KETEMU:

Menjembatani Diskusi, Riset, dan Kebijakan untuk Teknologi Etis

Dari Corps de Ballet ke Ansambel: Koreografi Kolektif untuk Satu Data Indonesia

“We are currently still in decile 6, and today we are processing the decile reduction. Because if we are in decile 6, we cannot get the KIP Kuliah (Smart Indonesia Card for Higher Education), even though my family can be considered financially struggling because there are a lot of expenses for college now.” (Siti Wardah, 53 years old, parent, Detik.com, September 4, 2026.)

Similar stories to Siti Wardah’s have recently flooded Indonesian media. The decile mechanism, which categorizes the population by socioeconomic status, has garnered negative sentiment, despite its intent to facilitate effective planning and social aid.

Data collection and analysis are foundational elements for generating evidence, informing policy decisions, and supporting effective monitoring and evaluation, becoming even more crucial in the digital transformation era. Data collection, categorization, and population grouping are standard practices in data analysis. When conducted properly, this data holds powerful potential to inform public policies and secure a better future for countries and societies. 

However, ethical questions arise when citizens, the owners of this personal data, are unaware that their information is being collected and cross-referenced with other sources, such as electricity bills, bank savings, and vehicle ownership records.

In other words, without proper safeguards, data exchange and interoperability risk objectifying citizens, eroding public trust, and undermining the efficacy of public policy processes. In short, establishing thoughtful safeguards before scaling is an investment.

In relation to these data governance challenges and Indonesia’s GovTech aspirations, the ongoing deliberations surrounding the Satu Data Indonesia Bill provide a timely opportunity to reinforce trustworthy data governance and advance the national Digital Public Infrastructure ecosystem. As the bill moves through the legislative priority program, a review of the publicly available 2022 draft suggests a need for enhanced safeguards to align government data-sharing efficiency with the right to personal data privacy as protected by the Personal Data Protection (PDP) Law enacted in 2022.

Against this backdrop, KETEMU has identified safeguard mechanisms derived from best practices in four countries and region that offer a pathway toward data governance integrating bureaucratic efficiency, dignity, and equity.

1. Estonia: X-Road Architecture & Security Principles

Estonia launched X-Road in 2001 to connect fragmented government databases. Its architecture uses security-by-design principles to guarantee data sovereignty. In 2016, Estonia open-sourced the platform’s core code, and the Nordic Institute for Interoperability Solutions (NIIS) now manages its global development. Over 25 countries currently rely on X-Road as a secure backbone for public digital infrastructure.

X-Road functions as a distributed data exchange layer. It connects separate information systems over the internet without storing data in a single location. Centralized databases create vulnerable honeypots; X-Road avoids this risk through direct, peer-to-peer transfers. Each participating institution runs a Security Server (a technical gatekeeper that handles authentication, encryption, and digital signatures). A central registry sets system rules, but it never sees or holds the underlying data.

2. India: Data Empowerment & Protection Architecture (DEPA)

India’s Data Empowerment and Protection Architecture (DEPA) centers on the ‘Consent Manager’ model, a secure, neutral intermediary that restores data ownership to the citizen. Rather than acting as a data repository, these managers serve as ‘data-blind’ conduits. They manage only consent artifacts in the form of digitized, granular, and revocable records of permission, while facilitating secure data transfers between providers and users through standardized APIs. 

This architecture transitions data governance from an institutional-centric model (often reliant on risky manual practices like screen scraping or blanket ‘take-it-or-leave-it’ forms) to an individual-centric one, where citizens gain real-time, auditable control over their personal information. By separating the consent layer from the data flow, this mechanism enables legally compliant sharing without creating vulnerable, centralized databases.

3. Singapore: Trusted Data Sharing & Innovation Frameworks

Singapore’s Infocomm Media Development Authority (IMDA) established the Trusted Data Sharing Framework to solve legal, technical, and operational hurdles in data exchange. The framework establishes shared standards across institutions through standardized contract templates, practical data valuation models, and explicit governance rules. These pre-approved legal tools help government agencies share data safely without facing regulatory uncertainty or institutional resistance.

4. European Union: Interoperability & Privacy Baselines

The European Union’s approach to public sector interoperability is defined by a two-tiered baseline. First, the European Interoperability Framework (EIF) establishes a conceptual model standardizing integration across four layers: legal, organizational, semantic, and technical. Second, the Interoperable Europe Act (2024) serves as the binding regulation that codifies these standards, mandating that public bodies perform interoperability assessments before developing new digital systems and enforcing a ‘share and reuse’ policy for digital assets. These baselines move public administration beyond voluntary cooperation, requiring an interoperable-by-design strategy that ensures digital infrastructure remains cohesive, secure, and adaptable.

