Preparing for Indonesia PP Tunas. Webinar Recap.
0:00 · Welcome and speaker introductions
3:02 · What PP Tunas is, and who it applies to
6:24 · The timeline and the transition period
8:53 · The Minister's September figures
10:22 · Enforcement in practice
13:13 · Who is in scope: the five pre-assessment indicators
17:07 · The age bands
19:57 · Completing the self-assessment
21:39 · The seven risk dimensions
24:33 · Age assurance and parental consent
27:49 · Facial age estimation vs facial recognition
29:54 · How k-ID helps
31:33 · What to prioritise: three strategies
38:41 · Live Q&A begins: penalties, fines and service blocking
43:12 · Age inference
45:15 · The 24-hour parental consent window
48:34 · Going 18+: does PP Tunas still apply?
What PP Tunas actually requires, and where to start
Indonesia's PP Tunas is Government Regulation 17 of 2025, Komdigi's risk-based child protection framework, reaching any business running an electronic system accessible to children in Indonesia: games, social platforms, AI products and most consumer apps. You do not have to target Indonesia to be in scope, and children do not have to be your intended audience. Komdigi screens on five indicators covering your documentation, users, advertising, design and Indonesian traffic. Stated intent is not one.
The core obligation is the self-assessment. You score your service against seven mandatory risk factors, from contact with strangers to addiction and psychological impact, and submit it to Komdigi, which sets your risk level. All seven must come back low for an overall low-risk rating, and the burden of proof sits with you. Chat, user-generated content, public profiles, friend lists and streaming all push toward high risk. The rating sets what you can ship: high risk closes the service to under-16s, low risk sets the floor at 13. Parental consent is required for under-18s, age verification applies regardless of rating, and consent must be in Indonesian and obtained before access, with no waiting state.
Enforcement is already running. On 14 September the Minister reported 2,052 products self-assessed, 60 verified, 22 high risk and 38 low, and named X, Meta, YouTube and TikTok. The six percent revenue penalty is not yet operative while the fines mechanism is pending, but ISP-level blocking is. The regulation has been enforceable since March 2026 and the filing deadline now runs to the end of 2026. Controls change the outcome: Komdigi has rated near-identical services differently on what each had in place before filing. The session covers the age bands, the 24-hour consent window, and what counsel would prioritise this quarter.
Where to start
Counsel’s practical sequence from the webinar session:
- Run the scope check first. Work the five indicators against your own product honestly, including your internal documentation and your Indonesian traffic. If you are in scope, you want to know now rather than after a letter arrives.
- Complete and file the self-assessment. The filing deadline has been extended to the end of 2026. A result coming back does not mean you immediately have to build; there is back and forth with Komdigi before obligations crystallise. If you have already had a letter from the ministry, start here to show goodwill.
- Put controls in place in parallel, not afterwards. Filing with age assurance and feature-level controls already in place materially improves the rating you receive. Where the two can run together, run them together.
- Fix the consent flow early. It is the piece most likely to need real engineering. Consent before access, no waiting state, and an Indonesian-language consent request and privacy policy.
- Bring the right people to the assessment. Komdigi’s guidance advises child psychologists and IT security alongside legal, product and sales. As Iqsan Sirie put it, you need a village to complete a self-assessment.

Assegaf Hamzah & Partners

Assegaf Hamzah & Partners

Full Webinar Transcript
Welcome and speaker introductions
Joe Newman, k-ID: Thank you, Dots, and thank you everyone for attending. I know it’s a little bit late for Californians, and all hours here, but we are recording this, and thank you for spending some time with us, and thank you, a huge thank you, we’re very privileged and honored to be joined by some amazing experts in the field, from Assegaf Hamzah & Partners, I hopefully pronounced that correctly. We’ve got Iqsan and Zacky. If you guys want to give a very brief intro, and then we’ll kick it off.
Assegaf Hamzah & Partners: Okay, thank you, Joe and k-ID, for having us this morning. It’s top of the morning here in Jakarta, Indonesia, but as I noted there, it’s probably at the end of the day in the western part of the U.S, and relatively evening in the eastern part of the US. But it’s midday in Europe, I guess. So, Iqsan and I are from Assegaf Hamzah & Partners, as Joe mentioned. We are an Indonesian law firm. Our practice focuses on technology and telecommunication issues, so this issue of online child safety is pretty much within our purview, and we’re delighted to be able to share some of the information and insight about this regulation this morning. Iqsan and I will be doing this as a tag team, I will start, and then Iqsan will go into much of the details in the later part of the presentation. Thank you.
