Long-Awaited Implementing Regulation of Personal Data Protection Law

On July 16, 2026, the Government of Indonesia enacted Government Regulation No. 33 of 2026 on Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”). GR 33/2026 comprises 225 articles across 12 chapters and is the first implementing regulation issued under Law No. 27 of 2022 on Personal Data Protection, as amended by Law No. 1 of 2026 (the “PDP Law”). Please note that while GR 33/2026 is dated July 16, 2026, to our knowledge GR 33/2026 was only available to the public in late August this year.

This Newsflash is a continuation of our previous client newsflashes on the PDP Law, namely “The Highly-Awaited Indonesian Personal Data Protection Law Is Passed” (September 22, 2022) and “Expiry of Transitional Period of Personal Data Protection Law” (October 18, 2024). In the latter, we noted that the two-year transitional period under the PDP Law had lapsed without any implementing regulation in place, leaving key aspects of compliance unclear. GR 33/2026 now addresses the first of those missing links.

We summarize the pertinent provisions of GR 33/2026 below.

Joint Controllers
GR 33/2026 clarifies how Joint Controllers (Pengendali Data Pribadi Bersama) process personal data. Article 11 of GR 33/2026 stipulates that the processing of personal data may be carried out by Joint Controllers, being two or more Controllers that jointly determine the purpose of, and exercise control over, the processing of personal data, as defined under Article 1(20) of GR 33/2026. Article 11(3) of GR 33/2026 prescribes six minimum contents for the agreement of Joint Controllers, namely (i) the processing basis of each Controller; (ii) the interrelationship between the processing purposes controlled by each Controller; (iii) a description of the agreed manner of processing; (iv) the types of personal data to be processed; (v) the allocation of roles and responsibilities for the fulfilment of each Controller’s legal obligations under prevailing laws and regulations; and (vi) the jointly appointed contact point. Under Article 11(4) of GR 33/2026, Joint Controllers are collectively responsible for ensuring that the processing is carried out in accordance with both that agreement and prevailing laws and regulations.

Article 12 of GR 33/2026 expressly states that Joint Controllers bear joint and several liability (tanggung renteng) for the processing of personal data in accordance with prevailing laws and regulations. The PDP Law requires an allocation of roles and responsibilities between Joint Controllers but does not state the consequence of that allocation as against Data Subjects and third parties.

Elaboration on Lawful Bases for Processing
Under Article 20 of the PDP Law, a Controller is required to have a basis for processing Personal Data, of which there are six. Article 30 of GR 33/2026 restates those bases and requires the basis to be in place before the processing is carried out, and GR 33/2026 elaborate the requirements for each basis as follows:

    • Consent – GR 33/2026 elaborates on consent as a basis for processing personal data. Article 32(1) of GR 33/2026 stipulates that a Controller may use explicit valid consent as its basis for processing personal data, and Article 32(2) of GR 33/2026 stipulates that such consent must be obtained from the Data Subject freely, knowingly, specifically, and unambiguously.

      Where processing is based on explicit valid consent, Article 33 of GR 33/2026 requires the Controller to convey the Information in accordance with GR 33/2026, which must be conveyed before the consent is obtained and must be given to the Data Subject concisely, accurately, and in accordance with the processing activities actually carried out by the Controller. To that end, the Controller must provide a mechanism for obtaining the Data Subject’s consent, whether electronic or non-electronic, which must be connected to that Information, as stipulated under Article 34 of GR 33/2026. Article 36 of GR 33/2026 further requires the Controller to demonstrate proof of the consent given by the Data Subject, which is to be carried out within the framework of accountability for the processing of personal data. Consent, once given, may be withdrawn at any time, and Article 37 of GR 33/2026 requires the Controller to ensure that right may be exercised through a mechanism the Controller makes available.

