After nearly four years of waiting, the detailed rules on compliance with Indonesia’s personal data protection law are finally here. Government Regulation No. 33 of 2026 (“GR 33/2026”), the long-anticipated implementing regulation for Law No. 27 of 2022 on Personal Data Protection (“PDP Law”), was signed by President Prabowo Subianto on 16 July 2026. It takes effect on 16 January 2027. Businesses now have roughly four months to prepare. However, there is a challenge. Several provisions in GR 33/2026 require a supervisory authority that does not yet exist. Businesses can act on some of these requirements now, but others will only become actionable once the authority is in place.
Key Takeaways
- GR 33/2026 is the implementing regulation for Indonesia’s personal data protection law. It contains 225 articles across 12 chapters and supplies the procedural detail that the PDP Law, enacted in October 2022, left out.
- The regulation takes effect on 16 January 2027, establishing the operational enforcement framework for administrative fines and sanctions. The parent PDP Law’s substantive obligations have been active since October 2022. Businesses operating in Indonesia or processing Indonesian personal data have approximately four months to achieve compliance with these new procedural rules.
- The regulation establishes six lawful bases for processing: consent, contractual necessity, legal obligation, vital interests, public interest or authority, and legitimate interests. The legitimate interests basis appears for the first time and offers a significant alternative to consent for many processing activities.
- Cross-border data transfers follow a three-tier framework: adequacy determination, binding safeguards, and data subject consent. However, the instruments for the first two tiers depend on a supervisory authority that the government has not yet established.
- Administrative fines can reach 2% of a controller’s annual gross revenue. Under Article 185(2), fine calculations are subject to ten statutory variables, though the regulation does not prescribe a specific calculation methodology. The regulation also provides a detailed enforcement and objection procedure. A 72-hour (3 x 24 hours) response window applies across multiple data subject rights, including access requests, corrections, and breach notifications.
- Businesses should distinguish between self-executing obligations (effective from 16 January 2027 regardless of institutional readiness) and provisions that depend on the supervisory authority (the “Lembaga”) for operationalisation.
Why GR 33/2026 Matters
As recently as October 2022, Indonesia enacted a personal data protection law. It sets out a number of broad principles with serious penalties for non-compliance. Importantly, however, it does not set out the detailed rules for organizations to comply with the new law.
More than twenty matters were deferred by the PDP Law to a government regulation, including provisions on consent, cross-border transfers, breach notification, and the methodology for calculating sanctions. As a result, businesses spent four years operating under a law that imposed obligations without specifying the procedures for meeting them.
GR 33/2026 fills that gap. The government published it in the State Gazette as Lembaran Negara No. 88 of 2026 (Tambahan LN No. 7190). The regulation runs to 225 articles accompanied by a 52-page Elucidation (“Penjelasan”) and addresses virtually every procedural matter the PDP Law left open.
The regulation’s arrival was remarkably quiet. Despite being the most significant Indonesian data protection instrument in four years, GR 33/2026 circulated without a formal government announcement. Indeed, it only reached the broader legal community in late August 2026. There was no public consultation draft, no ministerial press briefing, and no phased implementation guidance. The six-month grace period prescribed by Article 225 simply began running from the date of promulgation.
In practice, this means that businesses in Indonesia have a compliance deadline of 16 January 2027 to comply with the personal data protection law (Indonesia PDP Law). Since the regulatory text has now been published, the preparation time frame is short.
Scope and Architecture of Indonesia’s Personal Data Protection Law
What the Regulation Covers
The regulation spans 12 chapters (BAB I through BAB XII). In scope, it tracks the matters the PDP Law deferred: categories of personal data, data subject rights, controller and processor obligations, lawful bases for processing, cross-border data transfers, data protection impact assessments, data security requirements, supervision and enforcement, administrative sanctions, and dispute resolution. The final chapter covers transitional provisions and the effective date.
