FROM PRINCIPLES TO PRACTICE: GR 33/2026 STRENGTHENS PERSONAL DATA PROTECTION COMPLIANCE
Introduction
Following the issuance of Government Regulation No. 33 of 2026 on the Implementation of Law No. 27 of 2022 on Personal Data Protection (”GR 33/2026”), Indonesia has significantly expanded its operational personal data protection framework. While Law No. 27 of 2022 on Personal Data Protection (”PDP Law”) established the principal rights of Personal Data Subjects and the fundamental obligations of Personal Data Controllers and Personal Data Processors, many aspects of the regulatory framework remained relatively high level and required further implementing guidance. GR 33/2026 fills many of these gaps by introducing more detailed governance requirements, operational procedures, documentation obligations, and compliance mechanisms applicable throughout the entire personal data processing lifecycle. The Regulation will become effective on 16 January 2027, providing organizations with a six-month transition period to assess and strengthen their existing data protection frameworks before the new requirements become enforceable.
Rather than fundamentally changing the legal principles established under the PDP Law, GR 33/2026 primarily transforms those principles into concrete compliance obligations. Businesses may now be expected to adopt more structured internal governance measures, reassess the lawful basis supporting each processing activity, maintain prescribed internal documentation, strengthen cross-border transfer arrangements, and establish more comprehensive procedures for handling data subject requests and personal data incidents. While several aspects of the framework continue to depend on future implementing regulations from the Personal Data Protection Authority (”PDP Authority”), the Regulation already provides a substantially more detailed roadmap for organizational compliance.
Key Changes
Organizations Should Reassess Their Lawful Basis for Processing
One of the most significant developments introduced by GR 33/2026 is the greater emphasis placed on selecting and documenting the appropriate lawful basis before any processing activity begins. Rather than treating consent as the default legal basis, Controllers are expected to determine which lawful basis most accurately reflects the purpose and necessity of each processing activity. The Regulation therefore encourages organizations to distinguish more carefully between processing based on consent, contractual necessity, legal obligations, public interests, vital interests, and legitimate interests.
Where consent is relied upon, GR 33/2026 introduces more prescriptive requirements regarding how consent must be obtained and managed. Consent must be freely given, specific, informed, and unambiguous, while organizations should implement accessible mechanisms enabling data subjects to withdraw consent electronically or non-electronically. Importantly, the Regulation also clarifies that businesses generally should not reduce the quality of goods or services merely because an individual refuses consent unless the relevant processing is genuinely necessary to provide those goods or services. This represents a notable shift away from broad or bundled consent clauses commonly found in existing privacy notices.
Similarly, organizations relying on contractual necessity must ensure that the underlying agreement satisfies specific content requirements and that the relevant processing is genuinely necessary to perform the agreement or respond to a pre-contractual request. Legitimate interests also become subject to a structured assessment requiring Controllers to document the necessity of the processing, balance competing interests, evaluate potential adverse impacts, and identify appropriate mitigation measures.
Internal Governance and Documentation Become Central Compliance Obligation
GR 33/2026 substantially expands the internal governance framework expected of Controllers and Processors. Compliance is no longer limited to implementing appropriate security measures or obtaining valid consent. Instead, organizations are expected to establish and maintain various internal policies, records, and procedures that collectively demonstrate accountability throughout the data processing lifecycle.
Among others, Controllers and Processors are now expected to prepare and maintain:
- Personal Data Processing Policies;
- Personal Data Protection Failure Prevention and Response Policies;
- Personal Data Retention Policies;
- Procedures for handling compensation requests;
- Records of Processing Activities (ROPA);
- Minutes evidencing the deletion or destruction of personal data; and
- Certain governance policies relating to public interest processing where applicable.
The introduction of these governance documents reflects a broader shift toward accountability-based compliance. Rather than focusing solely on substantive legal obligations, organizations may increasingly be expected to demonstrate compliance through documented policies, internal records, and governance processes that can be produced during regulatory supervision or audits.
High-Risk Processing Requires More Structured Assessment
GR 33/2026 also provides significantly greater operational detail regarding Data Protection Impact Assessments (“DPIAs”). Whereas the PDP Law generally required a DPIA for processing activities presenting high risks to data subjects, the implementing Regulation now clarifies that the assessment should be completed before such processing commences and prescribes the minimum matters that must be evaluated
The DPIA must address, among other matters:
- the relevant processing activities and their purposes;
- the necessity and proportionality of the processing;
- risks posed to data subjects; and
- mitigation measures implemented by the Controller.
Where applicable, the Controller must also consider and document the advice of its Data Protection Officer (”DPO”).
Notably, the Regulation expressly recognises artificial intelligence, machine learning, smart technology, and the Internet of Things as examples of technologies that may involve potentially high-risk processing. As organizations increasingly integrate automated technologies into their business operations, the practical importance of DPIAs is likely to continue expanding.
Cross-Border Personal Data Transfers Become More Comprehensive
GR 33/2026 introduces a considerably more structured framework governing international personal data transfers. In addition to requiring Controllers to identify the appropriate legal basis supporting a transfer, the Regulation expects organizations to record and map the transfer cycle, assess the effectiveness of the relevant legal instruments, periodically review transfer arrangements, and notify data subjects before transferring their personal data overseas.
Where the recipient jurisdiction has not been recognised as providing an equivalent level of protection, Controllers may instead rely on legally binding and enforceable instruments, standard contractual clauses, binding corporate rules, or other mechanisms recognised by the PDP Authority. Consent remains available only in limited circumstances and is subject to additional conditions designed to ensure that it functions as an exception rather than the primary transfer mechanism.
These developments suggest that multinational businesses may need to review existing data transfer arrangements and consider whether additional contractual documentation or governance measures are required before the Regulation becomes effective
New Operational Obligations Extend Beyond Traditional Privacy Compliance
Beyond governance and lawful bases, GR 33/2026 introduces several operational obligations that businesses should not overlook.
The Regulation establishes more detailed requirements for data breach notifications, clarifying when the statutory 3 × 24-hour notification period begins. It also requires Controllers to cease processing personal data within the same timeframe following a verified withdrawal of consent. In practice, these requirements may require organizations to strengthen their incident response procedures and establish internal verification mechanisms capable of meeting relatively short regulatory deadlines.
The Regulation also introduces additional obligations relating to indirectly collected personal data, prohibits exoneration clauses within privacy notices, establishes a more detailed joint controller framework, and prescribes notification requirements applicable to mergers, acquisitions, consolidations, spin-offs, and dissolutions involving personal data transfers. These provisions illustrate that compliance under GR 33/2026 extends well beyond traditional privacy policies and will likely require coordination across legal, compliance, information technology, human resources, procurement
What Businesses Should Do
With the Regulation scheduled to become effective on 16 January 2027, businesses should begin reviewing whether their existing personal data governance framework aligns with the more prescriptive requirements introduced by GR 33/2026. In particular, organizations should consider reviewing the lawful basis supporting each processing activity, updating consent mechanisms and privacy notices where necessary, establishing the internal governance policies and records required by the Regulation, evaluating cross-border data transfer arrangements, identifying processing activities that may require a Data Protection Impact Assessment, and strengthening internal procedures for handling data subject requests, data breaches, and other operational compliance obligations. While further guidance from the PDP Authority is still expected, the Regulation already provides a sufficiently detailed compliance framework to justify commencing implementation efforts during the remaining transition period.