Indonesia has published the implementing regulation for its 2022 personal data protection statute, a 225-article instrument signed on 16 July 2026 that sets 72-hour response deadlines, mandates impact assessments for large-scale profiling, and names advertising targeting of vulnerable groups as a decision individuals can refuse.
Government Regulation No. 33 of 2026 was signed in Jakarta on 16 July 2026 by President Prabowo Subianto and promulgated the same day by State Secretary Prasetyo Hadi, entering the State Gazette of the Republic of Indonesia for 2026 as number 88. It runs to 225 articles across twelve chapters and carries an explanatory memorandum of comparable length. Under Article 225, the regulation takes effect six months after promulgation, which places the compliance date in mid-January 2027.
The instrument fills a gap that has been open since Law No. 27 of 2022 on Personal Data Protection entered into force in October 2022. That statute imposed obligations on controllers and processors, attached criminal provisions to certain misuses of personal data, and delegated ten specific areas to further regulation. Those ten areas, listed in the explanatory memorandum, cover objections to automated processing, compensation procedures, data portability, the mechanics of processing, impact assessments, notification duties in corporate transactions, the data protection officer function, transfers outside Indonesian jurisdiction, the imposition of administrative sanctions, and the exercise of the supervisory authority's powers.
Scope reaches processing conducted outside Indonesia
Article 2 sets the territorial reach. The regulation binds any person, public body or international organisation performing legal acts in the implementation of personal data protection within Indonesian jurisdiction, and also those outside it whose acts produce legal effects inside Indonesia or affect Indonesian citizens abroad. The explanatory memorandum states that the second limb exists to give legal protection to Indonesian data subjects located outside the country whose data is processed abroad and who suffer loss as a result.
Article 3 carves out purely personal or household processing, defined as activity conducted for an individual's own needs, activity that is neither professional nor commercial, and activity not intended for the public.
Specific personal data under Article 6 covers health data and information, biometric data, genetic data, criminal records, children's data, personal financial data, and further categories that ministries or agencies may designate in coordination with the supervisory body. General personal data under Article 7 covers full name, sex, nationality, religion, marital status, and any personal data combined to identify a person. The combination methods named in Article 7 are direct reference, mapping reference, triangulation, and other combinations, and the article states expressly that combination includes the use of data available in the public domain.
That last clause matters for identity resolution vendors. Data assembled from publicly available sources becomes personal data once the combination identifies someone, and the supervisory body is directed to issue further rules on how combination is assessed.
Consent bundled with terms and conditions is treated as ambiguous
Article 30 lists six processing grounds: explicit valid consent for one or more stated purposes, performance of a contract to which the data subject is party or steps taken at the subject's request before contracting, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of authority, and other legitimate interests weighed against the rights of the data subject.
Article 32 requires that explicit consent be obtained freely, consciously, specifically and unambiguously. The explanatory memorandum supplies a definition of ambiguity that will be familiar to anyone who has read European enforcement decisions on consent design. It states that consent is ambiguous where agreement to process personal data is combined with agreement to terms and conditions, such that the data subject is deemed to have consented to processing merely by reading the terms.
The construction closely tracks the reasoning behind Turkey's ruling that bundled consent and clarification texts must be presented as separate documents, and the line of European cases on consent interfaces that the same decision drew on. Indonesia has now written the principle into the text of a government regulation rather than leaving it to regulatory guidance.
Article 35 addresses the specific case of offers of goods and services. Where consent covers marketing purposes, the controller must state clearly the third parties that will receive the data, the form the offer will take, and the mechanism both for withdrawing consent and for reporting continued offers after withdrawal. Article 35 paragraph 3 prohibits obtaining consent through deceptive or misleading means. Article 35 paragraph 1 requires that a refusal to consent must not reduce the quality of goods, services or support provided, except where provision genuinely requires the processing.
Article 36 places the evidential burden on the controller, which must be able to demonstrate the consent given. Article 37 requires a withdrawal mechanism available at any time.
Seventy-two hours becomes the standard response clock
The regulation attaches a deadline of three times twenty-four hours to nine separate obligations. Article 71 sets that period for correcting or updating inaccurate personal data from receipt of the request. Article 77 applies it to granting access. Article 78 applies it to confirming a request for a copy and stating the time needed to supply it. Article 87 applies it to notifying erasure or destruction, before or after the act depending on the ground. Article 92 requires processing to stop within the same window once consent is withdrawn. Articles 99, 100 and 103 apply it to suspending or restricting processing, to refusing such a request, and to notifying that suspension has taken place. Article 114 applies it to breach notification.