Table 1: GR 33/2026 Regulation Architecture
| Chapter | Subject Matter | Key Articles |
|---|---|---|
| BAB I | General Provisions and Definitions | Art. 1–10 |
| BAB II | Controllers, Processors and Joint Controllers | Art. 11–30 |
| BAB III | Processing of Personal Data (incl. lawful bases, consent, data subject rights, ROPA) | Art. 31–109 |
| BAB IV | Transfer and Disclosure of Personal Data | Art. 110–113 |
| BAB V | Personal Data Breach | Art. 114–119 |
| BAB VI | Data Protection Impact Assessment | Art. 120–139 |
| BAB VII | Data Protection Officer | Art. 140–147 |
| BAB VIII | Cross-Border Data Transfer | Art. 148–168 |
| BAB IX | Data Security | Art. 169–178 |
| BAB X | Supervision and Administrative Sanctions | Art. 179–199 |
| BAB XI | Dispute Resolution | Art. 200–222 |
| BAB XII | Transitional and Closing Provisions | Art. 223–225 |
Who the Regulation Applies To
The Indonesia personal data protection law applies beyond Indonesia’s borders. GR 33/2026 maintains the PDP Law’s extraterritorial reach, covering entities outside Indonesia whose processing activities produce legal consequences within the country or that target Indonesian data subjects. Multinational corporations processing Indonesian customer data from regional hubs in Singapore, Hong Kong, or elsewhere fall within scope. They should treat these obligations as applicable to their operations.
Categories of Personal Data
As confirmed by GR 33/2026, the categories of personal data, as stated in the PDP Law, are general personal data (e.g. name, date of birth, ID number) and specific personal data (e.g. health data, biometric data, genetic data, criminal record data, children’s data, and financial data). Businesses must comply with special protection requirements for such data. The supervisory authority may also determine whether other data are classified as specific personal data.
Lawful Bases for Processing: Moving Beyond Consent
The Six Lawful Bases
GR 33/2026 establishes six lawful bases for personal data processing. These are consent of the data subject, contractual necessity, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, and fulfilment of legitimate interests.
This is a significant development. Indonesian data protection practice has long been consent-centric. Many businesses operating in Indonesia have relied on consent as the default (and sometimes only) basis for processing personal data. The PDP Law mentioned other bases but did not elaborate on their conditions or documentation requirements. GR 33/2026 changes that by providing detailed rules for each basis.
Table 2: Lawful Bases for Processing Under GR 33/2026
| Lawful Basis | Key Conditions | Practical Example |
|---|---|---|
| Consent | Freely given, conscious, specific, unambiguous (Art. 32). Pre-collection disclosure required (Art. 62). | Customer agrees to marketing communications via a clear opt-in mechanism. |
| Contractual Necessity | Processing necessary to perform or prepare a contract with the data subject. GR 33/2026 does not specify the criteria for determining when processing is “necessary” for this purpose, which leaves room for interpretation in practice. | Collecting delivery addresses to fulfil e-commerce purchase orders. |
| Legal Obligation | Processing required to comply with a statutory or regulatory obligation. | Retaining employee tax records as mandated by Indonesian tax law. |
| Vital Interests | Processing necessary to protect the life or physical safety of the data subject or another person. | Processing medical data in an emergency situation. |
| Public Interest / Authority | Processing necessary for a public interest task or the exercise of official authority. | Government agency processing census or public health data. |
| Legitimate Interests | Three-part test: necessity, no adverse impact on data subject, mitigation measures (Art. 53). Documented analysis required (Art. 54). | Security monitoring, fraud prevention, network and information security. |
Consent Requirements
Article 32 of the regulation specifies four elements for valid consent. Consent must be:
- freely given,
- informed,
- specific, and
- unambiguous.
Article 62 further requires that before obtaining consent, controllers disclose several items to the data subject. These include the lawfulness of processing, the processing purpose, the types and relevance of data collected, the retention period, details of information collected, the processing timeframe, and the data subject’s rights.
In addition, the regulation prohibits deceptive or misleading consent mechanisms. Notably, the Elucidation of GR33/2026 suggests that businesses may no longer rely on a data subject’s consent to the controller’s general terms and conditions as a basis for processing, since such consent may create ambiguity as to what processing the data subject has actually agreed to. Controllers must also continue to provide goods or services to a data subject who withholds consent, without reducing the quality of those goods or services, unless the processing of personal data is itself necessary to provide them. Where consent accompanies the provision of goods or services, the agreement between controller and data subject must meet nine prescribed conditions (Article 43). Controllers may not include exoneration clauses that purport to exclude their liability to data subjects in any data protection notice (Article 65).
