You Have a Website or App. Are You Operating a Registered PSE?

Digital

You Have a Website or App. Are You Operating a Registered PSE?

Building a website or application is not only a design and technology decision. Once a business operates an electronic system, functions, data, security and regulatory obligations need to be mapped.

Many digital projects begin with practical questions.

What domain should the company use? Which technology should power the website? Does it need login? How should the payment gateway work? Will the application be available on iOS and Android?

Another question deserves to appear much earlier:

What kind of electronic system is the company actually building?

The issue became particularly visible again in September 2026 when Indonesia's Ministry of Communication and Digital Affairs intensified compliance with Private Electronic System Operator—PSE Privat—registration. Komdigi sent notices to 25 operators and, on 27 September, said seven had yet to meet the requirement and had received formal warnings.

The lesson for business owners, however, is larger than remembering to register.

Once a website or application begins performing business functions, the company no longer has only a digital presence.

It is operating a system.

PSE Is Not Simply Another Term for an E-Commerce Website

Government Regulation No. 71 of 2019 defines Electronic System Operators broadly as parties that provide, manage and/or operate electronic systems for themselves or others. For Private Electronic System Operators, the framework includes internet portals, sites and applications used for specified functions.

Komdigi's official guidance lists six categories, including offering or trading goods and services, financial transactions, distribution of paid digital content, communications services, search engines or electronic-information services, and personal-data processing for public-facing operations associated with electronic transactions. Meeting one relevant criterion can trigger the registration requirement.

The legal distinction therefore should not be simplified into:

company profile = exempt

e-commerce = registration required.

Even a site without checkout should not automatically be assumed to fall outside the scope merely because a business describes it as a company profile; provision of electronic information is itself included in the official criteria.

The assessment needs to examine what the system actually does.

Start With Function, Not the Product Label

Two businesses may both call their digital product a “website” while operating fundamentally different systems.

One may only publish company information.

Another collects inquiries, stores customer data, generates quotations, accepts bookings, creates customer accounts, tracks orders and integrates with internal systems.

Visually, both are websites.

From an operational and governance perspective, their complexity is very different.

Komdigi's own registration guidance asks operators to describe the system's name, sector, URL, domain or server IP address, business model, function and business process, Personal Data processed, and locations where electronic systems and data are managed, processed or stored.

That list reveals something important.

The regulator is not looking only at the pages the customer sees.

It also looks at the system operating behind them.

Go-Live Is Not Only a Technology Milestone

Ministerial Regulation No. 5 of 2020, as amended by Regulation No. 10 of 2021, provides that Private PSE registration should take place before the electronic system begins being used by users. Domestic registration is generally handled through Indonesia's OSS system.

That has a direct implication for project planning.

Many digital projects treat compliance as a late-stage task:

design → development → testing → deployment → legal questions.

The problem with that order is that obligations may only become visible after the system is expensive to change.

A healthier approach is to perform regulatory mapping while features are still being defined.

Adding a customer account is not only a UX decision; it can introduce authentication, data-governance and security requirements.

Chat is not merely a convenience feature.

Payment integration is not merely a conversion feature.

Customer-document storage is not merely a storage choice.

Every function changes the profile of the system.

PSE Registration Is Not the End of Compliance

Another mistake is treating registration as the final checkbox.

Government Regulation 71/2019 contains broader obligations for electronic-system operation. Operators are required to maintain audit trails and secure electronic-system components, as well as implement procedures and safeguards against disruption, failure and loss.

The PSE registration process itself asks for commitments relating to information security and Personal Data protection under applicable laws.

Receiving a PSE registration certificate therefore does not mean governance work is finished.

Businesses may still need to address cybersecurity, personal-data protection, terms and conditions, consent, access control, vendor and cloud arrangements, incident management and sector-specific regulation.

Registration is one layer of compliance, not the entire compliance architecture.

What Happens When This Is Left Until Later?

Komdigi's actions in September 2026 show that registration remains an actively enforced requirement.

Ministerial Regulation 5/2020 provides administrative sanctions for Private PSEs that fail to register. The framework allows electronic-system access to be blocked for non-registration, with normalisation mechanisms when registration requirements are subsequently fulfilled.

For business owners, the practical risk can extend beyond regulatory enforcement.

A late compliance review may also reveal that customer information is spread among several vendors, incident response has no clear owner, subprocessors are not fully mapped or the system lacks sufficient audit trails.

What first looks like a regulatory gap may expose an operational gap.

Five Questions Before Launch

GATICORP uses five questions as an initial readiness screen.

What does the system do?

Does it only provide information, or does it also provide services, communications, transactions or other digital functions?

Who uses it?

Employees, customers, partners, the public or a combination?

What data does it process?

Including Personal Data, documents, transactions, communications and logs.

How does the business process work?

What happens from user input until the service is completed?

Which obligations follow those functions?

PSE, personal-data protection, security, sectoral requirements, consumer protection or other obligations.

This is not a legal test for PSE status. It is a GATICORP readiness framework for identifying when deeper assessment is needed.

A Website Stops Being a Brochure When It Starts Running the Business

Corporate websites were once often treated like printed profiles transferred onto a screen.

Today, one system can capture leads, identify customers, create accounts, receive orders, manage bookings, run subscriptions and communicate with multiple third-party services.

The technology transition can look simple.

The change in responsibility may not be.

That is why compliance questions should appear while architecture and features can still be changed—not after deployment.

For companies developing digital channels, the important question is no longer only:

“Is the website or app ready to use?”

It is also:

“Are we ready to be the organisation operating it?”

  • Government Regulation No. 71 of 2019 on Electronic Systems and Transactions. Used for definitions of Electronic Systems and Electronic System Operators, Private PSE categories, registration before system use, audit-trail requirements and electronic-system security. PP 71/2019 remains in force.
  • Minister of Communication and Informatics Regulation No. 5 of 2020 on Private Electronic System Operators, as amended by Regulation No. 10 of 2021. Used as the basis for registration obligations, processes and administrative sanctions.
  • Komdigi Private PSE Registration Portal. Used for the six registration criteria, required registration information, OSS process and confirmation that registration is free of charge.
  • Komdigi, 16 September 2026 — notification to 25 Private PSEs. Used as current context for compliance enforcement.
  • Komdigi, 27 September 2026 — written warnings to seven Private PSEs. Used to demonstrate continued supervision of operators that had not complied following notification.
  • This article does not state that every website automatically requires registration or that a company-profile website is automatically exempt. Assessment should consider the actual functions of the Electronic System and applicable regulatory criteria.
  • PSE registration does not replace other obligations involving Personal Data protection, information security, consumer protection or sector-specific regulation.
  • The five readiness questions are a GATICORP editorial framework, not a legal test or official Komdigi determination.
  • This article is intended for business education and does not constitute legal advice. The status of a specific system should be assessed based on its actual functions and applicable regulation.

Published: October 9, 2026