PP 33/2026 · Business guide

Indonesia’s PP 33/2026: PDP Law Duties for Businesses

Moch Hikmat Gumilar, Sworn Translator, explains Indonesia’s PDP Law and PP 33/2026: NDAs, business duties, vendors, data transfers and bilingual documents.

A client once asked me to translate a business presentation for use in Indonesia. Before the work began, the client wanted assurance that the material would remain confidential and asked me to prepare a non-disclosure agreement, or NDA.

As a sworn translator, my professional oath already binds me to protect matters that must remain confidential in my work. That duty exists before a client asks for an NDA. Still, this request called for a fuller explanation of how I would handle the documents: who could access them, how they would be stored, and how a request to delete them would be carried out. It also meant providing an NDA to record the confidentiality arrangements.

I understood the concern. The client wanted to know what would happen to the files after sending them. To me, that is an important part of trust in a translation assignment. Deletion arrangements also need to be clear about any records that must still be retained to meet legal obligations.

With Government Regulation No. 33 of 2026 implementing Indonesia’s Personal Data Protection Law, I expect these questions to become more common. Almost every business handles information about customers, employees or partners. Business confidentiality and personal data protection do have different scopes: a presentation can contain confidential strategy without personal data, while a contact list within it may identify individuals.

That experience is why I wrote this guide. I want to help business owners understand what to check when receiving, storing, translating or sharing documents, particularly when an assignment involves partners outside Indonesia.

Download PP 33/2026

Read the Indonesian regulation: 120 pages, 225 articles. Promulgated 16 July 2026; effective 16 January 2027 under Article 225.

Download the Indonesian PDF (5.49 MiB)

Download unofficial English translations

Read the full English texts in searchable PDFs with article bookmarks and a legaltrans.id watermark.

These are unofficial reference translations, not sworn or certified translations. The Indonesian texts prevail. The Law No. 27 of 2022 download follows the enacted 2022 text and is not a consolidated edition of later amendments or court decisions.

Key dates: Government Regulation No. 33 of 2026 (PP 33/2026), implementing Law No. 27 of 2022 on Personal Data Protection (the PDP Law), was promulgated on 16 July 2026. Article 225 provides that it takes effect six months after promulgation, making its commencement date 16 January 2027. The PDP Law itself took effect on 17 October 2022 and allowed up to two years for adjustment under Article 74. Businesses must therefore meet the underlying PDP Law obligations before the PP takes effect. PDP Law, Articles 74 and 76.

Updated on 14 September 2026. References to the PP help businesses prepare for its commencement; references to the PDP Law explain existing duties. Check the rules specific to your sector as well.

Which businesses must comply with Indonesia’s PDP Law?

The PDP framework covers electronic and non-electronic processing. Paper archives, visitor registers and printed documents belong in the assessment alongside software and databases.

It can also apply to parties outside Indonesia where their actions have legal consequences in Indonesia and/or for Indonesian citizen data subjects abroad. The personal or household exception should not simply be applied to professional or commercial activities. A home-based seller processing buyers’ information for business needs to assess its business obligations. See PP Articles 1–3 and PDP Law Articles 1–2.

Start by identifying who decides how the data will be used. These roles affect the contract and each party’s responsibilities:

  • Personal data controller: determines the purpose and controls processing. An example is a company deciding how customer information is used for sales.
  • Personal data processor: processes on a controller’s behalf. An example is a payroll provider following its client’s instructions.
  • Joint controllers: jointly determine processing purposes and methods. PP Articles 11–12 address their agreement, allocation of responsibilities, shared contact and liability.

A company may be a controller for employee information and a processor for client information. Contract labels need to be checked against actual activities.

Data protection duties by business type

Find the business type closest to your operation in the table below. Use the duties column to identify what to examine first, then the document column to plan the follow-up. Whether a document needs a bilingual version or sworn translation depends on its readers, intended use and recipient requirements.

