> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Indonesia KOMDIGI Sender & Marketing Rules

> Indonesia sender and marketing rules on Orbit — the KOMDIGI (formerly Kominfo) regime that pre-registers alphanumeric sender IDs, the opt-in consent posture under PDP Law No. 27/2022, Bahasa Indonesia STOP keyword handling, KYC documents, the UTC+7 marketing window, and the send-time gates each obligation feeds.

# Indonesia KOMDIGI Sender & Marketing Rules

Indonesia regulates commercial electronic messaging through the
**Ministry of Communication and Digital Affairs (KOMDIGI)** — formerly the
Ministry of Communication and Informatics (Kominfo) — and the operators it
supervises. KOMDIGI runs a sender-registration regime for A2P SMS:
an **alphanumeric sender ID reaches a `+62` handset only once that sender
name is registered**, and unregistered sender traffic is blocked at the
carrier edge, not queued for review. Indonesia also operates under
**Personal Data Protection Law No. 27 of 2022 (PDP Law)** — the country's
first comprehensive data-protection statute, which requires a lawful basis
for personal-data processing and elevates consent for marketing use. The
channels the regime touches on Orbit are SMS (pre-registration of the
sender name), voice (no sender ID, but consent and content rules apply),
and email only through the consent and content layer.

Everything below is a **tenant-owned control**. Orbit ships the surfaces —
the consent ledger, suppression and the Bahasa Indonesia opt-out keyword
aliases, tenant-configurable quiet hours, sender-registration tracking,
the send-gate — defaults-open; your organization configures them for
Indonesia. Compliance with KOMDIGI's requirements and the carriers'
vetting remains yours, and the regulator and the operators enforce it
regardless of what any toggle says. This page is documentation, not legal
advice.

<Note>
  This page is documentation, not legal advice — an engineering map of the
  Orbit surfaces, not a legal opinion. Enforcement exposure is real:
  KOMDIGI can direct operators to block unregistered sender traffic at the
  carrier edge without notice, and PDP Law No. 27/2022 carries administrative
  sanctions including fines of up to 2% of annual revenue. Have counsel
  review your sender-name choice, your consent text and proof capture, and
  your marketing-window posture before you send to Indonesian recipients.
</Note>

***

## 1. The ID route: sender-name pre-registration

Read the live ID row of `GET /compliance/country-rules?channel=sms` on
[Country Compliance Requirements](/compliance/country-requirements) before
you provision. The Indonesian SMS edge accepts alphanumeric sender IDs
only once registered — an unregistered sender is filtered at the carrier
edge rather than delivered, and the send-gate holds traffic until an
`approved` entry exists for ID.

```bash theme={null}
curl "https://api.orbit.devotel.io/api/v1/compliance/country-rules?channel=sms&country=ID" \
  -H "Authorization: Bearer $ORBIT_API_KEY"
```

Indonesia is a pre-registration market — budget several weeks of lead time,
the same planning window the UAE and Saudi pages document on
[Sender-ID Registration](/compliance/sender-id-registration).

Three naming rules catch ID submissions early:

* **Sender ID must match the brand.** KOMDIGI rejects generic names — a
  `INFO`, `SMS`, or `ALERT` class sender ID that does not tie back to your
  registered brand identity. Pick a registrable brand name that the KYC
  documents you upload can support.
* **A KYC-backed brand identity, not just a string.** The carriers expect
  the sender name attached to a KYC-verified entity; thin submissions
  bounce. Emphasize the legal `company_name`, the `company_website`, and a
  complete `use_case` on
  [Organization KYC Onboarding](/guides/organization-kyc-onboarding).
* **Register before traffic.** Unlike a post-paid registration market,
  Indonesia rejects the traffic itself when the name is unregistered —
  the send-gate returns the ID sender-not-registered error on any A2P
  attempt until the entry is `approved`, per
  [Troubleshooting Compliance Error Codes](/compliance/troubleshooting-compliance-error-codes).

File the registration through
[Sender-ID Registration](/compliance/sender-id-registration) with KYC
document refs the carriers accept:

* a `business_doc` — a business registration document (SIUP, NIB, or
  equivalent) issued to the entity, and
* an `authorization` — an authorization letter appointing the sender.

For an individual registrant, attach an `id_proof` — an Indonesian KTP
(national identity card) — in place of the business registration; the role
on the [KYC identity model](/compliance/kyc-identity-model) is the same
`id_proof` slot the documents page uploads to. Upload each document once
on [KYC Documents](/compliance/documents-kyc) and reuse the returned
`doc_…` ID across registrations. Until the ID entry reports `approved`,
keep marketing traffic in rehearsal — the send-gate holds ID and returns a
sender-not-registered error (422) on any A2P attempt.

