legal bases for Personal Data processing include:
-
-
explicit valid consent from the Personal Data Subject for 1 (one) or several specific purposes that have been communicated by the Personal Data Controller to the Personal Data Subject;
-
fulfillment of contractual obligations where the Personal Data Subject is a party or to fulfill the Personal Data Subject’s request when entering into an agreement;
-
fulfillment of the legal obligations of the Personal Data Controller in accordance with the provisions of laws and regulations;
-
fulfillment of the protection of the vital interests of the Personal Data Subject;
-
performance of a task in the public interest, or exercise of the authority of the Personal Data Controller pursuant to laws and regulations; and/or
-
fulfillment of other legitimate interests, taking into account the purpose, necessity, and balancing of the interests of the Personal Data Controller and the rights of the Personal Data Subject.
-
In addition, referring to Article 31, the Personal Data Controller must ensure that the processing of Personal Data is not discriminatory against the Personal Data Subject.
- Obligation to Notify Personal Data Protection Failures
Referring to Article 114, in the event of a Personal Data Protection Failure, the Personal Data Controller must provide written notification no later than 3 x 24 (three times twenty-four) hours to the Personal Data Subject and the Authority from the time the Personal Data Protection Failure is known with certainty, reasonably, and properly. Such notification must at least contain the Personal Data disclosed, the time and manner in which the Personal Data was disclosed, the handling and recovery measures taken, and information regarding the PPDP or contact person appointed by the Personal Data Controller. Furthermore, referring to Article 115, the Personal Data Controller must notify the public of the Personal Data Protection Failure through electronic and/or non-electronic media if the failure disrupts public services and/or has a serious impact on the public interest.
Under Articles 116 through 119, the Personal Data Controller must prepare documentation of every Personal Data Protection Failure, which must at least contain:
-
-
the Personal Data protected;
-
a description of the Personal Data Protection Failure;
-
the impact or consequences of the Personal Data Protection Failure on the Personal Data Subject and the Personal Data Controller;
-
the handling and recovery measures that have been, are being, and will be undertaken; and
-
the period for notification to the Personal Data Subject and the Authority.
-
Such documentation must be submitted to the Authority. The Personal Data Controller must also establish and implement internal policies, procedures, and/or guidelines concerning the prevention and handling of Personal Data Protection Failures, including the allocation of roles and responsibilities, incident analysis and handling mechanisms, documentation and reporting, and periodic review and updating. Where the failure occurs in processing carried out by a Personal Data Processor, the Processor must report it to the Personal Data Controller at the first opportunity. Further provisions concerning notification of Personal Data Protection Failures shall be regulated in an Authority Regulation.
- Claims and Compensation
Referring to Articles 105 through 110, Personal Data Subjects have the right to bring claims and receive compensation for violations in the processing of their Personal Data in accordance with the provisions of laws and regulations. A request for compensation shall be submitted to the Personal Data Controller and must at least contain the identity of the Personal Data Subject, data, information, and/or documents as evidence, as well as the legal relationship between the Personal Data Subject and the Personal Data Controller in relation to the processing of Personal Data. The Personal Data Controller must have mechanisms and policies for handling compensation requests and must assess and provide a response to such requests. If the request is rejected or no agreement is reached regarding compensation, the Personal Data Subject may file a claim in accordance with the provisions of laws and regulations. Provisions concerning requests for compensation against state public bodies shall be implemented in accordance with the provisions governing state administrative matters, while further provisions concerning the handling and settlement of compensation shall be regulated in an Authority Regulation.
- Personal Data Protection Impact Assessment
Referring to Articles 120 through 122, the Personal Data Controller must conduct a Personal Data Protection impact assessment prior to carrying out processing that has the potential to result in a high risk to Personal Data Subjects, including the processing of specific Personal Data, processing on a large scale, use of new technologies, automated decision-making that has legal or significant effects, as well as evaluation, scoring, systematic monitoring, data matching or combination activities, and processing that restricts the exercise of the rights of Personal Data Subjects. Such assessment must at least cover a description and purposes of the processing, an assessment of necessity and proportionality, risks to the rights of Personal Data Subjects, and protective measures implemented, and must be documented and reviewed if there are changes in risk. Where a PPDP is present, the PPDP’s advice must be taken into consideration and documented, while consultation with the Authority may be conducted under certain circumstances as provided in Article 122.
