Current Region:
Global

Indonesia

Age verification and child online safety are now a significant part of Indonesia’s digital regulatory framework. The Government Regulation No. 17 of 2025 on the Governance of Electronic Systems for Child Protection (PP TUNAS)[1] established a dedicated framework for protecting children from harmful online content, exploitation, cyberbullying, scams, digital addiction and risks to their personal data.

The framework is implemented by the Ministry of Communication and Digital Affairs (Kemkomdigi)[2], with Ministerial Regulation No. 9 of 2026 providing detailed requirements for age limits, child-user verification, risk assessment and child-protection measures.

PP TUNAS takes a risk-based approach and applies broadly to electronic system operators whose products, services or features may be accessed by children in Indonesia. This can include social media, games, AI products, websites and other consumer digital services. A service does not necessarily have to be designed or marketed for children to fall within the scope of the regulation.

Social Media

Minimum Age Requirements

Indonesia has introduced age-based restrictions for digital services under PP TUNAS.

Eight services were initially designated as high risk:

  • YouTube
  • TikTok
  • Facebook
  • Instagram
  • Threads
  • X
  • Bigo Live
  • Roblox

High-risk services have a minimum account age of 16. Children under 16 must not be permitted to hold accounts on these services.

The wider framework uses five age bands:

  • Under 3
  • 3–5
  • 6–9
  • 10–12
  • 13–15
  • 16–17

The framework requires platforms to:

  • Prevent children under 16 from holding accounts on high-risk digital platforms
  • Provide clear information about minimum age requirements
  • Apply safeguards appropriate to different age groups
  • Implement mechanisms to verify child users and assess the risks associated with their services

There are also different age classifications for different obligations. For example, parental controls use two classifications: users under 17 and users aged 17 and over.

Age verification applies to users across the relevant services, regardless of whether the service is ultimately classified as high or low risk.

Platform Enforcement and Compliance

The Indonesian Government has moved beyond voluntary commitments and has begun actively enforcing the new requirements. In March 2026, Kemkomdigi summoned Google and Meta over compliance with the under-16 restrictions.[3]

The Government has also reported positive compliance measures from major platforms. Meta subsequently aligned Facebook, Instagram and Threads with a minimum age of 16, while Roblox committed to complying with PP TUNAS following discussions with the Government.

The Minister reported in September 2026 that 2,052 products, services and features had been self-assessed. Of the 60 assessments that had been verified by the Ministry at that point, 22 were classified as high risk and 38 as low risk.

The Government can also determine the risk classification itself where an operator does not submit the required self-assessment.

Risk Assessment and Self-Assessment

One of the key features of PP TUNAS is the requirement for providers to complete and submit a risk self-assessment to Komdigi.

Providers are required to assess products, services and features that may be accessed by children. The assessment considers seven risk dimensions:

  1. Contact or interaction with other users, including strangers
  2. Exposure to inappropriate content, including pornography, violence and other content that may endanger children
  3. Commercial exploitation of children
  4. Risks to children's personal data and privacy
  5. Addiction and potentially addictive use
  6. Risks to children's psychological health
  7. Risks to children's physical health

Existing safeguards and mitigation measures can be taken into account when determining the risk classification. As a result, two otherwise similar services may receive different risk classifications depending on the controls and protections they have in place.

All seven dimensions need to be assessed as low risk for a service to receive an overall low-risk classification. The burden of demonstrating that the service is low risk rests with the business.

The assessment is not simply an internal exercise. Providers must submit their assessment to Komdigi for review.

The original self-assessment deadline has been extended to 31 December 2026.

If a provider does not submit an assessment, the Government can determine the risk profile of the relevant product, service or feature itself.

The assessment is intended to be a multidisciplinary exercise. Komdigi's guidance recommends involving relevant specialists alongside legal and privacy teams, including child safety or psychology specialists, IT security, product and sales teams.

Transition Period

PP TUNAS originally provided for a maximum transition period of two years following its introduction in 2025.

However, the Indonesian Government expedited implementation and began enforcement in March 2026 rather than waiting for the full two-year transition period to expire.

This means that providers should not treat March 2027 as the point at which compliance begins. Enforcement is already taking place, while the self-assessment filing deadline has been extended to the end of 2026.

Age Assurance

Age assurance is a central part of the PP TUNAS framework.

Providers are required to implement mechanisms to verify users' ages, and the requirement applies regardless of whether a service is ultimately classified as high or low risk.

The regulations do not prescribe a single age assurance technology. Providers therefore have flexibility in how they demonstrate that their approach is sufficiently reliable and appropriate to the risks involved.

Age assurance should take account of privacy and data-protection principles, including data minimisation and avoiding the collection of excessive information.

Age inference may also be used as part of an age assurance approach, although it is not specifically mandated by PP TUNAS. Providers remain responsible for demonstrating that the method they use is sufficiently reliable to meet the regulatory requirements.

Parental Consent and Controls

PP TUNAS includes specific requirements for parental consent and controls.

For children under 16, parental consent is required before access is provided where the relevant requirements apply.

For users aged 16–17, the framework provides for parental notification and a 24-hour period during which a parent or guardian can revoke consent.

Importantly, access cannot be provided while the parental consent or notification process is pending. There is no general "waiting state" in which the child can access the service while consent is being obtained.

The consent request must be clear and understandable. The regulations do not currently prescribe a single method for verifying the identity of the parent or guardian, although providers must consider the relevant privacy and assurance requirements.

