Laws & Guides

Indonesia’s PDPL Implementing Regulation: Key GDPR Differences

Indonesia’s PDPL Implementing Regulation: Key GDPR Differences

On 16 July 2026, Indonesia promulgated Government Regulation No. 33 of 2026 (“PP 33/2026”), detailing the implementation of Law No. 27 of 2022 on Personal Data Protection (“PDPL”). The regulation contains 225 articles and takes effect on 16 January 2027. The Chinese and English titles used for Indonesian legislation in this article are working translations.

According to Hogan Lovells, the certified copy of the regulation only began circulating widely in late August. However, the six-month period specified in Article 225 still runs from the date of promulgation, 16 July.

PP 33/2026 addresses lawful bases, individual rights, processing records, breach notifications and international transfers. Although these arrangements share many features with the GDPR, their specific requirements differ. Some differences were already established in the PDPL, including extraterritorial scope, deadlines for access and rectification requests, and the 2% fine ceiling. The implementing regulation further specifies what contracts must contain, what information processing records must include, and what international transfer conditions still apply after consent has been obtained.

1. Extraterritorial scope

Article 2 of PP 33/2026 follows the PDPL. Even where a business is located outside Indonesia, Indonesian law may apply if its acts concerning personal data protection have legal consequences within Indonesia or for Indonesian citizens residing abroad.

Article 3 GDPR first covers processing in the context of the activities of an establishment in the EU. For businesses without an EU establishment, extraterritorial application principally depends on whether they offer goods or services to individuals in the EU or monitor their behaviour within the EU. Holding an EU Member State passport is not, by itself, sufficient to trigger either of those extraterritorial provisions.

Indonesian law also expressly protects Indonesian citizens abroad. A business serving Indonesian citizens in a third country therefore needs to consider its processing activities and their legal consequences when assessing whether the PDPL applies. Operating outside Indonesia alone does not exclude its application.

The PDPL and PP 33/2026 provide six lawful bases: consent, contractual performance, compliance with legal obligations, protection of vital interests, public-interest tasks and other legitimate interests.

Where a business relies on consent, Indonesian law requires “valid explicit consent” (persetujuan yang sah secara eksplisit). The GDPR generally requires freely given, specific, informed and unambiguous consent expressed through affirmative action. Explicit consent is additionally required in particular circumstances, including the processing of special categories of data. This difference in wording does not mean Indonesian law requires a separate signed consent form for every processing activity.

Article 35 of PP 33/2026 provides that, where an individual refuses consent, the controller must generally continue providing goods, services or facilities without reducing their quality. An exception applies where the processing is necessary to provide them. The GDPR also restricts tying services to unnecessary processing through its requirement that consent be freely given and through Article 7(4). The Indonesian regulation further states the obligations concerning continued service provision and quality following a refusal of consent.

Where contractual performance is the lawful basis, the Indonesian regulation also prescribes contractual content. Article 43 lists nine mandatory items, including the processing purposes and their relationship to the contract’s purpose, individual rights and controller obligations, service details, the consequences of not processing the data, effects on individual rights, commitments to compliance and rights protection, and the parties involved in processing. If the contract lacks the required content, the controller cannot rely on contractual performance as its lawful basis.

Article 6(1)(b) GDPR principally requires processing to be necessary for performing a contract with the individual or for taking pre-contractual steps at that individual’s request. It does not prescribe the same nine contractual items. Even after establishing necessity under the GDPR, a business must therefore check whether its contract includes the information required under Indonesian law.

3. Deadlines for individual rights

The PDPL already requires controllers to handle access and rectification requests within 3 × 24 hours of receipt. Articles 71 and 77 of PP 33/2026 retain this deadline and add requirements for verifying requests, correcting data and providing access. Although controllers must first verify the request, the period still starts when the request is received.

By comparison, Article 12(3) GDPR requires controllers to respond without undue delay, explaining the action taken on requests under Articles 15–22, no later than one month after receipt. Where requests are complex or numerous, the period may be extended by a further two months, provided the individual is notified within the first month and given reasons.

Withdrawal of consent follows a different rule. Article 92 of PP 33/2026 requires controllers to stop the relevant processing no later than 3 × 24 hours after receiving a withdrawal request. Article 7(3) GDPR allows individuals to withdraw consent at any time; after withdrawal, controllers cannot continue processing in reliance on that consent. The one-month response deadline does not permit a business to continue processing for another month after consent is withdrawn.

