Indonesia digital sovereignty

Indonesia's One Data Law Puts Parliament in the Path of Every Cross-Border Transfer of Closed Government Data

Indonesia's new Satu Data law centralises government data under state control and gives the DPR a veto over closed-data transfers abroad, at the cost of predictability.

Indonesia's One Data Law at a Glance People of Internet Research · Indonesia 141 Articles in the law The law has 20 chapters and 141 ar… 15 yrs Maximum prison term Article 133 penalty for attacks on… 24 hrs Incident reporting deadline The law mandates incident reportin… peopleofinternet.com
Indonesia's One Data Law at a Glance People of Internet Research · Indonesia 141 Articles in the law 15 yrs Maximum prison term 24 hrs Incident reporting deadli… peopleofinternet.com

Key Takeaways

On 6 October 2026 Indonesia's House of Representatives (DPR) passed the One Data Indonesia (Satu Data Indonesia, SDI) Law in plenary. The text has 20 chapters and 141 articles. The working committee (Panja) began deliberating on 23 September, and the Legislative Body (Baleg) and the government agreed the final text on 5 October, according to the DPR's own reporting. That is roughly two weeks of committee work for a statute that reorganises how the state holds, shares and exports its data.

The strongest case for the law

The government's argument is sound as far as it goes. Indonesian agencies from ministries down to village governments produce overlapping, inconsistent datasets, and that makes social-assistance targeting, budgeting and planning worse. The law replaces Presidential Regulation 39/2019 with a statute that sets common standards, metadata, reference codes and a national data catalogue. It also creates an SDI organiser answerable directly to the President, which must be established within a year. Planning Minister Rachmat Pambudy framed the law as a historic step toward the 2045 centenary. A single data standard and a mandatory 24-hour incident-reporting rule are the kind of plumbing Indonesia lacks. This reasoning would be hard to dispute if the law stopped there.

What the law adds beyond plumbing

The sovereignty provisions go further. According to the DPR, National Basic Data is placed under state control as the reference for planning, fiscal policy and social assistance. Reporting on the text quotes the clause that access to and transfer of closed data outside Indonesian jurisdiction must obtain DPR approval. The same reporting says that digital technology, blockchain and AI use must preserve national data sovereignty. The law also adds sovereignty audits alongside security audits.

The criminal provision is the sharpest. Katadata quotes Article 133. It covers attacks, sabotage, manipulation, destruction, unauthorised dissemination or takeover of the national data centre or SDI infrastructure, and carries up to 15 years in prison or a top-category fine. Article 135 reportedly adds one-third to the penalty for state officials. Prosecuting genuine sabotage of government infrastructure is legitimate. The risk lies in the verbs. "Manipulation" and "unauthorised dissemination" are broad words, and a journalist or researcher who publishes leaked government data could argue they fall outside the provision's intent, though the text's reach is untested.

A parliamentary veto is an unusual export-control tool

Most data-localisation regimes assign transfer decisions to a regulator, a minister or the data controller. Giving a legislature case-by-case approval is different, and it sits awkwardly with how Indonesia's courts have treated data flows. On 19 January 2026 the Constitutional Court, in case 137/PUU-XXIII/2025, rejected a challenge to Article 56 of the 2022 Personal Data Protection Law. The petitioner had wanted DPR approval for cross-border personal data transfers. The Court held that not every transfer requires parliamentary approval, and that administrative mechanisms can assess whether the destination offers adequate protection. Commentary on the ruling in Conflict of Laws notes that the Personal Data Protection Authority still does not exist and implementing rules are missing.

The result is two regimes. Personal data moves under an administrative adequacy test that Indonesia has not finished building. Closed government data moves only with a vote of the House. The drafters' choice is understandable, since national data is not the same as customer data. But the reporting I reviewed does not say what "closed data" covers, which body prepares a request, or how quickly the DPR must decide. If the classification is drawn widely, ministries running routine cloud, analytics or AI contracts will face a political gate for decisions that are normally operational.

Why this matters for innovation

Sovereignty rhetoric is not new, and it is not unique to Indonesia. The EFF argues that digital sovereignty is worth pursuing when it centres user autonomy through open, interoperable systems. It warns that states can use the idea to cut off or splinter access. A parallel debate in India makes the same point from industry. Airtel told the India Mobile Congress that sovereignty goes beyond storage to who can access data and whether a foreign government can switch services off, citing Microsoft's July 2025 suspension of services to Nayara Energy. The lesson there is resilience, meaning contractual guarantees, portability and multi-vendor design. A veto over exports does not deliver any of those.

There is also a process concern. A statute that governs AI, blockchain, cross-border data and criminal liability was negotiated across seven committee sessions between 23 September and 5 October. The final plenary vote came a day after the text was agreed. All eight factions backed it, so there was little opposition scrutiny.

What to watch

The law's quality will be decided in implementing rules, not in the statute. Four questions matter most:

A proportionate version of this law would give Indonesia consistent government data and a credible security baseline while keeping transfer decisions with a regulator that can act in days. The version as passed leaves much of that to chance.

Sources & Citations

  1. DPR: Panja agrees 20 chapters and 141 articles (5 Oct 2026)
  2. DPR: Plenary passes SDI Law (6 Oct 2026)
  3. Satu Data portal: Baleg and government agree SDI bill
  4. Constitutional Court decision 137/PUU-XXIII/2025
  5. Katadata: SDI Law, 15-year penalty (Article 133)
  6. Conflict of Laws: cross-border transfers after the Constitutional Court ruling
  7. EFF: Digital Sovereignty: What It Is, What It Could Be
  8. MediaNama: Airtel on data sovereignty at IMC 2026