Indirect Collection: The 30-Day Notice Window
When a controller collects personal data indirectly, it must provide the same disclosures required for direct collection. Article 64 sets this deadline at 30 business days from the collection or procurement of the data. However, it is important to understand that the period starts from the date the controller receives or acquires the data and not from the date when it first processes or uses it. For businesses that source personal data through third parties, data brokers, or corporate acquisitions, this means the date of receipt must be tracked as a compliance requirement. The regulation does not specify how a controller should conclusively determine the start of this notification period where receipt is not a single, clearly identifiable event, nor does it address cases where notification could itself have adverse implications or where the controller holds only limited information about the data subject.
Legitimate Interests: A New Compliance Pathway
Article 53 of GR 33/2026 introduces the legitimate interests basis, a genuinely new concept in Indonesian data protection practice. Controllers may rely on legitimate interests where they satisfy the following three conditions.
- They must conduct a balancing analysis of necessity and purpose against the data subject’s rights.
- They must assess that the processing does not adversely affect the data subject.
- They must implement mitigation measures against any potential impact.
The Elucidation provides illustrative examples, including security monitoring, health and safety protection, crime prevention, and network and information security. For businesses that currently collect consent for processing activities that would qualify as legitimate interests under comparable regimes, GR 33/2026 offers a pathway to reduce consent fatigue while maintaining compliance.
Importantly, controllers must document the analysis and assessment and maintain those records (Article 54).
Key Compliance Obligations
Records of Processing Activities
Beyond the ROPA, GR 33/2026 requires controllers and processors to establish and maintain a broader suite of internal policies, records, and procedures, including: a personal data processing policy; a policy, procedure, or guidelines for the prevention and handling of personal data protection failures; a mechanism and policy for handling indemnity (compensation) requests; a personal data retention period policy; a policy on the performance of public interest tasks or exercise of official authority as a basis for processing; the record of processing activities (ROPA); and minutes of the deletion or destruction of personal data.
The processing policy must be prepared in accordance with drafting guidelines to be issued by the supervisory authority, which has not yet been established. Every controller must maintain the ROPA (Article 74). The regulation treats the ROPA as both an activity register and a data-flow map and prescribes thirteen minimum content elements. These cover the controller’s name and contact details, the source and purpose of data collection, the lawful basis, the types and categories of data, third parties with access, data subject rights fulfilment, data flow mapping, retention periods, and technical and organisational security measures. Where a controller engages a processor, that processor must maintain its own record with four additional elements.
The ROPA is where data protection compliance starts. It is the foundation document and typically the first document a regulator will ask for during an investigation. Therefore, before the compliance deadline of January 2027, the priority should be to have the ROPA ready.
Data Protection Impact Assessments
Seven categories of processing trigger a mandatory data protection impact assessment, or DPIA (Article 120). These cover automated decision-making that produces legal or similarly significant effects, large-scale processing of specific personal data, systematic monitoring, and processing involving new technologies. The Elucidation explicitly names artificial intelligence, machine learning, smart technology, and the Internet of Things. The list also covers cross-border data transfers and processing that prevents data subjects from exercising their rights.
Table 3: DPIA Trigger Categories Under Article 120
| Trigger Category | Description |
|---|---|
| Automated Decision-Making | Decisions producing legal or similarly significant effects on data subjects. |
| Large-Scale Specific Data | Large-scale processing of specific (sensitive) personal data, assessed contextually by volume, duration, and geographic scope. |
| Systematic Monitoring | Regular and systematic monitoring of data subjects in a public or accessible area. |
| New Technologies | Processing involving new technologies. The Elucidation explicitly names artificial intelligence, machine learning, smart technology, and the Internet of Things. |
| Cross-Border Transfers | International transfer of personal data to jurisdictions outside Indonesia. |
| Rights Restriction | Processing that may prevent data subjects from exercising their rights under the PDP Law. |
| Combined Risk Factors | Processing activities combining multiple high-risk characteristics from the categories above. |
Notably, the regulation takes a contextual approach to “large-scale processing.” It does not set a fixed numerical threshold. Instead, the number of data subjects, the volume of data, the duration of processing, and the geographic scope all feed into the assessment.
