🧔♂️ A friendly human may check it before it goes live. More news here
Indonesia plans biometric face checks for new mobile users
Indonesia’s Ministry of Communication and Digital (Komdigi) is preparing new rules requiring face recognition for registering new mobile phone numbers.
The draft regulation mandates that new customers use biometric face data alongside their national identity number (NIK) during registration.
Currently, users register with their NIK and family card, but authorities say this system is vulnerable to misuse for criminal activities such as online scams and spam.
The new rules will allow registration with the existing method for one year after the regulation takes effect, after which biometric face data will become mandatory for new users.
Children under 17 or those without biometric records will register using the head of their household’s data.
The regulation will cover both prepaid and postpaid services, eSIM users, and will not require existing customers to re-register with biometric data.
Komdigi said the aim is to improve the accuracy and security of mobile user data nationwide.
🔗 Source: CNN Indonesia
🧠 Food for thought
Implications, context, and why it matters.
Dukcapil integration timeline still unclear
- Telkomsel, XL Axiata, and Indosat tested KYC-compliant facial checks 1. The one-year grace period in the rule 2 implies ongoing talks on how to link with the Directorate General of Population and Civil Registration (Dukcapil), which runs the national population database.
- The holdup is how to validate faces against Dukcapil records. Another open item is who pays the “additional costs for data validation” 1. That choice could shape rollout speed and who absorbs verification expenses, either the government or mobile network operators (telcos).
- No signed data-sharing deal exists between Komdigi (also called Kominfo, the communications ministry) and Dukcapil 1. The date for full enforcement after the transition remains uncertain, even with operator systems in place.
Biometric software development kit (SDK) and compliance vendors can tap telco buying cycles
- Mobile network operators are trying ISO 30107-compliant liveness checks 3 to block deepfake attacks (AI-generated impersonations). This spurs near-term demand for anti-spoofing SDKs that plug into current registration systems.
- Indonesia’s Personal Data Protection Law requires Data Protection Impact Assessments (DPIAs) by business actors 4. This creates room for compliance tools focused on consent management and biometric data governance in Southeast Asia.
- Retail outlets such as Telkomsel’s GraPARI service centers are testing biometric enrollment 3. Vendors can work with SIM agent networks, which are third-party SIM card retailers, to supply kiosks and mobile tools before full enforcement after the one-year transition period 2.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