    • Contracts – Article 40(1) of GR 33/2026 permits a Controller to rely on the fulfilment of contractual obligations as its basis for processing personal data in two situations, namely (i) where the Data Subject is a party to the contract concerned; or (ii) where the processing is carried out to fulfil the Data Subject’s request at the time the Data Subject is about to enter into a contract. A contract requiring the processing of personal data may contain one or more processing purposes, although the Controller may not process personal data beyond what has been determined in the contract relied upon as its basis.

      Article 41(1) of GR 33/2026 stipulates the five conditions that must be satisfied before a Controller may process Personal Data with the basis of contract, namely (i) there is a valid contract between the Controller and the Data Subject in accordance with the prevailing laws and regulations; (ii) there is a need for the Controller to process personal data in order to perform the contract; (iii) the personal data protection measures to be afforded to the Data Subject have been fulfilled; (iv) the Controller has considered the risk impact of the processing on the Data Subject; and (v) the Controller has considered its ability to fulfil the rights of the Data Subject and to carry out its own obligations in the processing of personal data in accordance with GR 33/2026. Where the processing concerns the personal data of a Child or of a Person with Disabilities, Article 41(2) of GR 33/2026 requires the contract to be accompanied by the consent of the parent or guardian of the Child, or of the guardian of the Person with Disabilities.

    • Legal Obligation – According to Articles 45(1) and (2) of GR 33/2026, a Controller may rely on the fulfillment of its own legal obligations under the prevailing laws and regulations, which legal obligations also include court orders and judgments, and decisions of state administrative officials issued under prevailing laws and regulations.
    • Vital Interests – The Vital Interests basis is elaborated that a Controller may process the Personal Data in the event there is a threat to the life, physical safety, or property or assets of the Data Subject or another party, and it is difficult to obtain the Data Subject’s consent in relation to that threat, in accordance with Article 46 of GR 33/2026.

      It is further stipulated that the Controller must inform the Data Subject of the processing, covering the action to be taken once the purpose has been fulfilled, the type of threat that would arise if the processing were not carried out, and the other information required under GR 33/2026.

    • Public interest, public service, or exercise of authority For this specific basis, a Controller must maintain an adequate policy document covering, at a minimum, the scope of the task and the purpose of the processing as stipulated under Articles 50(1) and (2) of GR 33/2026.

      Articles 51(1) – (4) of GR 33/2026 stipulates that information must be given to the Data Subject when the processing begins; where doing so would risk prejudicing the public interest or public service concerned, it may be deferred until the purpose has been achieved, and where direct delivery is not possible it may be given by public announcement through electronic and non-electronic media.

    • Other Legitimate Interests – To carry out data processing based on this basis, Article 53 of GR 33/2026 requires a Controller to (i) carry out an analysis of the necessity, purpose, and balance between the Data Subject’s rights and the controller’s interests, with the result showing that it has a legitimate interest in carrying out the processing, and (ii) assess that the processing has no legal impact on, and causes no loss to, the Data Subject, with the result showing that the Controller has and has implemented mitigating measures should any impact arise.

Controller Obligations
GR 33/2026 also provides new and expanded obligations for a Controller in the processing of personal data, as follows:

    • Records of Processing Activities – Article 31 of the PDP Law requires a Controller to record all of its personal data processing activities without specifying what those records must contain. Now, under Article 74 of GR 33/2026, it is set out that content, requiring the record to contain at least (i) the name and contact details of the Controller, any Joint Controller, and/or any Processor; (ii) the contact details of the Officer or Personnel Performing the Personal Data Protection Function (Pejabat atau Petugas yang Melaksanakan Fungsi Pelindungan Data Pribadi or PPDP); (iii) the source of collection and the purpose of transmission of the personal data; (iv) the basis for processing; (v) the purpose of processing; (vi) the types of personal data; (vii) the categories of Data Subject; (viii) parties other than the Controller that are able to access the personal data; (ix) the fulfilment of the rights of the Data Subject; (x) the mapping of the personal data flow; (xi) the Retention Period; (xii) the technical and organizational measures taken to secure the personal data; and (xiii) the details of any transfer of personal data.