An assessment will need to be updated where there has been a change in the risk profile of processing activities already assessed. Where a DPO has been appointed, a controller must seek the view of that DPO in carrying out the assessment.
Data Protection Officer Appointment
GR 33/2026 sets out the conditions under which a controller must appoint a data protection officer, or DPO (Articles 140 to 147). Constitutional Court Decision MK 151/2024 clarified that the appointment triggers operate as alternative-cumulative (‘and/or’) conditions rather than “and” conditions. Satisfying any single trigger is therefore sufficient.
For the DPO role to be meaningful and not become a tokenistic exercise, GR 33/2026 requires that the DPO function independently and shall participate in all matters relating to personal data processing, have direct access to senior management of the controller, be given adequate resources and operate free from interference in the performance of their duties. In practice, businesses with existing compliance structures may need to adjust reporting lines and governance arrangements to satisfy these conditions.
Data Breach Notification: The 3 x 24-Hour Rule
When a personal data breach occurs, the controller must notify both data subjects and the supervisory authority within 3 x 24 hours (72 hours) (Article 114 onward). However, the clock does not start when the breach happens. It starts when the controller has “established with certainty and on reasonable grounds” (“pasti, patut dan wajar”) that a failure of data protection has taken place.
The notification must include specified content elements. In addition, the controller must maintain documentation of the breach and its response. Furthermore, companies have to establish internal rules for the prevention of data breaches and for handling of such data breaches. A team of employees has to be assigned for the handling of data breaches in the company.
Data Subject Rights and the 72-Hour Response Window
Additionally, GR 33/2026 operationalises data subject rights with a consistent 72-hour response window. Controllers must respond to correction requests within 3 x 24 hours of receipt (Article 71). Controllers must provide access within the same period (Article 77) and deliver copies of personal data within the same timeframe (Article 78). Where a data subject withdraws consent, the controller must cease processing within 3 x 24 hours (Article 92). Suspension or restriction of processing upon request follows the same timeline (Article 99).
Controllers must verify the data subject’s identity before fulfilling any request. Article 25 mandates a “proportional mechanism” for this verification. In practice, the level of identity checking should match the sensitivity and risk of the request.
Cross-Border Data Transfers: The Framework and Its Gaps
The Three-Tier Transfer Hierarchy
Cross-border transfers of personal data follow a three-tier framework (Articles 160 to 168). The hierarchy is mandatory, meaning controllers must apply the tiers in sequence rather than choosing freely among them.
- Tier 1 is an adequacy determination. The supervisory authority assesses whether the receiving jurisdiction provides an equivalent level of personal data protection. The regulation sets out detailed assessment criteria, covering the receiving country’s legal framework, the existence and effectiveness of an independent supervisory body, international commitments, and reciprocity arrangements.
- Tier 2 applies where no adequacy determination exists. Controllers may transfer data using appropriate safeguards, including standard contractual clauses (to be published by the supervisory authority), binding corporate rules (requiring supervisory authority approval), or other legally binding instruments between controllers.
- Tier 3 is the consent fallback. A transfer may proceed on the basis of data subject consent. However, the regulation imposes strict conditions: the transfer must be non-recurring, involve a limited number of data subjects, and follow a completed risk assessment. The controller must also disclose the transfer and its risks to both the supervisory authority and the data subjects.
Table 4: Cross-Border Transfer Hierarchy
| Tier | Mechanism | Key Requirements | Current Status |
|---|---|---|---|
| Tier 1 | Adequacy Determination | Supervisory authority assesses equivalent data protection in the receiving jurisdiction. Covers legal framework, independent supervisory body, international commitments, and reciprocity. | Unavailable; Lembaga not yet established |
| Tier 2 | Binding Safeguards | Standard contractual clauses (Lembaga-published), binding corporate rules (Lembaga-approved), or other legally binding instruments between controllers. | Unavailable; instruments pending Lembaga |
| Tier 3 | Data Subject Consent | Non-recurring transfer, limited number of data subjects, completed risk assessment. Controller must disclose to both Lembaga and data subjects. | Available; subject to strict conditions |
The Missing Infrastructure
This is where GR 33/2026 reveals its most significant practical challenge. The adequacy list, the standard contractual clauses, and the binding corporate rules approval procedures all depend on the Lembaga. As of September 2026, the Lembaga does not exist. Its establishment requires a Presidential Regulation that the government has not yet issued. Meanwhile, Constitutional Court Case MK 236/2024, which could compel the executive to act, remains pending.