4. Processing records, retention policies and audits

The PDPL already requires controllers to record all processing activities. Article 74 of PP 33/2026 specifies 13 categories of mandatory information. In addition to party details, purposes, data categories, retention periods and security measures, records must include the lawful basis, data sources and transfer destinations, fulfilment of individual rights, and data-flow maps. Article 30 GDPR does not expressly list some of these items, although businesses may still need this information to demonstrate compliance.

The exceptions to record-keeping also differ. Article 30(5) GDPR permits organisations employing fewer than 250 people to dispense with records under certain conditions. However, records remain required where processing is likely to pose a risk to individuals’ rights and freedoms, is not occasional, or involves special categories of data or criminal-conviction and offence data. Article 74 of PP 33/2026 contains no equivalent small-organisation exception.

Article 75 also requires controllers to adopt a retention policy containing ten items, including retention periods and their basis, the individuals and data types concerned, destruction methods, processor requirements, responsible persons, documentation and notifications.

Auditing is another express requirement. Article 138 requires controllers to conduct internal and external personal data protection audits. The GDPR requires controllers to demonstrate compliance and to adopt, review and update appropriate measures according to risk, but its text does not impose a general requirement on every controller to conduct both internal and external privacy audits.

5. Breach notification requirements

Article 46 PDPL already requires controllers to notify individuals and the supervisory authority within 3 × 24 hours of a personal data protection failure. Article 114 of PP 33/2026 clarifies that the period begins when the controller knows of the incident with certainty and on reasonable grounds. The accompanying elucidation requires the controller’s incident records to be used in determining when it became aware. The notification must also provide details of the data protection officer or designated contact.

The GDPR sets different conditions for notifying the authority and notifying individuals. Under Article 33, controllers must notify the authority without undue delay after becoming aware of a breach and, where feasible, within 72 hours. Notification is not required if the breach is unlikely to result in a risk to individuals’ rights and freedoms. Article 34 requires notification to individuals only where a breach is likely to result in a high risk, and provides exceptions, including where the data has been effectively protected.

Article 114 of PP 33/2026 directly requires notification to both individuals and the authority, without adopting the GDPR’s risk thresholds. A business therefore cannot decide against notifying Indonesian individuals simply because its GDPR assessment found that the incident did not present a high risk. In special situations involving statutory public functions, the exceptions in Article 50 PDPL must also be considered.

6. International transfer mechanisms and risk assessments

Article 165 of PP 33/2026 follows Article 56 PDPL. Before transferring data abroad, the controller must first confirm whether the recipient country provides an equivalent or higher level of protection. If it does not, the controller must ensure that adequate and binding safeguards exist. Only where neither condition can be met may the transfer proceed on the basis of individual consent. The regulation also addresses the adoption or approval of adequacy lists, standard contractual clauses and binding corporate rules.

Even after consent is obtained, the transfer must satisfy Article 173. Among other conditions, the transfer must not be repetitive, must involve only a limited number of individuals, must not subordinate their interests, rights and freedoms to the transfer purpose, and must be supported by a completed risk assessment and protective measures. The controller must also inform the authority and individuals about the transfer and the compelling legitimate interests it serves (kepentingan sah yang mendesak). Ongoing group data synchronisation or routine cloud-service transfers will therefore struggle to meet the non-repetitive condition.

Article 49 GDPR is structured differently. Point (a) of the first subparagraph of paragraph 1 permits transfers by way of derogation after the individual has been fully informed of the risks and has explicitly consented. Non-repetitiveness, limited numbers of individuals and compelling legitimate interests appear in the second subparagraph. That provision is available only where adequacy, appropriate safeguards and all the preceding derogations are unavailable.

In other words, the Indonesian regulation attaches similar conditions directly to consent-based transfers, whereas the GDPR regulates the two separately. However, the derogations under Article 49 GDPR must also be interpreted strictly and cannot serve as a general substitute for mechanisms supporting ongoing transfers.

Beyond selecting a transfer basis, Articles 161–164 of PP 33/2026 require controllers to map transfers, assess whether the legal instrument used can effectively protect individuals, add safeguards where necessary and reassess periodically. Before transferring data, they must also explain the purpose, safeguards, risks and mitigation measures to individuals.

