Indonesia Weighs New Cross-Border Data Rules in One Data Bill Talks

Indonesia Weighs New Cross-Border Data Rules in One Data Bill Talks

Indonesia’s One Data Bill is bringing cross-border data transfers and data sovereignty into formal negotiations. Image: Nick Agus Arya/Unsplash

Indonesia’s One Data Bill puts cross-border data transfers, data sovereignty, and overseas processing rules under formal negotiation.

Sep 23, 2026
We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

Indonesia’s push to unify government data is running into a border problem: What happens when that data leaves the country? Lawmakers are now weighing how Indonesian authority should apply when information is stored or processed overseas.

The House of Representatives and government began joint deliberations on the One Data Indonesia Bill on Sept. 23, bringing data sovereignty and cross-border transfers into formal negotiations. The bill is primarily aimed at fragmented government data, but the outcome could also affect cloud providers, contractors, and other companies handling Indonesian public-sector information.

The talks followed a Sept. 22 meeting in which Coordinating Minister Yusril Ihza Mahendra called for legal certainty for businesses on data use and cross-border transfers. Lawmakers also said the framework should give government agencies common national data references without stripping them of authority over the information they produce, according to same-day reporting on the deliberations.

For companies operating across Southeast Asia, Indonesia’s rules can shape where cloud workloads run and how regional systems are designed. Businesses already face cross-border friction across ASEAN as regulations and digital infrastructure vary by market, even as governments pursue deeper regional integration.

Indonesia’s existing cross-border data rules

Indonesia already has a separate legal framework for sending personal data overseas. Government Regulation No. 33/2026 implements the country’s 2022 Personal Data Protection Law and was promulgated July 16 with a six-month transition period.

The regulation follows a tiered transfer mechanism. Controllers first look to whether the destination provides equivalent or stronger protection; if not, they must use adequate and binding safeguards. Consent is available only as a fallback under specified conditions, according to an analysis by Assegaf Hamzah & Partners.

The One Data Bill is a different proposal focused on national and government data governance. It does not replace Indonesia’s existing personal-data transfer rules or currently impose a second binding transfer regime on private companies. Regional governments are also expanding digital ties, including recent Singapore-Thailand cooperation on digital trade and cross-border payments.

What the One Data bill could change

Advertisement

The DPR adopted the bill as a chamber initiative in July to address data fragmented across ministries, agencies, regional governments, and other public bodies. The government finalized its negotiating position on Sept. 8, restructuring its version into 138 articles while maintaining that individual institutions would retain authority over their data.

Cross-border authority had already surfaced during drafting. In April, a Baleg lawmaker proposed giving the state power to set conditions, limits, and mechanisms when data moves beyond Indonesian jurisdiction. Those provisions remain subject to negotiation.

The debate is unfolding as Indonesia expands its domestic computing capacity. Zankore recently secured up to $3.1 billion for Nvidia-powered AI infrastructure beginning in Indonesia, giving enterprises more local capacity as policymakers consider how certain data should move across borders.

The unresolved issues are whether the final bill creates localization requirements for government or strategically important data, how Indonesian jurisdiction applies to information processed abroad, and whether obligations extend to private providers handling government workloads.

Until those provisions are settled, GR 33/2026 remains the clearer compliance baseline for personal-data transfers. Cloud providers, government contractors, and multinationals using regional infrastructure will need to watch for rules that change where Indonesian public-sector data can be processed and under whose authority.

Also read: Elsewhere in Southeast Asia, Thailand’s Cloud Security Standard is now in force, adding compliance requirements for covered government agencies, critical-infrastructure organizations, and cloud providers.