The transitional provision in Article 223 offers limited guidance. Controllers and processors may continue processing pending the issuance of Lembaga regulations, provided their activities do not conflict with GR 33/2026 itself. In practice, this creates a compliance floor but falls short of a safe harbour. Businesses transferring personal data across borders should therefore document the legal basis for each transfer and map their data flows. They should also prepare contractual frameworks that they can adapt once the Lembaga-issued instruments become available.
The most defensible approach, for now, is to implement transfer safeguards aligned with the regulation’s stated principles, even without the formal instruments. Doing nothing while waiting for the Lembaga is not a viable compliance strategy.
Enforcement, Sanctions, and Dispute Resolution
Administrative Sanctions
GR 33/2026 graduates the sanctions across several tiers (Articles 184 to 199). The Lembaga may impose a written warning, temporarily suspend processing activities, order the deletion or destruction of personal data, or levy an administrative fine of up to 2% of annual revenue. Article 185 defines “revenue” as gross economic inflows from normal business activities that increase equity, excluding contributions from investors. Because this captures gross revenue rather than net profit, the potential exposure is substantially larger than it might first appear. Notably, an administrative fine may also be reduced to zero in certain circumstances, although the regulation does not detail what those circumstances are.
Under Article 185(2), fine calculations are subject to ten statutory variables. These are: the negative impact caused by the violation, the duration of the violation, the type of personal data affected, the number of data subjects affected, how the violation was discovered, the level of transparency and cooperation shown by the controller or processor during the examination process, the business scale of the entity, the entity’s ability to pay, the entity’s compliance, and any other relevant variables that the supervisory authority may determine.
It is important to note that the regulation does not prescribe a specific formula or methodology for translating these variables into a fine amount. Article 185(4) provides that the calculation will follow non-tax state revenue regulations, and Article 187 defers the detailed procedure to future regulations issued by the supervisory authority. Under certain circumstances, the fine may be set at Rp 0.00 (Article 185(3)).
Table 5: Ten Fine-Calculation Variables (Art. 184–199)
| No. | Variable | Measurement Approach |
|---|---|---|
| a | Negative impact of the violation | The severity and downstream consequences of the breach will directly influence the fine. Controllers should document containment measures and impact assessments. |
| b | Duration of the violation | How long the violation persisted. Prolonged violations or delayed detection could increase exposure. |
| c | Type of personal data affected | Violations involving specific (sensitive) personal data, such as health, biometric, or financial records, are likely to attract higher penalties. |
| d | Number of data subjects affected | The scale of affected individuals. Mass-impact violations carry greater regulatory weight. |
| e | Process of discovering the violation | Whether the violation was self-reported, discovered by the regulator, or reported by a third party. Self-reporting may be viewed favourably. |
| f | Transparency and cooperation during examination | The controller’s or processor’s openness and cooperation during the regulatory investigation. Active obstruction or non-responsiveness would weigh against the entity. |
| g | Business scale of the controller or processor | Larger enterprises may face proportionally different treatment. This aligns the fine to the entity’s size and market position. |
| h | Number of Data Subjects | A financial capacity assessment. This variable aligns the fine to the entity’s actual financial position, potentially moderating the amount for smaller organisations. |
| i | Compliance of the controller or processor | The entity’s overall compliance with data protection obligations. A pattern of non-compliance could result in heavier penalties. |
| j | Other relevant variables determined by the supervisory authority | A catch-all provision granting the Lembaga discretion to consider additional factors. The scope of this variable will become clearer once the supervisory authority begins issuing decisions. |
Objection and Appeal
Controllers and processors may file an objection within 14 working days of receiving an administrative sanction decision. Critically, filing an objection does not automatically suspend enforcement of the sanction. Accordingly, a business facing an administrative fine may need to pay or provision for that amount even while contesting it through the PTUN. Because the fine base is top-line gross revenue, the sums involved can be substantial. For CFOs and treasury teams, this creates a working-capital and liquidity consideration that should be factored into compliance planning. Appeal to the administrative court (“Pengadilan Tata Usaha Negara”) remains available as a further remedy.
