PP 33/2026: Six Implementation Priorities before 16 January 2027
RSM INDONESIA CLIENT ALERT – 18 SEPTEMBER 2026
Indonesia promulgated Government Regulation No. 33 of 2026 concerning the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (PP 33/2026) on 16 July 2026. Under Article 225, the regulation will take effect six months later, on 16 January 2027.
This is not the beginning of PDP compliance. The UU PDP is already in force and its two-year adjustment period has ended. PP 33/2026 now provides more detailed operational requirements and strengthens expectations that organizations can demonstrate—not merely state—their compliance.
Across its 225 articles, the regulation provides greater detail on lawful processing, Data Subject rights, high-risk processing and Data Protection Impact Assessment (DPIA), breach management, Processor and international transfer arrangements, PPDP governance, accountability, supervision, and administrative sanctions.
Indonesia issued Government Regulation No. 33 of 2026 (PP 33/2026), implementing Law No. 27 of 2022 on Personal Data Protection (UU PDP), on 16 July 2026. Under Article 225, PP 33/2026 takes effect six months after its promulgation, on 16 January 2027.
WHAT THE REGULATION REQUIRES IN PRACTICE
Many of the core duties originate in the UU PDP. PP 33/2026 translates those duties into more detailed operational and evidentiary requirements and specifies mechanisms that organizations may not yet have embedded in their processes and systems, including internal and external personal data protection audits for Controllers (Article 138). The practical question is no longer whether a policy exists, but whether the organization can demonstrate that its controls operate in practice. The six implementation priorities below identify the areas that require review.
SIX IMPLEMENTATION PRIORITIES
- Processing inventory, lawful bases, notices, and consent
PP 33/2026 sets out the lawful bases for processing (Article 30). Where processing relies on consent, that consent must be explicit, freely given, informed, specific, and unambiguous, with a mechanism to obtain and withdraw it and evidence that it was given (Article 30(3)(a) and Articles 32–37). The obligation to keep personal data accurate remains a core principle (Article 9), supported by operational obligations on data quality (Article 69). Separately, Controllers must maintain a record of all processing activities (Article 74), which underpins the processing inventory.
Organizations should ensure these elements are reflected consistently across their processing inventory, privacy notices, internal procedures, systems, and contracts.
- Data Subject rights and operational response mechanisms
The regulation sets out rights that systems and processes must be able to support. The right to object applies to a decision based solely on automated processing, including profiling, that produces a legal effect or a significant impact on the Data Subject (Articles 93–96). It does not extend to all automated processing.
The right to data portability and interoperability applies only where the processing is based on explicit consent or performance of a contract and is carried out by automated means (Article 111(3)). Organizations should confirm that their procedures for handling Data Subject requests, objections, and data export operate in practice.
- High-risk processing, DPIA, and AI-related processing
A DPIA is required where processing poses a high risk to Data Subjects. Article 120(2) sets out the categories of high-risk processing that require a DPIA. The Elucidation to Article 120(2)(f) expressly identifies artificial intelligence, machine learning, smart technology, and the Internet of Things as examples of new technology. Where these technologies are used to process personal data, the processing falls within the new-technology category and requires a DPIA. Under Article 120(2), the categories of high-risk processing that require a DPIA are:
automated decision-making with a legal or significant effect;
processing of specific (sensitive) personal data;
large-scale processing;
systematic evaluation, scoring, or monitoring of Data Subjects;
matching or combining of data sets;
use of new technology, including artificial intelligence and machine learning; and
processing that restricts the exercise of Data Subject rights.
Two further indicators are worth screening even though they are not statutory triggers under Article 120:
processing that involves third parties or complex data-sharing; and
processing that involves international transfers.
Organizations should determine which initiatives require a DPIA, rather than treating all third-party or cross-border processing as automatically in scope. The assessment should address the processing, its necessity and proportionality, the risks to Data Subjects, and the measures to mitigate those risks.
- Processors, subprocessors, and international transfers
The engagement of a Processor must be based on a written agreement that sets out the required minimum terms (Article 14). Where a Processor engages a further Processor (subprocessors), the Controller’s prior written approval is required, and an equivalent level of protection must be maintained (Article 15). Organizations should review arrangements with cloud providers, SaaS platforms, outsourcing providers, and group entities against both requirements.
For international transfers, organizations should identify where personal data is stored, accessed, or transferred outside Indonesia, and apply the transfer basis in the order set out in Article 165. The destination must first provide an equivalent or higher level of protection. If that condition is not met, the transfer must be based on adequate and binding safeguards. Only where neither condition is met may the transfer rely on the Data Subject’s consent.
- Personal data breach readiness
PP 33/2026 sets out operational obligations for managing a personal data breach (Articles 114–118). These obligat