TL;DR
- Government Regulation No. 33 of 2026 runs to 225 articles across twelve chapters, and Article 225 sets it in force six months after promulgation, placing the compliance date in mid-January 2027.
- Article 2 binds controllers outside Indonesia whose acts produce legal effects inside the country or affect Indonesian citizens abroad, so a Bangkok advertiser handling Indonesian user data is in scope.
- The explanatory memorandum treats consent as ambiguous when agreement to process personal data is bundled with agreement to terms and conditions.
- Article 35 requires marketing consent to name the third parties receiving the data, the form the offer will take, and how to withdraw or report continued offers.
- Nine obligations carry a three-times-twenty-four-hours deadline, including breach notification under Article 114 and stopping processing after withdrawal under Article 92.
Indonesia has published the implementing regulation for the personal data protection law it passed in 2022, and the date that matters for anyone advertising into the country is mid-January 2027. Government Regulation No. 33 of 2026 was signed in Jakarta on 16 July 2026 by President Prabowo Subianto and promulgated the same day by State Secretary Prasetyo Hadi, entering the State Gazette of the Republic of Indonesia for 2026 as number 88. PPC Land, which set out the contents of the instrument in its report on the new rules, describes a text running to 225 articles across twelve chapters, with an explanatory memorandum of comparable length.
Article 225 provides that the regulation takes effect six months after promulgation. Counting from 16 July 2026, that places the compliance date in the middle of January 2027, which leaves roughly five months of runway from the end of August 2026. The regulation does not invent the underlying obligations. Law No. 27 of 2022 on Personal Data Protection did that when it entered into force in October 2022, imposing duties on controllers and processors and attaching criminal provisions to certain misuses of personal data. What the 2022 statute did not supply was the operating detail, and it delegated ten areas to a later instrument. Regulation No. 33 is that instrument.
The ten gaps Regulation No. 33 closes
The explanatory memorandum lists the ten areas that Law No. 27 of 2022 left to further regulation, and they read like a checklist of the things a marketing organisation actually has to operate: objections to automated processing, compensation procedures, data portability, the mechanics of processing, impact assessments, notification duties in corporate transactions, the data protection officer function, transfers outside Indonesian jurisdiction, the imposition of administrative sanctions, and the exercise of the supervisory authority's powers. For four years those ten items sat in a statute without a manual. A controller could read the obligation and could not read the procedure. That is the gap the July 2026 regulation fills, and it is why the mid-January 2027 date is a real deadline rather than a formality.
Two of those ten items sit directly on the desk of anyone buying media. Objections to automated processing is the ground on which an individual can refuse a decision taken about them by an automated system. Transfers outside Indonesian jurisdiction is the rule that governs whether Indonesian user data may sit in a Singapore data warehouse, a Bangkok agency's reporting stack, or a United States ad platform. Neither is a back-office concern.
Article 2 gives the regulation extraterritorial reach
Article 2 sets the territorial scope, and it has two limbs. The first binds any person, public body or international organisation performing legal acts in the implementation of personal data protection within Indonesian jurisdiction. The second binds those outside that jurisdiction whose acts produce legal effects inside Indonesia, or whose acts affect Indonesian citizens who are abroad. The explanatory memorandum states that the second limb exists so that Indonesian data subjects located outside the country, whose data is processed abroad and who suffer loss as a result, still have legal protection.
Read that second limb against a normal Bangkok media operation. An agency running a lead generation campaign into Jakarta collects a name, a phone number and a WhatsApp handle through a form, pushes them into a CRM hosted outside Indonesia, syncs a hashed audience back to an ad platform, and suppresses converters from the retargeting pool. Every one of those steps is a legal act producing effects inside Indonesia on the data of Indonesian subjects. The processing happening on a server in another country is precisely the situation Article 2 was drafted to catch. The agency does not need an Indonesian entity, an Indonesian office or an Indonesian bank account for the regulation to apply to what it does with the data.
