The Government of Indonesia (“GoI”) has just enacted the Government Regulation No. 33 of 2026 on the Implementing Regulation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”), which will be effective on 12 January 2027. The said GR introduced, one of which, specific requirements concerning the installation and use of visual data processing devices, or in other words, Closed-Circuit Television (“CCTV”) which involves the processing of personal data.
The general overview of the relevant provisions under GR 33/2026 are as follows:
The installation of a visual data processor and processing device in public places and/or public service facilities shall be carried out under several conditions; [1]
However, GR 33/2026 set certain exemption to the above conditions. For instance, for Point B and C above, it shall be exempted for criminal prevention and law enforcement processes purposes in accordance with the provisions of laws and regulations. (Article 17.2 of GR 33/2026).
Personal Data Controller and/or Personal Data Processor shall ensure that the recording is carried our consistently and ensure personal data protection, in which it shall be place and use to monitor the targeted area in accordance with the monitoring objectives.[2]
In the public setting, the Personal Data Controller and/or Personal Data Processor must display information that a visual data processor and processing device is installed in the area[3], in which it must be conveyed clearly, directly, and concisely[4]. To be specific, the information shall at least contain[5]:
The above information must fulfill the following condition as stipulated by Article 19.4 of GR 33/2026 as follows:
In relation to its implementation, in addition, companies should consider the general personal data protection requirements applicable to their CCTV activities. This may include conducting a DPIA for high-risk processing, including systematic monitoring[6], appointing a DPO where the CCTV activities involve large-scale, regular, and systematic monitoring[7] and documenting any third-party processing arrangements as mandated by Article 13 and 14 of GR 33/2026.
Further, companies using CCTV should review their existing arrangements to ensure compliance with GR 33/2026, including the purpose and legal basis of processing, camera placement and coverage, signage and transparency, third-party arrangements, and any CCTV systems that enable the identification of individuals or involve biometric data. Companies should implement any necessary adjustments before GR 33/2026 takes effect on 16 January 2027.
If you have any questions, please do reach out to us.
Thank you.
[1] Article 17.2 of GR 33/2026
[2] Article 18 of GR 33/2026
[3] Article 19.1 of GR 33/2026
[4] Article 19.2 of GR 33/2026
[5] Article 19.3 of GR 33/2026
[6] Article 120.1 and Article 120.2(d) of GR 33/2026
[7] Article 142.1(b) of GR33/2026