Article 1 defines a Day as a working day, which affects the longer procedural periods in the enforcement chapter but not the hour-denominated deadlines.
Article 64 sets a different clock for data obtained indirectly. Where personal data is not collected from the data subject, the controller has 30 days from collection to supply the information required by Article 62, which covers the legality of processing, purposes, types and relevance of data, retention period, details of information collected, processing duration, and the rights of the data subject. The explanatory memorandum states that legality includes the controller's identity, a short description, contact details, a representative where required, the contact details of the data protection officer, the processing ground, and the legal basis.
Article 65 prohibits exoneration clauses in privacy notices.
Ad targeting of vulnerable groups is named as a significant effect
Article 93 gives data subjects the right to object to decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect them. The operative text is unremarkable. The explanatory memorandum is not.
It defines legal effect to include decisions affecting legal status, such as citizenship, and decisions determining rights or obligations under law, giving visa refusal, withdrawal of social benefits, and contract termination as examples. It then defines significant impact as decisions with a large influence on a person's living conditions, behaviour or choices, listing credit refusal, employment refusal, the formation of differential prices based on personal data, and advertising targeting that strongly affects vulnerable groups.
Differential pricing and vulnerable-group targeting are therefore identified, in the official explanation of an Indonesian government regulation, as categories that trigger an individual right to object. Article 94 requires controllers to hold a mechanism for responding to such objections and to provide adequate information about the technology used and the consequences the data subject will experience. Where an objection is verified and accepted, the controller must offer an alternative involving human intervention or a route that does not rest on automated processing.
Article 95 permits refusal only where there is no legal effect or significant impact, and where the controller has a system with very good accuracy and mitigation measures to avoid impact on the data subject. Refusal does not extinguish the right to withdraw consent.
The structure resembles Article 22 of the European regulation, on which the Dutch authority opened a consultation on explanation obligations in April 2026, and which British guidance has applied to profiling tools used in online safety systems. What differs is the explicit naming of advertising in the explanatory text.
Impact assessments attach to seven processing categories
Article 120 requires a personal data protection impact assessment where processing carries high potential risk, and lists seven triggers: automated decision-making with legal effect or significant impact, processing of specific personal data, large-scale processing, systematic evaluation, scoring or monitoring, matching or combining sets of data, use of new technology, and processing that restricts the exercise of data subject rights.
The explanatory memorandum states that large scale is assessed against the volume of data, the number of subjects involved, the duration of processing, the type of data, the purpose, and the geographic area affected. New technology is illustrated with artificial intelligence, machine learning, smart technology and the internet of things.
Article 121 requires the assessment before processing begins, sets its minimum contents, and requires review whenever processing risk changes. Article 122 allows consultation with the supervisory body where processing may cause material or immaterial loss, or where no technical operational measure is available.
Matching and combining data sets, systematic scoring, and large-scale automated evaluation describe the routine mechanics of audience segmentation, lookalike modelling and identity graph construction. Under Article 120 those activities carry a documented assessment obligation before they begin.
A data protection officer becomes mandatory in three cases
Article 142 requires controllers and processors to appoint an officer performing the data protection function where processing serves public services, where core activities require regular and systematic monitoring of personal data on a large scale, or where core activities consist of large-scale processing of specific personal data or data relating to criminal offences.
Article 143 sets the appointment criteria as professionalism, knowledge of the law and of data protection practice, and capacity to perform the tasks. Article 145 lists the officer's minimum duties: advising the controller or processor on compliance, monitoring compliance with data protection law and internal policy, advising on impact assessments and monitoring performance, and acting as coordinator and contact point.
Article 146 sets the conditions the organisation must meet. The officer must be involved in all processing activities, hold a reporting line to the highest level of management, operate objectively, without intervention and independently, receive adequate resources to perform the role and maintain expertise, obtain appropriate access to processing activity and to other services holding relevant information, be consulted during impact assessments, and have the performance of the role documented in detail. Article 146 paragraph 2 requires that the role not create a conflict of interest.
Article 144 allows the function to be filled by one person or several, drawn from inside or outside the organisation.
Records, retention and breach notification
Article 74 requires controllers to record all processing activity, with thirteen minimum fields including the contact details of the data protection officer, the source of collection and destination of transmission, the processing ground, the types of data and categories of subject, parties other than the controller able to access the data, the mapping of data flows, the retention period, technical and organisational security measures, and details of transfers. Processors keep a shorter record covering their name and contact, the scope of processing, transfer details, and a general description of security measures. Records must be produced to the supervisory body on request and made available for audit.
