On August 4, 2026, Communications and Digital Affairs Minister Meutya Hafid told a Jakarta press briefing that platforms operating in Indonesia have collectively downgraded or deactivated five million underage accounts since PP Tunas — Government Regulation No. 17 of 2025 on the governance of electronic system implementation in child protection — took effect on March 28, 2026. Two hundred platforms across 79 registered electronic system providers filed self-assessments under the law; eight rated themselves high-risk under its tiered framework.
Hafid framed the total as beating "what TikTok achieved in Australia" — a reference to the platform's compliance with Australia's under-16 social media ban. The comparison does a lot of work: Australia's law is a blanket prohibition enforced against a short list of named platforms, while PP Tunas is a risk-tiered regime applied across 200 services of wildly different scale and business model. "Australia implements a total ban, whereas we conduct a risk assessment," Hafid said, drawing the distinction herself. "What we prohibit for children under 16 is access to high-risk platforms."
The Numbers Are Lopsided
The five-million figure is also concentrated in one company's compliance effort. As of July 1, TikTok alone accounted for roughly 4.1 million of the then-4.9 million accounts removed, with YouTube contributing 600,000 and Meta's apps — Facebook, Instagram, Threads — just 185,000. That's TikTok doing roughly 84% of the work counted toward a national statistic. It says less about the regulation's reach across 200 platforms than about which single platform had the resources, and the reputational incentive after its own Australia experience, to comply fast.
The Case for a Risk-Tiered Model
Indonesia has real cause for urgency here, and the regulation deserves a fair reading before a critical one. Officials tied the PP Tunas push to Indonesia's 235-million-strong internet population, a young and heavily online user base, and documented patterns of cyberbullying and exploitation targeting minors. A regulator requiring privacy-by-default settings, restricting behavioral profiling and targeted advertising aimed at children, and forcing platforms to actually assess and disclose their own risk exposure — rather than issuing a statement and calling it done — is responding to a genuine harm, not manufacturing one.
The risk-tiered structure is also, on its own terms, a more defensible design than Australia's approach. A blanket age ban treats a moderated educational forum the same as an algorithmically optimized short-video feed; it forecloses the low-risk, high-value uses of the internet for teenagers along with the dangerous ones. PP Tunas's model — where under-16 access hinges on a platform's assessed risk profile rather than a flat age cutoff — is closer to what child-safety researchers generally recommend: proportionate friction concentrated on the features that actually cause harm, such as unmoderated direct messaging, addictive engagement design and opaque recommender systems, rather than a blunt gate on the internet itself.
Where the Rigor Runs Out
The problem is that "risk assessment" is currently self-assessment. Komdigi is grading platforms on their own homework: the eight "high-risk" classifications came from the platforms themselves, and there is no published methodology showing how the ministry would catch a platform under-reporting its own tier. Reporting on the rollout has noted that most companies still haven't adopted meaningful age-verification methods — estimation models, behavioral signals — and instead rely on self-declared birthdates, the same mechanism that has failed to keep children off the internet for two decades.
That gap matters because the more rigorous alternatives carry real costs of their own. As the Electronic Frontier Foundation has argued, even privacy-preserving verification methods like zero-knowledge proofs aren't a silver bullet: they still require some trusted party to first verify a user's age and issue a credential, which reintroduces the identity-document and biometric-collection problem regulators claim to be solving. SAFEnet, Indonesia's leading digital rights group, has raised the domestic version of this concern directly, warning that pushing platforms toward stricter monitoring of young users risks pulling in more invasive tracking and biometric checks than PP Tunas's own privacy provisions are meant to prevent — and it logged the regulation's access restrictions among the internet-access violations in its Q1 2026 digital rights report.
The Regional Signal
For anyone tracking platform regulation across Asia-Pacific, PP Tunas is worth watching less for the five-million headline than for what it actually tests: whether a risk-tiered, self-certified compliance model can hold up without an independent audit function behind it. Indonesia's approach is the more proportionate template — it doesn't need Australia's blunt instrument to take child safety seriously, and it deserves credit for trying tiered friction over a flat ban. But a regulation that lets platforms self-certify their own risk category, with penalties triggered only after the fact, is one uneven quarter away from being mostly a single platform's compliance program wearing the state's name. Komdigi's next test isn't a bigger removal number; it's publishing an audit methodology that makes the "self" in self-assessment credible.