      Where the Controller appoints a Processor, it must ensure that the Processor also records its processing activities, containing at least the Processor’s name and contact details, the scope of its processing activities, the details of any transfer, and a general description of the organizational and technical measures taken to secure the personal data, although this does not remove the Controller’s own recording obligation. Article 74 of GR 33/2026 further requires the results of the recording to be stored and managed in written form, whether electronically or non-electronically, and to be updated where any of the recorded Information changes. The Controller and/or Processor must furnish the recording documents when requested by the Institution, and must make them available where required for the purposes of audit and supervision.

    • Retention Policy – While Article 16(2)(g) of the PDP Law provides that personal data is to be erased or destroyed once the retention period ends, and Article 21(1)(d) of the PDP Law requires the retention period to be conveyed to the Data Subjects, neither Article prescribes how that period is to be set. This is being elaborated under GR 33/2026. Article 75 of GR 33/2026 requires a Controller to establish the Retention Period through a Retention Period policy document, containing at least (i) the definition and duration of the Retention Period; (ii) provisions on archival retention and other related provisions; (iii) the Data Subjects governed; (iv) the types and components of personal data governed; (v) provisions on de-identification, where the personal data is used for statistical and scientific research purposes; (vi) the methods of destruction, both electronic and non-electronic; (vii) provisions applicable to the Processor; (viii) the person responsible; (ix) documentation and notification; and (x) the legal basis for the arrangement, where the Retention Period arises from a legal obligation under the prevailing laws and regulations.
    • Internal Processing Rules – Article 28(1) of GR 33/2026 requires a Controller to prepare and establish provisions on the processing of personal data applicable within its own organization. Those provisions must be prepared and established in accordance with guidelines for the preparation of processing provisions to be issued by the Institution.
    • Delivery of Information to Data Subjects – Article 21(1) of the PDP Law confines the obligation to convey the seven prescribed items of Information to processing carried out on the basis of a consent under Article 20(2)(a) of the PDP Law. Article 62 of GR 33/2026 retains those seven items, and extends the obligation to convey them to all of the processing bases referred to in Article 30(3) of GR 33/2026. The Information must be delivered through a personal data protection notification facility that is easily accessible to the Data Subject and remains available for so long as the Controller carries out the processing, and the obligation must be discharged before the processing begins. Where there is a change to that Information, the Controller must notify the Data Subject before the change occurs.
    • Accountability and Audit – Article 47 of the PDP Law requires a Controller to be responsible for its processing of personal data and to demonstrate accountability in fulfilling its obligations, without identifying the measures by which that is to be done. Article 138 of GR 33/2026 provides that, in discharging that accountability, a Controller must at least (i) establish and implement appropriate technical and organizational measures to meet accountability requirements; (ii) document all of its personal data processing activities; (iii) respond to requests for Information from the Institution; (iv) demonstrate its compliance and produce documentary evidence of all of its processing activities; and (v) conduct personal data protection audits, both internally and externally. A corresponding obligation applies to the Processor under Article 141 of GR 33/2026, which requires it to document all of its processing activities, respond to requests for Information from the Institution, demonstrate compliance and produce documentary evidence, and conduct an audit.
    • Security of Personal Data – Article 35 of the PDP Law requires a Controller to protect and ensure the security of the personal data it processes by formulating and applying technical operational measures and by determining the level of security having regard to the nature and risk of the personal data concerned. Article 123 of GR 33/2026 specifies what those technical operational measures must involve, namely (i) pseudonymization, encryption of personal data, and/or other technical measures capable of preventing or protecting against the risk of a Personal Data Protection Failure; (ii) ensuring that the systems and services used maintain the security and resilience of personal data on a consistent basis in the processing; (iii) ensuring that the systems and services used are able to restore access to and the availability of personal data in a timely manner in the event of a physical or technical incident; and/or (iv) maintaining a process for periodic testings, evaluations, and assessments in order to establish the level of effectiveness of those technical and operational measures. The determination of the security level is to be made where there is a potential impact on the Data Subject, covering at least the destruction of personal data without right, the loss, alteration, or disclosure of personal data without right, access to personal data stored, transmitted, or processed in another form, and any violation in the processing of personal data. The Institution is to formulate the technical operational measures and the determination of security levels in accordance with the prevailing laws and regulations.
    • Non-Discrimination – Article 31 of GR 33/2026 requires a Controller to ensure that its processing of personal data is not discriminatory towards the Data Subjects.

