Indonesia KOMDIGI Sender & Marketing Rules
Indonesia regulates commercial electronic messaging through the Ministry of Communication and Digital Affairs (KOMDIGI) — formerly the Ministry of Communication and Informatics (Kominfo) — and the operators it supervises. KOMDIGI runs a sender-registration regime for A2P SMS: an alphanumeric sender ID reaches a+62 handset only once that sender
name is registered, and unregistered sender traffic is blocked at the
carrier edge, not queued for review. Indonesia also operates under
Personal Data Protection Law No. 27 of 2022 (PDP Law) — the country’s
first comprehensive data-protection statute, which requires a lawful basis
for personal-data processing and elevates consent for marketing use. The
channels the regime touches on Orbit are SMS (pre-registration of the
sender name), voice (no sender ID, but consent and content rules apply),
and email only through the consent and content layer.
Everything below is a tenant-owned control. Orbit ships the surfaces —
the consent ledger, suppression and the Bahasa Indonesia opt-out keyword
aliases, tenant-configurable quiet hours, sender-registration tracking,
the send-gate — defaults-open; your organization configures them for
Indonesia. Compliance with KOMDIGI’s requirements and the carriers’
vetting remains yours, and the regulator and the operators enforce it
regardless of what any toggle says. This page is documentation, not legal
advice.
This page is documentation, not legal advice — an engineering map of the
Orbit surfaces, not a legal opinion. Enforcement exposure is real:
KOMDIGI can direct operators to block unregistered sender traffic at the
carrier edge without notice, and PDP Law No. 27/2022 carries administrative
sanctions including fines of up to 2% of annual revenue. Have counsel
review your sender-name choice, your consent text and proof capture, and
your marketing-window posture before you send to Indonesian recipients.
1. The ID route: sender-name pre-registration
Read the live ID row ofGET /compliance/country-rules?channel=sms on
Country Compliance Requirements before
you provision. The Indonesian SMS edge accepts alphanumeric sender IDs
only once registered — an unregistered sender is filtered at the carrier
edge rather than delivered, and the send-gate holds traffic until an
approved entry exists for ID.
- Sender ID must match the brand. KOMDIGI rejects generic names — a
INFO,SMS, orALERTclass sender ID that does not tie back to your registered brand identity. Pick a registrable brand name that the KYC documents you upload can support. - A KYC-backed brand identity, not just a string. The carriers expect
the sender name attached to a KYC-verified entity; thin submissions
bounce. Emphasize the legal
company_name, thecompany_website, and a completeuse_caseon Organization KYC Onboarding. - Register before traffic. Unlike a post-paid registration market,
Indonesia rejects the traffic itself when the name is unregistered —
the send-gate returns the ID sender-not-registered error on any A2P
attempt until the entry is
approved, per Troubleshooting Compliance Error Codes.
- a
business_doc— a business registration document (SIUP, NIB, or equivalent) issued to the entity, and - an
authorization— an authorization letter appointing the sender.
id_proof — an Indonesian KTP
(national identity card) — in place of the business registration; the role
on the KYC identity model is the same
id_proof slot the documents page uploads to. Upload each document once
on KYC Documents and reuse the returned
doc_… ID across registrations. Until the ID entry reports approved,
keep marketing traffic in rehearsal — the send-gate holds ID and returns a
sender-not-registered error (422) on any A2P attempt.
Voice origination carries no sender-ID registration, but KOMDIGI-level
carrier obligations apply at the operator level; confirm your carrier’s
posture for voice separately.
2. Bahasa Indonesia opt-out vocabulary
The seeded Bahasa Indonesia keyword aliases on the Opt-Out Keyword Alias Table target ID:
The matcher is locale-insensitive case-folding with Unicode normalisation,
so a reply
BERHENTI, a reply berhenti, and a reply STOP all write
the suppression entry. The matching rule runs against the exact keyword
(or the keyword plus trailing punctuation) — publish the opt-out keyword
you reference in your consent text and footer.
Your auto-reply should acknowledge the opt-out in both Bahasa Indonesia
and English (Anda telah berhenti berlangganan. You are now unsubscribed. is the shape), covering the bilingual audience the
Indonesian market expects. Set the two-language auto-reply text on the
alias table’s editor.
Apply the same two scope rules every seed bundle carries:
- Channel scope. The seeded aliases apply to SMS. Extend the list yourself for WhatsApp or RCS scope when you run ID traffic on those channels.
- Suppression scope. Route an ID revocation at scope
all: a contact that repliesBERHENTIto your SMS should not then be voice-dialed or emailed by the same program. See Opt-Out & Suppression Lists.
3. Consent posture under PDP Law No. 27/2022
PDP Law No. 27 of 2022 makes consent one of the lawful bases for personal-data processing, and marketing use without a lawful basis is exposed. Treat promotional SMS and voice as opt-in-strict — the same posture every jurisdiction with a consent-based data-protection statute converges on. The consent record rides on the consent ledger withlawful_basis: "consent" and a consent-text version pinned at capture:
refuse for marketing sends, which is the
correct default for ID-bound promotional traffic under a consent-based
statute. See Consent Management for the
record contract, and verify before the first send with
GET /compliance/consent/lookup.
Data-subject rights under PDP Law — access, rectification, erasure, and
data portability — are exercised through the
DSAR portal. Configure your tenant DSAR workflow
before you collect Indonesian recipient data at scale.
4. Marketing quiet-hours posture
The Indonesian convention for marketing SMS follows a conservative recipient-local window: avoid the overnight hours (21:00–07:00 WIB is the starting convention carriers honor on marketing traffic). Indonesia runs three time zones — WIB (UTC+7), WITA (UTC+8), and WIT (UTC+9) — with no daylight saving on any of them. Most+62 mobile numbers resolve
to WIB (UTC+7), the country’s dominant time zone; Orbit’s
recipient-timezone resolution handles the three-zone fan-out per-number so
your window applies correctly across the archipelago.