Article 3 supplies the only carve-out worth noting: purely personal or household processing, defined as activity conducted for an individual's own needs, activity that is neither professional nor commercial, and activity not intended for the public. Commercial marketing fails all three tests. If you are running paid social campaigns into Indonesia for a client, the carve-out does not reach you.
What counts as personal data, including data you assembled yourself
The regulation splits personal data into two classes. Article 6 defines specific personal data as health data and information, biometric data, genetic data, criminal records, children's data, personal financial data, and further categories that ministries or agencies may designate in coordination with the supervisory body. Article 7 defines general personal data as full name, sex, nationality, religion, marital status, and any personal data combined to identify a person.
That last clause in Article 7 is the one that changes how a data team should think. The article names the combination methods: direct reference, mapping reference, triangulation, and other combinations. It then states expressly that combination includes the use of data available in the public domain. PPC Land flagged what this means for identity resolution vendors, and the point generalises. Data assembled from publicly available sources becomes personal data at the moment the combination identifies someone. The regulation also directs the supervisory body to issue further rules on how combination is assessed, which has not happened yet.
The practical translation: a spreadsheet of company names, public LinkedIn job titles and guessed email patterns is not a neutral prospecting asset under this text. Once the combination resolves to an identifiable person, it is personal data with a processing ground requirement attached. The same applies to a customer data platform that stitches a device identifier to a public directory listing to a form fill. The stitching is the act that creates the obligation. If your analytics and measurement setup is the place where those joins happen, that is where the audit will land.
Six processing grounds, and a definition of ambiguous consent
Article 30 lists six grounds for processing: explicit valid consent for one or more stated purposes; performance of a contract to which the data subject is a party, or steps taken at the subject's request before contracting; compliance with a legal obligation; protection of vital interests; performance of a public interest task or exercise of authority; and other legitimate interests weighed against the rights of the data subject. Article 32 requires that explicit consent be obtained freely, consciously, specifically and unambiguously.
The explanatory memorandum then defines ambiguity, and the definition is narrow enough to be actionable. It states that consent is ambiguous where agreement to process personal data is combined with agreement to terms and conditions, such that the data subject is deemed to have consented to processing merely by reading the terms. Indonesia has written that principle into the text of a government regulation rather than leaving it to regulatory guidance.
Every Thai marketing team knows the pattern that fails this test, because most lead forms still use it. One checkbox, one line of copy, something close to: I accept the terms and conditions and agree to receive offers. Under the memorandum's definition that is bundled consent, and bundled consent is ambiguous consent, and ambiguous consent is not valid consent under Article 32.
A compliant separation is not complicated to build, it is just more work than one checkbox. The terms of service acceptance is one control. The marketing consent is a second, independent control, unticked by default, with its own copy naming the purposes. If the data will move to a third party, that is stated in the marketing control itself rather than buried in a privacy policy the user never opens. The form should record which control was ticked, when, and against which version of the copy, because Article 36 places the evidential burden on the controller, which must be able to demonstrate the consent given. A screenshot of the form as it looks today is not evidence of what a user saw fourteen months ago.
Article 35 is the marketing article
Article 35 addresses offers of goods and services directly, and it is the provision a media team should read first. Where consent covers marketing purposes, the controller must state clearly three things: the third parties that will receive the data, the form the offer will take, and the mechanism both for withdrawing consent and for reporting continued offers after withdrawal. Article 35 paragraph 3 prohibits obtaining consent through deceptive or misleading means. Article 35 paragraph 1 requires that a refusal to consent must not reduce the quality of goods, services or support provided, except where provision genuinely requires the processing. Article 37 requires a withdrawal mechanism available at any time.
The hardest of those to satisfy is naming the third parties. A typical martech stack does not have a short list. A single lead form can hand data to a form provider, a tag manager container, a CRM, an email service provider, a call tracking vendor, a data warehouse, a conversions API endpoint at one or more ad platforms, a customer data platform, and whatever reporting layer sits on top. Most organisations have never written that list down in a form a user could read, and several of those recipients were added by a developer or an agency rather than by a marketing decision.