Exercise of Data Subject Rights
Article 14 of the PDP Law provides that the exercise of the rights of the Data Subject under Articles 6 to 11 thereof is submitted through a recorded application delivered electronically or non-electronically to the Controller, without prescribing the manner in which such applications are to be made or handled. Under GR 33/2026, the foregoing requirements are restated and further governed.

Article 21(1) of GR 33/2026 stipulates that a Controller shall provide a channel for applications for the exercise of the rights of the Data Subjects. In the event the Controller processes personal data electronically, the application must be submitted electronically.

It is also further stipulated in Article 22 of GR 33/2026 that the time of receipt of an application submitted electronically is counted from the time the application enters the electronic system under the Controller’s control, and for an application submitted non-electronically, from the date on the receipt of the application.

The application for the exercise of rights of a Data Subject may be applied by the Data Subject, the parent and/or guardian of a Child, the guardian of a Person with Disabilities, or an attorney of the Data Subject, as stipulated under Article 23 of GR 33/2026.

Notification of Personal Data Protection Failures
Similar to what is regulated under the PDP Law, Article 114(1) of GR 33/2026 stipulates that in the event of a failure of personal data protection, the Controller shall notify the institution and the Data Subject within 3 x 24 hours, counted from time the personal data protection failure is known with certainty and on a proper and reasonable basis. The notification shall at least contain (i) information on the disclosed Personal Data, (ii) when and how the Personal Data is disclosed, and (iii) the remedial and recovery measures.

Article 115 of GR 33/2026 provides that a notification to the public is required where a Personal Data Protection Failure disrupts public services and/or has a serious impact on public interest and is to be made generally through electronic and/or non-electronic media.

Personal Data in Corporate Actions
GR 33/2026 elaborates how Personal Data shall be treated in the event there is a corporate action by a company (i.e., merger, spin-off, acquisition, consolidation, or dissolution). It is important to note that Articles 131(1) and (2) of GR 33/2026 permit the transfer of Personal Data from the old Controller to the new Controller where a merger, spin-off, acquisition, consolidation, or dissolution of a legal entity takes place. However, it is further stipulated in Article 131(3) of GR 33/2026 that the Controller shall assess the rights of the Data Subject and the obligations of the Controller in the field of personal data protection that must still be fulfilled during and/or after the corporate action, to update its personal data protection impact assessment in accordance with the results of that assessment, and, on the basis of both, to prepare the technical operational steps for the transfer of personal data from the old Controller to the new Controller. The relationship between the old Controller and the new Controller under a corporate action is considered Joint Controllers until the corporate action is complete in accordance with the prevailing laws and regulations, as stipulated under Article 131(6) of GR 33/2026.

It is important to note that both the old Controller and the new Controller must notify the Data Subject of the transfer of Personal Data, before and after the corporate action takes effect, as stipulated under Articles 133(1), (2), and (5) of GR 33/2026. Articles 133(3) and (4) of GR 33/2026 stipulate the required contents as follows:

Article 134 of GR 33/2026 stipulates that the old Controller and new Controller shall enter into an agreement on personal data protection, for the purposes of the personal data transfers, containing at least the processing basis of each Controller, the fulfilment of the personal data protection principles, the fulfilment of the rights of the Data Subjects, and the division of obligations and responsibilities between the old Controller, the new Controller, and the parties involved in the processing.

