US telco SIM registration surveillance APAC

Indonesia's Biometric SIM Rule Shows the Cost of Tying Phone Numbers to Face Data, and Why the FCC's Method-Neutral Approach Is Better

Indonesia is enforcing face-verified SIM registration after finding retail gaps. The FCC's SIM-swap rules avoid mandating identity data, and that restraint is worth keeping.

Biometric SIM Registration: Indonesia vs US SIM-Swap… People of Internet Research · US 9.3M Biometric registrations Jan-Jul Registrations, not unique people, … ~310M Phone numbers in circulation Versus roughly 220 million adults … ~500 FCC SIM-swap complaints, 2022 Up from about 300 in 2020, per FCC… peopleofinternet.com
Biometric SIM Registration: Indonesia … People of Internet Research · US 9.3M Biometric registrations Ja… ~310M Phone numbers in circulation ~500 FCC SIM-swap complaints, 2022 peopleofinternet.com

Key Takeaways

What Indonesia is enforcing

Indonesia's Ministry of Communication and Digital Affairs (Komdigi) is tightening enforcement of its biometric SIM registration rule. Since July 1, 2026, new mobile numbers require facial-biometric verification. According to Komdigi's own press release, three weeks after the rule took effect operators were told to make sure every outlet, sales partner and digital channel follows the process. Inspectors had found an operator still running the old ID-number registration on day one. That was followed up with clarification requests and warnings.

MLex reported on July 24 that the ministry counted more than 10 million completed biometric registrations as of July 16. I could not access MLex's full text. The figure that ID Tech reported is 9.3 million registrations from January through July, with 4.6 million in the month to July 19. That outlet also notes these are registrations rather than unique people. It also notes that sellers registering SIMs with their own faces is a known way to defeat the system.

The strongest case for the rule

The case for Indonesia's approach is real. Light Reading reports that officials attribute about 7 trillion rupiah (roughly US$393 million) in fraud losses in a year to unverified phone numbers. About 310 million numbers circulate in a country with roughly 220 million adults. The old system, which relied on a national ID number and family card number, is easy to abuse because those numbers leak and can be reused by anyone who has them. Comparing a live face against the civil registry closes that gap. Komdigi also says the rule was piloted from January to April, and that registration for existing numbers stays voluntary. A regulator facing industrial-scale SIM fraud is not being irrational.

Where the design should worry policymakers

The risk is structural. A rule that ties every new number to a face template held against a national population database builds an identity checkpoint into basic connectivity. Per Light Reading, operators encrypt facial data and send it to the civil registry (Dukcapil), and the number activates only after approval. That may be secure today. But the enforcement news shows how the system will evolve: the response to gaps at retail outlets is more oversight of distribution partners, not less data collection. Compliance pressure tends to push toward more verification, more logging and more retention, not less.

The gap between the fraud problem and the tool matters too. Komdigi says it has received more than 30,000 complaints about SIM misuse through July 16, according to Okezone's report. That is a real harm. But no published evidence yet shows what share of fraud the biometric step prevents. It also does not address fraud by people who hold legitimate numbers, or by insiders at retail outlets who register SIMs with their own faces. Proportionate regulation should be able to show a measured reduction in harm before treating a national biometric database as the default answer.

What this means for the US

The US has no SIM registration mandate, and this article does not claim one is coming. But Indonesia is a live test of a proposal that periodically surfaces in US debates: verify identity harder at the point where a number is issued. The US has instead focused on the point where fraud actually happens, which is when a number is moved to a new SIM or carrier. In FCC 23-95, the FCC required wireless providers to use secure methods to authenticate customers before SIM changes, to notify customers immediately of SIM-change and port-out requests, to offer account locks, and to keep records. It did so while explicitly declining to mandate specific authentication methods. The Commission said prescriptive lists would give fraudsters a roadmap and discourage innovation. It also cited about 300 SIM-swap complaints in 2020, 400 in 2021 and 500 in 2022.

The design difference matters. The FCC rule sets an outcome (reasonable confidence that the person asking is the account holder) and requires an annual review of methods. It does not require a face scan, a government ID match or a central identity database. A carrier may use biometrics where they add value, but nothing forces every user into that system.

The US surveillance precedent worth heeding

The risk to watch is what happens once identity data exists. The Electronic Frontier Foundation's critique of Flock Safety's reforms makes a general point: when a vendor's business model depends on collecting and retaining sensitive data, voluntary limits like shortening default retention from 30 days to 7 are no substitute for legal constraints such as warrant requirements. The same logic applies to identity data collected at SIM activation. If US carriers or biometric-verification vendors were ever required to build face-matching into number issuance, the durable safeguards would have to be statutory: purpose limits, deletion schedules and warrant standards for law-enforcement access. Company promises would not be enough.

A proportionate path

Three principles follow. First, regulate the moment of fraud: the FCC's authentication, notification and account-lock approach targets SIM swaps without building a population-scale database. Second, require evidence: any jurisdiction adopting biometric SIM registration should publish fraud-rate data before and after, plus failure rates and error rates. Indonesia's figures so far count registrations, not outcomes. Third, keep data minimal. If face matching is used, templates should be discarded after verification and not retained by operators or vendors.

Indonesia may well reduce anonymous-number fraud, and its results deserve attention. But the lesson for US policymakers is not to copy the mandate. It is to keep favouring flexible, outcome-based rules that stop fraud where it occurs without making a face scan the price of a phone number.

Sources & Citations

  1. ANTARA News: Kemkomdigi confirms biometric SIM verification mandate and operator enforcement
  2. FCC 23-95 SIM swap and port-out fraud Report and Order
  3. Light Reading: Indonesia's new SIM rule
  4. ID Tech: 9.3 million biometric SIM registrations
  5. Okezone: Komdigi strengthens biometric oversight
  6. EFF: Flock admits their technology needs reforms