
By Dyah Pitaloka, Associate Professor Digital Communications & Marketing, and Muhamad Erza Aminanto, Assistant Professor Cyber Security, Monash University Indonesia
At a glance
- From regulation to architecture: Indonesia’s social media ban for children under 16 signals a shift from reactive policy to active digital governance, but its success depends on implementation—not the decree itself.
- Ecosystem-wide responsibility is essential: Child online protection cannot rest on parents or platforms alone. Effective safeguards require coordinated action across regulators, tech companies, civil society, and regional partners, anchored in independent oversight, privacy-preserving age verification, and centralised reporting systems.
- Safety by design is the next frontier: Beyond access restrictions, sustainable protection requires embedding safety into platform design, algorithmic transparency, and digital literacy—ensuring that Southeast Asia moves towards a trusted, interoperable, and child-safe digital ecosystem.
Share this insight
The rapid expansion of Indonesia’s digital landscape has exposed young people to severe online risks like cyberbullying, inappropriate content, and data exploitation. TFGI’s in its policy brief “Safeguarding the Digital Generation” reveals that 79% of children aged 8-18 across the Southeast Asia region have encountered “at least one form of online risk” with around 2.2% of Indonesian children have reported being sexually abused online.
The enactment of Government Regulation No. 17 of 2025, widely known as PP TUNAS (Tunggu Anak Siap), and its subsequent implementing regulation, Ministerial Regulation No. 9 of 2026, marks a watershed moment in Indonesia’s move to ban social media use for children under 16 as part of its broader approach to digital sovereignty. By restricting access to “high-risk” social media platforms, Indonesia has moved beyond passive concern into active intervention. Given that social media use is inherently social, it is important to recognise that a ban that is easy to circumvent is only as effective as the technical and institutional infrastructure that enforces it.
As Indonesia begins the arduous task of deactivating accounts and auditing Big Tech, the focus must shift from the “what” (the decree) to the “how” (the implementation). Indonesia’s journey serves as a live laboratory for child online protection (COP) policy in Southeast Asia.
The Southeast Asian Context: A Regional Mandate
Indonesia’s move does not happen in a vacuum. As noted in TFGI’s “Safeguarding the Digital Generation” brief, Southeast Asia is home to some of the world’s most digitally active youth. However, the region suffers from regulatory fragmentation such as some allow or experiment with softer compliance mechanisms, such as parental consent checkboxes or algorithmic behavioral age estimation.
If Indonesia successfully implements PP TUNAS, it could create a “Brussels Effect” within ASEAN. When Big Tech is required to build robust age verification (AV) and safety tools for 280 million Indonesians, the marginal cost of extending those protections to Malaysia, Thailand, or Vietnam drops significantly.
However, there is a risk that a “hard ban” in one country like Australia simply pushes children towards less regulated, borderless platforms or increases the use of VPNs. This is why Indonesia’s policy should be paired with regional interoperability. There is a need for an ASEAN-wide standard for what constitutes “high-risk” digital features, as well as a shared database for reporting cross-border digital harms.
The Three Pillars of Implementation
What we propose is an understanding that safety is not a technical term that should be applied later. It is a value that multi-actors such as tech companies and developers, regulators and law enforcements must uphold and must be anchored from the very start. A regulation like PP Tunas can serve as a form of ‘automated exclusion’ that would systematically limit and, to some extent, forbid children from participating in technology. There is a need to question whether restrictions – such as auto remove certain content or filter some information, compromise children’s freedom of expression, and able to address the root causes of online harm, such as addictive platform design and lack of media literacy
Therefore, for PP TUNAS to be more than a “paper tiger” — a policy that appears strong on paper but lacks meaningful enforcement or real-world impact — the Indonesian government must solidify three missing pillars that bridge the gap between policy intent and digital reality.
1. Independent Oversight: The “eSafety” Blueprint
Protection cannot be an “extra task” for existing ministries. Currently, the Ministry of Communication and Digital Affairs (Komdigi) acts as both the regulator and the enforcer. This creates a bottleneck. Indonesia requires an independent statutory body, similar to Australia’s eSafety Commissioner which is Australia’s independent national regulator for online safety.
This body must serve as a neutral arbiter between citizens and Big Tech such as Meta or Google, free from the volatility of political cycles. Its primary mandate should be the continuous auditing of platform algorithms and the verification of safety-by-design standards. Without an independent “digital sheriff,” enforcement risks becoming inconsistent—penalising some platforms while allowing others to bypass regulations due to their economic or political clout.