Transfers of Personal Data Outside Indonesia
Article 160(1) of GR 33/2026 permits a Controller to transfer Personal Data to an offshore Controller and/or a Processor of Personal Data. It is further stipulated under Article 165 of GR 33/2026 that there are three tiers as follows:

    • Tier 1: Equivalent or Higher Level of Personal Data Protection – Under Article 165(1) of GR 33/2026, a Controller carrying out a transfer must first ensure that the country in which the recipient Controller and/or Processor is domiciled has a level of personal data protection equivalent to or higher than that provided under the PDP Law. The assessment of that level is carried out by the Institution as stipulated under Article 167 of GR 33/2026.

      Article 168(1) of GR 33/2026 provides that the assessment is made on the basis of whether that country (i) has laws and regulations in the field of personal data protection; (ii) has a personal data protection supervisory institution or authority; and (iii) has international commitments or is subject to other obligations arising from international agreements or legally binding instruments, and from its participation in multilateral or regional systems relating to personal data protection. The Institution must establish a list of countries and/or International Organizations having an equivalent or higher level of personal data protection, and where a transfer is made to a country and/or International Organization on that list, the Controller may carry out the transfer while continuing to ensure that it is implemented in accordance with the prevailing laws and regulations.

    • Tier 2: Adequate and Binding Personal Data Protection – In the event the first requirement is not met, Article 165(2) of GR 33/2026 stipulates that the Controller shall ensure that there is adequate and binding personal data protection. The foregoing may take the form of (i) a legally binding and enforceable instrument for agencies or authorities based on their authority under the prevailing laws and regulations; (ii) standard contractual clauses for personal data protection; (iii) binding corporate rules for a corporate group; and/or (iv) another adequate and binding personal data protection instrument recognized by the Institution as stipulated under Article 169(1) of GR 33/2026. The Controller shall prove its accountability for the fulfilment of that requirement to the Institution in the form of a written and/or recorded document, and the existence of that document does not remove or reduce the Institution’s authority to assess the fulfilment of the transfer requirements.
    • Tier 3: Consent of the Data Subject – If both of the above requirements not met, Article 165(3) of GR 33/2026 requires the Controller to obtain the consent of the Data Subject. Article 173 of GR 33/2026 provides that a transfer on that basis may be carried out only where (i) the transfer is not repetitive; (ii) the transfer involves a limited number of Data Subjects; (iii) the transfer is necessary for the purpose of fulfilling provisions that do not override the interests or the rights and freedoms of the Data Subject; (iv) the Controller has assessed the risks and applied appropriate personal data protection measures; and (v) the Controller has informed the Institution and the Data Subject of the transfer activity and of the compelling legitimate interest fulfilled by it.

GR 33/2026 takes effect 6 (six) months after its promulgation, i.e., on or about January 16, 2027. Controllers and Processors therefore have a defined runway to close remaining compliance gaps before the detailed obligations become enforceable.

Furthermore, we expect the establishment of the “Institution” as referred to above will take place during before GR 33/2026 comes into effect, as the PDP Law provides that the Institution is established by the President, with further provisions concerning the Institution to be regulated by a Presidential Regulation.

AKSET

Please contact Johannes C. Sahetapy-Engel (jsahetapyengel@aksetlaw.com), or Ammarsyarif G. Goenawan (agoenawan@aksetlaw.com) for further information.

 

Disclaimer:

The foregoing material is the property of AKSET and may not be used by any other party without our prior written consent.  The information herein is of general nature and should not be treated as legal advice, nor shall it be relied upon by any party for any circumstance.  Specific legal advice should be sought by interested parties to address their particular circumstances.

Any links contained in this document are for informational purposes and are available and relevant at time this publication is made.  We provide no liability whatsoever in respect of any information or content in such links.