Skip to content
CloudkuCloudku

Indonesia's PP 33/2026 on Personal Data Protection: What Businesses Must Prepare Before 16 January 2027

A practical guide to PP 33/2026, Indonesia's PDP Law implementing regulation: controller and processor duties, 72-hour breach notice, DPO, DPIA, fines.

Cloudku teamPublished

Indonesia’s Personal Data Protection Law (Law No. 27 of 2022, or “UU PDP”) has been in force for some time, but many companies were waiting for the technical rules. Those rules have now arrived. Government Regulation (PP) No. 33 of 2026, the implementing regulation of the PDP Law, was enacted on 16 July 2026 and takes effect on 16 January 2027.

That gave businesses roughly six months to adjust. As of today, less than four months remain.

This article covers what matters most for any business operating in Indonesia that holds personal data about customers, employees or partners, followed by a practical checklist for small and mid-sized businesses.

Note: this article is for educational purposes only and is not legal advice. For compliance decisions, consult your legal adviser and check the official text of PP 33/2026.

PP 33/2026 at a glance

  • Full name: Government Regulation No. 33 of 2026 on the Implementation of Law No. 27 of 2022 on Personal Data Protection.
  • Enacted and promulgated: 16 July 2026.
  • In force: 16 January 2027, six months after promulgation.
  • Who it covers: data controllers (who decide why and how data is processed) and processors (who process data on a controller’s behalf, such as IT vendors and cloud providers).

Rajah & Tann Asia noted that in early September 2026 the text was not yet on the State Secretariat’s official legal database (JDIH) and was circulating among practitioners. Check article wording against the official publication once it is available.

What changes for controllers and processors

Controllers must have a lawful basis before processing begins (Article 30). Where consent is the basis, controllers must offer consent mechanisms, both electronic and non-electronic (Article 34), and keep proof of the consent they collect (Article 36).

For children’s data, controllers must take steps to identify child users and obtain verified consent from a parent or guardian. According to Katadata, a consent button or a user’s own declaration is not enough on its own (Article 38).

Processors and sub-processors

Engaging a processor requires a written agreement (Article 14). A processor that wants to bring in another processor needs the controller’s prior written approval (Article 15). In practice, this covers the cloud, hosting and IT service providers you already use.

Records of processing activities

Controllers must keep a record of all their processing activities (Article 74). According to Rajah & Tann, the minimum contents include data sources, purposes, lawful basis, data categories, third-party access, retention periods, security measures and transfer details.

Security and accountability

The regulation expects controllers to be able to demonstrate compliance, including through technical and organisational measures, documented processing, and internal and external audits (Article 138). Processors must also carry out audits (Article 141).

The summaries we reviewed do not list specific technical controls, such as a required encryption standard. More technical detail is expected in future regulations from the supervisory authority.

Breach notification: 3 x 24 hours

If a personal data protection failure occurs, the controller must notify affected data subjects and the supervisory authority in writing within 3 x 24 hours (Article 114). According to Rajah & Tann, the clock starts once the failure is established with reasonable certainty, not at the first suspicion.

Related incident duties:

  • Public notice when a breach disrupts public services or seriously affects the public interest (Article 115).
  • Documentation of each incident and its remediation (Article 116).
  • Internal policies for preventing and handling incidents, including roles and escalation (Article 117).
  • Processors must report breaches to the controller at the first opportunity (Article 118).

DPIA for high-risk processing

A data protection impact assessment (DPIA) is required before high-risk processing begins (Articles 120–121). Triggers include specific (sensitive) data, large-scale processing, systematic monitoring, automated decisions with significant effects and new technology. RSM notes that the elucidation names AI and machine learning as examples of new technology.

Data Protection Officer (DPO)

Not every business must appoint a DPO. It is required when processing serves public services, when core activities involve large-scale, regular and systematic monitoring, or when processing involves specific data or criminal-offence data at large scale (Article 142). The DPO must be independent and have direct access to top management (Articles 144–146).

Cross-border transfers

The order is: the destination country must offer equivalent or higher protection; if not, adequate and binding safeguards are needed; only if neither applies can the data subject’s consent be used (Article 165). The list of adequate countries and the standard contractual clauses still await the supervisory authority, so do not assume either is available yet.