Voice origination carries no sender-ID registration, but KOMDIGI-level
carrier obligations apply at the operator level; confirm your carrier's
posture for voice separately.

***

## 2. Bahasa Indonesia opt-out vocabulary

The seeded Bahasa Indonesia keyword aliases on the
[Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table)
target ID:

| Direction | Seeded aliases |
| - | - |
| Opt-out | `BERHENTI`, `STOP`, `UNSUBSCRIBE` |
| Opt-in | `MULAI`, `YA`, `START` |

The matcher is locale-insensitive case-folding with Unicode normalisation,
so a reply `BERHENTI`, a reply `berhenti`, and a reply `STOP` all write
the suppression entry. The matching rule runs against the exact keyword
(or the keyword plus trailing punctuation) — publish the opt-out keyword
you reference in your consent text and footer.

Your auto-reply should acknowledge the opt-out in **both Bahasa Indonesia
and English** (`Anda telah berhenti berlangganan. You are now
unsubscribed.` is the shape), covering the bilingual audience the
Indonesian market expects. Set the two-language auto-reply text on the
alias table's editor.

Apply the same two scope rules every seed bundle carries:

1. **Channel scope.** The seeded aliases apply to SMS. Extend the list
   yourself for WhatsApp or RCS scope when you run ID traffic on those
   channels.
2. **Suppression scope.** Route an ID revocation at scope `all`: a contact
   that replies `BERHENTI` to your SMS should not then be voice-dialed or
   emailed by the same program. See
   [Opt-Out & Suppression Lists](/compliance/opt-out-suppression).

Every inbound Bahasa Indonesia opt-out lands as a timestamped suppression
row. The row — not the message — is what an audit asks for.

***

## 3. Consent posture under PDP Law No. 27/2022

PDP Law No. 27 of 2022 makes **consent** one of the lawful bases for
personal-data processing, and marketing use without a lawful basis is
exposed. Treat promotional SMS and voice as **opt-in-strict** — the same
posture every jurisdiction with a consent-based data-protection statute
converges on. The consent record rides on the
[consent ledger](/compliance/consent-management) with
`lawful_basis: "consent"` and a consent-text version pinned at capture:

```bash theme={null}
curl -X POST https://api.orbit.devotel.io/api/v1/compliance/consent \
  -H "Authorization: Bearer $ORBIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "identifier": "+6281234567890",
    "channels": ["sms"],
    "opt_in": true,
    "lawful_basis": "consent",
    "purpose": "ID marketing — promotional SMS per PDP Law consent",
    "consent_text_version": "id-pdp-marketing-v1",
    "consent_proof_url": "https://signup.example.com/consent/evt_id_4d"
  }'
```

For recipients with no recorded consent, the tenant-owned
[unknown-marketing policy](/compliance/consent-default-policy) decides
what happens — it defaults to `refuse` for marketing sends, which is the
correct default for ID-bound promotional traffic under a consent-based
statute. See [Consent Management](/compliance/consent-management) for the
record contract, and verify before the first send with
`GET /compliance/consent/lookup`.

Data-subject rights under PDP Law — access, rectification, erasure, and
data portability — are exercised through the
[DSAR portal](/compliance/dsar). Configure your tenant DSAR workflow
before you collect Indonesian recipient data at scale.

***

## 4. Marketing quiet-hours posture

The Indonesian convention for marketing SMS follows a conservative
recipient-local window: avoid the overnight hours (**21:00–07:00 WIB** is
the starting convention carriers honor on marketing traffic). Indonesia
runs three time zones — WIB (UTC+7), WITA (UTC+8), and WIT (UTC+9) — with
**no daylight saving** on any of them. Most `+62` mobile numbers resolve
to WIB (UTC+7), the country's dominant time zone; Orbit's
recipient-timezone resolution handles the three-zone fan-out per-number so
your window applies correctly across the archipelago.

This is *not* Orbit's tenant quiet-hours: the send-gate does not flip it
on for you; you set your tenant quiet hours to cover it deliberately.
Configure the window on
[Quiet-Hours Configuration](/guides/quiet-hours-configuration) — the
recipient-resolution path handles `+62` numbers across all three zones —
and validate the recipient timezone resolution with
[Quiet-Hours Preview](/compliance/quiet-hours-preview) before you flip ID
live.

