Indonesia's Ministry of Communication and Digital Affairs made facial-biometric verification mandatory for all new prepaid SIM registrations starting July 1, 2026, under Peraturan Menteri Komunikasi dan Digital Nomor 7 Tahun 2026. New customers' faces are now checked live against the Dukcapil civil-registration database for citizens, or the immigration database for foreign visitors, replacing a system that relied solely on National Identity Number (NIK) and Family Card checks. As of July 14, roughly 6.8 million people had completed the new registration, according to Antara News. The policy followed a pilot that began in October 2025 with Telkomsel and expanded through a formal six-month trial from January 2026 involving the country's major carriers, per Biometric Update's coverage of the rollout.
The Case the Ministry Is Making
Indonesia's regulators have a real problem to solve. NIK-based registration was trivially gamed — SIM cards bought under stolen or borrowed identities have fueled scam calls, phishing, and gambling-linked fraud at industrial scale, which is why the ministry framed the switch as closing a loophole rather than expanding surveillance. A system where a face must match a government database in real time is, mechanically, harder to spoof than one where a typed ID number is taken on faith. That is a legitimate policy goal, and proportionate identity verification for telecom accounts is not inherently objectionable — Switzerland has required it since 2004.
What Switzerland Actually Requires — and Refused
That is the useful contrast. Switzerland's telecommunications surveillance ordinance (Verordnung über die Überwachung des Post- und Fernmeldeverkehrs, VÜPF) has obligated providers to record a prepaid customer's name, address, and date of birth against a valid passport or ID card since 2004, a rule tied to the Federal Act on the Surveillance of Post and Telecommunications. That is a real identification requirement, not a laissez-faire market. But when a Swiss carrier tried to go further and require customers to submit a live facial scan through its website to complete verification, the telecom ombudsman (ombudscom) ruled against it in 2020. The ombudsman found that browser-based facial capture was "unsafe from a data protection perspective" and that the statutory registration duty was already satisfied by presenting an ID document at a staffed post-office counter — a solution the ombudsman ordered the carrier to reimburse. In other words, a face-matching mandate was tested against Swiss practice and found unnecessary to meet the same anti-fraud objective Indonesia is now pursuing with biometrics.
That outcome is consistent with how Switzerland treats biometric data generally. Under the revised Federal Act on Data Protection (nFADP), biometric data that uniquely identifies a person is classified as sensitive personal data requiring explicit consent to process, and the Federal Data Protection and Information Commissioner (FDPIC/EDÖB) has stated plainly that "comprehensive facial recognition in real time," of the kind used for social scoring or blanket identity databases, falls into the category of AI-driven processing that Swiss law will not tolerate. Violations of the sensitive-data rules can draw criminal fines up to CHF 250,000 against the responsible individual, per the FDPIC's own summary of the statute's penalty provisions — a meaningful deterrent against exactly the kind of default-to-biometrics thinking Jakarta has now written into telecom regulation.
Why the Distinction Matters
Indonesia's system checks each new SIM registrant's face against Dukcapil, a national population database, every time a number activates — an automatic run through a government identity system for a routine commercial transaction. That is architecturally different from presenting a passport to a clerk. It creates a live biometric-matching pipeline between telecom operators and a national ID registry, with all the centralization risk that implies if that pipeline is breached, repurposed for unrelated law enforcement queries, or expanded to existing subscribers, whom the ministry says can currently register biometrically on a voluntary basis. Fraud reduction does not require that architecture. Switzerland's ID-document model has run for two decades, survives a legal identification requirement, and was specifically tested — and narrowed — when a provider tried to push it toward biometric capture.
The Proportionate Path
None of this means Indonesia's fraud numbers are imaginary or that its ministry is acting in bad faith; SIM-enabled scam networks are a documented regional problem across Southeast Asia, and a government under pressure to show results will reach for the technically strongest tool available. But "strongest" and "proportionate" are not synonyms. Regulators building or revising SIM-registration regimes — including in APAC markets watching Jakarta's rollout — should treat document-based identification, audited and enforced, as the default, and reserve biometric matching against national databases for cases where document checks demonstrably fail. Switzerland's ombudsman drew that line for one carrier in 2020. Telecom regulators facing the same fraud pressure Indonesia cites would do well to draw it in statute before the biometric default becomes irreversible.