There is a widely held assumption among foreign software companies that Indonesian regulation begins at the moment you incorporate there. No entity, no obligations. It is a reasonable assumption, it holds in a number of jurisdictions, and for electronic system registration it is wrong.
Under Ministerial Regulation No. 5 of 2020, as amended by Regulation No. 10 of 2021, registration as an electronic system provider is required of any party operating, managing or providing an electronic system to users in Indonesia. The trigger is reachability. If Indonesian users can access your service, you are within scope, whether or not you have a company, an office, a staff member or a server anywhere in the country.
There is no minimum number of users. There is no transaction threshold. And the primary enforcement mechanism is the one that matters most to a platform business, because it is the only one a regulator can apply unilaterally to a company with no local presence and no local assets.
What the obligation attaches to
The scope is drawn around the act of providing an electronic system to users in Indonesia. Not around incorporation, not around revenue earned there, and not around data being hosted there.
That framing catches a broader set of businesses than most foreign operators expect, and it catches them earlier. A company can be within scope before it has made a single sale in Indonesia, purely because the service is reachable.
Who Falls Within Scope
Ministerial Regulation No. 5 of 2020, as amended by Regulation No. 10 of 2021.
Websites and web applications
Any site collecting, storing, processing, displaying or distributing electronic information for users in Indonesia.
Mobile applications
Applications distributed to Indonesian users, regardless of where the publisher is registered or where the app store operates from.
SaaS and cloud services
Software delivered as a service to Indonesian customers, including business to business tools with a handful of enterprise accounts.
Marketplaces and platforms
Any service intermediating transactions or user generated content for an Indonesian audience.
No threshold exists
There is no minimum number of users and no transaction volume below which the obligation falls away. A platform with a hundred Indonesian users is in scope on the same basis as one with ten million.
Registration is completed through the OSS system. Ministry nomenclature has changed over time; the obligation has not.
Why blocking is the sanction that matters
Regulatory penalties usually come as fines, and fines can be modelled. A company can decide what level of exposure it is willing to carry, budget for it, and move on. That calculation does not work here.
The primary enforcement mechanism for failing to register is access blocking. Not a theoretical maximum reserved for egregious cases, but the standard tool, and for a straightforward structural reason: it is the only sanction a ministry can apply directly and immediately to a company that has no local entity, no local bank account and no local assets to attach.
It has been used. In the 2022 enforcement round, several major international platforms were blocked in Indonesia for failing to register before the deadline. Access was restored after registration was completed, which tells you the mechanism works as intended rather than as a threat.
For a platform business, blocking is not a cost line. It is the total loss of a market for as long as it lasts, with no partial compliance position available to soften it. There is no version of being seventy percent registered.
The cost that arrives before the regulator does
There is a second consequence, slower and less dramatic, and in practice it is the one most foreign companies encounter first.
Registration status is publicly checkable. Indonesian counterparties in regulated sectors, particularly financial services, healthcare and anything touching government procurement, routinely verify it before entering agreements. Procurement teams have this on their checklist because their own compliance obligations depend on it.
A brand still establishing itself in a new market therefore tends to lose deals over this before it loses access. The deal does not usually come with an explanation attached. It simply does not progress, and the reason surfaces months later, if at all.
What registration actually commits you to
Registration is frequently treated as a filing to be completed, filed away and forgotten. It is closer to the opening of an ongoing relationship with a regulator, and four commitments follow from it.
What Follows Registration
The filing is the beginning of the obligation rather than the discharge of it.
Content response windows
Takedown requests carry a response deadline, with a substantially shorter window for cases classified as urgent. This requires an operational process and a named owner, not an inbox someone checks weekly.
Incident reporting
System security incidents must be reported to the ministry rather than contained internally. A policy of handling quietly is not available.
Keeping the record current
Registration details must stay accurate and compliance reports submitted, particularly when systems change or corporate structure changes.
Personal data compliance
Processing must comply with Law No. 27 of 2022 on Personal Data Protection, covering lawful basis, transparency and user rights.
