Indonesia's New Data Protection Rules Take Effect in January 2027

09 Sep 2026

Indonesia's New Data Protection Rules Take Effect in January 2027

Four years after Indonesia passed Law No. 27 of 2022 on Personal Data Protection (the "PDP Law"), businesses finally have the implementing regulation they've been waiting for: Government Regulation No. 33 of 2026 on the Implementation of Law No. 27 of 2022 on Personal Data Protection ("PP 33/2026"). Its arrival matters because much of the PDP Law was written in broad strokes, leaving organizations without clear guidance on how to actually comply with it in practice.

PP 33/2026 was signed on 16 July 2026, runs to 225 articles, and takes full effect on 16 January 2027 — six months after enactment. For businesses and organizations that process personal data in Indonesia, that's not a lot of runway to bring policies, systems, and day-to-day practices in line with the new rules.


Who Does This Apply To?


Short answer: almost everyone. GR 33/2026 covers any individual, company, public body, or international organization that processes personal data within Indonesian territory — from small online stores and startups to e-commerce platforms, fintechs, hospitals, and state-owned banks. There's no exemption for being small or not having a legal team; the baseline obligations apply to anyone collecting, storing, or processing personal data, whether it belongs to customers or employees.


What Does It Actually Regulate?


PP 33/2026 fills in a lot of the technical detail the PDP Law left open. The parts most relevant to businesses include:

Data classification. The regulation draws a clear line between general personal data — full name, gender, nationality, religion, marital status — and specific personal data that requires stronger protection, such as health records, biometric data, genetic data, criminal records, children's data, and personal financial data.

Data subject rights. This covers the mechanics of how individuals can object to automated processing and how they can seek compensation if their data is mishandled.

Controller and processor obligations. This is the heavier part for businesses to absorb: every data controller must adopt an internal data processing policy aligned with the supervisory authority's guidelines, carry out a Data Protection Impact Assessment (DPIA) for high-risk processing, and appoint a Data Protection Officer (referred to locally as PPDP).

Data breach handling. The regulation sets out notification requirements to both the public and the authority in the event of a data breach or protection failure — so incidents can no longer just be quietly managed and hoped away.

Cross-border data transfers. Transfers outside Indonesian jurisdiction are only permitted if the destination country offers an equivalent or higher standard of data protection. If it doesn't, the controller has to put binding safeguards in place, typically through a contract or another legally binding instrument.


The Part That Makes Businesses Nervous: Sanctions


This is where most of the attention has landed. Article 184 sets out four types of administrative sanctions — a written warning, a temporary suspension of processing activities, deletion or destruction of data, and an administrative fine — and all four can be imposed together, with or without a prior warning.

On the fine itself, Article 185 caps it at 2% of annual revenue for the controller or processor involved. That figure isn't automatic, though — it's calculated based on a range of factors: how much harm the violation caused, how long it went on, what type of data was affected, how many individuals were affected, how the violation came to light, how cooperative the organization was during the investigation, the size of the business, its ability to pay, and its prior compliance record. In other words, the actual fine could land well below 2%, depending largely on how well an organization responds.


Why This Can't Wait


With the deadline just months away, several public policy observers have warned against Indonesia ending up with a regulation that looks strong on paper but falls apart in practice. A thorough regulation means little if businesses don't understand their obligations, or if individuals don't understand their rights as data subjects. And while not every implementing rule from the Personal Data Protection Authority has been issued yet, controllers and processors are still required to make sure their current practices don't conflict with PP 33/2026.

Realistically, there are a few things worth starting now rather than closer to the deadline: running a full compliance gap assessment against the PDP Law and GR 33/2026, updating internal privacy policies and procedures, carrying out DPIAs and maintaining Records of Processing Activities (RoPA) for high-risk processing, appointing a PPDP that meets the regulation's criteria, preparing an incident response plan, and reviewing cross-border data transfer contracts — particularly for organizations relying on overseas cloud vendors.

With fines that can reach 2% of annual revenue, plus the reputational risk of a public enforcement action, compliance with PP 33/2026 has effectively moved from a legal checkbox to a core part of business risk management.


Understanding the Rule Is Only Half the Work


Reading 225 articles is one thing. Turning them into policies, systems, and habits that actually hold up inside your organization before 16 January 2027 is a much bigger job.

That's the gap Perkom's Data Privacy Management service is built to close. Our team helps organizations run Privacy Impact Assessments (PIA) and RoPA to map compliance gaps, design privacy policies aligned with the PDP Law and PP 33/2026, build continuous monitoring to catch risks earlier, and train employees so compliance becomes part of how the organization actually works — not just a document sitting in a drawer.

Don't wait for the deadline to start closing the gap!.



This article is a general information summary and does not constitute legal advice. For a compliance assessment specific to your organization, please consult your legal team or a professional data privacy advisor.


get in touch with our team

Trusted by more than 2,500 customers

we’re delivering the best
customer experience

Welcome to perkom.co.id In order to provide a more relevant experience for you, we use cookies to enable some website functionality. Cookies help us see which articles most interest you; allow you to easily share articles on social media; permit us to deliver content, jobs and ads tailored to your interests and locations; and provide many other site benefits. For more information, please review our Privacy Notice.