Indonesia – Personal Data Protection Under 2026 Implementing Regulation.
Personal data protection in Indonesia was governed by Law No. 27 of 2022 on Personal Data Protection, as amended by Law No. 1 of 2026 (“PDP Law”). However, the PDP Law leaves certain matters to be further regulated and expressly mandated their implementation through a government regulation. After a four-year period of anticipation, the implementing regulations of the PDP Law were finally enacted on July 16, 2026, through the issuance of Government Regulation No. 33 of 2026 on the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (“PDP GR”). Nonetheless, this regulation will start comes into effect on 16 January 2027.
As the implementing regulation, the PDP GR does not alter the framework or overall approach to personal data protection established under the PDP Law but rather complement it and provides greater clarity and sets out more detailed mechanisms for implementing the framework established under the PDP Law. For instance, the PDP GR provides clarification on what constitutes data processing for private and domestic purposes, which are not subject to the PDP Law and the PDP GR.
This publication will summarize the important regulations concerning personal data protection in Indonesia, as regulated under the PDP Law and the PDP GR.
BASIS OF PERSONAL DATA PROCESSING
As previously stipulated under the PDP Law, a Personal Data Controller (“PDC”) is required to establish a legal basis for the processing of personal data prior to carrying out such processing. Under Article 30 of the PDP GR, such legal basis include: valid and explicit consent (“Consent”); the performance of contractual obligations where the Personal Data Subject (“Data Subject”) is a party to the relevant agreement; compliance with the PDC’s legal obligations; the protection of the Data Subject’s vital interests; the performance of a task carried out in the public interest pursuant to applicable laws and regulations; and/or the pursuit of other legitimate interests.
Consent. Consent in relation to personal data processing must be obtained specifically and unambiguously, either electronically or non-electronically, and must be accompanied by the relevant information in a manner that is concise, accurate, and relevant to the processing activities. The information, as stipulated under Article 62 GR PDP, should be provided by the PDC prior to obtaining consent and at a minimum include the legality and purpose of the processing, the types and relevance of the personal data to be processed, details of the information collected, the retention period for the documents and processing of personal data, and the rights of the Data Subject.
Consent for the processing of a child’s personal data must be obtained from the child’s parent and/or guardian in accordance with applicable laws and regulations. The PDP GR reaffirms this mechanism by requiring the PDC to take steps to identify children, obtain Consent from the parent or guardian, and verify such Consent by taking into consideration the available technology. The PDC is required to identify Data Subject with disabilities in accordance with applicable laws and regulations and provide accessible facilities and infrastructure. In the case that Consent is to be obtained from a Data Subject with a disability and/or their guardian, the PDC must facilitate communication through facilities and infrastructure which ensure that the Data Subject can understand and utilize, in accordance with applicable laws and regulations.
In the case that the processing is carried out for the purpose of offering/promotion of goods and/or services, the PDC must also provide information regarding the third parties that will receive the personal data, the form of the offer to be made, and the mechanism for withdrawing Consent and reporting any continued offering activities following the withdrawal of Consent. In the absence of such Consent from the Data Subject, the PDC must continue to provide the relevant goods, services, or facilities to the Data Subject without reducing their quality, unless the provision of such goods, services, or facilities requires the processing of personal data.
Contractual Necessity. The processing of personal data may be conducted on the basis of the performance of a contract, provided that the Data Subject is a party to the agreement. In such case, the contractual necessity basis remains subject to the rights and obligations set out under the PDP GR, and the PDC may not process personal data beyond the scope specified in the agreement. However, the agreement itself does not replace Consent as a legal basis for processing where Consent is required.
If the Data Subject is not a party to the agreement, as stipulated under Article 40 (1) (b) and 42(1) PDP GR, the performance of contractual obligations may still serve as a legal basis for fulfilling a written or recorded request from the Data Subject to the PDC prior to entering into an agreement. Such data processing is permitted provided that: (a) the PDC and the Data Subject will enter into an agreement that requires the processing of personal data; and (b) the agreement to be entered into by the Data Subject and the PDC will serve as the basis for exercising the rights and obligations of the Data Subject and the PDC.
