客户快讯

Navigating Indonesia’s New Personal Data Protection Regulation: Key Takeaways for Businesses

24 2026

Navigating Indonesia’s New Personal Data Protection Regulation: Key Takeaways for Businesses

 

On 16 July 2026, the Indonesian government enacted Government Regulation No. 33 of 2026 on the Implementation of Law No. 27 of 2022 on Personal Data Protection (“GR 33/2026”). GR 33/2026 provides the long-awaited implementing framework for the implementation of Law No. 27 of 2022 on Personal Data Protection (“Law 27/2022”). It is important to note that GR 33/2026 will enter into force six months after its enactment, which falls on 16 January 2027.

While GR 33/2026 provides clarity on several obligations, certain important aspects remain subject to further regulations to be issued. This client alert serves as a guide on the main key takeaways of GR 33/2026.

Conclusion and Implementation Readiness

With GR 33/2026 coming into force on 16 January 2027, businesses should use the six-month transition period to conduct a compliance review. In particular, businesses should review their existing personal data protection framework, policies and procedures against the requirements under GR 33/2026, including DPO, RoPA, DPIA, privacy by design, cross border personal data transfer and personal data breach management.

Businesses should also monitor the establishment of PDPA and its implementing regulation, as these will provide greater clarity on a number of requirements under GR 33/2026.