Article 75 requires a written retention policy document, with contents ranging from definitions and periods through de-identification provisions for statistical and scientific use to destruction methods and the responsible officer.
Article 114 requires written notification of a data protection failure to both the data subject and the supervisory body within three times twenty-four hours of the failure becoming certainly, properly and reasonably known. The notification must state the data exposed, when and how it was exposed, and the handling and recovery steps taken, together with the contact details of the data protection officer. Article 115 adds a public notification duty where the failure disrupts public services or seriously affects the public interest. Article 118 requires processors to report failures to the controller at the first opportunity.
Transfers require an assessment of the legal instrument used
Chapter V governs transfers outside Indonesian jurisdiction. Article 165 sets a three-step test. The controller must first ensure the recipient country provides a level of protection equal to or higher than the Indonesian statute. Failing that, it must ensure adequate and binding protection exists. Failing both, it must obtain the data subject's consent.
Article 167 assigns the equivalence assessment to the supervisory body, which under Article 168 must consider whether the destination has data protection legislation, whether it has a supervisory authority, and whether it holds international commitments or participates in multilateral or regional data protection systems. The body is directed to establish a list of countries and international organisations meeting the standard.
Article 169 lists the adequate and binding instruments: legally binding and enforceable instruments between authorities, standard contractual clauses set by the supervisory body, binding corporate rules for a corporate group, and other instruments the body recognises. Article 170 sets the minimum contents of the standard clauses, including breach notification duties and an obligation to conduct due diligence on onward recipients. Article 171 restricts binding corporate rules to entities in a control relationship and requires the body's approval before transfer.
Article 173 narrows consent-based transfers considerably. They are permitted only where the transfer is not repetitive, involves a limited number of data subjects, is necessary for purposes that do not override the interests or rights of the subject, follows a risk assessment and appropriate safeguards, and has been notified to both the supervisory body and the data subject.
Article 161 requires controllers and processors to record and map the transfer cycle, confirm that transferred data is adequate, relevant and limited to the purpose, identify the legal instrument, assess its effectiveness before transferring, use supplementary contractual, technical or organisational instruments where needed, and re-evaluate periodically.
Indonesia committed to recognising the United States as providing adequate protection as part of a trade framework announced in July 2025. Article 168 now supplies the domestic mechanism through which such a recognition would be made, and assigns it to a body that does not yet exist.
Corporate transactions carry a data transfer procedure
Articles 131 to 137 govern the transfer of personal data in mergers, spin-offs, acquisitions, consolidations and dissolutions. Before transfer, the controller must assess which data subject rights and which controller obligations remain to be fulfilled during and after the transaction, and update its impact assessment accordingly. Article 131 paragraph 6 provides that the legal relationship between the old and new controller constitutes joint controllership until the transaction is complete.
Article 134 requires a data protection agreement between old and new controller covering processing grounds, adherence to the principles, fulfilment of rights, and the division of obligations. Article 135 provides that the new controller may process data for its own purposes only after the period for data subject objections has ended. Article 136 sets the notification duties on dissolution.
For an ad tech sector in which audience data routinely moves with corporate ownership, the joint controllership rule and the objection window before repurposing are the operative constraints.
Sanctions reach 2 percent of gross revenue
Article 184 lists 36 articles whose breach carries administrative sanctions and names four sanction types: written warning, temporary suspension of processing, erasure or destruction of personal data, and administrative fine. More than one may be imposed at once, and any may be imposed without a prior written warning.
Article 185 sets the fine ceiling at 2 percent of the annual revenue or annual receipts of the controller or processor, applied against the violation variables. Those variables are the negative impact caused, the duration of the violation, the type of data affected, the number of data subjects affected, the process by which the violation was found, the degree of openness and cooperation shown during the examination, the scale of the business, the ability to pay, the compliance record, and other variables the supervisory body sets. Article 185 paragraph 3 permits a fine of zero.
The explanatory memorandum defines revenue for this purpose as the gross inflow of economic benefits arising from an entity's normal activities during a period where that inflow increases equity other than through contributions from investors. The measure is turnover, not profit. Article 186 directs collected fines to the state treasury as non-tax state revenue.