Dispute Resolution Pathways
GR 33/2026 establishes three parallel pathways for resolving data protection disputes: arbitration, the courts, and Lembaga-facilitated mediation (Articles 200 to 222).
The regulation sets out a detailed mediation framework. Seven governing principles apply: low cost, effectiveness, benefit, accessibility, balance, confidentiality, and fairness. The initial mediation period is 30 days, extendable once by an additional 30 days. A successful mediation produces a peace agreement (“kesepakatan perdamaian”). The Lembaga appoints mediators.
Data subjects have standing to sue and receive compensation for any violation of their rights, regardless of which specific right the controller breached (Article 105). Compensation claims follow a prescribed procedure. The data subject submits the claim to the controller, who must assess and respond. If the parties reach no agreement, the dispute proceeds to the courts (Articles 106 to 108).
Enforcement Before the Lembaga
Until the government establishes the Lembaga, the Ministry of Communication and Digital Affairs (“Komdigi”) enforces Indonesia’s personal data protection law using pre-existing instruments. Komdigi has already shown willingness to act on data protection matters through its PSE (electronic system operator) registration regime and periodic enforcement sweeps. Accordingly, businesses should not assume that the absence of the Lembaga means the absence of enforcement.
Data Protection in Corporate Transactions
Joint Controllership
GR 33/2026 provides important clarity on joint controllership (Articles 11 and 12). Where two or more controllers jointly determine the purposes and means of processing, the regulation treats them as joint controllers (“Pengendali Data Pribadi Bersama”). It confirms that joint controllers bear joint and several liability (“tanggung renteng”) for their processing activities. Each joint controller must provide prescribed additional disclosures to data subjects, including information about all controllers involved, the relationship between their respective processing activities, and a designated shared contact point (Article 63).
M&A, Restructuring, and Dissolution
The regulation addresses data handling in corporate transactions, including mergers, acquisitions, restructurings, and dissolutions. Controllers must notify data subjects both before and after such transactions. The notice must disclose the transfer details, the identity of the new controller, the intended processing purposes, timing, and the data subject’s objection mechanisms.
Between the signing of a transaction agreement and its legal completion, the regulation treats the parties as joint controllers. As a result, joint and several liability attaches from the moment the parties sign the agreement, not from the moment the transaction closes. For deal practitioners, this has direct implications for the structuring of share purchase agreements, asset transfers, and transitional services arrangements. Consequently, data protection due diligence is no longer optional in Indonesian M&A; it is a regulatory requirement.
Preparing for Compliance: What Businesses Should Do Before January 2027
Self-Executing Obligations versus Lembaga-Dependent Provisions
Not every obligation in GR 33/2026 takes effect in the same way. Some provisions are self-executing: they impose clear requirements that controllers can and must satisfy without any further regulatory action. Others depend on the Lembaga for operationalisation, whether through the issuance of adequacy determinations, approval of binding corporate rules, or publication of standard contractual clause templates.
Importantly, the transitional provision in Article 223 addresses only Lembaga-dependent obligations. It does not excuse compliance with self-executing requirements. Businesses should therefore treat all self-executing obligations as enforceable from 16 January 2027.
Practical Steps
Businesses operating in Indonesia or processing Indonesian personal data should take the following steps before the compliance deadline.
- Map current processing activities and build or update the record of processing activities. The ROPA is the foundational compliance document and the basis for demonstrating readiness to regulators.
- Review the lawful basis for each processing activity and, if currently only consent is used and processing for legitimate interests is more appropriate, prepare the necessary balancing test and required documentation.
- Verify whether the conditions as outlined in MK 151/2024 require the appointment of a DPO and check whether the current organizational structure satisfies the independence requirements as stipulated in MK 151/2024.