Producing that list is the single most useful piece of work a team can do between now and mid-January 2027, because it is a prerequisite for everything else. You cannot name the recipients in a consent notice until you know who they are. You cannot honour a withdrawal within a deadline until you know which systems have to be told. The exercise usually turns up recipients nobody currently owns. When the same audit runs on Facebook advertising pixels and conversion endpoints, the common finding is a container full of tags whose business owner left the company.
Article 35's requirement to state the form the offer will take deserves its own note. Consent to receive email is not consent to receive a phone call, and neither is obviously consent to be matched into a custom audience. The regulation asks the controller to be specific about the channel. That is a copywriting problem as much as a legal one, and it belongs to whoever owns the content and messaging on the form, not only to counsel.
The 72-hour response clock, and who owns the inbox
The regulation attaches a deadline stated as three times twenty-four hours to nine separate obligations. This is the operational core of the instrument, and it is where most organisations will fail first, because a deadline measured in hours cannot be met by a process that runs when someone remembers. The table below lists the nine obligations and the article each sits in.
| Article | Obligation carrying the 72-hour clock |
|---|---|
| Article 71 | Correcting or updating inaccurate personal data, counted from receipt of the request |
| Article 77 | Granting access to personal data |
| Article 78 | Confirming a request for a copy and stating the time needed to supply it |
| Article 87 | Notifying erasure or destruction, before or after the act depending on the ground |
| Article 92 | Stopping processing once consent is withdrawn |
| Article 99 | Suspending or restricting processing |
| Article 100 | Refusing a request to suspend or restrict processing |
| Article 103 | Notifying that suspension has taken place |
| Article 114 | Breach notification |
Article 1 defines a Day as a working day. That definition affects the longer procedural periods in the enforcement chapter, but it does not soften the hour-denominated deadlines. Seventy-two hours is seventy-two hours, and it can start on a Friday evening.
Operationally this means someone has to own an inbox. Not a shared alias nobody reads, and not a contact form that routes to a general enquiries queue. A named person with a named backup, a monitored destination, and a defined path from a request arriving to the systems being changed. Article 92 is the one that bites hardest on marketing, because stopping processing within 72 hours of a withdrawal means every downstream system holding that record has to be reachable within that window. If suppression from a retargeting audience is a manual quarterly job, that is a failure waiting for its first request.
The tracking exercise is worth running as a rehearsal. Send a subject access request to your own Indonesian data path and time it honestly. If the answer is that nobody is certain which systems hold the record, the answer is that the 72-hour clock cannot currently be met, and that is a useful thing to know in August rather than in January.
Thirty days for data you did not collect from the person
Article 64 sets a different clock for data obtained indirectly. Where personal data is not collected from the data subject, the controller has 30 days from collection to supply the information required by Article 62. That information covers the legality of processing, the purposes, the types and relevance of the data, the retention period, details of the information collected, the processing duration, and the rights of the data subject.
Purchased lists, partner co-registration, event attendee files handed over by an organiser, and enriched records from a data vendor all sit inside Article 64. Thirty days from collection is a short window for a process that, in most organisations, does not exist at all. The obligation is not to ask permission after the fact, it is to tell the person what you now hold and why, within a month.
About the 2 percent of revenue figure
PPC Land's headline states that data controllers face fines of 2 percent of revenue under Indonesia's new data rules. That figure is not in the body text available here. What the available text does confirm is that the imposition of administrative sanctions was one of the ten areas Law No. 27 of 2022 delegated to this regulation, so the instrument does carry an administrative sanctions regime. The specific ceiling was reported by PPC Land in its headline, and the article number carrying it is not something this report can point to.
That distinction is worth making plainly rather than papering over. A percentage-of-revenue ceiling is the kind of number that gets quoted in a board paper, and quoting it with a confident article reference that cannot be checked is how a compliance briefing loses its credibility. Treat the figure as reported by the outlet, and have counsel read Regulation No. 33 itself before it goes into any risk register with a number attached.
