Loading…
Loading…
Permenkomdigi No. 5/2025 is the operational implementing regulation replacing the prior Permenkominfo No. 5/2015 (Institutional Domain Name Registrar) and Permenkominfo No. 10/2015 (Electronic System Registration Procedures for State Administrative Institutions), bringing the Public-ESP governance framework under the authority of the newly restructured Kemkomdigi ministry (renamed from Kominfo under President Prabowo's October 2024 cabinet restructuring).
Data classification taxonomy (Article series on risk-based classification): The regulation introduces four data risk tiers: 1. Strategic data — highest tier; must be stored, processed, and managed exclusively within Indonesian territory under direct government oversight; covers data whose disclosure could impair national sovereignty, state secrets, or critical infrastructure integrity. 2. High-risk data — must be stored within Indonesia with strict access controls; covers data whose breach could cause serious harm to the state or individuals (identity databases, law-enforcement records, health records). 3. Medium-risk data — domestic storage requirement; may be processed abroad subject to protection and accessibility conditions and bilateral data-cooperation agreements. 4. Low-risk data — lightest tier; general administrative data with no mandatory localisation, subject to standard protection obligations.
Registration and re-registration mandate: All PSE Lingkup Publik must register or re-register with Kemkomdigi by the March 2026 deadline. Systems must meet security standards, pass feasibility testing (uji kelayakan), and demonstrate personal data protection compliance under Indonesia's PDPA framework (Perpres 62/2022 regime). Bank Indonesia and the Financial Services Authority (OJK) are explicitly exempted from certain provisions given their sector-specific prudential frameworks.
Content governance: Kemkomdigi retains authority to issue access-blocking orders for prohibited electronic information categories including: pornography, online gambling, terrorism/violent extremism content, hate speech, intellectual-property infringement, and state-security-impacting content. The blocking mechanism operates via the PSE's institutional domain infrastructure — government PSEs become direct enforcement conduits rather than passive recipients of blocking notices.
Institutional domain name governance: A distinct chapter consolidates the management of go.id, sch.id, ac.id, and related government-reserved second-level domain namespaces under Kemkomdigi's Domain Registry authority, absorbing the domain management function previously split across two separate ministerial regulations.
compliance obligations under the March 2026 deadline: AWS GovCloud, Microsoft Azure Government, Google Cloud for Government, and Alibaba Cloud must ensure their Indonesia government workloads meet the data-classification storage requirements — particularly the strategic and high-risk data tiers, which create a strong pull toward domestic-hosted infrastructure.
Oracle Cloud Infrastructure opened its Jakarta region in 2023; AWS, Azure, and GCP all operate in-country Availability Zones/regions in Jakarta. However, the tiered classification framework creates ongoing compliance and audit obligations that raise operational costs relative to domestic alternatives (Telkom Indonesia Indibiz, Biznet Metrocloud, Lintasarta).
(ISAT.JK), and their cloud subsidiaries benefit from the localisation pull on strategic/ high-risk tiers. The regulation operationalises a competitive moat for locally certified government-cloud providers.
tools) used by Indonesian government institutions must navigate the PSE Lingkup Publik registration requirement — this affects Microsoft 365 Government, SAP Indonesia government contracts, and similar platforms.
digital-sector regulatory architecture. Permenkomdigi 5/2025 operationalises the bifurcated PSE regime: public-scope (this filing) vs. private-scope (governed by separate implementing rules under PP 71/2019), together constituting Indonesia's functional equivalent of the Chinese CAC cross-border data-transfer framework (filed 2024-03-22) and Vietnam's Decree 53/2022 data-localisation regime (filed 2022-08-15).
of Electronic Systems and Transactions) is the statutory basis for Permenkomdigi 5/2025 but has not yet been separately filed in the IPTM register — a companion filing would complete the Indonesian data-governance architecture.
Lingkup Privat) is the parallel instrument; the prior Permenkominfo 5/2020 and 10/2021 governed this category — status under the Kemkomdigi rebrand and whether a new Permenkomdigi is forthcoming remains a watch item.
administrative sanctions uniformly or selectively (as with the July 2022 platform-blocking wave under Permenkominfo 5/2020 that briefly threatened to block Steam, PayPal, and Yahoo) will be the key implementation test.
(Government Regulation 71/2019 + Presidential Regulation 62/2022) is undergoing consolidation under a forthcoming Personal Data Protection Law — the interaction between Permenkomdigi 5/2025's data-classification obligations and PDPA's cross-border transfer provisions will shape the ultimate compliance burden for foreign cloud operators.