- Obligation to Appoint a PPDP (Data Protection Officer)
Referring to Articles 142 through 147, Personal Data Controllers and Processors must appoint a PPDP in the event that:
-
-
Personal Data processing is carried out for the purpose of public services;
-
the core activities require regular and systematic monitoring of Personal Data on a large scale; and/or
-
the core activities consist of large-scale processing of specific Personal Data and/or Personal Data relating to criminal offenses.
-
The appointment of a PPDP must take into consideration the structure, size, and needs of the organization, and must be based on professionalism, knowledge of Personal Data Protection laws and practices, and the ability to perform the duties. Referring to Article 145, the PPDP is responsible for providing advice and ensuring compliance, providing advice concerning impact assessments, and serving as a contact person for issues concerning Personal Data processing. Personal Data Controllers and Processors must also ensure that the PPDP is involved in processing activities, has access to the highest level of management, works objectively and independently, and receives adequate resources and access to perform its duties.
- Transfer of Personal Data Outside the Jurisdiction of Indonesia
Referring to Articles 160 through 166, the transfer of Personal Data outside the jurisdiction of Indonesia may be carried out provided that it is conducted in accordance with Personal Data Protection provisions. Prior to the transfer, the Controller must map the transfer lifecycle, ensure that the data transferred is necessary, identify and assess the legal instruments used, and assess the risks and impacts on the rights of Personal Data Subjects. The Controller must also provide information to the Personal Data Subject regarding the purpose of the transfer, the protection instruments and mechanisms, as well as the risks and mitigation measures.
Referring to Article 165, the Controller must ensure that the recipient country has a level of Personal Data Protection that is equivalent to or higher than that in Indonesia. If this requirement is not met, the Controller must ensure the existence of adequate and binding protection. If both requirements are not met, the Controller must obtain the consent of the Personal Data Subject. The same provisions shall apply to the exchange of Personal Data by law enforcement authorities outside the jurisdiction of Indonesia.
- Administrative Sanctions
Article 184 lists a number of provisions for which violations may be subject to administrative sanctions in the form of:
-
-
a written warning;
-
temporary suspension of Personal Data processing activities;
-
deletion or destruction of Personal Data; and/or
-
an administrative fine,
-
which may be imposed cumulatively for a single violation.
Administrative fines are regulated in greater detail in Article 185, with a maximum limit of 2% (two percent) of the annual revenue or receipts of the Personal Data Controller/Processor, calculated based on a number of variables such as the impact of the violation, the duration of the violation, the number of affected Personal Data Subjects, the scale of the business, and the level of cooperation of the relevant party during the examination process, with the possibility of reducing the fine to Rp0.00 (zero rupiah) based on certain considerations. The authority to impose administrative sanctions rests with the Authority, which may delegate such authority to an official of the Authority.
Transitional Provisions
Referring to Article 223, until the Authority Regulation concerning Personal Data processing is established, the Personal Data Controller and/or Personal Data Processor may continue to process Personal Data provided that such processing does not conflict with the provisions of GR 33/2026. This provision provides a basis for Personal Data Controllers and Processors to continue conducting processing activities while further technical regulations have not yet been established, while continuing to comply with the provisions of GR 33/2026.
Closing
With GR 33/2026 coming into force on 16 January 2027, Personal Data Controllers and Processors need to adjust their policies, procedures, and Personal Data processing practices to the provisions stipulated in GR 33/2026. Such adjustments include compliance with the rights of Personal Data Subjects, legal bases for processing, handling of Personal Data Protection Failures, impact assessments, appointment of PPDPs, transfers of Personal Data outside the jurisdiction of Indonesia, and compliance with provisions relating to administrative sanctions. Until the Authority Regulations serving as implementing provisions have been established, Personal Data Controllers and Processors may continue to process Personal Data provided that such processing does not conflict with GR 33/2026. Accordingly, GR 33/2026 constitutes an important basis for the implementation of more structured and operational Personal Data Protection obligations in Indonesia.
Related Regulations
Click a regulation to view details.
Learn More Than Just Articles with
Learning
Get more practical material through ready-to-use templates, webinar recordings, compliance checklists, and online classes from Veritask Learning.
Templates
A collection of ready-to-use standard legal documents for a range of business needs.
Webinar Recording
Access recordings of in-depth discussions with experienced legal practitioners.
Online Class
Structured classes to master specific legal topics comprehensively.
Compliance
Practical checklists to keep your business compliant with regulations.
Log in to comment
Log inWhat is
Veritask is an integrated AI-powered legal platform that helps with regulatory research, document preparation, and compliance management in one dashboard.
Free Subscription
Subscribe to receive a free weekly email with the latest legal analysis.