As stipulated under Article 43 PDP GR, such agreement must include the following:
- details of, and an explanation of, the purpose of the personal data processing;
- an explanation of the relationship between the purpose of the personal data processing and the purpose of the agreement to be fulfilled;
- the rights of the Data Subject and the obligations of the PDC;
- the type and characteristics of the needs or services to be provided to the Data Subject;
- the consequences if the personal data is not processed by the PDC;
- the impact of the personal data processing on the protection of the Data Subject’s rights;
- the PDC’s undertaking to process personal data in accordance with the applicable laws and regulations on personal data Protection;
- the PDC’s undertaking to fulfil the Data Subject’s rights; and
- the parties involved in the processing of personal data.
DATA PROCESSING REQUIREMENTS
Procedures and Obligations. The PDC must identify the purpose of personal data processing, which is limited to a specific purpose and should minimize the personal data processed by considering:
- the relation between the personal data processed and the purpose of the processing;
- the adequacy of the personal data processed to achieve the purpose; and
- ensuring that the personal data processed does not exceed what is necessary to achieve the processing purpose.
The purpose identified above should have been explicitly and clearly informed to the Data Subject, and should be explicitly documented (including any amendments) in the form of:
- the PDC’s internal policies; and
- a personal data protection notice that is readily accessible to the Data Subject.
Record Retention. During such processing, PDC shall, and shall ensure that any appointed Personal Data Processor, maintain records of all personal data processing activities. Such records shall be maintained, whether electronically or non-electronically, for the retention period stipulated in the applicable data retention document, in accordance with the relevant laws and regulations.
Once the applicable retention period has expired and the personal data is designated for destruction pursuant to the applicable records retention schedule, PDC shall destroy such personal data.
Impact Assessment. As stipulated under Article 120 (2) PDP GR, (a) automated decision-making that produces legal effects or significant impacts on Data Subjects, (b) processing of specific personal data or personal data on a large scale, (c) systematic evaluation, scoring, or monitoring of Data Subjects, (d) matching or combining multiple datasets, (e) the use of new technologies in personal data processing, and/or (f) processing that restricts the exercise of Data Subjects’ rights, are considered high risk data processing.
Accordingly, prior to processing personal data, the PDC is required to conduct and document a personal data protection impact assessment, which must at a minimum include:
- a description of the personal data processing activities and their purposes, including the PDC’s interests in the processing;
- an assessment of the necessity and proportionality between the purpose and the processing activities;
- an assessment of the risks to the rights of Data Subjects; and
- measures to protect Data Subjects from the risks arising from the processing of personal data.
The PDC shall document such personal data protection impact assessment, alongside measures taken by the PDC to protect Data Subjects from the risks associated with the processing of personal data. If such assessment determines that the processing of personal data causes harm to the Data Subject, the PDC should seek to consult the PDP Institution. In any case, the PDC must consider and document the Personal Data Protection Officer’s recommendations when conducting a personal data protection impact assessment.
PDP Institution will further regulate such personal data protection impact assessment. However, if the necessary technical and operational measures are not available, the PDC should seek to consult the PDP Institution.
CROSS BORDER DATA TRANSFER
In conducting cross-border transfers of personal data outside the jurisdiction of the Republic of Indonesia, PDC and/or Personal Data Processors are required to record and map the personal data transfer cycle and its implications, while ensuring that the personal data transferred is relevant and limited to what is necessary for the purposes of the transfer. Pursuant to Article 161 of the PDP GR, PDC are also required to identify the legal instrument serving as the basis for the transfer and assess its effectiveness prior to the transfer. If necessary, the PDC must further adopt supplementary instruments, including contractual, technical, and/or organizational measures, in which case the relevant procedural steps must also be implemented. In addition, the obligation for PDC to provide the Data Subject with information regarding the transfer of personal data prior to the transfer also applies to cross-border data transfers.
The PDP GR establishes a hierarchy of basis for the permit of conducting cross-border transfer of personal data, with transfers to countries providing an adequate level of personal data protection being the preferred basis. In the case that the recipient country does not provide an adequate level of personal data protection, a PDC must ensure that an adequate and legally binding level of personal data protection are in place, or as a last resort, the cross-border transfer of personal data may be conducted on the basis of Data Subject’s consent.

