Types of PSE
Penyelenggara Sistem Elektronik or Organization of Electronic Systems and Transactions “PSE” as written in Government Regulation No. 71 year 2019 are every person, state, company which provide, organizing and/or operating electronic system either individually or collectively to Electronic System User for their own benefit or others. Electronic System Organizers has been classified into two categories:
- Private Domain; and
- Public Domain.
Electronic System Organizers in the public sector include legislative, executive, and judicative institutions along with other agencies formed under the laws and regulations. While electronic system organizers in the private sector are Indonesia or foreign individuals, business entities and the community that manage and organize electronic systems.
The Minister of Communication and Informatics has issued the Minister of Communication and Informatics Regulation No. 5 year 2020 on Electronic System Organizers in the Private Sector. Under this regulation, all PSE operating within the private are required to register with the Ministry of Communication and Information Technology after obtaining a Business License (Nomor Induk Berusaha/NIB) from OSS.
Private PSE: Requirement and Procedure
Business actors which required to conduct a PSE license in Indonesia as regulated by Regulation No. 5 year 2020 and also as explained in Government Regulation No. 71 year 2019, those private sectors in the form of individuals, legal entities who have internet portals, sites or applications and are engaged in this scope of business;
- Management or operation of financial transaction services;
- The delivery of materials or paid digital content through data networks by downloading them portals or sites, through e-mails or through other applications to user’s devices;
- Search engines, electronic information in text, audiovisual, animation, music, video, film and game or any combination of them;
- Processing of personal data for the operation of public services related to electronic transaction activities; and
- Management and/or operation of goods and/or services and/or trading.
In addition to above, for private PSE operators that are established under the laws of another country or permanently domiciled in another country also required to obtain a PSE License, this for PSE operators who meet the following categories;
- Provide services within the territory of Indonesia;
- Do their business in Indonesia; and/or
- Their electronic systems are used or offered in Indonesian territory.
In order to obtain PSE License, the PSE operators should complete the registration forms which contains the following information;
- Procedure on how to operating the electronic system;
- The name of the electronic system;
- The sector of the electronic system;
- The URL Website;
- The domain name system and/or IP server address;
- Description of the business model;
- Brief description of the electronic system’s function and business process;
- Information about the personal data processed;
- Information about the location of the management, processing and storage of the electronic system and electronic data; and
- Statement that the PSE guarantees and will comply with the obligation to provide access to the electronic system and electronic data to ensure the effectiveness of supervision and law enforcement in accordance with the prevailing laws and regulations.
- Obligation to protect personal data in accordance with the prevailing laws and regulations; and
- Obligation to conduct an electronic system feasibility test in accordance with the prevailing laws and regulations.
For a foreign private PSE operators there’s and additional information to fill out with following information;
- Identity of the foreign private PSE;
- Identity of the company’s management or person in charge;
- Certificate of domicile or certificate of incorporation;
- The number of users in Indonesia; and
- The value of transactions from Indonesia.
Once a private PSE has successfully registered, the Minister of Communication and Informatics will issue proof of registration, and the private ESO will be placed on the list of private ESOs on the Minister of Communication and Informatics website.
The proof of registration will be valid automatically, furthermore, if there’s any change to the information provided during registration must also be reported to the Minister of Communication and Informatics.
ISO 27001

The National Cyber and Crypto Agency (Badan Siber dan Sandi Negara/BSSN) developing tools for evaluating the security of information for PSE operators.
In order to implement the provisions of Article 24 (4) of the Regulation No. 71 year 2019 which obligates PSE to have and run a procedure to secure the electronic system and avoid any distraction, failure and loss, BSSN issued a regulation No. 8 year 2020 regarding Security System in Operation of Electronic System. Article 9 (1) mentions that every PSE operator implementing a strategic electronic system is obligated to apply SNI ISO/IEC 27001. ISO 27001 is an international standard in information security management system (ISMS). Implementing ISO 27001 will help the operators to build and maintain ISMS. Implementation of ISMS consists of;
- ISMS standards according to the category of Electronic Systems;
- Preparation for implementing ISMS;
- Implementation of ISMS by electronic system operator; and
- Issuance of certificates, certification reporting, and revocation of certificates.
The electronic system category based on the principle of risk consists of three types of risk;
- Strategic electronic systems that has a serious impact on public interests, public services or state defense and security, this electronic system obligated to apply for SNI ISO/IEC 27001, other security standards related to cybersecurity issued by BSSN and by the ministries or agencies;
- High-risk electronic system is an electronic system with limited impact on the interest of certain sectors and/or regions, for high risk electronic system obligated to apply SNI ISO/IEC 27001 and/or other security standards related to cybersecurity issued by BSSN and ministries or agencies; and
- Low-risk electronic system is an electronic system that is not included in a strategic nor high-risk electronic system, obligated to apply SNI ISO/IEC 27001 or other security standards related to cybersecurity issued by the BSSN in accordance with the provisions of legislation.
In order to prepare the implementation of SNI ISO/IEC 27001 as referred to in Article 9 BSSN Regulation No. 8 year 2020, PSE Operators may conduct an assessment based on Index KAMI in accordance with the provisions of legislation.
Author: Sutria Puti Dwirahayu
Have a question? Let’s contact us on the following alternatives:
Hotline: (+62) 812 1111 8608 / (+62) 21 – 2271 8638
Email: info@ylpconsulting.com
Website: ylpconsulting.com
Read More: Sni License in Indonesia