Aug

29

A New Era of Data Protection in Indonesia: Understanding Government Regulation No. 33 of 2026

After nearly four years since the enactment of Law No. 27 of 2022 on Personal Data Protection (“PDP Law”), the Indonesian Government has finally issued Government Regulation No. 33 of 2026 concerning the Implementing Regulation of the PDP Law (“GR 33/2026″). This long-awaited regulation provides greater clarity on various technical aspects that were not comprehensively addressed under the PDP Law, including personal data processing, legal bases for processing, data subject rights, cross-border data transfers, regulatory oversight, and administrative sanctions.

The issuance of GR 33/2026 marks a significant milestone in the implementation of Indonesia’s personal data protection framework. Organizations now have more detailed guidance regarding their compliance obligations when collecting, processing, storing, transferring, or otherwise handling personal data. Importantly, the regulation adopts an extraterritorial approach, meaning that it applies not only to entities operating within Indonesia but also to parties located outside Indonesia whose data processing activities have legal consequences within Indonesia or affect Indonesian citizens.

One of the key features of GR 33/2026 is the classification of personal data into two categories: specific personal data and general personal data. Specific personal data includes health information, biometric data, genetic data, criminal records, children’s data, and personal financial data. General personal data includes information such as a person’s full name, gender, nationality, religion, marital status, and other data combinations capable of identifying an individual.
The regulation also reinforces the fundamental principles of personal data protection that must be observed by Personal Data Controllers and Personal Data Processors. These principles include lawful and transparent data collection, purpose limitation, protection of data subject rights, data accuracy, security safeguards, transparency regarding processing activities, data deletion after the retention period expires, and accountability in all data processing activities.

Furthermore, GR 33/2026 provides more detailed guidance regarding the rights of Data Subjects. Personal Data Controllers are required to establish accessible channels through which individuals may exercise their rights, whether electronically or through non-electronic means. Requests submitted by Data Subjects must be processed through a documented and proportionate verification mechanism.

For businesses, the regulation serves as a reminder that personal data protection compliance can no longer be treated as a mere formality. Organizations should conduct a comprehensive review of their privacy policies, consent mechanisms, vendor arrangements, internal governance structures, information security measures, and personal data breach response procedures. Such measures are essential to mitigate legal, operational, and reputational risks arising from non-compliance.

The introduction of GR 33/2026 also reflects Indonesia’s growing commitment to aligning its data protection framework with international standards. As data-driven business models continue to expand, companies operating in Indonesia are expected to adopt a more structured and accountable approach to personal data governance.

GR 33/2026 represents a major development in Indonesia’s personal data protection regime. Organizations that have already begun implementing data mapping exercises, privacy governance frameworks, and compliance programs will be better positioned to meet the new regulatory requirements. Conversely, companies that have not yet assessed their readiness should consider conducting a comprehensive compliance review to identify gaps between their current practices and the obligations imposed under the PDP Law and GR 33/2026.

Schinder Law Firm regularly advises domestic and multinational companies on personal data protection compliance, including privacy audits, privacy policy drafting, data processing agreements, Data Protection Officer (DPO/PPDP) appointments, internal compliance frameworks, cross-border data transfer assessments, and regulatory investigations involving personal data protection matters in Indonesia. Our team assists clients in developing practical and business-oriented compliance strategies that align with Indonesia’s evolving data protection framework while supporting operational efficiency and regulatory readiness. For further information or consultation regarding personal data protection compliance in Indonesia, please contact us at info@schinderlawfirm.com.

Author:
Dewi Susanti

Schinder Consultant London Ltd.

Introduction

Welcome to our London office, where a cadre of seasoned professionals is dedicated to providing an unparalleled standard of sophisticated legal services to a discerning global clientele. Our overarching mission is to facilitate the realization of your international life and business objectives with the utmost precision and finesse, ensuring a seamless integration into your new environment.
 
In the domain of our proficiency, we present a meticulously curated portfolio of services that extends across diverse sectors, encompassing investment immigration, real estate investment, educational consulting, concierge services, wealth management, and lifestyle services. Our commitment lies in the delivery of holistic, one-stop solutions that surpass conventional boundaries, attending to the intricate nuances of your distinctive needs with a prideful dedication to excellence. We embrace a commitment to excellence, striving to not only meet but exceed the expectations.