Indonesia's Ministry of Communication and Digital Affairs (Komdigi) sent notification letters on June 26, 2026 to 25 private-scope Electronic System Operators (PSEs) — 15 foreign and 10 domestic — covering 57 unregistered websites and apps, ordering them to complete registration by July 3 or face access blocking. The list included Strava, Qatar Airways, Qantas Airways, ANA, Accor, Best Western, Banyan Tree, WorldHotels, The Ascott Limited, and several Indonesian hotel groups, according to Komdigi's own statements reported by detik.com. When the deadline passed with most of the list still unregistered, Komdigi followed up on July 9 with a second warning letter to the 22 remaining non-compliant operators, giving them until July 13 before pursuing "pemutusan akses layanan" — administrative access blocking.
The Rule Being Enforced
The legal basis is Permenkominfo No. 5 of 2020 on Private-Scope Electronic System Operators, issued under Government Regulation 71/2019 on Electronic Systems and Transactions. The regulation requires any electronic system — website, app, or platform — offered to, operated in, or used by people in Indonesia to register through the ministry's online portal, regardless of whether the operator has a local legal entity. Non-compliance escalates through warnings to administrative sanctions, with blocking as the final stage.
Steelmanning Komdigi's Case
There is a real regulatory interest here, and it deserves a fair hearing before dismissal. A PSE registry gives Indonesian consumers a named point of contact and a domestic legal address when a foreign platform mishandles their data, fails to deliver a paid service, or hosts illegal content — without it, users have no local recourse and regulators have no lever to compel cooperation on data requests, consumer complaints, or content takedowns. Registration regimes like this exist across the region and the world in various forms precisely because "we have no jurisdiction over a server in another country" is an unsatisfying answer when a citizen has been defrauded or harmed. Komdigi is not inventing a novel censorship power in this case; it is executing a five-year-old rule of general applicability, on a mixed batch of airlines, hotel chains, and a fitness app — not a targeted list of dissident media or political speech.
Why the Enforcement Tool Is Still the Wrong One
The problem is not the registration requirement in principle — plenty of jurisdictions require a local point of contact for platforms serving their citizens. The problem is that Indonesia's chosen enforcement mechanism, blanket access blocking, imposes costs on Indonesian users and businesses that are wildly disproportionate to the compliance failure being punished. This is not hypothetical: in July 2022, Komdigi's predecessor agency ran the identical playbook against a larger list — Yahoo, Steam, Epic Games, Battle.net, Origin, and PayPal among them — with a July 27 deadline. When PayPal was blocked on July 30, freelance workers who relied on it to receive international payments found their funds inaccessible overnight, sparking the #BlokirKominfo backlash reported by The Register. The ministry had to reopen PayPal access for five days so users could withdraw funds before the block resumed — an admission, in effect, that the blocking had punished consumers rather than the company. PayPal registered days later and the block never returned.
The current list is lower-stakes than 2022's — an airline booking page or a hotel loyalty portal going dark inconveniences travelers rather than freezing their savings — but the mechanism is unchanged, and it still fails a basic proportionality test. A missed paperwork deadline by Qantas or Strava's compliance team does not obviously warrant Indonesian users losing access to flight bookings or fitness tracking, when narrower remedies — fines scaled to the operator's Indonesian revenue, or a public non-compliance registry that lets consumers make informed choices — would create real registration pressure without collateral damage to the public.
The Broader Pattern
SAFEnet, the Indonesian digital rights coalition, flagged this structural risk in a 2021 position paper analyzing Permenkominfo 5/2020: pairing a broad registration mandate with a blocking-based enforcement stack creates overreach risk even when the immediate targets are commercial rather than political. That risk compounds because the same infrastructure used to enforce registration compliance is available for content-based blocking too — a country that normalizes "register or we cut off access" as its default enforcement posture builds muscle memory and technical capacity that gets reused whenever the next dispute is about speech rather than paperwork.
What to Watch
The July 13 deadline for the remaining 22 operators is the next checkpoint. If Komdigi again grants a grace period once blocking actually starts — as it did with PayPal in 2022 — that will confirm the ministry itself recognizes blocking-first enforcement is too blunt, even as it keeps reaching for the same tool. A durable fix would formalize graduated penalties — escalating fines, then time-limited access curbs with advance public notice — into the regulation itself, rather than relying on ad hoc reversals each time the blowback proves the point.