Skip to content

Cold Email Laws in Indonesia: The PDP Law, PP 33/2026 and a Regulator That Does Not Exist Yet

September 28, 2026. Indonesia has no anti-spam statute for email. What it has, since October 17, 2022, is Law No. 27 of 2022 on Personal Data Protection, the PDP Law, modelled closely on the EU's GDPR, and since October 17, 2024 the two-year transition period is over and every provision is enforceable. For cold email that produces a familiar shape: a named person's work address is personal data, sending to it is processing, and the sender needs one of six lawful bases and must honour the right to withdraw and object. Two things changed this summer. On July 16, 2026 the government promulgated Government Regulation No. 33 of 2026, the PDP Law's implementing regulation, which takes effect on January 16, 2027 and spells out how consent is asked for, proved and withdrawn. What has not changed is the enforcement gap: the agency the law says will impose its administrative fines has still not been formed, and the Ministry of Communications and Digital Affairs told Bisnis Indonesia on September 13, 2026 that the draft Presidential Regulation creating it was submitted for the President's signature by a letter dated May 20, 2026 and is still waiting.

Cold email laws in Indonesia: the PDP Law, PP 33/2026 and a data protection agency that has not yet been formed

Key numbers

ItemNumber
PDP Law (Law 27/2022) enactedOctober 17, 2022
Transition period ended, all provisions enforceableOctober 17, 2024
PP 33/2026, the implementing regulation, promulgated (State Gazette 2026 No. 88)July 16, 2026
PP 33/2026 takes effect (six months after promulgation)January 16, 2027
Stop processing after a verified consent withdrawal (PP 33/2026 Article 92, then confirm to the data subject)3 x 24 hours
Administrative fine ceiling (imposed by the PDP Agency, which is not yet formed)2 percent of annual revenue
Unlawful collection of personal data, criminal (about USD 12,000; corporate fines up to 10 times)up to 5 years or IDR 200 million
Unlawful disclosure of personal data, criminalup to 4 years
Draft Perpres for the PDP Agency sent to the President (unsigned as of September 13, 2026 per Komdigi)May 20, 2026

DLA Piper's Indonesia guide (updated 13 February 2026), the PP 33/2026 record on paralegal.id and Bisnis Indonesia's reports of 29 August and 13 September 2026, all read on 28 September 2026.

What the PDP Law says that touches an outbound sender

  1. Six lawful bases. The PDP Law permits processing on explicit consent for specified purposes, contractual necessity, legal obligation, vital interest, public interest, or legitimate interest with due regard to the purpose, the need and the balance between the controller's and the subject's rights, per DLA Piper's country guide, updated February 13, 2026. That last basis is the one a B2B sender will reach for, and it carries a balancing test rather than a free pass.
  2. No specific electronic-marketing rule. DLA Piper's marketing note records that neither the PDP Law nor the older electronic-systems regulations address electronic marketing specifically; marketing is simply processing that needs a legal basis, and the same note records that one reason the right to withdraw consent was written into the law was the run of data breaches linked to direct-marketing practices.
  3. Consent, when used, is explicit. Consent must be explicit and given for one or more specific purposes conveyed by the controller. A pre-ticked box or silence does not qualify, which is why most B2B senders will document legitimate interest instead.
  4. Subject rights. The law guarantees the rights to be informed, to access, to rectify, to erase, to withdraw consent, to object to automated decisions, to restrict processing and to data portability, and it requires controllers to keep records of processing activities.
  5. The older layer still applies. The Electronic Information and Transactions Law (Law 11/2008, amended by Law 19/2016 and Law 1/2024) and Minister of Communications regulations such as Regulation 20/2016 on personal data in electronic systems remain in force where they do not contradict the PDP Law.

Government Regulation No. 33 of 2026 was signed and promulgated on July 16, 2026 and, under its final article, applies six months later, on January 16, 2027. Its Article 2 applies it to anyone processing personal data inside Indonesia and to anyone outside the country whose processing has legal effect there or concerns Indonesian citizens abroad, which is the clause that reaches a foreign sender. Bisnis Indonesia's reading of the text on August 29, 2026 sets out the consent mechanics: Article 30 requires a lawful basis before processing begins and names valid explicit consent for one or more specific purposes as the first; Article 32 requires that consent to be given freely, knowingly, specifically and unambiguously, and the regulation's explanatory note calls consent bundled into terms and conditions ambiguous; Article 33 requires the information to be given before consent, concisely and accurately; Article 34 requires a consent mechanism, electronic or not, linked to that information; Article 35 says a refusal may not cost the customer the product or service unless the processing is needed to provide it, requires that where data is used to offer goods or services the customer is told which third parties receive it, what form the offers take, how consent is withdrawn and how to report offers that continue after withdrawal, and bans deceptive or misleading consent requests; and Article 36 requires the controller to be able to show proof of the consent given. Article 92 then sets the operational number: once a data subject withdraws consent, processing must stop within 3 x 24 hours of the verified request, and the controller must tell the subject it has stopped.