**Ramadan and Idul Fitri seasonal sending.** Indonesian marketing traffic
reads season: Ramadan and Idul Fitri shift the hours recipients find
acceptable, and the convention tightens the acceptable window toward the
evenings during fasting hours. Orbit makes no platform-level seasonal
change (the quiet-hours window is tenant-configured); tighten the window
yourself during Ramadan and revert after Idul Fitri.

***

## 5. Obligations → Orbit surface table

| KOMDIGI / PDP Law obligation | Orbit surface that carries it |
| - | - |
| Alphanumeric sender-ID pre-registration | [Sender-ID Registration](/compliance/sender-id-registration) submit-and-track flow; the [send-time gate](/compliance/send-gates) returns a sender-not-registered error until the ID entry is `approved` |
| Sender name matches the brand (no generic names) | [Organization KYC Onboarding](/guides/organization-kyc-onboarding) — the sender name ties to the KYC-verified entity; generic-class names (`INFO`, `SMS`) are rejected in the KOMDIGI review |
| KYC documents the carriers accept | [KYC Documents](/compliance/documents-kyc) — `business_doc` (SIUP / NIB / business registration) + `authorization` (authorization letter); `id_proof` (KTP) for an individual |
| Lawful basis (consent) for marketing data processing under PDP Law | [Consent Management](/compliance/consent-management) — a consent record with `sms` scope and `lawful_basis: "consent"` before dispatch |
| Data-subject rights (access, rectification, erasure, portability) | [DSAR Portal](/compliance/dsar) — tenant-owned DSAR workflow for Indonesian recipients |
| No-overnight marketing window | [Quiet-Hours Configuration](/guides/quiet-hours-configuration) opt-in tenant control (deliberate, not default), validated with [Quiet-Hours Preview](/compliance/quiet-hours-preview) |
| Bahasa Indonesia + English STOP handling | [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table) — Bahasa Indonesia rows target ID; two-language auto-reply set on the editor; suppression at scope `all` via [Opt-Out & Suppression Lists](/compliance/opt-out-suppression) |
| Ramadan / Idul Fitri seasonal posture | Tenant quiet-hours window you tighten seasonally — no platform override; campaign-level decision |
| Restricted industries | [Restricted & Prohibited Industries](/compliance/restricted-industries) — content restrictions layer on top of every ID posture |

***

## 6. Send-time posture — org-level knobs

Two tenant-owned policies decide what happens for a contact with no
recorded consent on a marketing send, both deliberate knobs on
[Consent Posture: The Unknown-Consent Policies](/compliance/consent-default-policy):

```bash theme={null}
curl -X PATCH https://api.orbit.devotel.io/api/v1/settings/compliance/unknown-marketing-policy \
  -H "Authorization: Bearer $ORBIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "unknown_marketing_policy": "refuse"
  }'
```

* `refuse` (the default) is the fail-closed posture a PDP Law opt-in
  regime argues for — an unknown-consent marketing send is refused.
* Loosening to `allow_with_logging` is a deliberate, documented call with
  a required written justification; it is not the ID posture.

The sibling consent-default policy (`permit_on_missing` /
`deny_on_missing`) governs the CDP side, not the marketing-send gate;
leave it at the default unless your CDP posture calls for the stricter
variant.

***

## 7. Worked configuration before first ID send

<Steps>
  <Step title="Read the ID country-rules row">
    `GET /compliance/country-rules?channel=sms&country=ID` and read
    `sender_types`, `registration`, `content_restrictions`, and
    `stop_requirement`. If `registration` is `required`, the send-gate
    holds ID traffic until an `approved` sender is attached — this is the
    intended behavior, not a fault.
  </Step>

  <Step title="Pick the sender name">
    Alphanumeric, matching the brand identity your KYC documents support —
    no generic class names. Pre-flight it with `GET /compliance/check`
    before you file.
  </Step>

  <Step title="Upload KYC documents">
    Upload your Indonesian business registration (SIUP / NIB) as
    `business_doc` and an authorization letter as `authorization`; for an
    individual, an Indonesian KTP as `id_proof`. Note the returned
    `doc_…` IDs.
  </Step>

  <Step title="File the ID sender-name registration">
    `POST /compliance/sender-id-registrations` with the ID entry
    referencing your `doc_…` IDs. Wait for the ID country entry to reach
    `approved`; budget the pre-registration lead time the UAE page
    documents.
  </Step>

  <Step title="Capture marketing opt-in first">
    Record a consent entry with `sms` scope and
    `lawful_basis: "consent"` before any ID marketing send; the
    unknown-marketing policy defaults to `refuse`, which is the right call
    for the PDP Law regime.
  </Step>

