Regulations
Government Regulation 33/2026 brings businesses long-sought clarity on data protection, with enforcement awaiting a presidential approval of the data protection authority.
A man types on a laptop keyboard in this undated illustration photo of data theft. Cases of stolen personal or public data being sold on online forums, have continued to rise worldwide. (Unsplash/Towfiqu Barbhuiya)
Indonesia has published long-delayed implementing rules for its 2022 Personal Data Protection (PDP) Law, spelling out for the first time how companies may legally transfer personal data abroad, even as the authority to enforce those rules remains to be created four years after the landmark law took effect.Government Regulation No. 33/2026, signed on July 16 but only circulated publicly in late August, sets out detailed obligations for any business that collects or processes personal data, to consent requirements and how consumers can seek redress.
It also sets out a detailed regime for cross-border data transfers, recognizing adequacy decisions and binding corporate rules as legal pathways for moving Indonesian personal data overseas.







