Indonesia signed Government Regulation No. 33 of 2026 on 16 July 2026 – the long-awaited implementing rule for the country’s 2022 Personal Data Protection Law. It circulated publicly only in late August. The regulation fills in detail on cross-border data transfers, breach notification and impact assessments that businesses had navigated without since the law took effect in October 2024.
It does not complete the picture. Article 58 of the 2022 law calls for a dedicated authority to oversee personal data protection. As of September 2026, that authority has yet to be formally established.
Deputy Minister of Communication and Digital Affairs Nezar Patria said in July, at a US-ASEAN Business Council dinner in Jakarta, that the agency will “operate independently across all its structures.” The presidential regulation establishing it is still being finalised.
The Capital Is Already Moving
The investment cycle is not waiting. Indonesia currently has around 580 megawatts of operational data-centre capacity. Coordinating Minister for Economic Affairs Airlangga Hartarto said, as reported by the Jakarta Post on 12 July 2026, that investors had expressed interest in another 1.3 gigawatts. That represents an estimated USD 15–20 billion in additional investment.
Some of that is already committed. Firmus Technologies, working with Nvidia, is developing a 360-megawatt AI Factory campus in Batam designed for up to 170,000 Nvidia accelerators. Offtake agreements, Firmus says, could generate USD 25–30 billion over six years. EDGNEX has separately committed USD 2.3 billion to a 144-megawatt facility in Cikarang.
Where Digital Growth Meets Governance

Two cybersecurity leaders from Indonesia interviewed for this piece describe the same commercial dynamic playing out across Indonesian enterprises. Ardi Sutedja K., chairman of the Indonesia Cyber Security Forum, frames it as a question of pace at the enterprise level.
“In my experience, one of the most significant gaps lies in the speed at which organisations are investing in AI and cloud technologies versus the pace at which their security governance is maturing. Many Indonesian enterprises are quick to adopt new technologies, driven by the promise of increased efficiency and competitive advantage.
“However, the same urgency is not always applied to developing robust security frameworks. This often results in a reactive rather than proactive approach to cyber security, where measures are only put in place after a breach has occurred,” he explained.
Sugiarto RM, founder of the Indonesia CXO Network, sees it playing out across the wider economy.
“Indonesia already has a growing regulatory framework around personal data, critical information infrastructure and financial-sector cyber resilience, while enterprises are simultaneously increasing spending on cloud, AI and digital infrastructure. The challenge is making sure those two curves converge.”

The National Cyber Security Index provides another indication of the governance challenge. Indonesia scores 47.50, receiving full credit for having personal data protection legislation while scoring zero on the indicator for an empowered personal-data protection authority.
The result highlights the distinction between having a regulatory framework on paper and having the institutional capacity to enforce it.
Banks Already Know What Governance Looks Like
The clearest contrast is financial services. Indonesian banks sit inside a supervisory framework where technology governance and cyber maturity are binding requirements, not aspirations.
OJK Regulation 11/2022 established IT-governance rules for commercial banks. SEOJK 29/2022 added annual cyber-maturity assessments. POJK 1/2026, effective since 1 March 2026, tightened information-technology and third-party risk requirements further.
Philip Lee, head of Orange Cyberdefense APAC, told Bizruption.asia that this is the point at which cybersecurity stops being an IT problem and becomes a board one.
“This shift is increasingly driven by the evolving threat landscape, regulatory compliance and growing pressure from shareholders and local governments. With increased regulatory requirements around data protection, critical infrastructure, incident reporting, and cybersecurity governance, boards have become more engaged with the organisation’s operational environments.

“A major cyber incident or compliance failure can directly affect revenue, business continuity, reputation, customer trust and legal exposure. Translating technical risks into business outcomes helps boards understand their risk appetite and accountability. As cybersecurity becomes integrated into enterprise risk management, it is increasingly recognised as a strategic business resilience issue rather than simply an IT expense,” he said.
Banking has a mechanism for making that translation visible. The question for the rest of Indonesia’s digital economy is how the same discipline can develop as the data centres, cloud platforms and AI ventures now absorbing its investment wave continue to scale.”
What Actually Closes the Gap
Ardi frames the work ahead as cultural before it is technical.
“There must be a cultural shift within organisations where cyber security is viewed as a shared responsibility. This involves continuous education and awareness programs to ensure that every employee understands their role in protecting the organisation’s digital assets.”
Sugiarto describes the practical work still outstanding.
“The corresponding governance layer, who owns the risk, how data is classified, what can be put into an AI model, how third-party and cloud risks are assessed, how identities and access are controlled, and how quickly an organisation can recover from a compromise, is often still catching up.”
The measure that matters, Sugiarto added, is not the size of the security budget. It is whether the board understands the cyber risk it is buying, accepting or transferring. Asked what would close the gap, he ranks the constraints directly.
“Regulation is the catalyst, budget is the enabler, talent is the constraint, but governance and accountability are what will actually close the gap.”
That ranking matters for how capital gets allocated. A regulation can set the obligation and a budget can fund the response, but neither guarantees that someone at the top of the organisation is accountable when the controls fail. That accountability is what boards and investors are now being asked to underwrite.
The USD 15–20 billion now moving into Indonesian data centres is part of a much broader digital transformation. As the country’s infrastructure, AI adoption and digital economy continue to expand, the evolution of governance and accountability will become increasingly important to the companies, boards and investors participating in that growth.
For investors, understanding how governance develops alongside that opportunity will be an increasingly important part of the decision-making process.
References:
- Indonesia tumbles in cybersecurity ranking – The Jakarta Post
- Indonesia to set up independent personal data protection agency – ANTARA News
- National Cyber Security Index: Indonesia – e-Governance Academy, version dated 31 December 2025
- Law No. 27 of 2022 on Personal Data Protection, Republic of Indonesia (Article 58)
- Indonesia’s Financial Services Authority Strengthens the Digital Backbone of Banking Sector through Regulation No. 1 of 2026 – SSEK Law Firm
- OJK Enhances Governance and Risk Management for Sustainable Economic Growth – Financial Services Authority (OJK)
- Data Protection & Privacy 2026: Indonesia – Chambers and Partners
- Data Protection Laws of the World: Indonesia – DLA Piper
- IBM Study: ASEAN Data Breach Costs Rise to US$4.12 Million – IBM Newsroom ASEAN, 2026
- Govt eyes Nvidia investment to increase data center capacity – The Jakarta Post
- Indonesia secures US$2.3b Dubai investment for major data centre – Malay Mail





