Indonesia Finalizes Data Protection Law With Implementing Regulation
Indonesia's long-awaited implementing regulation for its Personal Data Protection Law sets specific operational requirements for consent, documentation, and data transfers, with a January 2027 effective date.
Indonesia has enacted Government Regulation No. 33 of 2026, the implementing regulation for its 2022 Personal Data Protection (PDP) Law, which will take effect on January 16, 2027. The regulation provides the detailed operational rules that were missing since the parent law was passed, creating specific new compliance obligations for organizations processing personal data in the country.
Sophisticated clients and counsel care because the regulation introduces concrete, GDPR-like requirements that may necessitate localizing existing global privacy programs. Key provisions detail the conditions for obtaining explicit consent, prescribe minimum content for records of processing activities and data-retention policies, and mandate data protection impact assessments (DPIAs) for high-risk processing, expressly including AI and machine learning. It also establishes a three-tier legal framework for cross-border data transfers, which will depend on adequacy decisions, binding safeguards, or, as a last resort, explicit consent.
Organizations have a six-month window to bring their governance and documentation into alignment with the new rules. A key next step is the formal establishment of the national Personal Data Protection Authority, which is empowered to issue further instruments, such as standard contractual clauses and adequacy lists for data transfers, and to enforce the regime.