Indonesia’s New Personal Data Protection Regulation (GR 33/2026): What Every Company Must Do Now

Table of Contents

After nearly four years of waiting, Indonesia finally has the operational rulebook its data protection law always promised. On 16 July 2026, the government signed Government Regulation No. 33 of 2026, the long-delayed implementing regulation for Law No. 27 of 2022 on Personal Data Protection. For companies that collect, store, or process personal data in Indonesia, this new personal data protection regulation is not a document to file away for later. It sets out concrete obligations, firm deadlines, and real financial exposure, and it gives businesses only six months to get ready.

What Is GR 33/2026, Exactly?

GR 33/2026 is a sweeping instrument, running to 225 articles across twelve chapters, with an explanatory memorandum of similar length. It does not rewrite the framework established by the 2022 PDP Law. Instead, it translates that law’s broad principles into specific, checkable requirements: how consent must be obtained, what a data breach notice must contain, when a Data Protection Officer is mandatory, and how personal data may legally leave Indonesian borders.

The regulation was promulgated on 16 July 2026 but only began circulating publicly in late August, several weeks after it was signed, and ahead of any formal government announcement. That quiet rollout does not change its legal weight. Under Article 225, GR 33/2026 takes effect six months after promulgation, which places the compliance deadline on 16 January 2027. Companies that assume they have more time are working from the wrong calendar.

Five Things That Change Under the New Rules

1. Consent and Lawful Basis Get More Structure

GR 33/2026 dedicates a full chapter to the six lawful bases for processing personal data recognized under Article 20 of the PDP Law, and each basis now comes with its own notice duties and documentation requirements. Businesses relying on “legitimate interest,” for instance, are expected to conduct and keep a documented Legitimate Interest Assessment covering situations such as security monitoring or fraud prevention.

2. Data Protection Officers Become a Real Obligation

The regulation sets out clear triggers for when a company must appoint a Data Protection Officer, along with governance expectations for how that role functions within the organization. This is no longer a best-practice recommendation; for companies that meet the triggers, it is a compliance requirement with its own sanctions for non-appointment.

3. Data Protection Impact Assessments Are Now Mandatory for High-Risk Processing

Where processing activities fall into high-risk categories, a Data Protection Impact Assessment must be completed before the processing begins. The regulation lists broad triggers rather than fixed numerical thresholds, so companies need to weigh factors like data volume, sensitivity, duration, and the number of individuals affected. The assessment must document the necessity of the processing, the risks involved, and the mitigation steps taken, and any recommendations from the Data Protection Officer must be considered and recorded.

4. Cross-Border Data Transfers Follow a Three-Tier Framework

For companies that send Indonesian personal data abroad, whether to a regional headquarters, a cloud provider, or a global HR system, GR 33/2026 sets out a structured framework built on adequacy of the destination jurisdiction, binding legal instruments such as standard contractual clauses or approved binding corporate rules, and consent as a narrow, limited option. Companies must map the full transfer cycle, confirm that only necessary data is being transferred, and identify the legal instrument justifying the transfer before it happens.

5. Breach Notification Runs on a 72-Hour Clock

The regulation confirms a 72-hour window for notifying the authorities of a personal data breach once the incident has been established with reasonable certainty, supported by documentation. Waiting to “be sure” before starting an internal investigation is no longer a safe strategy. Incident response plans need to build in that clock from the moment a possible breach is detected.

The Cost of Getting It Wrong

Administrative sanctions under GR 33/2026 can reach up to 2% of a company’s annual gross revenue, calculated on total economic inflow rather than net profit. Fines apply across a wide range of failures, including missing legal basis for processing, unmet data subject rights requests, improper cross-border transfers, absent DPIA or records of processing, and unreported breaches. The regulation also creates a bridge to criminal liability in more serious cases, alongside the civil and contractual exposure companies already face from clients and business partners.

One caveat worth noting: Indonesia’s dedicated Data Protection Authority, the body expected to enforce these rules, has not yet been formally established. A presidential regulation creating that authority was still pending as of mid-2026. That gap does not weaken the obligations under GR 33/2026, and companies should not treat it as a reason to delay compliance work.

Who Actually Needs to Act

GR 33/2026 applies broadly to any data controller or processor handling personal data connected to Indonesia, and the underlying PDP Law has extraterritorial reach. That means the regulation is relevant to Indonesian companies of every size, multinational businesses with Indonesian operations or customers, and foreign companies offering goods or services to people in Indonesia even without a local office. Sectors that already handle sensitive categories of data, such as finance, healthcare, insurance, e-commerce, and technology platforms, are likely to feel the impact first.

Getting Ready Before January 2027

Six months sounds like a reasonable runway, but for companies without mature privacy governance, the list of tasks is long. A realistic preparation plan generally covers:

  • Mapping what personal data is collected, where it flows, and why it is being processed
  • Reviewing privacy notices and consent mechanisms against the six lawful bases
  • Assessing whether the DPO appointment triggers apply to the business
  • Building or updating a register of processing activities and a written retention policy
  • Reviewing vendor and cross-border data arrangements against the new three-tier framework
  • Testing the incident response plan against the 72-hour notification clock

Companies that have already invested in privacy governance, whether through GDPR alignment or earlier voluntary compliance work, will find much of this familiar. Those starting from scratch should treat the coming months as the real deadline, not a buffer.

Practical Support for the Road Ahead

Regulatory readiness is only part of running a resilient business. Many of the companies we advise on personal data protection regulation compliance also face a related challenge: protecting cash flow while managing growing volumes of corporate receivables. Data governance failures and payment disputes tend to surface in the same conversations, since both come down to how well a company manages risk before it becomes a legal problem.

Through our practice areas, we offer Professional Debt Management services built specifically for finance executives handling high volumes of corporate accounts receivable. Our approach combines profiling, legal strategy, negotiation structure, and recovery execution, drawing on legal, commercial, and financial governance perspectives so companies can maintain stable cash flow without damaging the business relationships they have worked to build.

If your company needs help preparing for GR 33/2026 or managing corporate receivables with the same discipline the new regulation expects for data, you can reach out to our team on WhatsApp to start the conversation.

Frequently Asked Questions

It was signed on 16 July 2026 and became legally effective on 16 January 2027, six months after promulgation.

Yes. The underlying PDP Law has extraterritorial effect, so businesses offering goods or services to individuals in Indonesia can fall within scope regardless of where they are based.

Administrative sanctions can reach up to 2% of a company’s annual gross revenue, with the actual amount depending on the circumstances of the violation.

Not yet. As of the regulation’s issuance, the presidential regulation establishing the authority was still pending, though this does not delay companies’ compliance obligations.

Only companies that meet the specific triggers set out in GR 33/2026, such as processing certain volumes or categories of personal data, are required to appoint one.

Consult Your Legal Needs

Reach out to us for initial guidance on your legal inquiries.

Share the Post:
Related Posts