Business typeData and activities to examineMain obligation or triggerDocuments to prioritise
SMEs, online shops, restaurants and retailersBuyer contacts, delivery addresses, order histories, loyalty schemesSeparate transaction and marketing purposes; minimise data; provide information; retain evidence where relying on consent. PP Articles 30–37, 58–62Privacy notices, marketing consent forms, order-management agreements
Banks, fintech, insurers and finance companiesPersonal financial data, identity records, credit scoringSpecific personal data and automated decisions can trigger impact assessments; assess DPO duties and applicable sector rules. PP Articles 6, 120–121, 142Customer notices, impact assessments, processing and transfer agreements
Hospitals, clinics, laboratories and health appsMedical records, test results, biometric dataHealth data is specific personal data; assess impacts and apply security matching the risk; large-scale core processing requires a DPO assessment. PP Articles 6, 120–125, 142Patient notices, consent documents, laboratory and system-provider agreements
Schools, courses, edtech and children’s servicesChildren’s identities, development records, photographs and accountsObtain and verify parental/guardian consent; children’s data is specific data; provide rights procedures. PP Articles 6, 38, 120Parent notices, consent forms, education-platform agreements
Hotels, travel, visa and relocation businessesPassports, bookings, itineraries and family documentsLimit document copies; identify grounds for disclosures; assess transfers to overseas partners and recipients. PP Articles 58–62, 160–173Guest notices, partner agreements, international transfer information
All employers, recruitment and HR outsourcingCVs, payroll, bank accounts, biometric attendance and background checksSeparate recruitment and employment purposes; financial/biometric information is specific data; control payroll vendors and foreign headquarters access. PP Articles 6, 14–15, 120, 160–173Employee/applicant notices, payroll agreements, retention schedules
SaaS, cloud, IT providers, BPO and call centresClient databases, logs, service recordings and support accessFollow documented instructions; obtain written consent before engaging another processor; maintain security, records, audits and incident reporting. PP Articles 15, 118, 139–141Data processing agreements, subprocessor lists, incident procedures
Marketing agencies, CRM and advertising platformsLeads, profiles, segmentation and user behaviourPublic availability is not unrestricted permission; assess lawful grounds, sources, consent-based marketing and systematic scoring/monitoring. PP Articles 7, 30–37, 53–54, 120Privacy notices, consent evidence, client role-allocation agreements
Law firms, accountants, translators and consultantsCase files, transactions, identities and client recordsAssess roles for each assignment; limit access and control vendors/tools; assess impacts when specific data is involved. PP Articles 6, 13–15, 120, 123–126Engagement terms, NDAs, processing agreements, delivery and retention procedures
Foreign-invested companies, exporters and multinational groupsRegional CRM, employee information, supplier portals and parent-company accessMap recipients, countries, access and onward transfers; select a qualifying transfer mechanism. PP Articles 160–173Transfer agreements, group policies, transfer risk assessments, bilingual notices

Company size is not the only risk indicator. A small clinic can process specific personal data. A large company still needs to assess DPO duties against the legal criteria rather than employee headcount alone.

What is the lawful basis for using customer data?

Article 20 of the PDP Law and Article 30 of the PP identify six grounds: valid explicit consent; contractual performance; a legal obligation; vital interests; specified public-interest/public-service or legally authorised tasks; and other legitimate interests subject to the appropriate balancing assessment.

For example, using a delivery address to fulfil an order can be assessed in the context of contractual performance. Keeping records for tax compliance requires identifying the relevant legal obligation. Using the same telephone number for marketing is a separate purpose requiring its own assessment. A business’s contract with a vendor does not automatically establish a contractual ground for every use of customer data.

Where consent is used, PP Articles 32–37 require it to be freely given, informed, specific and unambiguous. Provide information before obtaining consent, keep evidence, and enable withdrawal. Refusing consent must not automatically reduce service quality, except where the processing is necessary to provide the goods or service. For consent-based offers, explain third-party recipients, the form of the offer, and withdrawal and complaint mechanisms.