Joe Newman, k-ID: Fantastic. Yeah, and as I mentioned, I’m a senior legal counsel at k-ID. I am not, by any means, an Indonesian law expert, so that’s why I’m so glad to be joined by those who are. And again, my goal here is to ask some questions. I’ve certainly learned a whole lot about this new law through our conversations. And, yeah, hopefully we’ll get some questions answered.
What PP Tunas is, and who it applies to
Joe Newman, k-ID: Kicking things off, just at a glance, PP Tunas, this is a law, or excuse me, a regulation, that has actually been around since 2025, but is now just starting to come into effect. What I understand about it is there’s an age verification mandate, parental controls, and what is unique about this regulation is the self-assessments that must be submitted to the ministry of communication, we will be referring to them throughout the webinar as Komdigi, and we’ll talk a lot about how Komdigi works, and how they are evaluating these self-assessments. Similar to a lot of other online safety acts out there, there are some real teeth to this particular regulation, with potentially up to 6% of the company’s global revenue, although the implementation mechanism for fines is still pending. In the meantime, there is still the possibility of suspension of services, which was something that we were going to talk about as one of the real, immediate consequences for noncompliance. And we have seen, actually, as of earlier this week, Komdigi has publicly called out some of these companies, such as X, Meta, YouTube, TikTok, as not being fully compliant. So they are serious about this. Anything you guys want to add before we get into a timeline?
Assegaf Hamzah & Partners: Maybe just briefly about the regulation itself. We’ll get into the timeline, but just on the title, if you will. It relates to, in Bahasa at least, Tata Kelola Penyelenggaraan Sistem Elektronik. So it deals with the management of electronic systems, in how it protects children. So this is clearly a regulation where the intent is that those who are electronic system operators will fall under this regulation, and the intention is to protect children, in the sense that if you are an electronic system operator, and your service includes children, this regulation will be applicable to you. Electronic system, in simple terms, or maybe just use an example, it’s like a platform, or website, or online payment gateway, things that have an electronic system in it that interacts with customers, with external parties, that is broadly what electronic system under the Indonesian regulation is about.
Joe Newman, k-ID: Makes sense. Yeah, from what we understand, it’s a pretty broad mandate, and I think most of the people on this call are.
The timeline: why March 2027 is not the deadline
Joe Newman, k-ID: Running some form of an electronic service. Now, I think the question of whether or not it’s appealing to kids is something we’ll get into. Now, in terms of a timeline. You see what’s on the slide here, that was initially passed in 2025. There was a two-year transition period, but as you guys pointed out, that has actually been expedited, right? So that was cut short, so a lot of people, the March 2027 deadline gets thrown around a little bit, and that’s actually not right, which is what I learned in the prep for this. However, March 28th was earlier this year, when enforcement began, and then the self-assessments were due back in June. Six months now into the implementation, what are you seeing companies doing in the Indonesian markets? Are the platforms compliant? Are they still implementing? Are they determining? I mean, we already saw that Komdigi isn’t thrilled with what some of the platforms are doing, but where do you see the overall market in Indonesia? How they’ve reacted to this?
Assegaf Hamzah & Partners: Yeah, maybe a little bit on the clarification on the transition period, so you’re correct, Joe. When the regulation was enacted in March 2025, they have a maximum transition period of 2 years. So the deadline usually, that 2-year transition period usually runs its course, but not in this particular regulation. So you’re correct, the ministry expedited it to March 2026, which is one year into the transition period. So it is being implemented in March 2026, so that is confirmed. What we see from the update or the report that was given by the Minister just this week, on Monday, 14 September. To us it’s also indicative of how companies are reacting.
The Minister’s September figures
Assegaf Hamzah & Partners: 2,052 sorts of products, services, and features are already being self-assessed by companies, and we understand the verification by the ministry has been, they have completed 60 verifications of the products, services and features. And out of the 60, 22 have been designated as high risk, and 38 as low risk. So if there is any indication, there is a high level of attention by the service providers, by the platforms. If this is another thing that will trigger further compliance, the ministry are actually taking steps to monitor, to provide updates, and then to continue calling out those who are not in compliance yet.
Joe Newman, k-ID: Yeah, that makes sense. Well, I think it’s a good segue into, what is the self-assessment process and how does that look? I think for companies who have not even thought about PP Tunas before tonight, I think it’s important to point out that enforcement
Enforcement is already happening
Joe Newman, k-ID: is happening, right? So in addition to these public call-outs, without naming names, k-ID is aware of at least one company that’s been contacted directly by the Indonesian government, and told, hey, you have like a week to raise the minimum age of your service. So this has been laying somewhat dormant, and now things are getting real for companies, so the timing of this webinar is good timing for us to talk. Anything to add, or I think we can just jump right into the requirements?