Assessed Recipient Countries. For cross-border transfers of personal data, the PDC must ensure that the country in which the receiving PDC and or Personal Data Processor is domiciled provides a level of personal data protection that is equivalent to or higher than stipulated under the PDP Law.
The PDP Institution will conduct an assessment and will provide a list of country or international organization where the level of personal data protection meets the required standard. The assessment is conducted based on several criteria including whether the recipient country has adequate personal data protection regulations, institutions or authorities overseeing personal data protection, and relevant international commitments or obligations concerning personal data protection, and further provisions on the assessment procedures to be regulated by the PDP Institution.
If the recipient is domiciled in a country included in the list established by the PDP institution, the PDC may proceed with the transfer, provided that the transfer is carried out in accordance with the applicable laws and regulations.
Binding data protection mechanism. If the recipient is not domiciled in a country included in the list established by the PDP institution, the PDC must ensure that other adequate and binding personal data protection safeguards are in place through a written and/or recorded instrument. The PDC must be able to demonstrate to the PDP Institution that the required personal data protection safeguards have been duly implemented. Further provisions concerning the implementation of such safeguards will be regulated under a regulation to be issued by the PDP Institution.
As contemplated under Articles 169–170 of the PDP GR, such safeguards may take the form of:
- legally binding and enforceable instruments, applicable to institutions or authorities pursuant to their respective powers under applicable laws and regulations;
- standard contractual clauses on personal data protection, which must at least cover the relevant definitions and terms, the basis for processing personal data, personal data protection provisions, notification obligations in the event of failure in personal data protection, and feasibility test obligations with respect to other parties receiving the transferred personal data;
- binding corporate regulation applicable within a corporate group; and/or
- other adequate and binding personal data protection instruments recognized by the PDP Institution.
Approval for Exceptional Circumstances. If the recipient is domiciled in a country included in the list established by the PDP institution, and the PDP Institution determines that the PDC has not fulfilled its obligation to ensure adequate and binding personal data protection safeguards, the transfer may nevertheless be carried out if:
- the transfer is non-recurring, involves a limited number of Data Subject, and is necessary for purposes that do not override the interests or rights and freedoms of the relevant Data Subject;
- the PDC has conducted a risk assessment and implemented appropriate personal data protection measures, and has informed the PDP Institution and the relevant Data Subject of the transfer activity and the urgent legitimate interest to be fulfilled through such transfer; and
- the PDC has obtained the consent of the relevant Data Subject. Further provisions concerning the implementation of obtaining such consent will be regulated under a regulation to be issued by the PDP Institution, as contemplated under Article 174 of the PDP GR.
DISPUTE SETTLEMENT MECHANISM
The PDP GR provides comprehensive regulations on alternative dispute resolution mechanisms for disputes arising from personal data protection processing through the PDP Institution. This alternative dispute resolution mechanism will be conducted through a mediation process. However, as the PDP Institution is still in the process of being established, more detailed regulations on this alternative dispute resolution mechanism are anticipated to be issued in the near future.
IMPLEMENTATION TIMELINE AND PRACTICAL CONSIDERATIONS
Although PDP GR provides more detailed rules for the implementation of Indonesia’s personal data protection framework, the regulation does not take effect immediately. PDP GR will come into force six months after its promulgation providing businesses with an opportunity to assess their existing personal data processing activities and align their policies, procedures, contractual arrangements, and technical measures with the requirements. Such alignment is generally expected to involve only targeted refinements, as the PDP GR primarily elaborates on, rather than changes, the obligations already established under the PDP Law.
Given that certain implementation details and requirements remain subject to further regulations and guidance from the PDP Institution, which itself has yet to be established, business actors should review their existing personal data processing practices while awaiting further clarity on matters that remain subject to further regulation by the PDP Institution. However, if no further regulation or guidance is issued, businesses should proceed with the necessary adjustments based on the requirements under the PDP GR as the transition period draws to a close.

For Further Information, Please Contact:
MetaLAW, Legal Consultant, Jakarta, Indonesia
general@metalaw.id




