Indonesia SIM card binding identity

Indonesia's Biometric SIM Mandate Trades Anonymity for Fraud Prevention, With No Privacy Regulator Yet in Place

Komdigi's facial-recognition SIM rule has verified 10 million users toward a 291-million target, but Indonesia still has no independent data protection authority.

Indonesia's Biometric SIM Rollout, By the Numbers People of Internet Research · Indonesia 10M Users registered so far Completed facial-biometric SIM ver… Rp9.5T Cybercrime losses, Jan-Apr 2026 Reported by Indonesia's Anti-Scam … 310M vs 220M Mobile numbers vs. adults Numbers in circulation exceed Indo… 6 months Regulation transition period Enacted Jan 19, 2026; mandatory co… peopleofinternet.com
Indonesia's Biometric SIM Rollout, By … People of Internet Research · Indonesia 10M Users registered so far Rp9.5T Cybercrime losses, Jan-Apr … 310M vs 220M Mobile numbers vs. adults 6 months Regulation transition period peopleofinternet.com

Key Takeaways

Indonesia's Ministry of Communication and Digital (Komdigi) announced on July 23, 2026 that 10 million mobile subscribers had completed facial-biometric SIM verification, with Minister Meutya Hafid setting a goal of 10 million more within a month. That is a small fraction of the roughly 291 million active mobile connections the ministry ultimately wants re-verified under Permenkomdigi No. 7 of 2026, the regulation that has made facial recognition the sole method for activating a new SIM card since July 1, 2026.

What the Rule Actually Requires

Signed into force on January 19, 2026 after a six-month transition, Permenkomdigi 7/2026 replaces the customer-registration provisions of the 2021 telecoms regulation and imposes a formal Know-Your-Customer standard on every mobile operator. New subscribers must submit a live facial scan that Telkomsel, Indosat, and XL Smart run against Indonesia's Dukcapil population registry before a number activates; Komdigi's public portal describes the process as using liveness detection built to ISO/IEC 30107-3 and says biometric images are matched, not retained, by operators or the ministry. Existing subscribers can re-register voluntarily for now; the eventual plan is to extend the same requirement to all 291 million connections currently active on the older NIK-and-family-card system.

The Case the Government Is Making

The fraud numbers are real and worth taking seriously. Indonesia's Anti-Scam Centre logged Rp 9.5 trillion (roughly $580 million) in cybercrime losses between January and April 2026 alone, per figures Komdigi cited when it tightened operator oversight. The structural problem is stark: Light Reading reports more than 310 million mobile numbers were in circulation against an adult population of roughly 220 million, a gap regulators say lets scam operations acquire numbers in bulk under borrowed or fabricated identities. A five-month pilot from January to April 2026 processed 1.4 million registrations with sign-up taking under two minutes — evidence the ministry can point to that biometric onboarding is fast enough not to strand legitimate users. Binding a phone number to a verified face is, on its face, a more direct fix for SIM-based fraud, phishing, and identity-theft rings than any awareness campaign has been.

Why Proportionality Still Matters

The steelman only goes so far. Indonesia's Personal Data Protection Law was enacted in 2022, but the independent supervisory agency it requires still has no operational timeline as of mid-2026 — enforcement currently sits inside Komdigi itself, the same ministry writing and running the biometric mandate. That is a structural conflict: the agency collecting sensitive biometric data at national scale is also its own regulator. ELSAM, the Indonesian policy-research institute, flagged this before the rule took effect, warning that biometric data is inherently sensitive, that operators — not just the state — will handle collection and validation, and that less invasive alternatives (SIM-swap PINs, authenticator apps) were never seriously weighed. Legal aid group LBH Pers points to precedent that makes the gap concrete: a June 2024 ransomware attack hit Indonesia's National Data Center across 282 government institutions, and years earlier the hacker "Bjorka" put over a billion NIK-linked records up for sale after a breach of the old SIM database. A regulator with no independent oversight body is asking for a second, higher-value trove of national biometric data before it has shown it can secure the first one.

The ministry's own rollout has already surfaced compliance friction: MLex reported that Komdigi had to order Dukcapil to disable the old NIK-verification pathway entirely on July 4, 2026, after some operators kept activating SIMs without running the biometric check three days past the deadline. That is a reasonable enforcement response to evasion — but it also shows the technical capacity to bypass verification exists inside the system operators themselves administer, which is exactly the kind of internal control gap an independent regulator, rather than the policy's own author, should be auditing.

The Actual Trade-Off

None of this is an argument against identity verification for telecoms — most developed democracies require some form of it, and Indonesia's 310-million-number oversupply is a genuine enforcement blind spot worth closing. The design choices so far (match-not-store biometrics, ISO liveness standards, private registration booths for veiled users) suggest the ministry has thought about proportionality at the technical layer. What is missing is proportionality at the institutional layer. Extending this system from 10 million early adopters to all 291 million existing connections is an order-of-magnitude expansion of a national identity-linked communications database, and it should not happen on the current timeline while the PDP Law's supervisory authority remains unformed. Indonesia does not need to abandon biometric SIM registration to get this right; it needs to sequence it — stand up the independent data authority, publish an audit of the match-not-store claim, and only then scale the mandate to the legacy subscriber base that dwarfs the 10 million who have registered so far.

Sources & Citations

  1. JDIH Komdigi — Permenkomdigi No. 7/2026 official record
  2. Komdigi public portal — biometric SIM rollout announcement
  3. ANTARA News — 10 million biometric SIM registrations
  4. Light Reading — facial biometrics mandatory from July 1
  5. ELSAM — privacy threat analysis of biometric SIM plan
  6. LBH Pers — privacy risk and data breach precedent
  7. MLex — Indonesia tightens enforcement of biometric SIM registration