2. Privacy-Preserving Age Verification (AV)
The most significant technical hurdle is age verification. The objective should be age assurance—the ability to confirm that a user meets an age threshold without collecting or retaining their exact age or identity. This requires avoiding simplistic “checkbox” approaches, where users merely self-declare that they meet age requirements. At the same time, regulators and platforms must guard against solutions that swing too far in the opposite direction by requiring excessive collection of personal data, such as facial scans, biometric information, or government-issued IDs, in order to demonstrate compliance.
Indonesia should lead the development of a decentralised, privacy-preserving AV framework that leverages the national digital identity system without handing over sensitive data to private corporations. We can learn from the open-source mobile application developed by the European Commission that allows users to cryptographically prove they meet a specific age threshold (such as 13+, 16+, or 18+) via zero-knowledge proofs without revealing their name, exact birthdate, or any identifying data to online platforms. If this AV challenge is solved in a way that respects privacy, Indonesia could provide a template for the rest of ASEAN, where data privacy concerns remain a major hurdle to child online protection (COP) regulations.
3. Centralised Reporting and Digital Forensics
When a platform fails to protect a child, where does a parent go? Currently, reporting mechanisms are fragmented across various apps and ministerial hotlines. We need a high-throughput digital forensics pipeline. This infrastructure must be capable of handling millions of reports transparently, ensuring that when a parent flags harmful content or a grooming attempt, there is a clear, auditable trail of remediation. One example is BOSE, The Basic Online Safety Expectations (BOSE) is a legally binding framework enforced by Australia’s eSafety Commissioner that compels tech platforms to meet strict safety benchmarks and answer transparency notices regarding how they detect, report, and eliminate severe digital harms like child grooming and cyberbullying.
Moving Toward “Safety by Design”
In our previous work, we emphasised that banning access shifts responsibility from platforms to parents. While the March 2026 enforcement has seen platforms like X and Bigo Live comply, others such as TikTok and Roblox remain in a state, which are categorised as partially cooperative platforms.
The policy priority must shift towards Safety by Design and Default. This means:
- Feature-based regulation: Ensuring age-appropriate experiences on social media.
- Default privacy: Accounts for those aged 16–18 should be private by default, with geolocation and “suggested friend” algorithms disabled.
- Algorithmic transparency: Platforms must be required to disclose how their “high-risk” features (such as infinite scroll or targeted ads) are tuned for younger demographics.
- Risk profiling: Under Ministerial Regulation 9/2026, features are classified as high or low risk. It is important to ensure that “high risk” is not just a label, but a trigger for mandatory independent audits.
While these four recommendations place the regulatory burden on platforms, true ‘Safety by Design’ requires a holistic ecosystem. Technical controls must be matched by a societal commitment to digital literacy, empowering the parents and educators who manage the daily ‘human element’ of youth internet use.
The Human Element: Beyond Technical Controls
Finally, we must acknowledge that no algorithm can replace a parent. As the government rolls out technical deactivations, it must simultaneously invest in digital literacy. Research shows that maternal education and geographic location are strong predictors of a child’s level of digital addiction.
A policy that focuses solely on the child is incomplete; it must also support the parent. Placing responsibility equally on platforms—for example, requiring them to turn off recommender algorithms aimed at children—would help establish an “environment of trust” where each actor contributes to creating safe spaces for children. We need community-based “mediated moderation” programmes that equip parents not only to restrict access, but also to engage in meaningful dialogue with their children about the digital world. This is a policy and environment not built merely for children, but with them.
Conclusion: From Foundation to Building
PP TUNAS is a necessary foundation, but it is not the finished building. The success of Indonesia’s age-restriction policy will not be measured by how many accounts are deleted, but by how much the digital environment itself is transformed.
We must shift the burden of safety from the “navigators” (children and parents) alone to a shared responsibility across the ecosystem, including the “architects” (platforms), regulators, and wider stakeholders. By strengthening independent oversight, embedding privacy-centric technology, and advancing regional cooperation, Indonesia can move beyond the “decree” and towards a multi-stakeholder digital ecosystem where technology humanises, rather than undermines, the childhood of the next generation.
The views and recommendations expressed in this article published are solely of the author and do not necessarily reflect the views and position of the Tech for Good Institute.