Keep one entry for each processing purpose, identifying the data, lawful ground, owner, recipients, retention and supporting evidence. Where relying on other legitimate interests, document the analysis and assessment required by PP Articles 53–54.

What should a privacy notice explain?

PP Article 62 sets out information duties across all lawful grounds. Required information includes the legality and purpose of processing, data types and relevance, retention, details collected, processing period and individual rights. The general rule is to provide information before processing and keep it accessible throughout processing, subject to specific provisions, including those for indirectly obtained data.

Do not simply replace the company name in a global privacy policy. Check whether its vendors, access locations, purposes, contacts and retention match Indonesian operations. Article 28 addresses internal processing rules; Article 68 connects the recorded purposes with internal policies and accessible notices.

Language also matters. Article 22(4) of the PDP Law requires consent requests that include other purposes to be distinguishable, accessible and understandable, using simple and clear language. Its elucidation specifies Bahasa Indonesia. An English version can help foreign readers and regional teams, but must remain consistent with the Indonesian version. This language provision does not itself impose a blanket requirement for sworn translations of privacy notices. PDP Law and elucidation to Article 22.

Is an NDA enough to protect client documents?

The request at the start of this article shows why an NDA discussion needs to reach the day-to-day handling of files. Confidentiality commitments need practical arrangements for access, use, storage and deletion. The sworn translator’s oath itself includes a duty not to disclose matters that must remain confidential in the assignment; see Minister of Law Regulation No. 4 of 2025, Article 13(5).

PP Article 14 sets minimum content for an agreement appointing a processor: processing scope and methods; processing type and purpose; personal data types; data subject categories; duration; each party’s rights and obligations; supervision, documentation, audit and inspection mechanisms; dispute resolution; engagement of other processors; and a jointly designated contact.

An NDA limited to non-disclosure may not cover those elements. Article 15 also requires written controller consent before a processor engages another processor. Article 139 requires processing instructions to be documented and implemented consistently with the agreement.

Review payroll, cloud, CRM, call-centre and translation-provider contracts. Record who accesses the files, why, whether subprocessors are involved, how incidents are reported, and how data is returned, deleted or destroyed. Agree operational commitments that the provider can actually deliver.

What if personal data is accessed from outside Indonesia?

Sending attachments is only one activity to examine. PP Article 160 includes making data available to a receiving controller or processor outside Indonesian jurisdiction. Access by foreign support teams or a foreign headquarters should therefore be mapped and assessed.

PDP Law Article 56 and PP Article 165 establish a sequence: equivalent or higher protection in the recipient’s country; if that condition is not met, adequate and binding protection; and if neither is met, the data subject’s consent.

A significant restriction appears in PP Article 173: the consent route is available only subject to conditions, including non-repetitive transfers, a limited number of data subjects, purposes that do not override their interests or rights and freedoms, risk assessment and safeguards, and information to the Authority and data subjects. A general sign-up consent should therefore not be assumed to support recurring overseas CRM or payroll transfers.

PP Articles 161–164 also address mapping, assessment of instruments and risks before transfer, and information for data subjects. Articles 169–171 address instruments including standard contractual clauses and binding corporate rules. The Authority sets the standard clauses; use of binding corporate rules requires its approval before transfer. A foreign GDPR template should not be treated as automatically satisfying the Indonesian mechanism.

For work with overseas partners, prepare consistent language versions of the transfer map, risk assessment, processing/transfer agreement, group policy and data subject information. Legal advisers determine whether the mechanism is sufficient; translators preserve the meaning across languages.

When does a business need an impact assessment or DPO?

An impact assessment is required for processing presenting potentially high risks. PDP Law Article 34 and PP Article 120 cover, among other activities, specific personal data, large-scale processing, automated decisions with legal or significant effects, systematic scoring or monitoring, combining datasets and new technologies. PP Article 121 requires assessment before processing, records of risks and mitigation, and review when risks change.