Assegaf Hamzah & Partners: Maybe one thing which we found interesting from the press conference that the minister had earlier this week, she clearly said that she expects other companies to also submit their self-assessment and comply with the requirements. Maybe two points. One is that the deadline is extended till the end of this year, so if there is a deadline that was mid-year, which was in June, that is set. We are giving time for more companies to comply by the end of the year. And second, if companies or platforms are still reluctant to submit their self-assessment, the determination of the risk level will be given by the government, so they have the option to give that, the government saying that you are a high-risk service provider or a low-risk service provider.
Joe Newman, k-ID: Basically, submit your self-assessment soon, or we’re going to decide for you, right? Yeah, gotcha, interesting. That’s good to know. Okay, alright, let’s dive into the requirements. I know we want to make sure we have plenty of time for questions, so apologies for rushing through a little, but in terms of the requirements, we keep talking about this self-assessment, and I think this is, for me, one of the things that was most striking about the law, because in the US and the EU and most of the world, you’re required to do these assessments, right? You have to do a data privacy impact assessment, you have to do this paperwork, but you’re not necessarily required to proactively send it to a government regulator for them to evaluate. And that, to me, is where I think this is unique. And I think a lot of what we’re talking about now is how to do that assessment so that you can get a favorable result. But before we even get there.
Who is in scope: the five pre-assessment indicators
Joe Newman, k-ID: Let’s talk about the scope, because this only applies to services that may be accessed by a child, or by children. How does Komdigi determine if children are likely to access a service? Are they looking at demographics, age ratings of the app store listing, marketing, product design? I know it’s broad, but what are they looking at in terms of applicability?
Assegaf Hamzah & Partners: Okay, the regulation sets out, before you do the self-assessment, there is like a pre-assessment, where they have indicators which should trigger whether you can continue with the full assessment, which are as follows. They say that if the electronic system operator’s internal documentation itself indicates that the product, services, or features are to be used or accessed by children, which is obvious. Second is if there is strong enough evidence demonstrating that children constitute a significant user of the services. If there are advertisements relating to the relevant product, service, or feature that are directed at children. If there are design elements of the relevant services that are created or presented in a manner that is appealing to children, so that’s another indicator. Lastly, if there is a relevant product or service or feature that is substantially similar or identical to the product or services that you’re providing. So this association is also a triggering point, an indicator that your service also falls under the requirements of the PP Tunas. So those are some broad indicators. So when you say it’s broad, it’s really the government taking an approach that is all-inclusive, if you will. If you want to make the argument that you are not a high-risk profile, then you have to go through the assessment.
Joe Newman, k-ID: Got it. Makes sense. I know we were talking about Komdigi also going to look at web traffic to Indonesia, and I think this is very similar to how the western world views it, where they’re like, if there are kids who are accessing this, then they’re probably going to be able to make the case. So, similar regulators of interest, I think.
Assegaf Hamzah & Partners: Joe, that is correct. I think for the initial eight that were automatically determined by the government as high risk, we understand that the indicators are the traffic of users in Indonesia, and those are the ones that continue to be called out by the minister in her office yesterday, just to give a recap of who is progressing, who is not progressing. So for the initial eight, they were named. Automatically they’re considered as high risk, while the rest have, if you will, a process of going through the self-assessment before getting the verdict.
The age bands
Joe Newman, k-ID: Okay, so the other thing that I understand that’s somewhat unique about PP Tunas, and please correct me if I misunderstood, is this concept of age bands. So in the U.S, for example, we’ve got COPPA, which sets 13 as the magic number. There are some other ages that matter, depending on what state you’re in, but under the PP Tunas, there’s really these separate age bands. So under 3, just no access at all. Between 3 and 12, the classification of your service, whether it’s high risk, low risk, or low risk specifically designed for children, affects the general product access. Is that right? It affects who can actually get in the front door.
Assegaf Hamzah & Partners: Yeah, that’s correct, Joe. But on top of that, they also have different age bands or classifications for the other rules of the PP Tunas. So, for example, in terms of parental controls, they have only used two classifications, so below 17 years old and 17 years old and above. So that’s another variation that’s unique to the PP Tunas in relation to age bands.
Joe Newman, k-ID: Gotcha. And then similarly, if you say that you’re above 18, PP Tunas is requiring, if you’re in scope, if you’re likely to be accessed, then everyone will have to undergo age verification. Is that correct?
Assegaf Hamzah & Partners: That’s correct. The age verification requirement applies across the board, regardless of whether your product or services is considered low risk or high risk.
