Hogan Lovells·PRIVACY / DATA SECURITY

Indonesia Details Data Protection Law Rules, Sets Jan 2027 Effective Date

A new implementing regulation provides long-awaited operational detail on consent, documentation, impact assessments, and cross-border data transfers, with a compliance deadline of January 16, 2027.

Indonesia has published Government Regulation No. 33 of 2026, the long-awaited implementing regulation for its 2022 Personal Data Protection (PDP) Law, which will take effect on January 16, 2027. The regulation provides concrete operational rules that had been missing since the PDP Law's passage, creating clearer compliance obligations for any organization processing the personal data of Indonesian subjects. The new rules specify detailed conditions for obtaining explicit consent and establish minimum content requirements for records of processing activities (ROPAs) and data retention policies. The regulation also clarifies when a data protection impact assessment (DPIA) is required, expressly including processing that involves AI and machine learning. For cross-border data transfers, it establishes a three-tiered framework based on recipient-country adequacy, contractual safeguards, or, as a last resort, data-subject consent. Because Indonesia's Personal Data Protection Authority has not yet been established, key mechanisms like an adequacy list and standard contractual clauses are not yet available. Businesses have a six-month period to review their privacy programs and adapt them to Indonesia’s specific requirements before enforcement begins.

data-privacyindonesiapdp-lawcompliancecross-border-data-transfersdpia
Read the original firm alert → Tuesday, September 1, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.