Strategic Relevance for the Satu Data Indonesia Bill

Safeguard Mechanisms Indonesia’s Strategic Application
Decentralized Interoperability: 
Secure, peer-to-peer exchange without central storage.
(Based on the framework of Estonia’s X-Road.)
Serve as the connective tissue for Satu Data to avoid centralized honeypots.
Consent-Based Architecture: 
Granular, revocable user control via Consent Managers.
(Based on the framework of India’s DEPA.)
Operationalizes the PDP Law requirements for informed, specific consent.
Governance Accelerator: 
Standardized contracts to break ego-sectoral silos.
(Based on the framework of Singapore’s IMDA.)
Provides blueprints to resolve legal liability and inter-agency friction.
Multi-Layered Standards: 
Mandatory assessments ensuring an interoperable-by-design practice.
(Based on the framework of the EU’s EIF.)
Ensures national-to-regional cohesion beyond simple technical connectivity.

The international frameworks above provide inspiration for addressing the structural and ethical limitations in the current Satu Data Indonesia Bill. By integrating these lessons, the upcoming legislation can shift from an administrative efficiency tool to a rights-respecting, secure, and trustworthy governance architecture. Potential strategic applications include:

    1. Design Choices that Choreograph Trust

To mitigate the systemic risk of central honeypots, the Satu Data Indonesia Bill should consider choreographing a decentralized data exchange framework modeled on Estonia’s X-Road. Rather than consolidating sensitive citizen records into a single monolithic database, governance should mandate direct, peer-to-peer interoperability. Instead of forcing ministries and agencies to surrender their information into a central pool, this choreography enables them to participate in a shared, standards-based ecosystem without sacrificing control or sovereignty. Data remains securely held at the source by the originating ministry or agency, while encrypted gateways facilitate seamless, auditable transactions.

By transforming the national data infrastructure from a static, fragile accumulation of records into a dynamic and reliable network, the government can overcome the primary barrier of institutional reluctance. This architectural shift particularly allows individual agencies to retain ownership and stewardship of their specific data sets, which effectively removes the root cause of ego-sectoral resistance. 

    1. Rights-Respecting Governance

Aligning the Satu Data Indonesia Bill with the PDP Law necessitates a philosophical transition from paternalistic institutional control toward respect for individual agency. By emulating India’s Data Empowerment and Protection Architecture (DEPA), Indonesia can introduce neutral, data-blind Consent Managers that operationalize citizen rights.

This shift transforms the citizen’s role from a passive data subject into an active, empowered data owner. Instead of navigating broad, take-it-or-leave-it consent forms, the citizens gain granular, real-time control over how their information flows across public entities, ensuring transparency, enforcing purpose-bound usage, and establishing a sustainable foundation of public trust.

    1. Inter-agency Coordinated Cadence

Overcoming off-rhythm Indonesian inter-agency friction requires moving beyond vague policy declarations toward actionable, standardized operational tools. Drawing from Singapore’s IMDA framework, the Satu Data Indonesia Bill should institutionalize pre-approved legal templates and trusted data-sharing blueprints. These instruments are developed to eliminate the bureaucratic hesitancy driven by legal uncertainty and fear of liability. In tandem, the legislation should adapt the rigorous multi-layered approach found in the EU Interoperable Europe Act. This ensures legal, organizational, semantic, and technical alignment.

By requiring public bodies to utilize these standard practices, the government can replace fragmented, ad-hoc data arrangements with a unified framework. This transition enables agencies to collaborate with confidence, making national data exchange a predictable, efficient, and secure administrative function.

    1. Data Governance as a Living System

Long-term data governance ideally evolves from a static, rigid legislative framework into an adaptive, responsive system that mirrors the complexities of public administration. The experiences of citizens like Siti Wardah demonstrate the immediate societal harm caused by automated categorization when citizens possess no meaningful recourse to challenge or rectify incorrect data. Citizens like Siti should have the opportunity to know who accesses their data, why, when, and under what legal authority. They need accessible channels to question, correct, and seek redress for its use. 

Trust is not built by asking citizens to trust the system but by making the system worthy of their trust. Accordingly, the Satu Data Indonesia Bill should institutionalize continuous feedback loops, formalizing channels for public input and transparent dispute resolution. By explicitly treating data governance as an iterative and living system, public sector interoperability remains technically functional and fundamentally accountable. This will keep the national data infrastructure agile, inherently protective of individual dignity, and consistently aligned with the lived experiences and evolving needs of the Indonesian populace.

Leave a Reply

Alamat email Anda tidak akan dipublikasikan. Ruas yang wajib ditandai *