{
    "success": true,
    "data": {
        "id": 1989039,
        "msgid": "pp-33-2026-six-implementation-priorities-before-16-january-2027-1789761022",
        "date": "2026-09-18 18:25:03",
        "title": "PP 33\/2026: Six Implementation Priorities before 16 January 2027",
        "author": " ",
        "source": "GALERT",
        "tags": "",
        "topic": "Regulation",
        "summary": "Indonesia has promulgated Government Regulation No. 33 of 2026, providing detailed operational requirements for the implementation of the Personal Data Protection Law. The regulation, which takes effect on 16 January 2027, mandates stricter compliance measures for organisations, including mandatory data protection impact assessments for high-risk processing and enhanced protocols for international data transfers.",
        "content": "<p>RSM INDONESIA CLIENT ALERT \u2013 18 SEPTEMBER 2026<\/p>\n<p>Indonesia promulgated Government Regulation No.\u00a033 of 2026 concerning\nthe Implementing Regulation of Law No.\u00a027 of 2022 on Personal Data\nProtection (PP 33\/2026) on 16 July 2026. Under Article 225, the\nregulation will take effect six months later, on 16 January 2027.<\/p>\n<p>This is not the beginning of PDP compliance. The UU PDP is already in\nforce and its two-year adjustment period has ended. PP 33\/2026 now\nprovides more detailed operational requirements and strengthens\nexpectations that organizations can demonstrate\u2014not merely state\u2014their\ncompliance.<\/p>\n<p>Across its 225 articles, the regulation provides greater detail on\nlawful processing, Data Subject rights, high-risk processing and Data\nProtection Impact Assessment (DPIA), breach management, Processor and\ninternational transfer arrangements, PPDP governance, accountability,\nsupervision, and administrative sanctions.<\/p>\n<p>Indonesia issued Government Regulation No.\u00a033 of 2026 (PP 33\/2026),\nimplementing Law No.\u00a027 of 2022 on Personal Data Protection (UU PDP), on\n16 July 2026. Under Article 225, PP 33\/2026 takes effect six months\nafter its promulgation, on 16 January 2027.<\/p>\n<p>WHAT THE REGULATION REQUIRES IN PRACTICE<\/p>\n<p>Many of the core duties originate in the UU PDP. PP 33\/2026\ntranslates those duties into more detailed operational and evidentiary\nrequirements and specifies mechanisms that organizations may not yet\nhave embedded in their processes and systems, including internal and\nexternal personal data protection audits for Controllers (Article 138).\nThe practical question is no longer whether a policy exists, but whether\nthe organization can demonstrate that its controls operate in practice.\nThe six implementation priorities below identify the areas that require\nreview.<\/p>\n<p>SIX IMPLEMENTATION PRIORITIES<\/p>\n<ol type=\"1\">\n<li>Processing inventory, lawful bases, notices, and consent<\/li>\n<\/ol>\n<p>PP 33\/2026 sets out the lawful bases for processing (Article 30).\nWhere processing relies on consent, that consent must be explicit,\nfreely given, informed, specific, and unambiguous, with a mechanism to\nobtain and withdraw it and evidence that it was given (Article 30(3)(a)\nand Articles 32\u201337). The obligation to keep personal data accurate\nremains a core principle (Article 9), supported by operational\nobligations on data quality (Article 69). Separately, Controllers must\nmaintain a record of all processing activities (Article 74), which\nunderpins the processing inventory.<\/p>\n<p>Organizations should ensure these elements are reflected consistently\nacross their processing inventory, privacy notices, internal procedures,\nsystems, and contracts.<\/p>\n<ol start=\"2\" type=\"1\">\n<li>Data Subject rights and operational response mechanisms<\/li>\n<\/ol>\n<p>The regulation sets out rights that systems and processes must be\nable to support. The right to object applies to a decision based solely\non automated processing, including profiling, that produces a legal\neffect or a significant impact on the Data Subject (Articles 93\u201396). It\ndoes not extend to all automated processing.<\/p>\n<p>The right to data portability and interoperability applies only where\nthe processing is based on explicit consent or performance of a contract\nand is carried out by automated means (Article 111(3)). Organizations\nshould confirm that their procedures for handling Data Subject requests,\nobjections, and data export operate in practice.<\/p>\n<ol start=\"3\" type=\"1\">\n<li>High-risk processing, DPIA, and AI-related processing<\/li>\n<\/ol>\n<p>A DPIA is required where processing poses a high risk to Data\nSubjects. Article 120(2) sets out the categories of high-risk processing\nthat require a DPIA. The Elucidation to Article 120(2)(f) expressly\nidentifies artificial intelligence, machine learning, smart technology,\nand the Internet of Things as examples of new technology. Where these\ntechnologies are used to process personal data, the processing falls\nwithin the new-technology category and requires a DPIA. Under Article\n120(2), the categories of high-risk processing that require a DPIA\nare:<\/p>\n<ul>\n<li><p>automated decision-making with a legal or significant\neffect;<\/p><\/li>\n<li><p>processing of specific (sensitive) personal data;<\/p><\/li>\n<li><p>large-scale processing;<\/p><\/li>\n<li><p>systematic evaluation, scoring, or monitoring of Data\nSubjects;<\/p><\/li>\n<li><p>matching or combining of data sets;<\/p><\/li>\n<li><p>use of new technology, including artificial intelligence and\nmachine learning; and<\/p><\/li>\n<li><p>processing that restricts the exercise of Data Subject\nrights.<\/p><\/li>\n<\/ul>\n<p>Two further indicators are worth screening even though they are not\nstatutory triggers under Article 120:<\/p>\n<ul>\n<li><p>processing that involves third parties or complex data-sharing;\nand<\/p><\/li>\n<li><p>processing that involves international transfers.<\/p><\/li>\n<\/ul>\n<p>Organizations should determine which initiatives require a DPIA,\nrather than treating all third-party or cross-border processing as\nautomatically in scope. The assessment should address the processing,\nits necessity and proportionality, the risks to Data Subjects, and the\nmeasures to mitigate those risks.<\/p>\n<ol start=\"4\" type=\"1\">\n<li>Processors, subprocessors, and international transfers<\/li>\n<\/ol>\n<p>The engagement of a Processor must be based on a written agreement\nthat sets out the required minimum terms (Article 14). Where a Processor\nengages a further Processor (subprocessors), the Controller\u2019s prior\nwritten approval is required, and an equivalent level of protection must\nbe maintained (Article 15). Organizations should review arrangements\nwith cloud providers, SaaS platforms, outsourcing providers, and group\nentities against both requirements.<\/p>\n<p>For international transfers, organizations should identify where\npersonal data is stored, accessed, or transferred outside Indonesia, and\napply the transfer basis in the order set out in Article 165. The\ndestination must first provide an equivalent or higher level of\nprotection. If that condition is not met, the transfer must be based on\nadequate and binding safeguards. Only where neither condition is met may\nthe transfer rely on the Data Subject\u2019s consent.<\/p>\n<ol start=\"5\" type=\"1\">\n<li>Personal data breach readiness<\/li>\n<\/ol>\n<p>PP 33\/2026 sets out operational obligations for managing a personal\ndata breach (Articles 114\u2013118). These obligat<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/pp-33-2026-six-implementation-priorities-before-16-january-2027-1789761022",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}