- Audit cross-border transfers of personal data and document the legal basis for each transfer of personal data. Prepare contract clauses which can be updated when regulations are issued by the Lembaga.
- Develop procedures to notify data breach within 72 hours. Establish a team to handle such breaches, and procedures internally to notify of a data breach.
- Conduct a data protection impact assessment for high-risk processing, especially the processing that uses artificial intelligence, machine learning, smart technologies, Internet of Things, cross-border transfer of personal data and processing that restricts data subjects’ right.
- Review all privacy notices for both directly and indirectly collected data. Ensure notices are complete, accessible, and free of exoneration clauses. For data obtained through indirect collection, confirm that the 30-day notification deadline can be met.
- Prepare data subject request workflows with proportional identity verification and 72-hour response protocols for access, correction, deletion, and portability requests.
Monitoring the Regulatory Landscape
Several developments will shape how the Indonesia personal data protection law framework evolves over the coming months. Businesses should monitor the following: establishment of the Lembaga, issuance of adequacy determinations, publication of standard contractual clause templates and binding corporate rules approval procedures, DPIA methodology guidance, and the outcome of Constitutional Court Case MK 236/2024. The last of these could impose a judicial deadline on the executive to establish the supervisory authority.
Partner Perspective
“GR 33/2026 is the most consequential development in Indonesian data protection since the PDP Law was enacted in October 2022. For four years, businesses operated under a law that imposed obligations without telling them how to comply. That period is now over.”
Three aspects of this regulation deserve particular attention from our clients.
First, the compliance window is real but narrow. Businesses have until 16 January 2027, roughly four months from the time this regulation became widely known. The government issued GR 33/2026 without public consultation or phased guidance, and the regulatory text only reached the broader legal community in late August 2026. This is not a situation where businesses can wait for further clarification. The self-executing obligations (building a ROPA, reviewing lawful bases, preparing breach notification procedures, conducting DPIAs, and updating privacy notices) are enforceable from that date regardless of whether the supervisory authority exists.
Second, the absence of the Lembaga creates a genuine structural gap, but not a compliance holiday. The cross-border transfer framework is the starkest illustration: two of the three transfer tiers are inoperable without the supervisory authority, and the remaining tier (data subject consent) is deliberately constrained to non-recurring, limited-scope transfers. This means that businesses with routine cross-border data flows, including multinationals processing Indonesian data from regional hubs, cannot rely on any of the regulation’s formal transfer mechanisms today. Our advice is to document every cross-border transfer, prepare contractual safeguards aligned with the regulation’s stated principles, and design those instruments to be upgraded once the Lembaga publishes its standard contractual clauses and binding corporate rules templates. Doing nothing while waiting is not defensible.
Third, the legitimate interests basis is a significant opportunity that many businesses are not yet prepared to use. Indonesian data protection practice has been heavily consent-centric. GR 33/2026 introduces a genuine alternative: the legitimate interests basis under Article 53, which allows processing without consent where a documented balancing analysis demonstrates that the controller’s interests do not override the data subject’s rights. For activities such as fraud prevention, security monitoring, and network protection, this is a substantial compliance simplification. However, it requires upfront documentation (the balancing analysis and its maintenance) that most organisations have not built. Businesses should identify processing activities currently resting on consent that would be better served by the legitimate interests basis and begin preparing the required assessments.
Beyond these three points, deal practitioners should note that GR 33/2026 has direct implications for corporate transactions. The regulation treats parties to a signed but uncompleted transaction as joint controllers, meaning joint and several liability attaches from signing, not from closing. Data protection due diligence is now a regulatory requirement in Indonesian M&A, not merely best practice. Share purchase agreements, asset transfers, and transitional services arrangements will need to reflect this.
Finally, the enforcement picture is not as empty as it might seem. The Ministry of Communication and Digital Affairs (Komdigi) retains enforcement authority until the Lembaga is established, and it has already demonstrated a willingness to act through its PSE registration regime. Administrative fines of up to 2% of gross revenue (not net profit) represent a material financial exposure. Businesses should treat the January 2027 deadline as firm and allocate resources accordingly.
