The Regulatory Framework for CCTV under the Government Regulation No. 33 of 2026 on the Implementing Regulation for Law No. 27 of 2022 on Data Protection Law

Published on
October 5, 2026

The Government of Indonesia (“GoI”) has just enacted the Government Regulation No. 33 of 2026 on the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”), which will be effective on 12 January 2027. The said GR introduced, one of which, specific requirements concerning the installation and use of visual data processing devices, or in other words, Closed-Circuit Television (“CCTV”) which involves the processing of personal data.

The general overview of the relevant provisions under GR 33/2026 are as follows:

  1. Permitted Purposes and Limitations on CCTV Use

The installation of a visual data processor and processing device in public places and/or public service facilities shall be carried out under several conditions; [1]

  1. For security, disaster prevention, and/or traffic management purposes or the collection, analysis, and arrangement of traffic information;
  2. Must display information in the area where a visual data processor and processing device has been installed; and
  3. Not used to identify a person.

However, GR 33/2026 set certain exemption to the above conditions. For instance, for Point B and C above, it shall be exempted for criminal prevention and law enforcement processes purposes in accordance with the provisions of laws and regulations. (Article 17.2 of GR 33/2026).

  1. Privacy and Monitoring Area Requirements

Personal Data Controller and/or Personal Data Processor shall ensure that the recording is carried our consistently and ensure personal data protection, in which it shall be place and use to monitor the targeted area in accordance with the monitoring objectives.[2]

In the public setting, the Personal Data Controller and/or Personal Data Processor must display information that a visual data processor and processing device is installed in the area[3], in which it must be conveyed clearly, directly, and concisely[4]. To be specific, the information shall at least contain[5]:

  1. Information that a visual data processor and processing device is operating; and
  2. Contact person for a visual data processor and processing device.

The above information must fulfill the following condition as stipulated by Article 19.4 of GR 33/2026 as follows:

  1. Placed at the entrance to the area where a closed visual data processor and processing device is installed; or
  2. Placed in a location that is easily accessed and read before entering the area monitored by a visual data processor and processing device in an open area.
  1. Considerations

In relation to its implementation, in addition, companies should consider the general personal data protection requirements applicable to their CCTV activities. This may include conducting a DPIA for high-risk processing, including systematic monitoring[6], appointing a DPO where the CCTV activities involve large-scale, regular, and systematic monitoring[7] and documenting any third-party processing arrangements as mandated by Article 13 and 14 of GR 33/2026.

Further, companies using CCTV should review their existing arrangements to ensure compliance with GR 33/2026, including the purpose and legal basis of processing, camera placement and coverage, signage and transparency, third-party arrangements, and any CCTV systems that enable the identification of individuals or involve biometric data. Companies should implement any necessary adjustments before GR 33/2026 takes effect on 16 January 2027.

If you have any questions, please do reach out to us.

Thank you.


[1] Article 17.2 of GR 33/2026

[2] Article 18 of GR 33/2026

[3] Article 19.1 of GR 33/2026

[4] Article 19.2 of GR 33/2026

[5] Article 19.3 of GR 33/2026

[6] Article 120.1 and Article 120.2(d) of GR 33/2026

[7] Article 142.1(b) of GR33/2026

Find Articles

LOKA LAW OFFICE
WTC 5, 6th floor
Jl Jend Sudirman Kav. 29, Jakarta, 12920