On Tuesday, 6 October 2026, Indonesia's House of Representatives (DPR) passed the One Data Indonesia Bill into law at its 9th plenary session. The law has 20 chapters and 141 articles. Until now, One Data ran on Presidential Regulation Number 39 of 2019. It now sits on a statute, complete with administrative sanctions and criminal provisions.

If you run a rural bank (BPR) or any bank, your first reaction may be that this is a matter for ministries and local governments. That is partly true. Coverage so far names ministries, agencies, regional governments, and village governments as the data producers. But the way a state governs its own data tends to become the yardstick for judging data everywhere else, banks included. This article walks through what the law actually covers, then what is worth fixing now.

What the law actually covers

According to Antara's summary, One Data does not mean moving all data into a single warehouse. What gets standardised is the rulebook: data standards, metadata, and reference codes, so that data from different agencies can connect. Sturman Panjaitan, deputy chair of the DPR's legislation body, put the cost of poorly managed data plainly: aid that misses its target and programmes that overlap.

Other points worth noting:

  • National Basic Data (DDN) is controlled by the state and serves as the reference for development planning, fiscal policy, budgeting, and social assistance. Liputan6 reports that DDN is split into six clusters.
  • Data classification has three classes: open, limited, and closed, each with different access rules.
  • Security covers data security standards, cryptographic infrastructure, digital certificate management, security audits, and data sovereignty audits.
  • Data security incidents must be reported within 1 x 24 hours at the latest.
  • Access to and transfer of closed data outside Indonesian jurisdiction requires DPR approval.
  • A One Data administrator is created, reporting directly to the President.
Grid of four points from Indonesia's One Data Law: one shared data standard, three classes of data, auditable security, and a 24 hour incident reporting limit

Why bank directors should read it too

There are three reasons, and none of them depends on whether banks are named in the articles themselves.

First, banks run on data the state also holds. Customer ID numbers, addresses, and region codes are the same kinds of data whose standards One Data sets. Once government agencies use uniform reference codes, bank data in messy formats will stand out more whenever it is matched or exchanged.

Second, the reporting clock is getting shorter. Article 46 of the Personal Data Protection Law (Law 27 of 2022) already requires a personal data controller to notify data subjects and the authority in writing within 3 x 24 hours of a data protection failure. The One Data Law requires the administrator to report incidents within 1 x 24 hours. The 24 hour rule binds government data administrators, not banks. But the direction is clear: what counts as "fast" when handling a data incident is shifting.

Third, auditors and supervisors read the same news. Once a statute talks about data classification, security audits, and data sovereignty audits, questions such as "what class is this data" and "who can open it" will come up more often in board meetings. It is better to have the answers before anyone asks.

Four layers to check at your bank

The simplest way to read data readiness is as a stack. The upper layers cannot hold if the ones beneath them are weak.

Four layers of data readiness at a rural bank: data inventory as the foundation, then standards and reference codes, classification and access, and incident response on top

Data inventory is the foundation. Many banks can name the systems they use but struggle to say which data is stored where and who owns it. Customer data can be spread across core banking, the credit application, a marketing spreadsheet, and field officers' WhatsApp groups.

Standards and reference codes come next. If one customer appears with three different address formats in three systems, reconciliation and reporting will always take longer than they should.

Classification and access make sure customer data, internal data, and public data are not treated the same way. Every access to sensitive data should be logged, so that when questions come you can show the trail rather than just describe the procedure.

Incident response sits at the top. Who detects, who decides, and how many hours until the report is ready to send. Without the three layers beneath it, the team ends up hunting for data while the clock is already running.

Homework you can start this week

There is no need to wait for implementing regulations. Most of the steps below stay useful whatever the technical details turn out to be.

  1. Map your data. List the data the bank holds, the systems storing it, and the unit responsible. Start with customer and credit data.
  2. Align formats. Pick one format for ID numbers, addresses, and region codes, and use it across core banking, the credit system, and reports.
  3. Classify data. Decide what is open, limited, and closed, then reset access rights to match each class.
  4. Time a drill. Run a simple incident simulation and count how many hours it really takes until a written report is ready. If the answer is more than 3 x 24 hours, that is a problem today, not later.
  5. Track the details. Follow the implementing rules of the One Data Law and adjust procedures once they are published.
Five clean-up steps: map your data, align formats, classify data, time an incident drill, and track the implementing rules

The fourth step is often skipped because it feels like a fire drill. That is exactly where banks tend to discover that access logs are incomplete, or that nobody knows for sure who is authorised to sign the report.

What is still unclear

It is worth being honest about the limits. Coverage published so far does not detail the implementing regulations, the timeline for applying them, or which private parties are directly bound. The details of the sanctions have not been spelled out in the reporting either. So the 24 hour figure is best read as a signal of direction, not an obligation that automatically applies to banks tomorrow morning. What binds banks today is still the Personal Data Protection Law and the rules of financial sector supervisors.

National Development Planning Minister Rachmat Pambudy called the law's passage a new historic milestone. For banks, the milestone is not in the parliament building. It is in how tidy your data is when someone asks.

Want a second pair of eyes on your data readiness?

XETUP helps banks and companies organise their data and build custom systems that fit the way they work: from mapping scattered data and aligning formats across systems to logging every access so it is easy to audit. If you want to check how ready the data or systems at your bank are, talk to our team directly on WhatsApp +62 823 1499 5005.