After nearly four years of waiting, Indonesia finally has the operational rulebook its data protection law always promised. On 16 July 2026, the government signed Government Regulation No. 33 of 2026, the long-delayed implementing regulation for Law No. 27 of 2022 on Personal Data Protection. For companies that collect, store, or process personal data in Indonesia, this new personal data protection regulation is not a document to file away for later. It sets out concrete obligations, firm deadlines, and real financial exposure, and it gives businesses only six months to get ready.
What Is GR 33/2026, Exactly?
GR 33/2026 is a sweeping instrument, running to 225 articles across twelve chapters, with an explanatory memorandum of similar length. It does not rewrite the framework established by the 2022 PDP Law. Instead, it translates that law’s broad principles into specific, checkable requirements: how consent must be obtained, what a data breach notice must contain, when a Data Protection Officer is mandatory, and how personal data may legally leave Indonesian borders.
The regulation was promulgated on 16 July 2026 but only began circulating publicly in late August, several weeks after it was signed, and ahead of any formal government announcement. That quiet rollout does not change its legal weight. Under Article 225, GR 33/2026 takes effect six months after promulgation, which places the compliance deadline on 16 January 2027. Companies that assume they have more time are working from the wrong calendar.
Five Things That Change Under the New Rules
1. Consent and Lawful Basis Get More Structure
GR 33/2026 dedicates a full chapter to the six lawful bases for processing personal data recognized under Article 20 of the PDP Law, and each basis now comes with its own notice duties and documentation requirements. Businesses relying on “legitimate interest,” for instance, are expected to conduct and keep a documented Legitimate Interest Assessment covering situations such as security monitoring or fraud prevention.
2. Data Protection Officers Become a Real Obligation
The regulation sets out clear triggers for when a company must appoint a Data Protection Officer, along with governance expectations for how that role functions within the organization. This is no longer a best-practice recommendation; for companies that meet the triggers, it is a compliance requirement with its own sanctions for non-appointment.
3. Data Protection Impact Assessments Are Now Mandatory for High-Risk Processing
Where processing activities fall into high-risk categories, a Data Protection Impact Assessment must be completed before the processing begins. The regulation lists broad triggers rather than fixed numerical thresholds, so companies need to weigh factors like data volume, sensitivity, duration, and the number of individuals affected. The assessment must document the necessity of the processing, the risks involved, and the mitigation steps taken, and any recommendations from the Data Protection Officer must be considered and recorded.
4. Cross-Border Data Transfers Follow a Three-Tier Framework
For companies that send Indonesian personal data abroad, whether to a regional headquarters, a cloud provider, or a global HR system, GR 33/2026 sets out a structured framework built on adequacy of the destination jurisdiction, binding legal instruments such as standard contractual clauses or approved binding corporate rules, and consent as a narrow, limited option. Companies must map the full transfer cycle, confirm that only necessary data is being transferred, and identify the legal instrument justifying the transfer before it happens.
5. Breach Notification Runs on a 72-Hour Clock
The regulation confirms a 72-hour window for notifying the authorities of a personal data breach once the incident has been established with reasonable certainty, supported by documentation. Waiting to “be sure” before starting an internal investigation is no longer a safe strategy. Incident response plans need to build in that clock from the moment a possible breach is detected.
The Cost of Getting It Wrong
Administrative sanctions under GR 33/2026 can reach up to 2% of a company’s annual gross revenue, calculated on total economic inflow rather than net profit. Fines apply across a wide range of failures, including missing legal basis for processing, unmet data subject rights requests, improper cross-border transfers, absent DPIA or records of processing, and unreported breaches. The regulation also creates a bridge to criminal liability in more serious cases, alongside the civil and contractual exposure companies already face from clients and business partners.
One caveat worth noting: Indonesia’s dedicated Data Protection Authority, the body expected to enforce these rules, has not yet been formally established. A presidential regulation creating that authority was still pending as of mid-2026. That gap does not weaken the obligations under GR 33/2026, and companies should not treat it as a reason to delay compliance work.
Who Actually Needs to Act
GR 33/2026 applies broadly to any data controller or processor handling personal data connected to Indonesia, and the underlying PDP Law has extraterritorial reach. That means the regulation is relevant to Indonesian companies of every size, multinational businesses with Indonesian operations or customers, and foreign companies offering goods or services to people in Indonesia even without a local office. Sectors that already handle sensitive categories of data, such as finance, healthcare, insurance, e-commerce, and technology platforms, are likely to feel the impact first.
Getting Ready Before January 2027
Six months sounds like a reasonable runway, but for companies without mature privacy governance, the list of tasks is long. A realistic preparation plan generally covers:
- Mapping what personal data is collected, where it flows, and why it is being processed
- Reviewing privacy notices and consent mechanisms against the six lawful bases
- Assessing whether the DPO appointment triggers apply to the business
- Building or updating a register of processing activities and a written retention policy
- Reviewing vendor and cross-border data arrangements against the new three-tier framework
- Testing the incident response plan against the 72-hour notification clock
Companies that have already invested in privacy governance, whether through GDPR alignment or earlier voluntary compliance work, will find much of this familiar. Those starting from scratch should treat the coming months as the real deadline, not a buffer.
Practical Support for the Road Ahead
Regulatory readiness is only part of running a resilient business. Many of the companies we advise on personal data protection regulation compliance also face a related challenge: protecting cash flow while managing growing volumes of corporate receivables. Data governance failures and payment disputes tend to surface in the same conversations, since both come down to how well a company manages risk before it becomes a legal problem.
Through our practice areas, we offer Professional Debt Management services built specifically for finance executives handling high volumes of corporate accounts receivable. Our approach combines profiling, legal strategy, negotiation structure, and recovery execution, drawing on legal, commercial, and financial governance perspectives so companies can maintain stable cash flow without damaging the business relationships they have worked to build.
If your company needs help preparing for GR 33/2026 or managing corporate receivables with the same discipline the new regulation expects for data, you can reach out to our team on WhatsApp to start the conversation.


