Skip to Content
OPINION

Notes from the Asia-Pacific region: Indonesia, Vietnam take to the data regulatory dance floor

Highlighting Indonesia's detailed compliance requirements and Vietnam's strengthened enforcement measures, as well as the practical steps organizations can take to prepare.

Published

Contributors:

Charmian Aw

AIGP, CIPP/A, CIPP/E, CIPP/US, CIPM, FIP

Partner

Hogan Lovells Cadwalader

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

After a lengthy rehearsal, the curtain has finally been raised to unveil Government Regulation No. 33 of 2026, the long-awaited implementing regulation for Indonesia's Personal Data Protection Law. The regulation was promulgated 16 July 2026 and will take effect 16 Jan. 2027.

It provides much-needed choreography to businesses operating in Indonesia, on lawful processing, consent, records of processing, retention, impact assessments, data protection officers, incident management and international transfers.

The PDPL established several lawful bases for processing personal data. GR 33/2026 now enables businesses to strike the right balance on how these bases operate in practice, including more detailed requirements around consent.

Consent must at its core be freely given, conscious, specific and unambiguous, with no tiptoeing around information provided to individuals as to the legal basis, purpose, categories of personal data, retention and their rights in respect of processing. 

Documentation really takes center stage. Controllers must maintain a ballet roster of processing activities, including data flows, retention periods, categories of data subjects and third-party access. A written policy which specifies the de-identification and destruction of data is also required.

GR 33/2026 will be a new dance partner for artificial intelligence compliance. It lends weight to data protection impact assessments, which are required for seven categories of processing. These include automated decision-making or profiling, with legal or significant effects impacting an individual, such as access to products, services, opportunities or benefits. 

DPIAs are also twirled in for new technologies, machine learning, smart technology and the internet of things, as well as large-scale processing, which is judged through a range of scores, including the volume and type of personal data, duration and purpose of processing, number of individuals affected and geographical reach.

International transfers will make up an intricate cross-border waltz under GR 33/2026. The regulation establishes a three-tier framework for transferring personal data outside Indonesia, whereby transfers can be made: to a country recognized as providing adequate protection; using appropriate and binding safeguards, which contemplates standard contractual clauses and binding corporate rules approved by the authority; or in limited circumstances, on the basis of explicit consent where neither of the first two routes is available.

The tempo should pick up in the next six months as businesses are advised to: map Indonesian processing activities and international data flows; review lawful bases, privacy notices and consent mechanisms; practice against the new record of processing activities and retention requirements; identify DPIA triggers, particularly for AI, automated decision-making and large-scale processing; assess data protection officer and broader privacy governance arrangements; review processor and joint-controller arrangements; test incident response processes; and assess the resilience of existing cross-border transfer mechanisms.

GR 33/2026 marks an important transition for Indonesia's privacy regime. The PDPL established the framework; the implementing regulation provides much of the detail needed to turn that framework into operational compliance. There will inevitably be challenges, careful adjustments and perhaps even some unexpected developments as businesses work through the new requirements. 

In another Southeast Asian spotlight, Vietnam has found its groove with a recently issued sanctions Decree No. 363/2026/ND-CP. It will take effect 11 Nov., setting a new rhythm for enforcement and giving organizations a short window to prepare.

The financial penalty is capped at USD7,700 for violations by a corporation. That figure may seem more like a quickstep than a grand finale, but the supplementary measures carry considerably more weight. Authorities may suspend business activities, revoke or suspend licenses or certificates, and order organizations to correct, delete, restore or otherwise remediate data-related processes. The fine may be modest, but the compliance consequences may still require careful preparation.

The decree also sets higher sanction bands for activities that merit closer attention: data sharing and provision; data analysis and aggregation; encryption and decryption; cross-border data processing; data risk management; and data intermediary and data exchange activities. This gives compliance teams a broader foxtrot to perform, with organizations needing to map controls, assign responsibilities and ensure data operations can keep pace with the new requirements.

The practical message is simple: do not wait for the encore. Organizations should use the remaining time to review their data practices, so that when the new regime takes its first cha-cha, they can glide rather than scramble.

This article originally appeared in the Asia-Pacific Dashboard Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here. 
CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Charmian Aw

AIGP, CIPP/A, CIPP/E, CIPP/US, CIPM, FIP

Partner

Hogan Lovells Cadwalader