Since July 1, 2026, no one in Indonesia can activate a new SIM card without scanning their face. Under Ministerial Regulation (Permen Komdigi) No. 7 of 2026, mobile operators must match a live facial capture against the civil registry — Dukcapil — before a number goes live, replacing a system that relied on customers typing in their National ID (NIK) and Family Card numbers. A six-month transition that opened the option voluntarily in January gave way, after a five-month pilot across Telkomsel, Indosat Ooredoo Hutchison and XL Axiata that processed roughly 1.4 million registrations between January and April 2026, to a hard mandate with, in the words of Digital Ecosystem Director General Edwin Hidayat Abdullah, "no more flexibility" (Tribrata News / Polri).
The Case Komdigi Is Making
The government's justification is not manufactured. Indonesia's prior ID-based verification regime was already broken: a hacker known as Bjorka put roughly 1.3 billion records from the NIK-linked SIM database up for sale in 2022, and officials now cite over Rp7 trillion (~$407 million) a year in scam losses, with the Indonesia Anti-Scam Center logging more than 380,000 fraudulent accounts and Rp4.8 trillion in losses by late 2025 (BiometricUpdate). A photocopied ID card is trivial to forge or borrow; a live face match against a government database is a materially higher bar, and Komdigi says the process now takes under two minutes with no reported customer complaints during the pilot. That is a real improvement in identity assurance, and critics of the policy should not pretend the status quo it replaced was working.
The rollout has also, by the government's own numbers, been fast. By July 5, cumulative biometric registrations — voluntary and mandatory combined — reached about 4.9 million, running near 201,000 new sign-ups a day (Barito Timur Media Center); by July 23, the ministry reported 10 million total biometric verifications and set a target of 20 million within two months of the mandate taking effect, with operators paying a government-set Rp3,000 (~$0.17) fee per facial check (BiometricUpdate). Daily SIM sales have stayed roughly flat, suggesting the friction hasn't collapsed demand. When Komdigi discovered on July 6 that some operators were still quietly activating numbers on the old NIK-only path, it ordered Dukcapil to disable that verification route outright and gave carriers under 24 hours to comply (MLex) — a regulator that is at least willing to enforce its own rule.
The Piece Komdigi Is Skipping
The problem is not the goal; it's the sequencing. Indonesia's 2022 Personal Data Protection Law requires an independent supervisory authority to oversee exactly this kind of sensitive-data processing. As of the mandate's launch, that authority still did not exist, and the law's implementing regulations for biometric data — including rules on mandatory deletion and breach response — remained unpublished. Indonesian press-freedom legal aid group LBH Pers has gone as far as to argue the regulation is void ab initio on those grounds, and separately flags that requiring a smartphone-camera-capable registration process is exclusionary for lower-income and rural users (LBH Pers).
That gap matters because of what a phone number now carries. Once a SIM is bound to a biometrically verified identity, the number stops being a pseudonym. Damar Juniarto, executive director of the digital-rights group SAFEnet, has warned that this makes it "easier for law enforcement to track and monitor people," with particular exposure for LGBTQ+ Indonesians: come out to friends on a specific number, he notes, and "the government knows these people are using these specific phone numbers, and can be tracked because of that" (Coda Story). That risk is not hypothetical in Indonesia, where Aceh enforces Sharia-based penalties for homosexuality and national law leaves LGBTQ+ Indonesians without anti-discrimination protection. A whistleblower, an abuse survivor hiding from an abuser, or a journalist's source loses the option of an unlinked number entirely.
What Proportionate Would Look Like
None of this argues for reverting to the NIK-only system Bjorka exposed. It argues for sequencing: stand up the independent PDP authority the 2022 law already promised, publish the biometric-specific implementing rules — retention limits, breach-notification timelines, an audit mechanism for Komdigi's claim that operators never store facial templates — and only then flip the switch nationwide. Indonesia is not choosing between fraud and privacy; it chose fraud reduction now and left the privacy backstop for later, betting that a database of 300+ million faces will hold up on trust in Dukcapil and telco security practices that have already failed once. Vietnam, Thailand and South Korea run comparable systems, but a regional trend is not a substitute for the domestic oversight body Indonesian law itself requires. The fraud problem was real. The fix arrived a step ahead of the law meant to govern it.