Skip to main content
Indotek Digital Nusantara

Regulation & Policy

PP 33/2026: What Indonesia's Data Protection Rules Require by 2027

Indonesia's Personal Data Protection Law finally has its implementing regulation, and it takes effect on 16 January 2027. PP 33/2026 turns the law's principles into deadlines, documents and named roles, while the authority meant to enforce it has still not been formed.

The Constitutional Court building in Jakarta, with a columned portico and a green dome
The Constitutional Court in Jakarta, which held a hearing in July 2026 on the delayed formation of Indonesia's personal data protection authority. Photo: Christophe95, CC BY-SA 4.0 (opens in a new tab)

Indonesia's Personal Data Protection Law now has its implementing regulation. Government Regulation No. 33 of 2026, known as PP 33/2026, takes effect on 16 January 2027. For organisations asking what PP 33/2026 requires, the short answer is that the principles of the 2022 law become operating duties, with time limits, documents and named roles attached. A little over three months remain to prepare.

What PP 33/2026 is and when it applies

The regulation implements Law No. 27 of 2022 on Personal Data Protection, the PDP Law. It was enacted and promulgated on 16 July 2026 and takes effect six months later. Katadata reported on 3 September that it was signed by President Prabowo Subianto. The law firm ABNR counts 225 articles in 12 chapters.

It arrived quietly. A note published by the law firm Hogan Lovells on 31 August says the text only began circulating in late August, about six weeks after enactment and before any formal government announcement. The same note recalls that the PDP Law took effect in October 2022 and that its two-year transition period ended in October 2024 with no implementing regulation in place.

Deadlines measured in hours

Two time limits stand out. The first concerns requests from individuals. ABNR's summary says controllers have 3 x 24 hours to respond when a person exercises the right to access or correct their data, to withdraw consent, or to restrict or suspend processing. The period runs from receipt of the request and, where applicable, its verification.

The second concerns incidents. A failure of personal data protection must be notified within 3 x 24 hours. Norton Rose Fulbright's summary says notice goes to the authority and to the affected individuals, and that the clock starts when the failure is definitively and reasonably established. ABNR notes that notification is required whatever the scale or severity of the incident. BDO adds that the notice must describe the data affected, the circumstances and the mitigation steps, and that controllers must keep breach records.

Records, impact assessments and officers

The regulation asks for evidence, not only good intentions. Hogan Lovells reports that the register of processing activities must contain at least thirteen items, including a data-flow map, retention periods and the categories of data subjects. A separate written retention policy needs at least ten more. Katadata reports that controllers must keep proof of consent and offer both electronic and non-electronic ways to give it.

A data protection impact assessment must be completed before high-risk processing begins. Hogan Lovells says the regulation lists seven categories of processing that trigger one. Two matter most to technology teams: automated decision-making, and new technologies, where the text names artificial intelligence, machine learning, smart technology and the internet of things. Large-scale processing has no numerical threshold; it is judged case by case.

A data protection officer must be appointed if any one of three conditions applies, according to ABNR: processing for public-service purposes, core activities that require regular and systematic monitoring on a large scale, or core activities that involve large-scale processing of specific personal data or data about criminal offences.

Transfers abroad and children's data

Cross-border transfers rest on three bases in decreasing order of preference, as Hogan Lovells describes them: the recipient country appears on an adequacy list; failing that, an adequate and binding safeguard is in place, such as standard contractual clauses set by the authority or binding corporate rules it has approved; failing both, the data subject gives explicit consent. The firm points out that the adequacy list, the standard clauses and the approved corporate rules do not yet exist. Norton Rose Fulbright cautions that global or GDPR-based arrangements should not be assumed to meet Indonesian requirements.

Children receive specific protection. ABNR notes that a child is defined as any person under 18 and unmarried. Controllers must actively identify children, verify the consent of a parent or guardian using available technology, and provide a transition mechanism for when the child reaches adulthood.

Sanctions, and an authority that does not yet exist

Administrative sanctions comprise written warnings, temporary suspension of processing, erasure or destruction of personal data, and fines of up to 2 per cent of annual revenue or income. ABNR notes that sanctions may be combined and imposed without a prior warning.