This is not Orbit’s tenant quiet-hours: the send-gate does not flip it
on for you; you set your tenant quiet hours to cover it deliberately.
Configure the window on
Quiet-Hours Configuration — the
recipient-resolution path handles +62 numbers across all three zones —
and validate the recipient timezone resolution with
Quiet-Hours Preview before you flip ID
live.
Ramadan and Idul Fitri seasonal sending. Indonesian marketing traffic
reads season: Ramadan and Idul Fitri shift the hours recipients find
acceptable, and the convention tightens the acceptable window toward the
evenings during fasting hours. Orbit makes no platform-level seasonal
change (the quiet-hours window is tenant-configured); tighten the window
yourself during Ramadan and revert after Idul Fitri.
5. Obligations → Orbit surface table
6. Send-time posture — org-level knobs
Two tenant-owned policies decide what happens for a contact with no recorded consent on a marketing send, both deliberate knobs on Consent Posture: The Unknown-Consent Policies:refuse(the default) is the fail-closed posture a PDP Law opt-in regime argues for — an unknown-consent marketing send is refused.- Loosening to
allow_with_loggingis a deliberate, documented call with a required written justification; it is not the ID posture.
permit_on_missing /
deny_on_missing) governs the CDP side, not the marketing-send gate;
leave it at the default unless your CDP posture calls for the stricter
variant.
7. Worked configuration before first ID send
1
Read the ID country-rules row
GET /compliance/country-rules?channel=sms&country=ID and read
sender_types, registration, content_restrictions, and
stop_requirement. If registration is required, the send-gate
holds ID traffic until an approved sender is attached — this is the
intended behavior, not a fault.2
Pick the sender name
Alphanumeric, matching the brand identity your KYC documents support —
no generic class names. Pre-flight it with
GET /compliance/check
before you file.3
Upload KYC documents
Upload your Indonesian business registration (SIUP / NIB) as
business_doc and an authorization letter as authorization; for an
individual, an Indonesian KTP as id_proof. Note the returned
doc_… IDs.4
File the ID sender-name registration
POST /compliance/sender-id-registrations with the ID entry
referencing your doc_… IDs. Wait for the ID country entry to reach
approved; budget the pre-registration lead time the UAE page
documents.5
Capture marketing opt-in first
Record a consent entry with
sms scope and
lawful_basis: "consent" before any ID marketing send; the
unknown-marketing policy defaults to refuse, which is the right call
for the PDP Law regime.6
Set the marketing no-overnight window
Turn on tenant quiet hours covering the overnight hours recipient
time; validate with
Quiet-Hours Preview. Plan Ramadan
and Idul Fitri campaigns against a tightened window.
7
Publish the Bahasa Indonesia opt-out
Confirm the seeded Bahasa Indonesia aliases (
BERHENTI, STOP,
UNSUBSCRIBE) cover the keyword your consent text and footer
reference, and set the auto-reply to acknowledge in both languages.8
Verify before first send
GET /compliance/sender-id-registrations shows ID approved;
GET /compliance/consent/lookup returns the recipient’s consent
row; the quiet-hours preview resolves the recipient timezone
correctly. Then send.Frequently asked questions
Does Orbit register my Indonesian sender name with KOMDIGI? No — carrier-facing registration is yours to file (or to file through your aggregator), the same as every market. Orbit exposes the ID country-rules row and the registration-status tracking so you can confirm the sender is attached, and it delivers your traffic once the entry isapproved.
Is the overnight window a platform gate?
No — the overnight no-send window is the market convention, not a gate
Orbit flips on. Setting tenant quiet hours to cover it is a deliberate,
tenant-owned opt-in — the same pattern the Saudi Arabia and UAE pages
document for GCC markets.
Why does the Indonesian page ask for Bahasa Indonesia opt-out handling?
Because Indonesian recipients can reply in Bahasa Indonesia, KOMDIGI’s
regime expects opt-out handling to work in the local language, and your
auto-reply should acknowledge in both languages. The Bahasa Indonesia
aliases (BERHENTI, MULAI, YA) ship seeded targeting ID — see
Opt-Out Keyword Alias Table.
Which KYC documents does an Indonesian registration accept?
An Indonesian business registration (SIUP, NIB, or equivalent) as
business_doc plus an authorization letter as authorization; for an
individual, an Indonesian KTP as id_proof. Upload each on
KYC Documents and reuse the doc_… IDs
across registrations.
Related references
- Country Compliance Requirements — the per-country matrix this page expands the ID row of.
- Regional Posture Hub — the matrix of country pages and the check-the-row-first workflow.
- Sender-ID Registration — the submit-and-track flow for the ID registration; lead-time table.
- KYC Identity Model — the
business_doc,id_proof, andauthorizationroles the carriers ask for. - Organization KYC Onboarding — the KYC-backed brand identity the ID sender name attaches to.
- Opt-Out Keyword Alias Table — the seeded Bahasa Indonesia aliases and the custom-rule extension path.
- Consent Management — the consent
record contract (
lawful_basis, proof URL, text version). - Consent Posture: The Unknown-Consent Policies —
the
refuse/allow_with_loggingdecision point. - DSAR Portal — data-subject rights workflow under PDP Law.
- Quiet-Hours Configuration — set the recipient-timezone-resolved window.
- Quiet-Hours Preview — validate the recipient timezone resolution before you go live.
- Troubleshooting Compliance Error Codes — the regional-gate error surface the ID row lands in.
- Saudi Arabia CST Sender & Marketing Rules — the sibling pre-registration market page; Saudi and Indonesian senders often follow the same KYC-backed pattern.