Joe Newman, k-ID: Gotcha. Yeah, and what I was reading from the public statement when they called out Meta, X and all those other companies, they were really focused on the efficacy of the age assurance. That’s top of mind all around the world right now, is how do you do age assurance properly? So we’ll get into that a little bit more. I’ll keep us moving. So we keep talking about this self-assessment. How do you go about doing a self-assessment? What are the important things to be taking into consideration when you are assessing whether or not your service is high risk, low risk, or specifically designed for children. How do you approach that?
Completing the self-assessment
Assegaf Hamzah & Partners: Yeah, the regulator, which is Komdigi, has already prepared templates for doing the self-assessment. So this template is advised to be used. And perhaps it’s also mandatory to be used by operators who are planning to do the submission. Under the template, there are already questions for each of these 7 dimensions that applicants can complete. So for each of these dimensions there are more than 5 sub-indicators, if you will. It’s quite a lengthy questionnaire, and to complete the template, it’s advisable to also include relevant stakeholders within the organization. So not only involving the privacy or the legal team, but Komdigi, through its guidelines for this self-assessment, advises also to bring on board specialists, for example child psychologists, the IT security team, and also to include the sales and the product team as well, to be the assessors for completing the self-assessment. So basically you need a village to complete a self-assessment so that you can get an overall assessment of the product or the feature.
The seven risk dimensions
Joe Newman, k-ID: Gotcha. Yeah, the other thing that jumped out to me when we were looking into this was that it’s my understanding that all seven of these dimensions have to be considered low risk for the overall product to be low risk. So if any one of these is considered high risk, then that actually changes the entirety of how people access your product, which seems pretty important to me. And again, what you guys mentioned is that the burden of proof is basically on you as a business to show that you’ve looked at all 7 of these dimensions and established that they are low risk.
Assegaf Hamzah & Partners: Yeah, but maybe one additional note, Joe, on completing the self-assessment. So as I mentioned earlier, in each of these seven dimensions, there are sub-indicators, and each of these indicators have their risk weight. They have scores. There are some sub-indicators that are probably inevitable, so most digital businesses would probably meet the requirement, and they would be considered fulfilling that indicator. But again, fulfilling one or two sub-indicators does not mean that it could make that particular dimension fulfilled. I don’t know if I’m being too technical.
Joe Newman, k-ID: No, no, that makes sense. Because it’s like what we were talking about with mitigations, right? If you have mitigations in place on each of these sub-dimensions or sub-factors, that’s something that you can use to help establish that, hey, yeah, no, we’ve taken care of this, right? Am I understanding correctly?
Assegaf Hamzah & Partners: Yeah, exactly, and this is also evident from the list of high-risk and low-risk services that was issued recently by the ministry of communication, or Komdigi. Where you can see that for the same services, one can be categorized as high, and the other one can be categorized as low. So again, it all depends on the controls that they have in place in each of the products. That could make the result of the assessment different, even though it’s the same service.
Joe Newman, k-ID: Yeah, I mean, that makes sense to me intuitively. If you’ve put controls in place to prevent kids from accessing stuff that they’re not supposed to, that intuitively makes the service as a whole lower risk. But yeah, that’s really helpful. Okay, let’s move on, because I want to make sure we have plenty of time for questions. Again, I see them piling up.
Age assurance and parental consent
Joe Newman, k-ID: In terms of age assurance and parental consent, this is another area where we’ve got a bunch of pre-submitted questions. Let’s break it down by age group. So if I understand correctly, if you’re under 16, parental consent and controls, supervision is required. If you’re 17, if I understand correctly, you can have access, but you have to notify the parent, and they have to respond within 24 hours, or have I missed that?
Assegaf Hamzah & Partners: The latter is 16 to 17.
Joe Newman, k-ID: Oh, 16 to 17, yes, okay, gotcha. So if you’re under 16 the parent has to consent, 16 to 17 they get this notification and right to opt out. And then if you’re 18, you get access, but you still have to verify that you’re 18. Got it. And in terms of what those parental consent monitoring supervision tools look like, do we have hard guidance on that, or is there any clear indication of what Komdigi considers an adequate parental consent mechanism?
Assegaf Hamzah & Partners: They have set up broad guidelines on this, so it’s also part of the implementing regulation of PP Tunas. The consent request must be clear and unambiguous. And it must also be in a form that is understandable by the reader. So that would mean the consent request must also be made available in the Indonesian language, among other things. But in terms of the methodology or the mechanism to request consent, it’s still unclear until now. There’s no further guidance yet. So whether or not it needs to be verifiable, through a government ID, or some financial documentation, whether it’s a credit card, it hasn’t been made clear yet, so pending that, I think as long as the broad requirement is fulfilled, that would be sufficient to be considered an acceptable form of consent.
