PP TUNAS: Child-Protection Standards for Digital Platforms

Digital

PP TUNAS: Child-Protection Standards for Digital Platforms

PP TUNAS moves child safety beyond content moderation. Digital platforms increasingly need to understand who can use their products, the risks embedded in features and how age, privacy and product design interact.

In the older model of digital safety, companies could treat child protection largely as a content issue: remove harmful material, provide reporting tools and strengthen moderation.

Indonesia's PP TUNAS framework takes the conversation further.

How is the product designed? Who can create an account? Who can contact a child? What data is collected? And can the feature itself increase risk?

Government Regulation No. 17/2025 and its implementing Ministerial Regulation No. 9/2026 establish Indonesia's electronic-system governance framework for child protection.[1][2]

For digital businesses, that makes child safety a product-governance issue, not merely a content-policy function.

Risk is assessed at product, service and feature level

The implementing regulation requires assessment of products, services and features designed for children as well as those that may be used or accessed by children.[2]

The risk criteria are broad.

Can children interact with strangers?

Could they encounter age-inappropriate material?

Could they be exploited as consumers?

How is their personal data protected?

Could the design contribute to addictive behaviour or psychological or physiological harm?

A product, service or feature can receive a high-risk profile when one or more specified aspects are assessed as high risk.[2]

That means a digital ecosystem should not always be understood only through the name of its corporate brand.

Different features can carry very different risks.

“High risk” does not mean a violation

This distinction matters.

On 4 August, Komdigi said eight platform operators had voluntarily classified products, services or features as high risk through the self-assessment process. The group included social-media, e-commerce and online-gaming services.[3]

That does not mean those companies were found to have broken the law.

PP TUNAS uses a risk-based approach.

The risk profile helps determine the protections that need to be applied.

In other words:

identifying risk is part of governance, not an admission of wrongdoing.

For product teams, this is an important cultural distinction. A mature organisation is not one that describes every feature as safe. It is one that understands where risk exists and can explain how it is managed.

The age-16 rule also needs context

Public discussion can reduce the framework to a misleading statement: “children under 16 are banned from the internet.”

That is not what the implementing regulation says.

Children aged 13 to under 16 may have accounts only on low-risk products, services or features with parental consent. Those aged 16 to under 18 may hold accounts with parental consent.[2]

Social-networking and social-media services are treated as high risk unless the assessment and ministerial determination establish otherwise, and the regulation contains specific requirements regarding accounts belonging to users below 16.[2]

The government began phased implementation of these requirements from 28 March 2026.[5]

The framework is therefore about risk profiles and service characteristics, rather than a universal prohibition on children using technology.

Age verification becomes a design problem

The regulation also requires operators to provide a child-user verification mechanism and technical and operational measures for age verification.[2]

Technology can be developed internally or provided through third parties, subject to applicable legal requirements.

That creates an important trade-off.

Stronger age assurance may require more information about a user.

Yet when the user is a child, the company also has heightened reasons to think carefully about personal-data protection.

Product teams therefore need to go beyond a simple date-of-birth screen.

The bigger question is how age assurance, privacy and user experience can function together.

Implementation is already visible

By 25 June, Komdigi said roughly 200 digital platforms had submitted self-assessments.[4]

The ministry also reported that TikTok had disabled about 4.1 million child accounts while YouTube had reported roughly 600,000, producing the government-reported total of approximately 4.7 million.[4]

The assessment process can also operate below company level.

In July, Komdigi said it was reviewing 14 Apple products, services and features, including iMessage, Safari, Siri, Apple Music and Apple TV, separately according to their characteristics and potential risks.[6]

That provides an important signal for businesses:

the feature itself can become a unit of regulatory analysis.

Questions worth bringing into product meetings

For digital businesses, six questions are worth integrating into product governance:

Could children use or discover our service?

Which features allow users to communicate with each other?

What content or recommendations could children receive?

What data do we collect, and why?

How do we establish a user's age?

Could a product change alter the risk profile?

This is an editorial framework rather than a substitute for formal legal assessment.

Its value is to move compliance from the legal department into the product-development process.

Child safety is becoming part of product quality

The most important change under PP TUNAS may ultimately be conceptual.

Child protection is no longer something that can be treated only as cleanup after something harmful appears.

It increasingly enters design before a feature launches.

That means legal, privacy, product, engineering, UX, trust-and-safety and management teams need to communicate earlier.

The approach can create additional development work.

But it also has a strategic side.

A platform that understands its users, recognises the risks in its features and can show how those risks are managed is building something broader than regulatory compliance:

trust in the digital product itself.

  • [1] Pemerintah Republik Indonesia / BPK Database Peraturan. PP Nomor 17 Tahun 2025 tentang Tata Kelola Penyelenggaraan Sistem Elektronik dalam Pelindungan Anak. Berlaku 27 Maret 2025.
  • [2] Kementerian Komunikasi dan Digital — JDIH. Permenkomdigi Nomor 9 Tahun 2026 tentang Peraturan Pelaksanaan PP 17/2025. 6 Maret 2026.
  • [3] Kementerian Komunikasi dan Digital. PP TUNAS Mulai Ubah Industri Digital, Delapan Platform Akui Layanannya Berisiko Tinggi. 4 Agustus 2026.
  • [4] Kementerian Komunikasi dan Digital. Lindungi Anak di Ruang Digital, 4,7 Juta Akun Anak Telah Dinonaktifkan Platform. 25 Juni 2026.
  • [5] Kementerian Komunikasi dan Digital. Pernyataan Menteri Komunikasi dan Digital tentang Penerbitan Permen Turunan PP TUNAS. 6 Maret 2026.
  • [6] Kementerian Komunikasi dan Digital. Kemkomdigi Verifikasi 14 Layanan Apple untuk Pastikan Ruang Digital Lebih Aman bagi Anak. 2 Juli 2026.
  • High risk tidak sama dengan pelanggaran. Ia merupakan profil risiko dalam pendekatan berbasis risiko.
  • Pembatasan usia tidak ditulis sebagai larangan universal anak di bawah 16 tahun menggunakan internet.
  • Social networking/social-media services memiliki ketentuan khusus mengenai profil risiko.
  • Angka 4,7 juta merupakan angka yang dilaporkan platform dan diumumkan Komdigi, bukan hasil audit independen GATICORP.
  • Artikel membedakan perusahaan/PSE dengan produk, layanan dan fitur yang dinilai.
  • Framework product meeting adalah kerangka editorial GATICORP.
  • Artikel bukan legal advice maupun penilaian kepatuhan platform tertentu.

Published: August 18, 2026