The first of those four is the one that most often has no owner. A takedown response window is an operational commitment measured in hours, and it assumes someone is monitoring a channel and empowered to act on it. For a company with no presence in the timezone, that is a staffing question disguised as a compliance question.
Personal data is a separate layer, not a subset
Law No. 27 of 2022 on Personal Data Protection sits alongside registration rather than inside it. Registration is the licensing layer: it establishes that the regulator knows who you are and can reach you. The data law governs how personal data is collected, stored, transferred and used once you are operating.
Satisfying one does not satisfy the other, and a company can be properly registered while handling data unlawfully, or handling data carefully while unregistered. They fail independently.
For a foreign platform, data obligations typically surface in three places simultaneously, and they are usually owned by three different people. The consent mechanism on the service itself, which sits with product. The data processing terms agreed with any Indonesian partner, vendor or reseller, which sits with legal or commercial. And the question of where data physically resides, which sits with engineering.
On that last point, localisation requirements exist for certain categories rather than across the board, which means there is no single answer that applies to every industry. It is a question for a licensed adviser who knows the sector, not a rule to look up.
Registration and Data Are Not the Same Obligation
A company can satisfy either one while failing the other.
Electronic system registration
Establishes that the regulator knows who you are and can reach you. Triggered by reachability. Enforced through access blocking.
Personal data protection
Governs how personal data is collected, stored, transferred and used once operating. Covers lawful basis, transparency and user rights under Law No. 27 of 2022.
Three owners, one obligation
Data obligations surface in the consent mechanism owned by product, the processing terms owned by legal or commercial, and the hosting question owned by engineering. Nobody owns all three by default, which is how gaps open.
Where the timeline usually goes wrong
Registration itself is not a long process once the documents are assembled. What stretches the timeline is what the documents require, and that is where foreign operators lose weeks they had not planned for.
Two things account for most of it. The first is that a company with no Indonesian entity is assembling corporate documentation from its home jurisdiction, which frequently means notarisation, legalisation and translation on a schedule set by other people. The second is that the submission asks for descriptive detail about the electronic system itself, including what data it handles and how, and that information usually lives with engineering rather than with whoever has been handed the compliance task.
Neither is difficult. Both are slow when started late, and both sit outside the control of the person accountable for the deadline. The practical implication is that the useful moment to begin is when Indonesian access becomes foreseeable, not when Indonesian revenue becomes material.
The part that is not a legal question at all
Assume the work is done. The registration is complete, the data terms are signed, the consent flow is compliant, the incident process has a named owner. What commercial return does that produce?
On its own, the absence of a penalty. Nothing else, unless the status is visible where it is actually checked.
This is the part that tends to fall between departments. Legal considers the matter closed when the filing is accepted. Marketing does not know the filing exists. And an Indonesian procurement team, or increasingly an AI assistant answering a question about whether a vendor is compliant, assembles its view from what is publicly discoverable rather than from what sits in a compliance folder.
Verifiable public evidence of compliance is a different discipline from obtaining compliance, and in most organisations it is nobody's job. For a foreign platform trying to win its first Indonesian enterprise accounts, it is also the difference between a compliance cost and a commercial asset.
What to do, in what order
Establish scope first, and answer it honestly rather than optimistically. If Indonesian users can reach the service, the obligation applies. Reachability is a factual question, not a matter of intent, and a service that has not marketed itself in Indonesia is still reachable from Indonesia.
Register before there is a reason to. The 2022 enforcement round showed what happens to companies that treat a deadline as the point at which to begin: a scramble, and in several cases a period of blocked access while the paperwork caught up. Registration completed quietly in advance costs the same and carries none of that.
Assign the operational commitments to named people, particularly the response window. A takedown deadline with no owner is a compliance failure waiting for a trigger.
Then treat the data layer as a separate project with its own scope, because it is one, and it will not be discharged by the registration filing.
And finally, publish the outcome somewhere a buyer can find it. Compliance that cannot be verified externally has cost you money and returned you nothing but the absence of a problem.