Joe Newman, k-ID: Gotcha. That’s a great segue, too. So, the elephant in the room, having to age verify all users. Do we have good guidance, or do we have a very clear picture of what is an acceptable form of age verification or age assurance? I assume self-declaration is probably not going to be enough by itself, but what else would be? Or do we not know?
Facial age estimation vs facial recognition
Assegaf Hamzah & Partners: What we see from practice, some have adopted facial recognition technology as part of the verification process. So the minister, during the press conference this week, specifically mentioned that there’s one of the eight service providers who were considered as high risk service providers. They’ve made significant changes, and the minister applauded and commended specifically the way this provider implemented the age verification process, and that process was by way of facial recognition. But when doing so, please be mindful of the additional requirements. PP Tunas requires that when doing age verification, although there is no specific methodology on how to do so, it must still consider the privacy elements. For example, make sure that the data that is collected is not excessive, still taking into account data protection or privacy principles, for example data minimization, and the other principles relevant to the context of privacy-preserving. That’s perhaps the additional note on age verification.
Joe Newman, k-ID: And if I can ask a clarifying question, when you say that they implemented facial recognition, does that mean they’re actually recognizing who you are based off of your face, or are they just doing facial age estimation to see, like, oh, this person looks like they’re of age?
Assegaf Hamzah & Partners: It’s the latter, for the purpose of making sure of the age, yeah.
Joe Newman, k-ID: Yeah, okay, that’s very helpful clarification, because when I saw some of the news reports saying they were doing facial recognition, that set off some privacy alarms. Wait a minute. So yeah, if it’s more like traditional facial age estimation, that makes more sense.
How k-ID helps
Joe Newman, k-ID: Okay, cool. So, moving right along, I just want to very quickly, I’m not going to derail us and talk about k-ID and all we do, but just to give a sense of how we have been helping companies comply with PP Tunas. First of all, we have neimo., which is our platform for tracking all of the various laws and legal requirements. And one of the things that you can see on the slide here is, now that we have an MCP connector and we can do AI, we can actually help you with your risk assessment, using information that you give us. So Dots will follow up, but we can set everyone up with the free demo for that. We do age verification, age assurance, we are an orchestrator of age assurance for a number of companies, and have a variety of methods that are available, including facial age estimation, which is why I was asking the question a little self-interestedly. And then finally, the CDK and parent portal, this is the provisioning of access to features based off both what the law requires in those various age bands, as well as the parent giving those parental controls. So it’s very tailor-made for helping with complying with these requirements and making sure that the parent gives access to features like chat, or push notifications, or certain monetization things. Okay, that’s my bit over. I’m going to keep us rolling. Let’s look ahead a little bit.
What to prioritise: three strategies
Joe Newman, k-ID: In the next 6 months, what do you guys think compliance looks like? If you were looking at this issue, how would you prioritize? What would you focus on first? Are you building to these new age bands? Are you focusing on your risk assessment? Let’s just say that I’m coming to you guys as a new client, and what would you say to do first?
Assegaf Hamzah & Partners: Well, I think you have to put it in a context. For example, if the government or the ministry has sent you a letter asking you to commence the self-assessment and then to comply with it, I think you have to do that, just to show your goodwill. But if you do not yet have that, I think it would make sense to put all this mitigation measure or controls in place. And then allow that to be integrated into your system, and then when you actually have to submit the self-assessment, you can already say that we already have these controls in place, and that will give you a better chance of getting a lower risk score. That’s my quick take on that. I think the point about having the correct understanding of PP Tunas is also one of the important things. And probably prioritize the obligations under PP Tunas. That’s more pressing. We know that the deadline has been extended until end of year to submit the self-assessment. I think that would be a good time for companies to assess whether they have the appropriate controls. But at the same time, perhaps also try to complete the self-assessment and do the submission as soon as possible, in parallel to preparing the necessary controls, or even, if needed, make the design changes to the product and services so that it is in alignment with PP Tunas. And lastly, we know a lot of our clients have started engagement with Komdigi as well, as part of their effort to show good faith that they are trying to comply with PP Tunas, so I think that’s also something that can be explored by companies, especially those who have been under the ministry’s radar and have been getting letters requesting compliance with the scheme. Just to add one point, Joe. If the press conference is any indication, when the madam Minister said that this one particular company we rate as performing good, one of the things that they did is they created a separate feature specifically for children. So you can also learn from this as maybe an option that you can consider for your company in terms of managing this risk, and then to get to a more favorable risk result. So that’s one of the things that we note, and not necessarily something that every company can do, or want to do, but if anything, that is something that is noted by the ministry as a good step in complying with the PP Tunas.
