The issuance of Government Regulation No. 33 of 2026 concerning the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”) marks a significant shift in Indonesia’s data protection landscape. While the Personal Data Protection Law (“PDP Law”) established the fundamental principles of personal data protection, GR 33/2026 provides the operational framework that organizations must follow when processing personal data.
For many businesses, the key question is no longer whether they are subject to Indonesia’s personal data protection regime, but whether they are adequately prepared to comply with it. Organizations that collect customer information, employee records, vendor data, marketing databases, website visitor information, CCTV recordings, or any other information relating to identifiable individuals should assess their readiness under the new regulatory framework.
- Conduct a Personal Data Mapping Exercise
Companies should identify what personal data they collect, where it comes from, how and where it is processed and stored, who has access to it, and whether it is shared with third parties. This mapping is essential to establish accountability throughout the personal data lifecycle and identify potential compliance gaps.
- Identify and Document the Legal Basis for Processing
Every processing activity should have a valid legal basis under GR 33/2026, including consent, contractual necessity, legal obligations, vital interests, public interest, or legitimate interests. Companies should maintain a processing inventory covering the data processed, purpose, legal basis, retention period, third-party or cross-border transfers, and responsible business unit.
- Review Privacy Notices and Consent Mechanisms
Companies should review their privacy notices and consent mechanisms to ensure they meet GR 33/2026 requirements. Where consent is relied upon, it must be freely given, informed, specific, and unambiguous. Privacy policies, application notices, employee and customer forms, marketing consents, and vendor onboarding documents should be reviewed, together with mechanisms for withdrawing consent.
- Develop Internal Personal Data Protection Policies
Personal Data Controllers should establish internal policies and procedures governing personal data processing. These may include policies on data protection, retention and destruction, data breach response, Data Subject rights, vendor management, and cross-border data transfers. The objective is to integrate data protection into daily business operations.
- Review Agreements with Vendors and Service Providers
Companies should review arrangements with third-party providers, including cloud, HR, payroll, software, marketing, and CRM providers. Where a third party acts as a Personal Data Processor, the relationship should be documented through an appropriate written agreement, including relevant data protection obligations. Existing agreements should therefore be reviewed to determine whether a separate Data Processing Agreement (DPA) is required.
- Establish Procedures for Data Subject Requests
Organizations should provide accessible channels for Data Subjects to exercise their rights, including access, correction, withdrawal of consent, deletion, and objection to processing. A centralized process for receiving, verifying, and responding to such requests can help minimize operational risks and delays.
- Review CCTV and Workplace Monitoring Practices
Organizations using CCTV or other visual data processing systems should ensure that appropriate notices are clearly displayed and provide relevant information, including contact details. This requirement is particularly relevant to offices, factories, warehouses, retail premises, and other monitored areas.
- Prepare for Increased Regulatory Scrutiny
GR 33/2026 reinforces an accountability-based approach to personal data protection. Companies should therefore maintain evidence of their compliance, including records of processing activities, consent, vendor agreements, internal policies, security measures, breach response procedures, and employee training. The ability to demonstrate compliance may be as important as the compliance measures themselves.
GR 33/2026 transforms Indonesia’s personal data protection framework from a principles-based regime into a more operational and enforceable compliance framework. Organizations that proactively review their data governance practices, contractual arrangements, privacy notices, and internal procedures will be better positioned to manage regulatory risks and build trust with customers, employees, and business partners.
The most effective approach to compliance is not to treat personal data protection as a standalone legal project, but as an enterprise-wide governance initiative involving legal, compliance, HR, IT, cybersecurity, procurement, and operational teams. In our experience, organizations that begin with a structured data mapping exercise and legal basis assessment are able to identify compliance gaps early and implement practical remediation measures before regulatory issues arise. Schinder Law Firm regularly assists domestic and multinational companies in conducting PDP compliance assessments, preparing privacy governance frameworks, drafting privacy notices and data processing agreements, reviewing cross-border data transfers, establishing DPO/PPDP functions, and developing practical compliance programs tailored to Indonesian regulatory requirements. Feel free to contact us at info@schinderlawfirm.com for further consultation.
Author:
Dewi Susanti