Comparable assessment and supplementary-measure requirements already exist in the EU following the Schrems II judgment and European Data Protection Board guidance. The Indonesian regulation primarily differs here by putting specific steps directly into the legislation. Transfer assessments themselves should not be described as uniquely Indonesian obligations.

7. Administrative fine ceilings and calculation factors

Article 57 PDPL already caps administrative fines at 2% of annual revenue or annual receipts. Article 185 of PP 33/2026 specifies that the calculation should consider the impact and duration of the violation, data types, the number of individuals affected, the business’s cooperation, business size and ability to pay, among other factors. A fine may be as low as zero in particular circumstances.

Article 83 GDPR establishes two tiers according to the type of infringement: €10 million or 2% of the undertaking’s total worldwide annual turnover in the preceding financial year, and €20 million or 4% of that turnover, whichever is higher in each case.

The Indonesian provision does not expressly refer to worldwide annual turnover. Further implementing rules will need to be considered when determining which revenue is included. The appearance of a 2% figure in both laws does not establish that they use the same calculation base.

8. The supervisory authority and further implementing rules

Some requirements in PP 33/2026 still need further rules from the supervisory authority. On 22 July 2026, Indonesia’s Ministry of Communication and Digital Affairs stated that the rules establishing the authority were still being finalised. At the time of this review, no official instrument formally establishing it or issuing the transfer tools discussed above had been located.

Further developments to follow include the authority’s establishment, standard contractual clauses, approval of binding corporate rules and fine procedures. Obligations already in force under the PDPL remain applicable; they cannot be deferred simply because the implementing regulation takes effect in January 2027.

References

Official PDPL text: https://jdih.komdigi.go.id/produk_hukum/view/id/832/t/crc32/; certified copy of PP 33/2026 (third-party mirror): https://docs.paralegal.id/PP/2026/PP-33-2026.pdf; Indonesian full-text navigation tool: https://pppdp2026.karsa-siber.com/; official GDPR text: https://eur-lex.europa.eu/eli/reg/2016/679/oj; EDPB recommendations on supplementary transfer measures: https://www.edpb.europa.eu/our-work-tools/our-documents/recommendations/recommendations-012020-measures-supplement-transfer_en; Indonesian government statement on establishing the authority: https://portal.komdigi.go.id/kanal-publik/berita-kini/10412; Hogan Lovells account of the text’s circulation [secondary source]: https://www.hlc.com/en/publications/indonesias-personal-data-protection-law-implementing-regulation-arrives-quietly.

Related reading

Laws & Guides

ChatGPT Is Now a VLOSE Under the DSA: What Changes?

The European Commission has designated ChatGPT as a very large online search engine. We explain the DSA threshold and six additional duties that follow.

·5 min
Laws & Guides

California DROP Starts August 1 with Ongoing Deletion Duties

California data brokers must process DROP requests from August 1, 2026. The rules cover 45-day cycles, ongoing deletion, matching, and vendor instructions.

·8 min
Laws & Guides

Privacy Alert | Vietnam’s Personal Data Protection Law (PDPL) Officially Enacted

Vietnam’s Personal Data Protection Law (PDPL), enacted in June 2025 and effective from January 1, 2026, establishes a comprehensive national framework for personal data protection, replacing the 2023 Decree No. 13/2023/NĐ-CP. Applicable to both domestic and foreign entities processing Vietnamese citizens’ or residents’ data, the PDPL introduces strict penalties (up to 10 times illegal proceeds for data trading or 5% of annual revenue for cross-border violations), a narrow “legitimate rights and interests” processing basis, and exemptions for micro-enterprises. It mandates explicit consent, data processing and transfer impact assessments (DPIA and TIA), and robust data subject rights, including access, correction, and deletion. Enterprises must implement consent mechanisms, data security measures, and compliance with data localization under the Cybersecurity Law, with specific rules for sensitive data like children’s or health information, and a 72-hour breach reporting requirement.

·6 min
Kaamel
info@kaamel.com
340 E Middlefield Rd, Mountain View, CA 94043
AICPA Drata
© 2026 Kaamel Inc. All rights reserved.