Finally Published! Implementing Regulations for the Personal Data Protection Act Officially Take Effect in January 2027 - iDE Tax & Legal
Loading...
Monday - Friday  |  08:00 AM - 05:00 PM
Finally Published! Implementing Regulations for the Personal Data Protection Act Officially Take Effect in January 2027
Legal Update

Finally Published! Implementing Regulations for the Personal Data Protection Act Officially Take Effect in January 2027

Back to all articles

After nearly four years of anticipation since the enactment of Law No. 27 of 2022 on Personal Data Protection (PDP Law), the goduction of this regulation marks an important milestone for all orvernment has finally issued its implementing regulations. On July 16, 2026, the President issued Government Regulation No. 33 of 2026 on the Implementing Regulations for Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”). The introganizations—including businesses, public agencies, and international organizations—that process the personal data of Indonesian citizens.

When Does It Take Effect?

Although it was promulgated on July 16, 2026, Government Regulation No. 33 of 2026 does not take effect immediately. Article 225 establishes a 6 (six)-month grace period from the date of promulgation, meaning the regulation will not take effect until January 16, 2027. This grace period allows organizations time to adjust their policies, procedures, and personal data management systems before compliance obligations begin to be enforced.

Scale and Scope of Regulation

While the PDP Law contains only 76 general articles, Government Regulation No. 33 of 2026 is far more detailed, comprising 12 chapters and 225 articles. This indicates that this Government Regulation is not merely a repetition of the PDP Law, but rather provides mechanisms and requirements that are far more operational and can be directly implemented by organizations. Its scope covers data classification, the legal basis for processing, the rights and obligations of the parties, cross-border data transfers, compliance oversight, international cooperation, and mechanisms for sanctions and dispute resolution.

Key Points to Keep in Mind

1. Legal Basis for Data Processing Any processing of personal data must have a valid legal basis, which may include explicit consent from the data subject, the performance of a contract, compliance with a legal obligation, the protection of vital interests, the performance of a task in the public interest, or other legitimate interests that still maintain a balance between the data subject’s rights and the data controller’s interests.

2. Requirements for Valid Consent Consent given by the data subject must be freely given, informed, specific, and unambiguous. This provision requires organizations to review their consent forms, privacy policies, and consent mechanisms currently in use.

3. Data Protection Impact Assessment (DPIA) Pursuant to Articles 120 through 122, the Data Controller is required to conduct a data protection impact assessment before carrying out processing that could pose a high risk to data subjects. Categories of high-risk processing include, among others, the processing of specific types of data, large-scale processing, the use of new technologies, automated decision-making with legal or significant consequences, as well as systematic evaluation, scoring, and monitoring activities.

4. Appointment of a Personal Data Protection Officer (PPDP) This Regulation reinforces the obligation to appoint a PPDP—a type of Data Protection Officer—whose role is to oversee an organization’s compliance with personal data protection provisions.

5. Cross-Border Transfer of Personal Data The provisions regarding the transfer of data abroad are set forth in greater detail, including the requirements that data controllers must meet before personal data can be transferred or accessed from outside Indonesia.

6. Administrative Sanctions and Damages Government Regulation No. 33 of 2026 sets forth the procedures for the imposition of administrative sanctions by the Personal Data Protection Agency, as well as the procedures for awarding damages to aggrieved data subjects. Specifically for claims for damages against state public agencies, the resolution of such claims follows the provisions governing public administration.

The Principle of Non-Discrimination

This Regulation also explicitly requires data controllers to ensure that all data processing is carried out in a non-discriminatory manner—a provision that is particularly relevant for organizations that use personal data for profiling, credit scoring, or other automated decision-making systems.

What Should Organizations Do Now?

For organizations that have already established compliance programs based on the PDP Act, the issuance of Government Regulation No. 33 of 2026 marks a significant milestone for:

Conduct a gap assessment of existing policies, procedures, and documentation related to personal data management;

Reviewing the consent mechanism and privacy policy;

Evaluate the need for a DPIA for high-risk data processing activities;

Mempertimbangkan penunjukan PPDP internal maupun eksternal; serta

Memastikan proses transfer data lintas negara telah memenuhi persyaratan baru.

Mengingat masa tunggu 6 bulan yang diberikan hanya cukup untuk persiapan mendasar, organisasi disarankan untuk tidak menunggu hingga mendekati 16 Januari 2027 sebelum mulai melakukan penyesuaian.

107 views
Attachments 1
PP-33-2026.pdf
9,339.1 KB