The procedure has fixed periods. Article 190 gives the supervisory body three days to examine a complaint. Article 192 requires the substantive examination to finish within 14 days, extendable by up to 60 days. Article 195 requires a sanction decision within 30 days of the examination closing, requires publication of the decision on the body's official media, and gives the sanctioned party 30 days from publication to comply. Article 197 allows a written objection within 14 days, requires a decision on that objection within 14 days, and provides that an objection is deemed granted where the deadline passes without decision. Objection does not suspend the sanction. Refusal opens the route to the administrative court.
Thirty delegations to a body that has not been created
The regulation refers 30 times to a Peraturan Lembaga, a regulation of the supervisory body, as the vehicle for further detail. Those delegations cover the assessment of data combination, the verification of children's consent, the mechanics of automated processing, portability, breach notification, impact assessments, the appointment and competence of the data protection officer, the transfer equivalence assessment, and the procedure for imposing sanctions.
The body issuing those regulations does not exist. On 10 August 2026, three weeks after this regulation was signed, the presidential regulation establishing the authority was still described as roughly two months from completion, with the underlying statute simultaneously under materiil review at the Constitutional Court in Case 236/PUU-XXIV/2026. Article 223 addresses the gap by providing that, until agency regulations are issued, controllers and processors may process personal data so long as they do not contravene this regulation.
That is a holding position rather than a solution. The substantive duties in Chapters III and IV are self-executing from January 2027. The interpretive apparatus, the country adequacy list, the standard contractual clauses, and the sanction methodology all await an institution.
Why this matters for the marketing community
Indonesia is the largest digital market in Southeast Asia, and the requirements in this regulation land on the same operational surfaces that carry campaign delivery.
Consent architecture is the first. The explanatory memorandum's treatment of terms-and-conditions bundling removes a common implementation pattern in Indonesian apps and websites, and Article 35 requires naming the third parties that will receive data for marketing purposes. Third-party disclosure at the point of collection is difficult to reconcile with a bidstream in which recipients are determined at auction time. European regulators have spent years on the same problem, and the record there suggests the resolution is slow: payment-based consent walls and machine-readable signals remain contested well after the underlying rules took effect.
Profiling is the second. Article 120 attaches an impact assessment to systematic scoring, data matching, and large-scale automated evaluation. Article 93 gives individuals a route to object where automated decisions significantly affect them, and the explanatory text names advertising targeting of vulnerable groups within that category. The European board has reached comparable conclusions about algorithmic curation, holding that content presentation through recommender systems can constitute an automated decision where the effects are significant.
Transfers are the third. Any platform moving Indonesian user data offshore for processing must document the instrument used, assess its effectiveness before transferring, and re-evaluate periodically. Until the supervisory body publishes a country list and standard clauses, the practical default is either binding corporate rules approved by a body that cannot yet approve them, or consent, which Article 173 restricts to non-repetitive transfers involving limited numbers of subjects.
Children are the fourth. Article 1 defines a child as anyone under 18, and Article 38 requires parental or guardian consent for processing children's data, with verification calibrated to available technology. That sits alongside the separate regulation known as PP Tunas, which prompted YouTube to warn Indonesian users under 16 that they may lose the ability to log in to the platform. Two instruments now draw age lines at different points, 18 for data processing consent and 16 for platform access, and both apply to the same audience.
Regional context sharpens the timing. Vietnam issued its implementing decree on the final day of 2025, India published its rules with consent managers in November 2025, Egypt issued executive regulations after a five-year delay, and Cambodia circulated draft legislation in July 2025. Buyers running programmatic campaigns across the region now face four separate national implementations with different deadlines, different consent standards and different transfer mechanics, arriving within roughly eighteen months of one another.
The European experience also offers a caution on enforcement durability. Analysis covered by PPC Land found that close to 40 percent of announced GDPR penalties have been annulled or are under active challenge, and a Luxembourg court returned Amazon's 746 million euro penalty to the regulator over the assessment of fault. A new Indonesian authority applying a 2 percent turnover ceiling will be constructing that record from the beginning.