  <Step title="Set the marketing no-overnight window">
    Turn on tenant quiet hours covering the overnight hours recipient
    time; validate with
    [Quiet-Hours Preview](/compliance/quiet-hours-preview). Plan Ramadan
    and Idul Fitri campaigns against a tightened window.
  </Step>

  <Step title="Publish the Bahasa Indonesia opt-out">
    Confirm the seeded Bahasa Indonesia aliases (`BERHENTI`, `STOP`,
    `UNSUBSCRIBE`) cover the keyword your consent text and footer
    reference, and set the auto-reply to acknowledge in both languages.
  </Step>

  <Step title="Verify before first send">
    `GET /compliance/sender-id-registrations` shows ID `approved`;
    `GET /compliance/consent/lookup` returns the recipient's consent
    row; the quiet-hours preview resolves the recipient timezone
    correctly. Then send.
  </Step>
</Steps>

***

## Frequently asked questions

**Does Orbit register my Indonesian sender name with KOMDIGI?**
No — carrier-facing registration is yours to file (or to file through your
aggregator), the same as every market. Orbit exposes the ID country-rules
row and the registration-status tracking so you can confirm the sender is
attached, and it delivers your traffic once the entry is `approved`.

**Is the overnight window a platform gate?**
No — the overnight no-send window is the market convention, not a gate
Orbit flips on. Setting tenant quiet hours to cover it is a deliberate,
tenant-owned opt-in — the same pattern the Saudi Arabia and UAE pages
document for GCC markets.

**Why does the Indonesian page ask for Bahasa Indonesia opt-out handling?**
Because Indonesian recipients can reply in Bahasa Indonesia, KOMDIGI's
regime expects opt-out handling to work in the local language, and your
auto-reply should acknowledge in both languages. The Bahasa Indonesia
aliases (`BERHENTI`, `MULAI`, `YA`) ship seeded targeting ID — see
[Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table).

**Which KYC documents does an Indonesian registration accept?**
An Indonesian business registration (SIUP, NIB, or equivalent) as
`business_doc` plus an authorization letter as `authorization`; for an
individual, an Indonesian KTP as `id_proof`. Upload each on
[KYC Documents](/compliance/documents-kyc) and reuse the `doc_…` IDs
across registrations.

***

<Warning>
  This page is documentation, not legal advice — an engineering map of the
  Orbit surfaces, not a legal opinion. KOMDIGI's sender-registration regime
  and the carriers' vetting carry real enforcement (carrier-edge filtering
  of unregistered traffic, name rejection), and PDP Law No. 27/2022 carries
  administrative sanctions. Have counsel review your sender-name choice,
  your consent text and proof capture, and your Ramadan/Idul Fitri
  marketing-window posture before you send to Indonesian recipients.
</Warning>

***

## Related references

* [Country Compliance Requirements](/compliance/country-requirements) —
  the per-country matrix this page expands the ID row of.
* [Regional Posture Hub](/compliance/country-rules-directory) — the matrix
  of country pages and the check-the-row-first workflow.
* [Sender-ID Registration](/compliance/sender-id-registration) — the
  submit-and-track flow for the ID registration; lead-time table.
* [KYC Identity Model](/compliance/kyc-identity-model) — the
  `business_doc`, `id_proof`, and `authorization` roles the carriers ask
  for.
* [Organization KYC Onboarding](/guides/organization-kyc-onboarding) —
  the KYC-backed brand identity the ID sender name attaches to.
* [Opt-Out Keyword Alias Table](/compliance/opt-out-keyword-alias-table) —
  the seeded Bahasa Indonesia aliases and the custom-rule extension path.
* [Consent Management](/compliance/consent-management) — the consent
  record contract (`lawful_basis`, proof URL, text version).
* [Consent Posture: The Unknown-Consent Policies](/compliance/consent-default-policy) —
  the `refuse` / `allow_with_logging` decision point.
* [DSAR Portal](/compliance/dsar) — data-subject rights workflow under
  PDP Law.
* [Quiet-Hours Configuration](/guides/quiet-hours-configuration) — set
  the recipient-timezone-resolved window.
* [Quiet-Hours Preview](/compliance/quiet-hours-preview) — validate the
  recipient timezone resolution before you go live.
* [Troubleshooting Compliance Error Codes](/compliance/troubleshooting-compliance-error-codes) —
  the regional-gate error surface the ID row lands in.
* [Saudi Arabia CST Sender & Marketing Rules](/compliance/saudi-arabia-cst-sender-rules) —
  the sibling pre-registration market page; Saudi and Indonesian senders
  often follow the same KYC-backed pattern.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.