PSE Deadline: Who Owns the Risk?

Digital

PSE Deadline: Who Owns the Risk?

Komdigi gave 25 private electronic-system providers until September 22 to complete registration requirements. The deeper issue is digital governance: many companies operate websites, apps and portals across different teams without a single regulatory inventory or clear accountable owner.

A company may have one legal entity.

Its digital systems can number in the dozens.

A corporate website.

Customer app.

Booking portal.

Loyalty programme.

Campaign microsites.

Marketplace interfaces.

Customer-service platforms.

Each may have been built at a different time by different teams.

That creates a deceptively simple question:

Who inside the company has a complete inventory of those systems and understands the regulatory obligations attached to each one?

That question becomes particularly relevant on September 22, 2026.

Indonesia’s Ministry of Communication and Digital Affairs gave 25 private electronic-system providers until that date to complete registration obligations.[1]

The notices were sent on September 16 to 23 domestic providers and two foreign providers across sectors including transport, shipping, e-commerce, property and professional services.[1]

But one clarification is essential:

September 22 is not a new universal deadline for every PSE in Indonesia.

It is the deadline given to those 25 notified providers.

The underlying registration duty has existed for years.

PSE is broader than “technology company”

Ministerial Regulation No. 5/2020 defines private electronic-system providers broadly.[2]

The requirement can apply to systems used for e-commerce, financial transactions, paid digital content, communications, information services and personal-data processing linked to electronic transactions.[2]

An airline, transport company, property platform or retailer can therefore fall within the framework.

Digital regulation follows the electronic service, not merely the label attached to the company.

The system matters—not only the corporate entity

Registration requires information about the electronic system itself.

System name.

Sector.

URL.

Domain.

Relevant technical and operational information.

Processing or storage location under applicable requirements.[2]

A company can therefore operate several relevant systems.

Corporate legal-entity governance alone is not enough.

Registration is meant to happen before public use

The 2020 regulation states that registration obligations apply before the electronic system begins being used by users.[2]

That has an important product-governance implication.

The better sequence is:

inventory;

regulatory review;

registration;

launch.

Not:

launch first and ask Legal later.

Foreign providers are covered too

The framework can also apply to providers established outside Indonesia if they provide services, conduct business, or offer systems used in Indonesia.[2]

Two of the 25 September notices went to foreign providers.[1]

Digital jurisdiction does not necessarily follow headquarters location.

What happens on September 22?

Komdigi announced that the 25 providers were required to complete registration by September 22.[1]

The ministry said failure to comply could lead to follow-up under the regulations, including warnings and administrative sanctions such as access blocking.[1]

That changes the nature of the risk.

It is not simply administrative.

Access blocking turns compliance into operational risk

If a digital service becomes inaccessible, the exposure can include:

lost revenue;

service interruption;

customer frustration;

reputational impact;

and operational disruption.

A ticketing platform that cannot operate is not merely a legal issue.

It is a business-continuity issue.

The more dependent a company becomes on digital channels, the more regulatory compliance becomes part of resilience.

Registration is not a quality certification

At the same time, PSE registration should not be misunderstood.

Registration does not mean the government has certified that a service is:

fraud-free;

bug-free;

perfectly secure;

financially sound;

or superior to competitors.

It is a regulatory registration mechanism.

It should not be used as a shorthand for product quality.

Legal teams rarely hold the full inventory

In many organisations, Legal knows corporate entities.

IT knows applications.

Product knows features.

Marketing knows microsites.

Procurement knows SaaS vendors.

Operations knows customer-service systems.

No team automatically sees everything.

That is the governance gap.

Product cannot carry the responsibility alone

Product teams understand what is being built.

But they may not know every regulatory requirement.

Legal knows the rules but may not know system architecture.

IT understands infrastructure but may not know how customers use the product.

Compliance understands controls.

Operations understands business criticality.

Digital governance requires shared responsibility.

Build a system inventory

A practical inventory can record:

system name;

business owner;

technical owner;

legal entity;

purpose;

users;

URL/domain;

vendor;

data category;

hosting;

integrations;

criticality;

PSE status;

and latest compliance review.

This links obligations to assets.

Without an inventory, compliance depends on memory.

Separate ownership roles

A system may have several forms of ownership.

Product ownership.

Technical ownership.