A personal data protection officer, referred to as PPDP in the regulation and often as a DPO in English, must be appointed where Article 142’s criteria apply: public-service processing; core activities requiring regular and systematic large-scale monitoring; and/or core activities involving large-scale processing of specific personal data or criminal-offence-related data. These criteria do not all have to be met together. PDP Law Article 53 must also be read in light of Constitutional Court Decision 151/PUU-XXII/2024, recorded in BPK’s law catalogue.

PP Articles 143–146 address competence, appointment, access to top management, independence, resources and conflicts of interest. Issuing an appointment letter alone does not fulfil the operational duties.

Handling requests, retention and data breaches

Provide an accessible request channel, verify requests proportionately, and record receipt times. Do not assume that every request has the same deadline. PP Article 71 gives up to 3 × 24 hours from receipt for updating/correcting data; Article 77 addresses access deadlines. Article 78 distinguishes providing a copy at the first opportunity from confirming the request and communicating the time needed to supply it.

Security starts during planning. PP Articles 123–124 address technical and operational measures proportionate to risk, restoring access and availability, and testing. Practical measures can include access restrictions, multifactor authentication, appropriate encryption, backups, recovery testing and removing access when employees leave.

Set retention periods by document category and legal basis. PP Articles 79–88 address ending processing, deletion, destruction, notices and processors’ involvement. Avoid both indefinite retention and automatic deletion that ignores an applicable legal duty. Article 138 also includes documenting all processing activities and internal and external data protection audits within controller accountability.

For a personal data protection failure, PDP Law Article 46 requires written notification within 3 × 24 hours to data subjects and the Authority. PP Article 114 clarifies that the period runs from when the failure is known with certainty, appropriately and reasonably, reflecting the Indonesian wording “diketahui secara pasti, patut, dan wajar.” Required contents include the disclosed data, when and how disclosure occurred, response and recovery measures, and DPO/contact information. Article 115 addresses public notification in specified circumstances; Article 118 requires a processor to report to the controller at the first opportunity.

Prepare Indonesian–English notification templates, escalation contacts, responsibility assignments and incident exercises. Populate templates with verified facts when an incident occurs. Build translation into the response plan so cross-border communications do not delay statutory notifications.

What are the penalties for PDP violations?

PDP Law Article 57 and PP Articles 184–185 address written warnings, temporary suspension of processing, deletion/destruction and/or administrative fines. The maximum fine is 2% of annual income or annual receipts, assessed against infringement variables. This is not an automatic 2% charge for every mistake and is not expressed as 2% of profit. The PP includes factors such as impact, duration, data type, affected individuals, cooperation, business scale, ability to pay and compliance history.

A suspension of processing may itself disrupt services. Evidence of implemented policies, vendor supervision, request handling and remediation therefore matters alongside the policy documents.

Where should a business start?

Start with one document flow that actually operates in your business, such as receiving CVs or sending records to a payroll provider. Follow it from receipt to deletion. The sequence below helps allocate the work; urgent findings still need immediate attention.

SequencePriority workDeliverable
MapMap data, purposes, roles, systems, paper records and overseas accessProcessing inventory and prioritised risk list
Check grounds and informationReview lawful grounds, notices, consent, retention and rights channelsPolicies and procedures with named owners
Review other partiesExamine vendor contracts, subprocessors, transfers, impact-assessment and DPO triggersContract changes and required assessments
Test implementationExercise requests and incidents, check implementation evidence, align languagesTest records, corrective actions and controlled document versions

When is sworn translation appropriate?