Adult Users and 18+ Services

Age verification does not simply stop once a user reaches 18. Where a service falls within the scope of PP TUNAS, age verification requirements apply across the relevant user population.

A service that genuinely operates as an 18+ service may potentially fall outside the child-protection requirements, but simply describing a service as 18+ does not necessarily remove it from scope.

The key question is whether children are likely to access the service. The Government can consider factors such as user demographics, advertising, product design, internal documentation and Indonesian traffic when determining whether a service is likely to be accessed by children.

Adult and Harmful Content Controls

The Indonesian framework links age assurance directly to the prevention of children's exposure to harmful and inappropriate content. The Government has identified pornography, cyberbullying, online fraud and digital addiction among the risks that the regulations are intended to address.

Platforms are expected to:

  • Restrict children's access to products, services and features that are inappropriate for their age or risk profile
  • Implement age and user-verification mechanisms
  • Design services with child safety incorporated into products and features
  • Provide mechanisms for reporting misuse or potential violations of children's rights
  • Apply stronger safeguards where products or features present greater risks to children

The risk assessment can apply at product, service and feature level. A particular feature, such as chat or user-generated content, can therefore have a significant effect on the overall risk classification of a service.

Chatbots, AI and Interactive Applications

PP TUNAS applies broadly to electronic systems, products, services and features rather than being limited to traditional social media.

This means AI products, chatbots, gaming services and other interactive applications may fall within the framework where they can be accessed by children in Indonesia.

The presence of an AI chatbot does not automatically make a service high risk. The classification depends on the characteristics and features of the service and the outcome of the risk assessment.

Providers should therefore consider the specific risks associated with features such as interaction with other users, user-generated content, public profiles, messaging, recommendations and other forms of interactive or personalised content.

Online Gaming and Other Digital Services

Indonesia's child online safety framework extends beyond social media. Roblox was included among the platforms targeted during the initial implementation of PP TUNAS, demonstrating that the Government's approach also covers gaming and interactive services.

The framework requires providers of digital products and services to consider:

  • The minimum age appropriate for their products, services and features
  • The risk profile of the service
  • Age verification and child-user verification
  • Parental involvement where required
  • Privacy and personal-data safeguards
  • The design of features and services according to children's developmental needs

Indonesia also operates the Indonesia Game Rating System (IGRS)[4], which provides age classifications for games. The wider PP TUNAS framework adds child-protection obligations to the regulatory environment for online gaming and interactive services.

Enforcement Powers and Regulatory Oversight

PP TUNAS is already being enforced.

The Government can investigate compliance and take action where providers do not meet their obligations.

The regulatory framework provides for sanctions including warnings, administrative fines, suspension and termination of access.

The mechanism for administering financial penalties under PP TUNAS is not yet fully operational. Fines of up to 6% of global revenue are being contemplated.

In the meantime, service blocking is an important enforcement mechanism. Komdigi can work with internet service providers to block access to a service, particularly where an overseas provider does not have an Indonesian presence.

Blocking can also be applied progressively. The Government may block a particular feature before moving to blocking the entire service.

This makes service or feature discontinuation an immediate practical compliance risk even while the financial penalty mechanism is still being developed.

Technical Implementation and Age Verification

Age and user verification are explicit components of the Indonesian framework. Ministerial Regulation No. 9 of 2026 requires electronic system providers to implement mechanisms for verifying child users according to the risk level of the service.

The Government has also recognised that simple self-declaration of age can be insufficient. In February 2026, the Deputy Minister of Communication and Digital Affairs stated that children frequently manipulate their stated age to bypass platform restrictions and called for platforms to consider age-inference and behavioural detection technologies.[5]

Technical implementation is therefore expected to consider:

  • The reliability of age verification mechanisms
  • The ability of systems to identify users attempting to circumvent age restrictions
  • The risk profile of the service
  • Privacy and personal-data protection
  • Proportionate verification measures appropriate to the service and user

The Government's July 2026 assessment of Apple's services further demonstrates the risk-based approach - individual products and features are being assessed according to their characteristics and potential risks to children.[6]

Child Data Protection and Algorithmic Safeguards

Child privacy and data protection form an important part of the PP TUNAS framework. Platforms must incorporate child protection into the design and operation of their services and consider the particular risks associated with processing children's personal data.

Child-focused safeguards include:

  • Protection of children's personal data and privacy
  • Consideration of data-protection risks when services are designed and operated
  • Restrictions on practices that could exploit children's data
  • Risk-based safeguards appropriate to the age and characteristics of child users
  • Greater protection where products, services or features present higher risks

The framework is intended to ensure that child protection is not limited to preventing access to inappropriate services, but also addresses risks arising after children are using a digital product or service.

PLEASE NOTE This page summarises current Indonesian law and regulatory developments as of August 2026 and does not constitute legal advice. Always consult independent legal advisers before making compliance decisions.


[1] https://ps-engage.com/pp-tunas-indonesias-new-digital-regulation-to-protect-children-online/

[2] https://www.komdigi.go.id/berita/pengumuman/detail/ministry-of-communication-and-information-technology-kominfo-task-of-kominfo-building-a-three-sector-of-information-technology

[3] https://www.thejakartapost.com/business/2026/03/31/govt-summons-meta-google-over-noncompliance-with-child-social-media-curbs

[4] https://igrs.id/

[5] https://en.antaranews.com/news/403322/digital-platforms-urged-to-create-solutions-for-child-age-faking

[6] https://www.mlex.com/mlex/articles/2497009/indonesian-ministry-to-verify-if-apple-services-comply-with-child-protection-rules