Data ownership.

Compliance ownership.

Business accountability.

Those roles should not be conflated.

A simple RACI structure is often sufficient.

Regulatory gates belong in launch checklists

Product launches already use readiness checklists.

Security.

QA.

Analytics.

Customer support.

Marketing.

Add:

Have all relevant regulatory registrations and disclosures been completed?

If not, someone should explicitly own the decision to delay or proceed.

That makes regulation part of the product lifecycle.

Registration information must stay current

The PSE framework also requires relevant registration changes to be reported.[2]

This means registration is not a one-time project.

Systems change.

Domains change.

Hosting changes.

Companies acquire businesses.

Customer journeys evolve.

The inventory must remain current.

M&A creates hidden digital compliance risk

A company can acquire another business while keeping its app, domain and customer infrastructure running.

If registration responsibilities are not included in integration planning, the acquired system can become an orphaned compliance asset.

Digital due diligence should therefore include registration status alongside cybersecurity, privacy and IP ownership.

Vendors create another blind spot

Many businesses do not build every system themselves.

They use SaaS, hosted portals, booking engines and embedded commerce systems.

The question of which party carries which regulatory role depends on the actual service structure.

A vendor being registered does not automatically mean every obligation of the customer company has been satisfied.

Do not register what you do not understand

Registration requires accurate information about systems and their operation.[2]

If no internal owner knows where data are processed, which vendor is responsible, how users interact with the system or how critical it is, the company has a broader governance problem.

The registration process can expose that weakness.

PSE registration is not privacy compliance

A registered system must still comply with applicable personal-data rules.

Legal basis.

Purpose limitation.

Security.

Retention.

Data-subject rights.

PSE registration is one layer of a larger compliance stack.

Nor is it cybersecurity certification

Registration also does not prove that access controls, backups, testing and incident response are mature.

A company needs separate security governance.

Digital compliance cannot be reduced to one registration number.

Someone needs enterprise accountability

The accountable executive might be the CIO, COO, Chief Digital Officer, compliance head or another leader depending on the organisation.

But someone should be able to answer:

How many public-facing electronic systems do we operate in Indonesia, and what is the compliance status of each one?

If the answer takes two weeks and eight departments to assemble, governance is fragmented.

Boards need a digital regulatory inventory too

Boards do not need IP-address details.

They do need visibility into:

critical systems;

registration status;

privacy exposure;

security exposure;

third-party dependency;

single points of failure;

and overdue actions.

Digital systems are becoming as operationally material as permits, taxes and insurance.

Smaller businesses can start with a spreadsheet

A startup does not need expensive governance software.

A simple spreadsheet can track:

system;

domain;

owner;

entity;

data;

vendor;

criticality;

PSE status;

privacy review;

security review;

last update.

Review it regularly and at every significant launch.

Simple governance is better than invisible risk.

September 22 is a reminder, not the beginning

The date matters because it is the deadline given to 25 specifically notified providers.[1]

But the legal duty itself did not begin this week.

The 2020 regulation already requires qualifying private providers to register, including before public use.[2]

For everyone else, the useful question is:

Is our own inventory accurate?

Digital compliance is now part of operations

As businesses digitise, more revenue and service capability live inside software.

When the software stops:

sales stop;

bookings stop;

service stops;

customers lose access.

That means regulatory obligations around digital systems are no longer back-office paperwork.

They are part of operational resilience.

The largest risk may not be a company deliberately ignoring regulation.

It may be a company that does not realise one of its systems has fallen outside its compliance inventory.

That is the real question behind the September 22 deadline:

not simply who has registered.

But who inside the organisation is accountable for ensuring that no important digital system operates without an owner, an inventory entry and a clear regulatory map.

  • [1] Indonesia Ministry of Communication and Digital Affairs. Komdigi Requests 25 Private PSEs to Fulfil Registration Obligations, September 17, 2026.
  • [2] JDIH Komdigi. Ministerial Regulation No. 5/2020 on Private Electronic System Providers.
  • September 22, 2026 is not a new universal registration deadline. It is the deadline communicated to 25 specifically notified providers.
  • PSE registration does not constitute a cybersecurity, financial-quality or service-quality certification.
  • Whether a specific company or system falls within particular obligations requires analysis of its actual operations and applicable law.

Published: September 21, 2026