Sanctions: up to 2% of annual revenue

Administrative sanctions include written warnings, temporary suspension of processing, deletion or destruction of data, and administrative fines. They may be imposed together (Article 184).

Fines are capped at 2% of annual revenue or receipts (Article 185). The amount takes into account impact, duration, number of affected data subjects, business scale and cooperation, and can be set as low as zero. According to Rajah & Tann, the elucidation defines revenue as gross inflows, not net profit.

Transition and the supervisory authority

Until the authority issues further technical rules, processing may continue as long as it does not conflict with PP 33/2026 (Article 223). RSM stresses that this is not a reason to delay preparations.

The data protection authority itself has not yet been formed. Bisnis.com reported on 13 September 2026 that the Ministry of Communication and Digital Affairs (Komdigi) is accelerating its formation and continues to handle oversight in the meantime, including incident handling and complaints. When the authority will be fully operational is not yet clear.

A practical checklist for SMBs

Start with the items that matter most:

  1. Map your data. List the personal data you hold (customers, employees, applicants, partners), which systems hold it and why.
  2. Build your record of processing. A simple spreadsheet works: purpose, lawful basis, data categories, third parties, retention period and security measures.
  3. Check your lawful basis and consent evidence. Make sure forms, websites and apps store proof of consent. Review flows if children might use your service.
  4. Review vendor contracts. Have written agreements with hosting, cloud, payroll, CRM and IT vendors, including sub-processor rules.
  5. Prepare a 72-hour incident procedure. Decide who makes the call, who contacts customers, which notification templates to use and how incidents are documented.
  6. Strengthen basic security. Turn on MFA, limit access rights, keep software updated and keep tested backups.
  7. Decide whether you need a DPIA or a DPO. This is especially important if you handle health or financial data, monitor users systematically, or use AI in decisions.
  8. Map overseas transfers. Note which services store data outside Indonesia.
  9. Set retention periods. Delete data you no longer need.
  10. Document everything. This regulation asks for evidence, not just good intentions.

Where separate, encrypted backup fits

Incidents like ransomware can lock up and leak data at the same time. When that happens, the 72-hour clock keeps running and the business still has to operate. A backup kept separate from your main systems lets you restore services without relying on the systems under attack. If the backup is encrypted, a stray copy is also much harder for anyone else to read.

Cloudku Cyber Protection (built on Acronis) backs up servers, PCs, VMs, cPanel web hosting and websites to an Acronis data center in Indonesia, separate from the systems it protects. Backups are encrypted with AES-256 using a password only you know, so not even Cloudku can open them. It includes AI-based anti-malware and anti-ransomware, covers unlimited devices and is priced by capacity. Microsoft 365, Entra ID and Google Workspace backup, Email Security, XDR, MDR and Disaster Recovery are available on request.

Backup is one technical measure, not a guarantee of compliance. But good backups leave you far better prepared when an incident hits. Learn more about Cloudku Cyber Protection or compare plans.

Sources

  1. Veritask — Technical Regulation on Personal Data Protection and the Obligations of Controllers and Processors Finally Issued through PP 33/2026 (3 September 2026)
  2. RSM Indonesia — Client Alert: PP 33/2026, Six Implementation Priorities before 16 January 2027 (18 September 2026)
  3. Rajah & Tann Asia — PDP Law Updates: The PDP Implementing Regulation Is Out (3 September 2026)
  4. Bisnis.com — Penerapan Aturan PP Pelindungan Data Pribadi Butuh Dukungan Otoritas Independen (1 September 2026)
  5. Katadata — PP Pelindungan Data Pribadi Berlaku Januari 2027, Ini Aturan Baru Data Anak (3 September 2026)
  6. Bisnis.com — Pembentukan Badan PDP Dipercepat, Implementasi UU PDP Dinilai Belum Efektif (13 September 2026)
  7. Justisio — PP PDP Disahkan, Jangan Sampai Kena Sanksi! (22 September 2026)

This article is for general information. Verify details against the cited sources before acting.

Need help applying this?

The Cloudku team can help you review your infrastructure and set up the right protection.

Talk to our team