The body meant to apply them has not been formed; it is to be established by presidential regulation. On 27 July 2026, Alexander Sabar, Director General of Digital Space Supervision at the Ministry of Communication and Digital Affairs (Komdigi), told a Constitutional Court hearing in case 236/PUU-XXIV/2026 that the draft had been harmonised and submitted to the President by a letter dated 20 May 2026, Kompas.com reported. He said the PDP Law sets no deadline for forming the agency and that his directorate general carries out the function in the meantime. The four petitioners asked the court to order the agency's establishment within two years.

Observers see a gap. Wahyudi Djafar, Executive Director of Catalyst Policy-Works, told CNBC Indonesia on 15 September that compliance standards are hard to operate without a functioning agency, and that the agency could need a further one to two years before it operates well. ABNR counts about 30 provisions that depend on future regulations from the authority, including on impact assessments, automated decision-making and transfer mechanisms. In the reporting reviewed for this article, we found no announcement that the presidential regulation has been issued.

What organisations can do before 16 January

The open questions are not a reason to wait. In our analysis, a three-day window is an architectural requirement as much as a legal one: when a customer's data sits in a core system, a data warehouse and several vendor platforms, meeting it depends on knowing where that data is. The steps below are practical preparation, not legal advice.

  • Map personal data. Build or update the register of processing activities, including data flows, retention periods and third parties with access.
  • Rehearse the 3 x 24 hour clocks. Test whether a data subject request can be verified and fulfilled across every system holding the person's data, and whether an incident can be assessed and notified in the same window.
  • List high-risk processing. Identify automated decisions, uses of AI and machine learning, and large-scale processing, and plan impact assessments before new processing starts.
  • Check the officer triggers. Decide whether a data protection officer is required and how that role reaches senior management.
  • Inventory cross-border flows. Record which data leaves Indonesia, to which countries and vendors, and on what basis.
  • Review consent and children's data. Confirm that proof of consent is retrievable, and that services likely to be used by people under 18 can identify them and verify parental consent.
  • Revisit processor contracts. Written controller-processor arrangements are among the areas the law firms advise reviewing.

What to watch next

  • The presidential regulation establishing the data protection authority, and how quickly the body becomes operational.
  • The outcome of Constitutional Court case 236/PUU-XXIV/2026 on the authority's formation.
  • The authority's own regulations, including the adequacy list and standard contractual clauses.
  • Any official guidance from Komdigi on supervision between 16 January 2027 and the authority's formation.

We will update this article when the authority is established or its first regulations are issued.

Sources

  1. Indonesia's Personal Data Protection Law implementing regulation arrives quietly: A first look at GR 33/2026 · Hogan Lovells(opens in a new tab)
  2. Indonesia's PDP Law Enters a New Phase: Enforcement Moves Forward under GR 33/2026 · ABNR(opens in a new tab)
  3. Indonesia's new personal data protection rules · Norton Rose Fulbright(opens in a new tab)
  4. Indonesia's PDP Law: Key Takeaways from the New Implementing Rules · BDO Indonesia(opens in a new tab)
  5. PP Pelindungan Data Pribadi Berlaku Januari 2027, Ini Aturan Baru Data Anak · Katadata(opens in a new tab)
  6. Komdigi Ungkap Perpres Pembentukan Badan Perlindungan Data Pribadi Sedang Disusun · Kompas.com(opens in a new tab)
  7. Lembaga Perlindungan Data Belum Ada di RI, Padahal Aturannya Sudah Ada · CNBC Indonesia(opens in a new tab)

This briefing was prepared by the Indotek editorial desk with AI assistance, from the public sources listed above. It is general information, not legal or professional advice.

Cloud & Data

How Indotek can help

Much of PP 33/2026 comes down to knowing where personal data lives, how it moves and who can reach it. That is data platform and cloud architecture work, which is the kind of work Indotek does. It is technology work, not legal advice.

  • Data platforms with lineage: we build lakehouse and warehouse platforms with governed ingestion and lineage, so the origin and flow of personal data are recorded.
  • Data as a product: we give each dataset an owner, a contract and a quality bar, so a question about a person's data has someone clearly responsible for answering it.
  • Security and residency by design: we let access, encryption and data-location requirements shape the architecture from the start, particularly for regulated workloads.
  • Platform engineering: we apply infrastructure as code and observability, so changes to the systems that hold personal data are visible and traceable.

Let's build what comes next

Whether you are modernising a legacy environment, building an AI-powered product or exploring a new digital business, let's create technology that delivers lasting value.