Timeline
- 17 October 2022: Law No. 27 of 2022 on Personal Data Protection enters into force, with a two-year transition period for controllers and processors
- 2 August 2024: Indonesian authorities block DuckDuckGo over gambling and pornographic content
- 17 October 2024: The transition period under the PDP Law expires, leaving obligations enforceable with no supervisory authority established
- 22 July 2025: Indonesia commits to recognising United States data protection adequacy as part of a trade framework
- 13 November 2025: India publishes the Digital Personal Data Protection Rules 2025, introducing registered consent managers
- 31 December 2025: Vietnam issues Decree 356/2025/ND-CP implementing its Personal Data Protection Law
- 18 February 2026: Turkey's data protection board rules that explicit consent and clarification texts must be presented separately
- April 2026: YouTube warns that Indonesian regulation PP Tunas may prevent users under 16 from logging in
- 25 April 2026: The Dutch data protection authority opens consultation on explaining automated decisions
- 20 May 2026: The draft presidential regulation on the data protection authority is submitted to the president
- 19 June 2026: The Constitutional Court registers petition No. 236/PUU-XXIV/2026 seeking materiil review of Law No. 27 of 2022
- 16 July 2026: Government Regulation No. 33 of 2026 is signed in Jakarta by President Prabowo Subianto and promulgated by State Secretary Prasetyo Hadi, entering the State Gazette as 2026 number 88
- 21 July 2026: The deputy communications and digital minister describes the authority as independent in structure while reporting to the president through the ministry
- 10 August 2026: The presidential regulation creating the supervisory authority remains outstanding, with completion described as roughly two months away
- Mid-January 2027: Government Regulation No. 33 of 2026 takes effect, six months after promulgation under Article 225
Related PPC Land coverage
- Indonesia's data law faces court test with DPA rules still two months away reports the ministry's account of the pending presidential regulation and the constitutional challenge to Law No. 27 of 2022, published on 10 August 2026, after the government regulation covered here was signed.
- Indonesia agrees to US data transfer framework in historic trade deal covers the July 2025 commitment to recognise United States adequacy, the arrangement that Article 168 would now formalise.
- Vietnam implements comprehensive personal data decree on final day of 2025 sets out the neighbouring implementation that took effect a year earlier.
- India launches comprehensive data protection rules with consent managers describes a phased implementation running to roughly May 2027.
- Egypt finally implements data protection law after five-year delay documents another statute that waited years for its executive regulations.
- Cambodia announces comprehensive data protection law covers the draft legislation circulated in July 2025 with a two-year implementation period.
- Turkey's DPA bans bundled consent texts in a ruling that reshapes data collection addresses the same bundling problem the Indonesian explanatory memorandum identifies.
- Dutch DPA opens consultation on explaining automated decisions to individuals examines the explanation duty attached to automated decision-making.
- ICO publishes guidance on profiling tools for online safety compliance applies the automated decision framework to profiling systems.
- European data protection board clarifies DSA compliance for marketers covers the finding that algorithmic curation can constitute an automated decision.
- Eight years of GDPR: 40% of the fines annulled or under challenge quantifies how much announced European enforcement has survived legal challenge.
- Luxembourg court annuls Amazon's 746m GDPR fine and sends case back to regulator details a penalty overturned on the assessment of fault.
- European websites achieve North Korean consent rates through payment barriers measures consent outcomes under payment-based walls.
- GPC could cut EU consent banners but law must catch up first assesses machine-readable consent signals against existing law.
- YouTube Premium Lite rolls out to Belgium, Venezuela, Peru and Guatemala reports the PP Tunas warning to Indonesian users under 16.
Summary
Who: The Government of the Republic of Indonesia, through President Prabowo Subianto, who signed the regulation, and State Secretary Prasetyo Hadi, who promulgated it. The obligations fall on personal data controllers and processors, including foreign entities whose processing affects Indonesian jurisdiction or Indonesian citizens abroad.
What: Government Regulation No. 33 of 2026, the implementing regulation for Law No. 27 of 2022 on Personal Data Protection. It runs to 225 articles across twelve chapters, setting response deadlines of three times twenty-four hours across nine obligations, mandating impact assessments for seven categories of high-risk processing, requiring a data protection officer in three defined cases, establishing a three-step test for transfers outside Indonesian jurisdiction, and setting an administrative fine ceiling of 2 percent of annual revenue across 36 articles.
When: Signed and promulgated in Jakarta on 16 July 2026, entered in the State Gazette for 2026 as number 88, and taking effect six months after promulgation under Article 225, which places the compliance date in mid-January 2027.
Where: Indonesian jurisdiction, plus processing conducted outside it that produces legal effects inside the country or affects Indonesian citizens abroad.
Why: Law No. 27 of 2022 delegated ten areas to further regulation and has operated since October 2022 without them, and without the supervisory authority it contemplates. This regulation supplies the substantive detail while referring 30 further matters to regulations of a body that has not been established, leaving controllers with enforceable obligations from January 2027 and no institution to interpret them.
Discussion