What this means for Thai marketers
The short version: if your campaigns, lead forms, CRM or retargeting touch Indonesian users, you have a compliance deadline in mid-January 2027 and roughly five months to prepare for it, and the fact that your company is registered in Thailand does not change that.
The work divides into four pieces, and none of them require a legal opinion to start. First, produce the recipient list. Write down every system, vendor and endpoint that receives Indonesian personal data from your properties, with a named owner for each. Article 35 requires you to be able to state the third parties, and no consent notice can be written until that list exists.
Second, unbundle the consent. Separate terms acceptance from marketing consent on every form that collects Indonesian data, make the marketing control independent and unticked, name the purposes and the channel in the control's own copy, and log the consent event with a timestamp and a copy version so Article 36's evidential burden can actually be discharged.
Third, assign the inbox and rehearse the clocks. One owner, one backup, a monitored destination, and a documented route from a request to a change in each system. Then test it against the tightest obligation you have, which for marketing is Article 92, stopping processing after a withdrawal.
Fourth, look at the joins. Article 7's combination clause means any process that assembles identity from separate sources, including public sources, is creating personal data. Prospecting databases, enrichment vendors and identity stitching inside a customer data platform all sit in that category. If nobody has mapped where those joins happen in your stack, that mapping is the prerequisite for everything above.
What the source does not cover
Several things are outside what can be said from the reporting. There is nothing about Thailand's own Personal Data Protection Act, so no read-across between the two regimes appears here. There is no enforcement history, because the regulation has not taken effect and no cases exist. There is no guidance yet from Indonesia's supervisory body, including on the combination assessment that Article 7 directs it to produce. There is no list of the further categories of specific personal data that ministries or agencies may designate under Article 6, and until those designations arrive, that category is open-ended.
Indonesia is a separate jurisdiction operating its own instrument. Nothing here compares the fine level or the provisions to any other country's law, because those texts are not in front of the writer, and a comparison built on memory is exactly the kind of detail that ends up quoted back at you in a client meeting.
Frequently asked questions
When does Indonesia's Government Regulation No. 33 of 2026 take effect?
Mid-January 2027. Article 225 provides that the regulation takes effect six months after promulgation, and it was promulgated on 16 July 2026 by State Secretary Prasetyo Hadi, which places the compliance date in the middle of January 2027.
Does the regulation apply to a Bangkok agency with no Indonesian entity?
Yes, if the agency's acts produce legal effects inside Indonesia or affect Indonesian citizens abroad. Article 2's second limb extends the regulation to controllers outside Indonesian jurisdiction on that basis, and the explanatory memorandum says the limb exists to protect Indonesian data subjects whose data is processed abroad.
Is a single checkbox covering terms and marketing offers valid consent?
No, on the definition in the explanatory memorandum. It states that consent is ambiguous where agreement to process personal data is combined with agreement to terms and conditions such that the subject is deemed to consent merely by reading the terms, and Article 32 requires explicit consent to be unambiguous.
What is the 72-hour deadline attached to?
Nine obligations across the regulation, stated as three times twenty-four hours. They cover correction under Article 71, access under Article 77, confirming a copy request under Article 78, notifying erasure under Article 87, stopping processing after withdrawal under Article 92, suspension and restriction under Articles 99, 100 and 103, and breach notification under Article 114.
What does Article 35 require in a marketing consent notice?
Three statements: the third parties that will receive the data, the form the offer will take, and the mechanism for withdrawing consent and for reporting continued offers after withdrawal. Paragraph 3 also prohibits obtaining consent by deceptive or misleading means, and paragraph 1 prevents a refusal from degrading the quality of the goods or services provided.
If you run acquisition into Indonesia and have not yet written down which systems receive that data, that list is the first deliverable, and it is a week of work rather than a quarter. Relevant Audience can help map the data path behind your campaign, form and measurement setup before the January 2027 date arrives.