Penalties, and who can impose them

The PDP Law provides two enforcement tracks, described in DLA Piper's enforcement section. The administrative track belongs to the PDP Agency: written warning, temporary suspension of processing, deletion or destruction of data, and administrative fines of up to 2% of the offending party's annual income or revenue. The criminal track belongs to the public prosecutor and already has effect: unlawfully obtaining or collecting personal data that does not belong to you, with intent to benefit and in a way that may cause loss, carries up to five years' imprisonment or a fine of IDR 200 million (about USD 12,000), unlawful disclosure up to four years or the same fine, and corporate fines can reach ten times the individual maximum, after Law No. 1 of 2026 re-based criminal fines on the criminal code. A corporation can additionally face confiscation of profits, suspension or closure of its business, licence revocation or dissolution. The administrative track is the one that cannot yet fire. The draft Presidential Regulation establishing the agency was discussed with stakeholders from March to September 2025, entered harmonisation at the Ministry of Law in October 2025, and, per the ministry's statement to Bisnis, has now cleared planning, drafting and harmonisation and sits with the President. During the transition the Ministry of Communications and Digital Affairs handles incidents, complaints, consultations and hearings under its existing powers; observers quoted in the same report expect the agency to operate effectively only by 2028.

What that gap does and does not mean

It does not mean the law is optional. The criminal provisions are live, the rights are live, and from January 16, 2027 the implementing regulation makes the consent record and the 72-hour stop clock concrete duties rather than principles. It does mean that in 2026 the practical risk for a foreign B2B sender is complaint-driven and reputational, through recipients, Indonesian counterparties and the ministry, rather than a scheduled audit. The moment the PDP Agency opens, the 2% of revenue ceiling becomes real, and the records-of-processing duty plus Article 36 of PP 33/2026 mean the first thing it will ask a sender for is the document that names the lawful basis for every list and the proof of any consent relied on.

What it means for operators

Indonesia is a legitimate-interest market with a consent-shaped culture, and the implementing regulation has just made the consent side more demanding. Build the sequence to survive the balancing test: business-relevant recipients only, a clear statement of who is writing and why, a working unsubscribe honoured well inside the 72 hours Article 92 allows, suppression that persists, and a written legitimate-interest assessment kept with the campaign. Do not rely on consent you cannot show in explicit, purpose-specific form, because Article 36 will ask for it. Keep the record of processing current, because it is the artefact the future agency's fine schedule will be built around. Operationally that is a suppression and consent-record problem before it is a copy problem, which is why we treat email infrastructure as the layer that stores the basis, the objection and the timestamp for every address. For neighbours with a tighter rule, our Vietnam guide covers a country where the anti-spam decree removes the legitimate-interest route entirely, our Singapore guide the region's most enforced regime, our country-by-country comparison table puts every regime side by side, and the opt-in vs opt-out map places them on one scale. An Indonesian lead generation programme should be scoped now on the assumption that the regulator arrives mid-campaign and the January 2027 rules apply to every address already in the sequence.

Want an Indonesia sequence built on a lawful basis you can document?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

There is no anti-spam statute for email. Under the PDP Law (Law 27/2022), fully enforceable since October 17, 2024, sending to a named person's work address is processing of personal data and needs a lawful basis. Legitimate interest is available with a balancing test; consent, if relied on, must be explicit and purpose-specific, and from January 16, 2027 PP 33/2026 requires the controller to be able to prove it.

Government Regulation No. 33 of 2026, promulgated July 16, 2026 and in force January 16, 2027, sets the mechanics: consent must be free, informed, specific and unambiguous and cannot be bundled into terms and conditions; the controller must give the information first, provide a consent mechanism and keep proof of consent; offers of goods or services must disclose third-party recipients and the withdrawal route; and processing must stop within 3 x 24 hours of a verified withdrawal, with confirmation to the data subject.

Administrative sanctions, to be imposed by the PDP Agency, run from a written warning to fines of up to 2% of annual income or revenue. Criminal offences enforced by the public prosecutor include unlawfully collecting personal data (up to five years' imprisonment or IDR 200 million) and unlawful disclosure (up to four years), with corporate fines up to ten times the individual maximum.

Not as of September 13, 2026. The Ministry of Communications and Digital Affairs told Bisnis Indonesia that the draft Presidential Regulation establishing the PDP Agency was submitted for the President's signature by a letter dated May 20, 2026 and is still awaiting it, and that the ministry handles complaints and incidents in the meantime. Administrative fines cannot be imposed until the agency exists.

The PDP Law gives data subjects the right to withdraw consent and to object to and restrict processing, and PP 33/2026 Article 92 requires processing to stop within 3 x 24 hours of a verified withdrawal request. A working opt-out honoured on the day, with persistent suppression and a confirmation to the recipient, is the practical minimum whatever lawful basis you rely on.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us