Indonesia autonomous vehicle data policy

Indonesia's Data Protection Regulation Is Now Its Default Rulebook for Connected Cars, and a Separate AV Data Law Would Be Premature

GR 33/2026 never mentions vehicles, yet its AI, IoT and cross-border rules govern every connected or autonomous car in Indonesia from January 2027.

GR 33/2026 at a glance People of Internet Research · Indonesia 2% Maximum fine, share of revenue Administrative fines can reach 2% … 72 hrs Breach notification window Runs from when a failure is establ… 3 Cross-border transfer tiers Adequacy list, then safeguards, th… 6 months Runway before entry into force 16 July 2026 signing to 16 January… peopleofinternet.com
GR 33/2026 at a glance People of Internet Research · Indonesia 2% Maximum fine, share of revenue 72 hrs Breach notification win… 3 Cross-border transfer tiers 6 months Runway before entry into force peopleofinternet.com

Key Takeaways

Indonesia has no dedicated autonomous vehicle law. A 2025 peer-reviewed study in Masalah-Masalah Hukum found that its traffic statutes lack AV provisions altogether, leaving a regulatory gap. Yet from 16 January 2027 every connected or driverless car operating there will fall under a detailed data-governance regime. Government Regulation No. 33 of 2026 (GR 33/2026) implements the Personal Data Protection Law (Law 27/2022, enacted 17 October 2022) and does not mention vehicles once.

According to the Indonesian law firm HLC, President Prabowo signed the regulation on 16 July 2026. It reached public view only in late August, and HLC's first analysis appeared on 31 August. That is a quiet arrival for the rulebook that will shape how vehicle data is collected, assessed and exported.

What the regulation asks of a vehicle operator

Three obligations matter most for a connected fleet.

Mapping these onto cars is our inference, since the text is technology-neutral. A vehicle with cameras, location tracking, driver monitoring and over-the-air telemetry is an AI-and-IoT system by any plain reading. An operator sending sensor data to a foreign headquarters or cloud for model training will almost certainly need the second tier. The consent tier is too narrow for continuous telemetry from a whole fleet.

The strongest case for tight rules

The case for caution is serious. A vehicle is a moving sensor platform, and location history is among the most revealing data there is. The Electronic Frontier Foundation's August 2026 policy position on automated license plate readers describes how such systems build a searchable map of everywhere a driver goes, queried by police and private vendors long after the fact. EFF argues that this risk cannot be configured away. Indonesia also has no AV statute to fall back on, so a regulator who wants binding limits today has only GR 33/2026. Ex ante impact assessments, the tool this regulation uses, are a reasonable way to surface those risks before deployment rather than after a breach.

Why proportionality still points away from a new AV data law

The ALPR analogy has limits. A plate-reader network exists to track everyone regardless of suspicion. An AV operator collects data to perform a driving function and can be held to purpose limitation, retention limits and security duties. That is exactly what a general, risk-based data protection law does, and it does so without freezing the technology into vehicle-specific rules that will age badly.

That suggests Indonesia should let GR 33/2026 do the data work and keep the driverless-vehicle safety rules now being drafted focused on safety, licensing and liability. Layering a second, vehicle-specific data regime on top would duplicate obligations and raise costs for early pilots, with little privacy gain.

The regulation is not free of problems, and four points deserve clarification before January.

  1. DPIA scope. If "new technologies" including IoT means a fresh assessment for every connected product, assessments become paperwork. Guidance should let one DPIA cover a vehicle platform and its fleet, updated when the data flows materially change.
  2. Transfer practicality. The first tier is only as useful as the adequacy list behind it. Until the authority publishes clear standard clauses and a list, operators will negotiate transfer terms without a template.
  3. The fine base. "Annual revenue" is ambiguous for a multinational whose Indonesian sales are a small share of its global turnover. The authority should say which revenue counts.
  4. Enforcement capacity. The six-month runway between promulgation and entry into force is short, and a rule is only as predictable as the agency applying it.

What to do with the gap

Where sector rules are needed, they should address what a general privacy law cannot. Examples are how long crash-event recorder data must be kept, and the standard for law-enforcement access to vehicle location history. On the second point EFF's warning is worth adopting: access should require judicial authorization and a stated purpose, rather than an open door to fleet data. That protects drivers without banning the sensors that make autonomy safe.

Indonesia's accidental outcome is defensible. A technology-neutral, risk-based data law is the better foundation, and the priority for the next four months is guidance that makes it workable, not a new statute.

Sources & Citations

  1. JDIH Kemenko Infra: UU No. 27/2022 on Personal Data Protection
  2. Djohan et al., Legal Reconstruction for Autonomous Vehicle Use in Indonesia (Masalah-Masalah Hukum, Vol. 54 No. 1, 2025)
  3. HLC: Indonesia's PDP Law implementing regulation arrives quietly (GR 33/2026)
  4. Norton Rose Fulbright: Indonesia's new personal data protection rules
  5. EFF: Policy Position on ALPR Surveillance