Joe Newman, k-ID: Yeah, that makes sense. I guess to summarize what you said, I think there are three potential strategies, and I won’t say any one is better than the other. The first is to do nothing, which is risky, right? You have companies that have come to k-ID, being like, we got a letter, and they’re telling us that we need to implement controls in a week, and that’s a scramble. So that’s a risk, but it is possible. The other, I think, is to submit a self-assessment now. And again, especially since there’s been an extension of deadline for getting those self-assessments in, that seems like reasonably low-hanging fruit. I think from what you told me, even when the self-assessment comes back, it doesn’t immediately mean that you have to go and build stuff. There’s some back and forth between you and Komdigi before you make the determination. The other option, which I think is a little bit more conservative, but potentially a really good idea, would be to build all of this stuff first, and then say, hey, we have all these controls, we have age verification, and then have that in place for Indonesia, and then use that to submit a self-assessment that potentially gets you a lower risk rating. And then maybe you front-loaded the work and you did it ahead of time. So I guess those are three different ways you can think about how you approach it?
Assegaf Hamzah & Partners: That’s a good summary, Joe.
Joe Newman, k-ID: Cool. Alright, so we are now 20 minutes out, so I think we’ve timed this pretty well. We’ve got a checklist here: completing that self-assessment, that risk assessment. Thinking about now how you’re going to be doing age verification, particularly if you’re viewed as high risk. Then you need to have a way of blocking everyone under 16 and doing age verification. You guys also mentioned doing internal data privacy and practice assessments, just in parallel and in addition, just to help get your ducks in a row for this. And then again, meaningful parental controls and monitoring tools. Those are becoming more required around the world. Anything else you want to add before we jump into these questions?
Live Q&A begins
Joe Newman, k-ID: Cool. I’ll start with the ones that were added in the chat here, and then we can go to some of the pre-submitted questions. We have a list of those. So the first one was from an attendee talking about extraterritorial application, and what are the penalties.
Penalties, fines and service blocking
Joe Newman, k-ID: My understanding here is that the legal mechanism for administering fines under PP Tunas is not yet done. And so you can’t get fined under this law, but the main risk and the practical reality is if you are not compliant, Komdigi can work with ISPs to actually disable service, is that correct?
Assegaf Hamzah & Partners: That’s correct. That’s their go-to effort to force compliance to those who are not in-country. So in the context of digital service providers that don’t have offices in Indonesia, that would be the force that applies.
Joe Newman, k-ID: Got it. So it’s not like you’re going to get arrested if you end up in Indonesia, it’s more just that they’ll shut off your service, and you’d be losing access to that market. And then eventually, maybe fines, but that’s the immediate risk.
Assegaf Hamzah & Partners: Yeah, unless you’re doing any violation of the immigration rules, then that’s a separate issue. On the blocking of the service, just additional information, they can also just block a certain feature of the service, so not the whole service. The minister yesterday also said that this is like a progression, so they can impose a warning first, and then blocking just the particular feature before the whole service.
Joe Newman, k-ID: Oh, that’s super helpful. And then I think there was another question in the Zoom chat about the age verification process for adults. I think we covered this a little bit. My understanding is that there isn’t clear guidance on what must be used, but it’s got to be reliable, and passport, driver’s license, KTP is an option, but you still have to be thinking about data minimization. Is that generally right?
Assegaf Hamzah & Partners: Although, unlike in other jurisdictions, I know in Australia there’s a prohibition to use government ID as documentation to verify age of a user. In Malaysia, there’s not yet. Although still, that requirement to make sure that when doing the age verification process, you need to take into account privacy aspects. That’s the only thing that you need to take into account when doing the process.
Joe Newman, k-ID: Yeah, and it can’t be only through ID, there has to be a variety of methods, makes sense. So there was one other question about implementing age-based access restrictions and the use of profiling. So essentially, age inference, right? The use of data in order to infer if someone is a child, and then is that also consistent with the principle of best interests of the child. I have some thoughts on the use of age inference, but I’m curious if this is something that Komdigi has weighed in on.
Assegaf Hamzah & Partners: They’ve mentioned this as part of the verification process, so doing age inference is a technique that operators can use. But again, this is not strictly required under the regulation, Joe, so if there are other techniques to be able to identify the user’s age, they’re open to it. Again, at the end of the day, it’s something that companies or operators need to justify, whether the technique is sufficient or not, to meet the legal requirement.
