Indonesia has no dedicated autonomous vehicle law. A 2025 peer-reviewed study in Masalah-Masalah Hukum found that its traffic statutes lack AV provisions altogether, leaving a regulatory gap. Yet from 16 January 2027 every connected or driverless car operating there will fall under a detailed data-governance regime. Government Regulation No. 33 of 2026 (GR 33/2026) implements the Personal Data Protection Law (Law 27/2022, enacted 17 October 2022) and does not mention vehicles once.
According to the Indonesian law firm HLC, President Prabowo signed the regulation on 16 July 2026. It reached public view only in late August, and HLC's first analysis appeared on 31 August. That is a quiet arrival for the rulebook that will shape how vehicle data is collected, assessed and exported.
What the regulation asks of a vehicle operator
Three obligations matter most for a connected fleet.
- Impact assessments. HLC reports that Article 120 lists seven categories of high-risk processing requiring a data protection impact assessment (DPIA). Two are relevant here: automated decision-making with legal or significant effects, and new technologies, expressly named as artificial intelligence, machine learning, smart technology and the internet of things. Norton Rose Fulbright's summary also treats AI-enabled decision-making, biometrics and large-scale processing as DPIA triggers.
- Cross-border transfers. HLC describes a three-tier ladder: transfer to a country on the authority's adequacy list; failing that, binding safeguards such as standard contractual clauses or approved binding corporate rules; and only then explicit consent, limited to non-recurring transfers involving a limited number of data subjects.
- Penalties and breach duties. Norton Rose Fulbright reports administrative fines of up to 2% of annual revenue, alongside possible suspension of processing and destruction of data, and a 72-hour breach notification window.
Mapping these onto cars is our inference, since the text is technology-neutral. A vehicle with cameras, location tracking, driver monitoring and over-the-air telemetry is an AI-and-IoT system by any plain reading. An operator sending sensor data to a foreign headquarters or cloud for model training will almost certainly need the second tier. The consent tier is too narrow for continuous telemetry from a whole fleet.
The strongest case for tight rules
The case for caution is serious. A vehicle is a moving sensor platform, and location history is among the most revealing data there is. The Electronic Frontier Foundation's August 2026 policy position on automated license plate readers describes how such systems build a searchable map of everywhere a driver goes, queried by police and private vendors long after the fact. EFF argues that this risk cannot be configured away. Indonesia also has no AV statute to fall back on, so a regulator who wants binding limits today has only GR 33/2026. Ex ante impact assessments, the tool this regulation uses, are a reasonable way to surface those risks before deployment rather than after a breach.
Why proportionality still points away from a new AV data law
The ALPR analogy has limits. A plate-reader network exists to track everyone regardless of suspicion. An AV operator collects data to perform a driving function and can be held to purpose limitation, retention limits and security duties. That is exactly what a general, risk-based data protection law does, and it does so without freezing the technology into vehicle-specific rules that will age badly.
That suggests Indonesia should let GR 33/2026 do the data work and keep the driverless-vehicle safety rules now being drafted focused on safety, licensing and liability. Layering a second, vehicle-specific data regime on top would duplicate obligations and raise costs for early pilots, with little privacy gain.
The regulation is not free of problems, and four points deserve clarification before January.
- DPIA scope. If "new technologies" including IoT means a fresh assessment for every connected product, assessments become paperwork. Guidance should let one DPIA cover a vehicle platform and its fleet, updated when the data flows materially change.
- Transfer practicality. The first tier is only as useful as the adequacy list behind it. Until the authority publishes clear standard clauses and a list, operators will negotiate transfer terms without a template.
- The fine base. "Annual revenue" is ambiguous for a multinational whose Indonesian sales are a small share of its global turnover. The authority should say which revenue counts.
- Enforcement capacity. The six-month runway between promulgation and entry into force is short, and a rule is only as predictable as the agency applying it.
What to do with the gap
Where sector rules are needed, they should address what a general privacy law cannot. Examples are how long crash-event recorder data must be kept, and the standard for law-enforcement access to vehicle location history. On the second point EFF's warning is worth adopting: access should require judicial authorization and a stated purpose, rather than an open door to fleet data. That protects drivers without banning the sensors that make autonomy safe.
Indonesia's accidental outcome is defensible. A technology-neutral, risk-based data law is the better foundation, and the priority for the next four months is guidance that makes it workable, not a new statute.