PP No. 33 of 2026 provides implementing requirements for Personal Data Protection (PDP) in Indonesia. The regulation supports the implementation of Law No. 27 of 2022 on Personal Data Protection and provides a more operational framework for organizations.
This topic was discussed in the CBQA Global webinar, “Understanding PP No. 33 of 2026: What Should Be the Organization’s Priorities?”, held online on 15 September 2026.
The webinar featured Anwar Siregar, Director Asia Pacific, and Edwin H. Chaidir, Head of IT Audit, with Karunia Nurhayati, IT Audit Manager, as the moderator.
What Is PP 33 of 2026?
PP 33 of 2026 does not replace the PDP Law. Instead, it provides implementing requirements related to personal data processing, data subject rights, controller and processor responsibilities, data transfers, and organizational compliance.
Therefore, organizations should understand Law No. 27 of 2022 and PP 33 of 2026 as an integrated regulatory framework.
When Should Organizations Start Preparing?
PP No. 33 of 2026 will take effect on 16 January 2027.
Organizations should use the preparation period to review their personal data governance, processes, controls, and documentation.
Key areas include data processing activities, lawful basis, ROPA, DPIA, DPO/PPDP, vendor management, data transfers, data breach response, and compliance evidence.
The effective date is not the date to start preparing.
What Are the Key Priorities?
1. Map Personal Data Processing
Organizations need to understand what personal data they process, why it is processed, who has access, where it is stored, how long it is retained, and which third parties are involved.
This provides the foundation for effective PDP governance.
2. Establish ROPA
A Record of Processing Activities (ROPA) provides visibility into personal data processing.
It can help connect processing activities with lawful basis, DPIA, vendor assessment, retention, and incident response.
3. Assess Risks and Lawful Basis
Organizations should determine the appropriate lawful basis for each processing activity and conduct a risk assessment to identify high-risk processing.
Where required, organizations should conduct a Data Protection Impact Assessment (DPIA).
4. Strengthen DPO/PPDP and Vendor Management
The DPO/PPDP function should be supported by clear responsibilities, authority, resources, and evidence of implementation.
Organizations should also review relationships with processors, subprocessors, cloud providers, and other vendors, particularly where personal data is transferred across borders.
5. Prepare for Data Breaches
Organizations need clear processes for detecting, responding to, escalating, and documenting data breaches.
An incident response policy should be supported by practical procedures and evidence that demonstrate how the process works.
How Does ISO/IEC 27701:2025 Support Organizations?
ISO/IEC 27701:2025 can help organizations establish a structured approach to privacy governance.
It can connect governance, risk assessment, controls, evidence, and assurance within privacy management.
Organizations still need to map regulatory requirements against their risks, controls, and actual implementation.
From Regulation to Readiness
Organizations can structure their preparation through:
Identify → Classify → Assess → Remediate → Evidence
This means identifying processing activities, classifying data and responsibilities, assessing risks, addressing gaps, and maintaining evidence of implementation.
The key principle is simple:
Compliance is not only about having policies. Organizations must also be able to demonstrate that those policies and controls are implemented.
Strengthen Your Personal Data Protection Readiness with CBQA Global
CBQA Global supports organizations through Cybersecurity, Privacy, Audit, Certification, and Training services.
For Personal Data Protection, ISO/IEC 27701:2025, ISO/IEC 27001, or ISO certification in Jakarta, contact CBQA Global to discuss your organization’s requirements.
Contact CBQA Global for further information:
Email: info@cbqaglobal.com
WhatsApp: 08118468777
Phone: +62 21 2781 4200
CBQA Global. We Inspire in Trust
Certification| Audit| Training| Sustainability