Age inference
Joe Newman, k-ID: Makes sense. My personal two cents on age inference is it’s a little bit black boxy, in that if you do it, it might work, but you’re almost inviting a regulator to come and investigate you as to how it’s working, why it’s working, if it is working. So there’s no free lunch, everything comes with a price. And there was one other question about self-assessments. You need to submit the self-assessment in order to get them to declare your service to be high risk, low risk, or low risk intended for children. And then that determines your obligations later. Cool, keep the questions coming, but I’m going to move to the pre-submitted questions, and we’ve got about 13 minutes, so I think we should be able to get through most of them. So, one question was, for a game that’s explicitly designed for young children, does that automatically push it into a high-risk category, or does it depend on the features and the target audience?
Assegaf Hamzah & Partners: Maybe a brief response to that question. You would need to complete the self-assessment first in order to make sure whether your service is considered high risk or low risk. So merely targeting children is not the way to determine the service is high risk. So you need to complete the assessment.
Joe Newman, k-ID: Yeah, that makes sense. So think of it in two steps. If your service is targeting children, that means that you’re in scope for PP Tunas in general, but then whether you get high risk or low risk depends on the outcome of the assessment.
The 24-hour parental consent window
Joe Newman, k-ID: Okay, so moving on, what access is allowed during the 24-hour window where parental consent is pending? Is it possible to do a limited state, or do they have to fully block access?
Assegaf Hamzah & Partners: The regulation requires no access is to be given during the consent request process, for getting the consent of the parents or legal guardian. That also applies in the context of kids age 17 years old, where the requirement is only to give notification. So before the end of the notification period, for kids under 17 years old, where the deadline is 24 hours, the period which is shorter is, I think, around six hours. So during that six hours, access cannot also be provided, so this regulation is quite strict. Compared to other jurisdictions, this is perhaps the shortest type of deadline.
Joe Newman, k-ID: Interesting. That is unique about it. In other jurisdictions, you have a lot longer in order to get that parental consent. It’s usually, you can hold onto the email address for up to 14 days in the US, give or take. And so this is much stricter. You have to get that parental consent pretty quickly. We’ve noticed, in our own metrics and telemetry when asking for parental consent, it usually takes a day or two. You get a big chunk of people where the parent is in the room, and they can do it immediately. But then some people, if the child requests access while the parent is at work, they may not see that email right away. So that is a thing that you have to work around, and the child may need to seek parental consent more than once, as a result of this 24-hour window. Okay, so where does self-declaration play into this? Does that count differently? I’ll just take this. I don’t think that Komdigi is saying you can’t ask people for their age, but I don’t think that in itself would be enough for it to be considered accurate or reliable age assurance. And then, does the privacy policy need to be in Indonesian? I think the answer to that one’s yes. And then a question about AI chatbots. My understanding is that the existence of an AI chatbot doesn’t automatically make you high risk, right? It’s just dependent on the circumstances, is that right?
Assegaf Hamzah & Partners: That’s correct.
Going 18+: does PP Tunas still apply?
Joe Newman, k-ID: Let’s move on. There’s a question about social platforms, particularly social platforms targeting audiences that are 18 and over. How do they comply? What would be your strategy for them, generally speaking?
Joe Newman, k-ID: I think if you’re actively targeting audiences above 18, there’s a question as to whether or not PP Tunas actually applies to you. Obviously, regardless of what you’re targeting, if kids are getting in, then you would be subject to it, and you’d probably be high risk, and the name of the game would be age assurance, right?
Assegaf Hamzah & Partners: Yeah, correct. Perhaps referring back to the five factors that are provided by the regulation, to determine whether your service is accessible or not to minors. I think the company would be best to make that assessment first, to make sure that their service is not in scope of the PP Tunas yet. If I can add, also from the minister’s press conference. One of the eight that was indicated in March as a high risk, there is one that has decided to be an 18-plus service provider. That seems to indicate that if you are moving to an 18+, maybe PP Tunas is not applicable, but that is not clear. She’s saying that one has indicated that they have blocked all the child side, and then moved to an 18-plus service. So that seems to be a decision that they made, that they’re not going to involve children in their service, so that’s the age group that they want to operate in. So I’m reading it as something to indicate that that’s not going to be applicable.
Joe Newman, k-ID: Got it. I think that makes sense, and that’s similar to how we’ve seen companies around the world. If they’re like, we don’t want kids, we don’t want to have to deal with these laws, we’re going to say that we’re an 18-plus service. From a practical perspective, that works to some degree, as long as you’re right, as long as the kids aren’t finding your service to be attractive or appealing. In fact, I think it’s probably worse for you if you’ve said that this is 18+, and yet there are a bunch of 12-year-olds running around. And that’s part of why the PP Tunas is drafted in the way that it is. If it’s likely to be accessed by children, regardless of what you said your intent was, then it applies. So the advice here would be, if you still have kids, regardless of how you classified it, then the PP Tunas would still apply.