For documents shared between Indonesian teams and foreign partners, terminology needs to be checked alongside the intended use. The table below shows how the requirements can differ:

DocumentLanguage needSworn translation status
Privacy notices and consent documentsUnderstandable language; consistent Indonesian and English versions where neededNot automatically mandatory merely because the document concerns PDP
Processing/transfer agreements and NDAsEquivalent terms, duties, exceptions and language versionsCheck the contract, transaction and recipient’s requirements
Group policies, impact assessments and SOPsHelp directors, local teams, auditors and partners understand responsibilitiesUsually determined by the purpose and engagement requirements
Documents for regulators, courts or formal proceedingsComplete translation in the appropriate formatConfirm whether the recipient requires a sworn translator and additional formalities

A sworn translation does not validate unlawful processing or replace legal advice. When sworn status or a particular form is required, selecting the appropriate translator early can reduce rework.

Returning to my client’s request, the NDA recorded the agreement; explaining how the documents would be handled made that agreement workable. In bilingual documents, access restrictions, retention periods, deletion duties and exceptions need to mean the same thing in both languages. That is where my translation work connects directly with carrying out the agreement.

Frequently asked questions

Does the PDP Law apply to small businesses?

Yes, where the business processes personal data within the PDP Law’s scope. Using buyers’ names, telephone numbers or addresses for sales is one example. SME or home-business status does not automatically qualify for the personal or household exception. See PDP Law Article 2.

Does every company need a DPO?

No. Appointment depends on the criteria in PDP Law Article 53 as interpreted by the Constitutional Court and PP Article 142, including regular and systematic large-scale monitoring as a core activity. A business still needs to allocate responsibility for data handling even where no formal DPO appointment is required.

Is using an overseas cloud service prohibited?

No general prohibition applies. A business needs to assess the data flows, recipients, transfer mechanism and sector rules. PP Articles 160–173 govern international transfers; server location alone does not establish whether all requirements are met.

Is an English-only privacy policy sufficient?

Not necessarily. Consent requests must meet the understandable-language requirements; the elucidation to PDP Law Article 22 specifies Bahasa Indonesia. An English version can accompany the Indonesian version for foreign readers, with both reflecting the actual business operation.

Does every PDP document require sworn translation?

No. The PDP provisions discussed here do not require every document to have a sworn translation. Check the intended use, receiving authority’s requirements, contract and legal rules applicable to the document.

Does a sworn translator still need an NDA?

A sworn translator’s oath already imposes a duty of confidentiality. An NDA can clarify the arrangements with a client. Where the assignment involves processing personal data on the client’s behalf, the agreement also needs to address the relevant processing responsibilities; a non-disclosure clause alone may not cover them. See PP 33/2026 Articles 14–15.


Sources: Government Regulation No. 33 of 2026, particularly the articles cited above, in the 120-page Indonesian text PP 33/2026 — Indonesian PDF; PP 33/2026 catalogue entry; Law No. 27 of 2022 and its elucidation, Komdigi JDIH; Constitutional Court decision recorded in BPK’s PDP Law catalogue.

This article provides general information. Compliance assessments must consider the business activity, sector, latest implementing instruments and company circumstances. Translation supports accurate communication and documentation; legal decisions remain for the appropriate advisers and authorities. English descriptions in this article are explanatory and are not an official or sworn translation of the legislation.

About the author

· Sworn Translator, Indonesian–English

Ministry of Law and Human Rights (Kemenkumham) appointment decrees:

  • AHU-68.AH.03.07.2022English to Indonesian
  • AHU-11.AH.03.07.2023Indonesian to English

This article draws on my translation work and the client experience described above. Professional credentials and services.

LegalTrans · Indonesia–English

Need help translating an NDA or PDP documents?

Tell me which documents you need translated, who will read them, and your deadline. At LegalTrans, we can agree confidentiality arrangements, including an NDA where needed, before you share the complete files. We will also clarify whether the intended use requires a sworn translation.

Discuss document translation

Next step

Not sure which service your matter requires?

Send a short non-confidential brief first. We will clarify conflict checks, scope, and the appropriate document channel before you decide.

Discuss on WhatsApp
Chat on WhatsApp