Indonesia's One Data Law Officially Passed, Here Are the 8 Key Points!
The House of Representatives (DPR), during a Plenary Session, officially passed the One Data Indonesia (SDI) Bill as law on Tuesday (6/10/2026). The ratification was finalised by the Speaker of the DPR, Puan Maharani, who presided over the session.
Prior to the ratification, the Vice Chairman of the DPR Legislative Body (Baleg), Sturman Panjaitan, presented the report on the discussions regarding the SDI Bill. Following this, Puan requested approval from the assembly.
“The time has come for us to ask all session participants: can the Bill regarding One Data Indonesia be approved to be enacted into law?” asked Puan during the 9th Plenary Session of the 1st Session Period 2026-2027 at the Nusantara II Building, Parliament Complex, Senayan, Jakarta.
All factions within the DPR and members present at the Plenary Session expressed their agreement, resulting in the official enactment of the One Data Indonesia Bill into law.
The SDI Law, an initiative of the DPR, regulates the National Basic Data (DDN), which will be fully managed by the state to serve as a reference for development planning, fiscal policy and budgeting, social assistance distribution, and national strategic needs.
The SDI Law consists of 20 chapters and 141 articles. It regulates the governance of SDI through an SDI master plan, SDI architecture, SDI management, and the SDI lifecycle. The law also addresses data security and protection through established data security standards.
In addition to regulating the governance of One Data Indonesia, the SDI Law provides the legal framework for the establishment of the SDI implementing agency, which will be accountable to the President. The division of data management authority is also regulated, ranging from the central level down to villages or sub-districts.
The SDI Law also covers regulations for data standards, metadata, reference codes and/or master data, the national data catalogue system, data interoperability, and the utilisation of digital technology, blockchain, and artificial intelligence (AI).
Furthermore, the SDI Law regulates data usage and access control, data security standards, security audits, data sovereignty audits, as well as administrative sanctions and criminal provisions for violators, alongside transitional provisions.
Sturman revealed that the implementation of One Data Indonesia is expected to reduce data discrepancies between ministries and agencies. With a single data reference, the government is expected to no longer face issues regarding conflicting data when addressing problems.
“Once One Data Indonesia is implemented, there will no longer be confusing data. There will no longer be different data held by various ministries regarding a single issue,” he stated, as quoted from the DPR RI website.
He added that the integrated data must be easy to use according to access regulations, well-organised, securely stored, and utilised according to requirements.
However, Sturman emphasised that data openness must still prioritise personal data protection. He noted that regulations regarding who can access data and how it is used must be carefully managed to prevent misuse.
“Personal data protection must also be our priority,” he said.
Here are the eight key points regulated in the SDI Law:
The SDI Law regulates National Basic Data (DDN), which is controlled by the state and serves as the primary reference for development planning, state financial policy and budgeting, social assistance distribution, and other national needs.
The SDI Law regulates the formation of the SDI implementing agency, which will be accountable to the President. This agency will replace the concept of the Indonesia One Data Agency.
The SDI Law mandates that all agencies producing and managing data must use the same data standards.
The SDI Law regulates the systems and means used in digital data management. Such management must prioritise national data security and sovereignty.
The SDI Law ensures that data held by various agencies is organised so that it can be interconnected and used collectively as needed.
The SDI Law regulates data security standards as determined by agencies in the field of cyber security and cryptography.
The public is provided with the space to provide input, report suspected data misuse, conduct oversight, and provide data voluntarily.
The SDI Law regulates the dispute resolution mechanism related to data management. Dispute resolution will prioritise out-of-court mechanisms or mediation.