Assegaf Hamzah & Partners: The consequences will be higher, I guess, if you’re actually, in fact, lying about the service that you’re providing.
Joe Newman, k-ID: Yeah, exactly. I think that raises your risk profile. Okay, a question about VR, I don’t think there’s anything specific on VR. There’s another question in the live chat around age inferential technology, because the Deputy Minister has talked about supporting this. Can we talk a little bit more about how behavioral inference could work under PP Tunas, and whether or not it would be effective? Outside of Indonesia, there’s been lots of ink spilled about this. Anything else that we can comment there?
Assegaf Hamzah & Partners: Little also do we know about the use of age inference technology. Again, the regulation is open to whatever mechanism or methodology to determine a user’s age. So this is open, but I think if one uses this technique, this shouldn’t be the single option. There should also be other controls or technology to be put in place to really make sure that the kids or users fall under which band of the age bands. Because that is important to allow them to use what type of services are suitable for them or not. But relying solely on age inference technology, I would question its sufficiency.
Joe Newman, k-ID: Yeah, I think that makes sense. From a common sense perspective, if it works and is defensible, then I think the regulators could accept it. There’s certainly situations where, if the user has had an account for 10 years, they’re probably over 10. If they’ve had an account for 20 years, they’re probably an adult. Beyond that, inferring that somebody is an adult based off of the activity that they’ve done is a little bit tougher, if it’s not obvious. And I think another big problem with age inferential technology, just as a rule, and we’ve talked to regulators around the world around this, is that you need a lot of data in order to make a good inference. And at the beginning of your relationship with the user, you don’t have that data, if they’re coming in fresh. So it’s hard to rely on inferential technology as your only source of age assurance, because it just won’t work in a lot of cases. Okay, I think we can go a little bit over, but I wanted to try a lightning round on the last couple of questions. A question about, is it worth hiring an expert on child psychology to assist with your self-assessment? I think you’ve said yes, I think that probably makes sense, if you can. There’s a question about what is adequate parental control technology. I think we’ve more or less answered that, in the sense that parental controls that allow for monitoring or notifications, or just control over risky features. Anything that we’ve missed that you want to touch on?
Assegaf Hamzah & Partners: I think the government allows for different types of parental control technology. One can build in-house, or use third-party services for these purposes. Unfortunately, there is little guidance on this, what type of control technology should ideally be used for the purpose of monitoring minors’ use of digital services. But from what we see in the market, I think some of them have tried using or putting in place parental portals that would allow the parents to monitor the use of the services by the kids. I think that’s what we’ve seen in practice.
Joe Newman, k-ID: Makes sense. Okay, I know we’re at time, I’m going to combine some of the last remaining questions that came in the Q&A. There are questions about, do we think this is likely to get delayed again? Do we think there is going to be an extension similar to the self-assessment reporting deadline? How does this work in terms of next steps and penalties and fines? Because I think that’s top of mind for everyone.
Assegaf Hamzah & Partners: Yeah, I think this is the clarification that we made at the beginning, that don’t look at the March 2027 transition period anymore, because it has been expedited. So forget about the 2027 period, because it’s already expedited to March 2026, so it’s already effective. We have not heard of any indication of extending that. What is being extended is the deadline for submitting the self-assessment. Till the end of this year.
Joe Newman, k-ID: Got it. And then again, as we mentioned at the beginning, we have been reached out to by companies who have been contacted saying, you need to get age verification in place. The mechanism for administering fines sounds like it’s still a little bit of a ways off, but we had a similar thing actually happen with Brazil earlier this year, where the government doesn’t necessarily have all of the legal processes in place to impose fines, but that doesn’t stop them from still coming to you and saying, you need to clean this up, or we can issue injunctions, we can shut down your service. Okay, I know we’re a little bit over time. I have been asked to help remind everybody, we do have another webinar coming up, on the new Türkiye regulation. That will be November 4th. Please join us for that. You can scan the QR code here to help with researching PP Tunas and hopefully helping with your self-assessment. I again want to give a huge, sincere thank you to Iqsan and Zacky. Thank you so much. This was incredibly informative. I hope that everybody who attended got as much out of it as I did. I learned a ton. So, thank you.
Assegaf Hamzah & Partners: Thank you, Joe. Thank you, everybody who’s attending the event. Thank you.
Dots Oyebolu, k-ID: Thank you, everyone, for attending. There will be a recording, as promised, after this webinar, just in case we’d like to recap a couple of things. And continue to follow us at k-id.com for more details on this subject and more. And you will also find our product, neimo. Thank you so much, everyone, and have a good day.