Frequently Asked Questions
1. What is GR 33/2026?
GR 33/2026 is the implementing regulation for Indonesia’s Personal Data Protection Law (Law No. 27 of 2022). President Prabowo Subianto signed it on 16 July 2026. It provides the detailed procedural rules that businesses need to comply with the PDP Law. The regulation contains 225 articles across 12 chapters. These cover lawful bases for processing, data subject rights, cross-border transfers, breach notification, sanctions, and dispute resolution.
2. When does GR 33/2026 take effect?
The regulation takes effect six months after promulgation, which places the compliance deadline at approximately 16 January 2027.
3. Does the Indonesia personal data protection law apply to businesses outside Indonesia?
Yes. The PDP Law and GR 33/2026 apply extraterritorially. Any entity outside Indonesia whose processing activities produce legal consequences within Indonesia or that target Indonesian data subjects falls within scope.
4. What are the lawful bases for processing personal data under GR 33/2026?
There are six lawful bases: consent, contractual necessity, legal obligation, vital interests, public interest or authority, and legitimate interests. The regulation provides detailed conditions for each basis. The legitimate interests basis is available for the first time. It allows processing without consent where a documented balancing analysis demonstrates that the controller’s interests do not override the data subject’s rights.
5. What are the penalties for non-compliance?
Administrative sanctions include written warnings, temporary processing suspensions, data deletion or destruction, and fines of up to 2% of annual gross revenue. Under Article 185(2), fine calculations are subject to ten statutory variables, including the negative impact of the violation, the number of affected data subjects, and the level of transparency and cooperation shown during examination.
6. How quickly must a business respond to a data subject request?
Controllers must fulfil most data subject requests within 3 x 24 hours (72 hours). This timeline applies to access requests, correction requests, data copies, consent withdrawal, and requests for suspension or restriction of processing.
7. What triggers the requirement for a data protection impact assessment?
Seven categories of processing require a DPIA. These include automated decision-making, large-scale processing of specific data, systematic monitoring, processing involving new technologies (the regulation explicitly names AI, machine learning, and IoT), cross-border transfers, and processing that may prevent data subjects from exercising their rights.
8. Is a data protection officer required?
GR 33/2026 sets out conditions for DPO appointment, and Constitutional Court Decision MK 151/2024 confirmed that these are “or” conditions. Satisfying any single trigger requires the appointment of a DPO. The DPO must have operational independence, direct access to senior management, and adequate resources.
9. How does GR 33/2026 regulate cross-border data transfers?
Cross-border transfers follow a mandatory three-tier hierarchy. The first tier is an adequacy determination by the supervisory authority. Where no adequacy finding exists, the second tier allows transfers using standard contractual clauses, binding corporate rules, or other binding instruments. The third tier permits transfers based on data subject consent under limited conditions. Because the government has not yet established the supervisory authority, the instruments for the first two tiers remain unavailable.
10. What should businesses do while the supervisory authority (Lembaga) is still pending?
Focus on self-executing obligations that do not depend on the Lembaga. Build the ROPA, review lawful bases, prepare breach notification procedures, conduct DPIAs, and update privacy notices. For cross-border transfers, document the legal basis for each flow and prepare contractual frameworks ready for adaptation once Lembaga instruments appear. Article 223’s transitional provision allows continued processing pending Lembaga regulations. It does not, however, excuse compliance with obligations that businesses can meet independently.
About Nusantara DFDL Partnership
Nusantara DFDL Partnership (NDP) is an Indonesian law firm and a member of the DFDL network, which operates across Southeast Asia. NDP advises foreign corporations, institutional investors, and Indonesian businesses across a full suite of corporate legal services, including corporate advisory, mergers and acquisitions, foreign direct investment, joint ventures, employment law, real estate, dispute resolution, restructuring, and cross-border transactions. NDP works with clients across sectors including digital infrastructure, financial services, energy, manufacturing, and property.
Disclaimer
This article is for general informational purposes only and does not constitute legal advice. Regulatory requirements in this area are subject to change. Readers should seek legal advice before taking steps to restructure, merge, transfer, dissolve, or otherwise reorganise an Indonesian entity or group.