Frequently Asked Questions
Does a foreign platform need Indonesian registration without a local entity?
Yes, if Indonesian users can access the service. The obligation under Ministerial Regulation No. 5 of 2020, as amended by Regulation No. 10 of 2021, attaches to providing an electronic system to users in Indonesia rather than to being incorporated there. A platform with no entity, no local staff and no local servers is still within scope.
Is there a user threshold for electronic system registration in Indonesia?
No. There is no minimum number of users and no transaction volume below which the obligation falls away. A platform with a small Indonesian user base is within scope on the same basis as a large one.
What is the penalty for not registering?
Access blocking is the primary sanction, and it has been applied in practice. In the 2022 enforcement round several major international platforms were blocked in Indonesia for failing to register before the deadline, with access restored once registration was completed. It is the standard tool rather than a maximum penalty, because it is the only sanction that can be applied directly to a company with no local presence or assets.
How does registration relate to the personal data law?
They are separate but connected. Registration is the licensing layer, establishing that the regulator knows who you are and can reach you. Law No. 27 of 2022 on Personal Data Protection governs how personal data is collected, stored, transferred and used once you are operating. Satisfying one does not satisfy the other, and they fail independently.
Do we have to store data in Indonesia?
Not uniformly. Localisation requirements apply to certain categories rather than across the board, so the answer depends on the sector and the nature of the data being processed. This is a question for a licensed adviser familiar with the sector rather than a general rule to look up.
What are the ongoing obligations after registering?
Four follow from registration: responding to content takedown requests within a set deadline, with a substantially shorter window for urgent cases; reporting system security incidents to the ministry rather than handling them internally; keeping registration details current and submitting compliance reports, particularly when systems or corporate structure change; and complying with Law No. 27 of 2022 in the processing of personal data.
Does compliance help commercially, or only avoid penalties?
Only if it is visible. Registration status is publicly checkable and Indonesian counterparties in regulated sectors routinely verify it before contracting, so non compliance tends to cost deals before it costs access. Equally, compliance that a buyer or an AI assistant cannot verify externally returns nothing beyond the absence of a penalty.
Sources & References:
- Ministerial Regulation No. 5 of 2020 on Private Scope Electronic System Providers, as amended by Ministerial Regulation No. 10 of 2021. Registration is required of any party operating, managing or providing an electronic system to users in Indonesia. The obligation attaches to reachability rather than to incorporation, and no minimum user or transaction threshold applies.
- Scope covers websites and web applications, mobile applications distributed to Indonesian users, software as a service and cloud platforms serving Indonesian customers, and marketplaces or platforms intermediating transactions or user generated content for an Indonesian audience.
- Registration is completed through the OSS system. Ministry nomenclature has changed over the period during which these regulations have been in force; the underlying obligation has not.
- Enforcement: access blocking is the primary sanction for failure to register. In the 2022 enforcement round, a number of major international platforms were blocked in Indonesia for failing to register before the applicable deadline, with access restored following completion of registration.
- Post registration obligations include response deadlines for content takedown requests, with a substantially shorter window for cases classified as urgent; mandatory reporting of system security incidents to the ministry; maintenance of current registration details and submission of compliance reports; and compliance with personal data obligations.
- Law No. 27 of 2022 on Personal Data Protection, governing collection, storage, transfer and use of personal data, including lawful basis, transparency and data subject rights. This regime operates alongside electronic system registration rather than as a component of it.
- Data localisation requirements apply to specified categories rather than universally, meaning sector and data type determine the position. Sector specific advice is required.
- Registration status is publicly verifiable, and is commonly checked by Indonesian counterparties in regulated sectors as part of procurement and contracting processes.
- This article is orientation for commercial planning, not legal advice. Arfadia is a digital agency and does not file electronic system registrations or provide data protection legal advice, which require licensed consultants and lawyers. Current requirements and procedures should be verified with the relevant ministry or a licensed adviser before acting.