A Fraud-Prevention Rule Lands in a Country That Just Fined Google for Gatekeeping
On September 30, 2026, Android phones in Indonesia, Brazil, Singapore and Thailand will stop installing apps from developers who haven't registered a verified identity with Google — whether the app comes from the Play Store, Samsung's Galaxy Store, Xiaomi's GetApps, or a developer's own website. Google spent the past year building the infrastructure for this: Limited Distribution accounts for hobbyists (free, no ID, capped at 20 devices), a Developer Console API for bulk registration, and an "advanced flow" that lets power users sideload unverified apps after a 24-hour cooling-off period and multiple warning screens. Indonesia is one of the four launch markets. It is also the country whose Supreme Court, on March 10, 2026, finished exhausting Google's last appeal in an antitrust case over the same app-distribution ecosystem this new rule now governs.
The Case for Verification
Start with the strongest version of Google's argument, because it isn't a pretext. Indonesia, Brazil, Singapore and Thailand were chosen, Google says, because they see disproportionate rates of app-based scams — fake banking apps, loan-shark apps, and repeat-offender developers who get removed from Play and simply re-upload under a new name. A developer identity check, decoupled from app-content review, is a reasonable tool against that specific pattern: it raises the cost of reappearing after a takedown without touching what an app is allowed to say or do. Sideloading remains technically possible, and Google is right that "sideloading is fundamental to Android, and it's not going anywhere" as a literal matter — ADB installs of unregistered apps still work.
Why the Timing Matters More Than the Policy
The trouble is what this policy sits on top of. On January 21, 2025, Indonesia's Komisi Pengawas Persaingan Usaha (KPPU) ruled that Google had abused a dominant position in Android app distribution by conditioning Play Store presence on exclusive use of Google Play Billing, charging service fees of 15–30% and threatening delisting for non-compliant developers. It fined Google Rp202.5 billion (~$12.4 million) and ordered it to open Play Store transactions to User Choice Billing with a five-point fee discount. The Central Jakarta Commercial Court upheld that ruling in June 2025; the Supreme Court rejected Google's final cassation appeal on March 10, 2026, making the remedy final and legally binding — for payments.
Developer verification is a different lever pointed at the same joint. The KPPU case pried open one gate — billing — inside Google's own store. The new rule builds a second gate in front of every store on certified Android devices, including the ones Indonesian regulators might have expected to benefit from a more contestable Play Store. An app that clears every antitrust-mandated alternative payment option still cannot reach a user's phone through any channel unless its developer has cleared Google's identity bar first. That is not the same conduct the KPPU punished, and Google is not violating the ruling's letter. But a regulator that spent three years and two appellate rounds forcing incremental openness in app distribution should notice when the same company recentralizes control one layer up the stack, in a rule it wrote unilaterally and can amend unilaterally.
The 71-Organization Objection
That is roughly the case made by Keep Android Open, a coalition that now counts 71 organizations across 23 countries — including F-Droid, the Electronic Frontier Foundation, Software Freedom Conservancy, KDE, Brave and Nextcloud — plus more than 100,000 petition signatures. Their central claim, in Software Freedom Conservancy's framing, is that requiring developers to submit government identification to distribute software is "an invasion of privacy" that endangers pseudonymous contributors and restricts what users can put on hardware they own. F-Droid has said the requirement, as designed, would end its ability to operate, since much of its catalog comes from volunteers who cannot or will not attach a legal name to their code. Google's $25 fee and 20-device cap on ID-free accounts address hobbyists building for personal use; they do nothing for a free-software repository redistributing thousands of other people's apps to the public.
A Narrower Rule Would Serve Indonesia Better
Indonesia already runs its own registration layer for digital services — Kominfo's PSE regime — so Jakarta has both the regulatory muscle and precedent to ask Google harder questions before September 30 than most jurisdictions can. A proportionate version of this policy exists: scope mandatory ID to developers distributing financial, lending or health apps — the categories actually driving Indonesia's scam problem — rather than every Android developer everywhere; preserve a genuinely low-friction sideload path instead of a 24-hour cooldown that functions as deterrence by design; and let KPPU or Kominfo audit, on a fixed schedule, whether the verification layer is being used to advantage Google's own store over the OEM stores it nominally also covers. None of that requires abandoning identity checks as a fraud tool. It requires Google to justify the breadth of a rule it can currently write and revise without any Indonesian regulator's sign-off — in the same market where a court just spent fourteen months making Google answer for exactly that kind of unilateral control.