News & Insights

Responsibilities of Digital Platforms Regarding Child Protection in the Indonesian Legal Framework

News & Insights

The development of digital technology and the increasing use of the internet have transformed patterns of social interaction in society, including among children. Social media and various digital platforms are no longer merely means of communication; rather, they have become part of children’s daily activities in accessing information, entertainment, education, and building social relationships. The ease of access to various digital services indicates that children today are growing up in an environment vastly different from that of previous generations. On the one hand, these developments offer numerous benefits, such as easy access to information, learning resources, and opportunities to develop creativity. On the other hand, however, the digital space also presents various risks for children, ranging from exposure to age-inappropriate content, cyberbullying, online sexual exploitation, and misuse of personal data, to various interactions that could potentially endanger children’s safety. Furthermore, the use of algorithms and content recommendation systems by digital platforms poses new challenges, as they can influence children’s behavior and patterns of digital service usage.

 

From a legal perspective, this situation raises questions about the extent to which the protection of children in the digital space falls under the responsibility of digital platform operators. This question is particularly relevant given that digital platforms today no longer function merely as passive communication tools but also play an active role in creating user experiences through algorithms, content moderation, personal data management, and various other features. Consequently, the risks faced by children do not always stem from other users but may also be related to the design and governance of the digital services themselves. Under the Indonesian legal framework, child protection is a constitutional right guaranteed by Article 28B(2) of the 1945 Constitution and further regulated by Law No. 23 of 2002 regarding Child Protection and its amendments (“Child Protection Law”). In line with the development of information technology, the approach to child protection has also evolved through the provisions of Article 16A of Law No. 11 of 2008 regarding Electronic Information and Transactions, as amended (“the ITE Law”); which requires electronic system operators to provide protection to children in their use of the digital products, services, and features they provide. These provisions subsequently formed the basis for the issuance of Government Regulation No. 17 of 2025 regarding the Governance of Electronic System Operations in Child Protection (“GR 17/2025”) and Minister of Communication and Digital Affairs Regulation No. 9 of 2026 regarding the Implementing Regulations for Government Regulation No. 17 of 2025 on the Governance of Electronic System Operations in Child Protection (“MOC 9/2026”). The existence of these regulations demonstrates that child protection in the digital space is no longer viewed solely as the responsibility of the state and the family, but also as part of the legal obligations of digital platform operators.

 

Based on this background, this article will discuss the status of children as subjects who must be protected under the Indonesian legal framework, the evolution of regulations governing digital platforms, the concept of digital platform liability in child protection, the challenges of implementation, and the development of similar regulations in several other countries for comparative analysis.

 

Children as Subjects that Must Be Protected Under Indonesian Law

Under the Indonesian legal framework, children are legal subjects who are specifically granted protection by the state, society, and their families. This protection is based on the fact that children are still in the process of growth and development and therefore require greater protection than adults against various threats that could affect their physical, mental, social, and emotional development. The constitutional basis for child protection is found in Article 28B, paragraph (2) of the 1945 Constitution, which affirms that every child has the right to survival, growth, and development, as well as the right to protection from violence and discrimination. These guarantees are further regulated in the Child Protection Law. Article 1, point 1, of the Child Protection Law defines “Child” as a person under the age of 18, including a child who has not yet been born, while Article 1, point 2, defines “Child Protection” as all activities aimed at ensuring and protecting children and their rights so that they may live, grow, develop, and participate to the fullest extent possible, while being protected from violence and discrimination.

 

In addition to being sourced from domestic law, child protection in Indonesia is also influenced by developments in international law through the ratification of the Convention on the Rights of the Child (CRC) pursuant to Presidential Decree No. 36 of 1990. One of the fundamental principles of the CRC is the principle of the best interests of the child. Article 3(1) of the CRC stipulates that in all actions concerning children, the best interests of the child must be a priority concern. This principle has since become a fundamental basis for the formulation of various policies and laws related to child protection in Indonesia. Advances in information technology have expanded the scope of application of this child protection principle. Children’s activities are no longer limited to the physical environment but also include various activities in the digital space through social media, online games, communication apps, and various other electronic services. Therefore, the digital space must be viewed as part of the environment in which children grow and develop an environment that also requires sufficient legal protection.

 

In this context, child protection is no longer limited to threats that arise in the physical world but also includes various risks arising from the use of digital technology and electronic systems. This approach is reflected in regulatory developments in Indonesia, which have begun to address child protection in the digital space, including through regulations regarding the responsibilities of electronic system operators toward child users. Therefore, child protection under Indonesian law is based on principles that have long been recognized in both national and international law, yet its application continues to evolve in response to technological changes and shifts in societal interaction patterns. Such protection is now directed not only toward children’s activities in the physical world but also toward their experiences and interactions in the digital space, which is increasingly becoming an integral part of daily life.

 

Internet and Digital Platform Regulations in Indonesia

The development of information technology has led to the enactment of various regulations governing public activities in the digital space. In this context, digital platforms are essentially part of electronic system operators that are subject to various legal obligations in the provision of internet-based services. The primary basis for these regulations is found in the ITE Law. The ITE Law serves as the fundamental legal framework governing electronic information, electronic transactions, and the operation of electronic systems in Indonesia. One of the key principles set forth in Article 15(1) of the ITE Law is the obligation of electronic system operators to operate electronic systems in a reliable, secure, and responsible manner. These regulations are further detailed in Government Regulation No. 71 of 2019 on the Operation of Electronic Systems and Transactions (“GR 71/2019”), which requires electronic system operators to maintain the security and reliability of their systems, including in the areas of data protection and digital service governance. Various digital platforms used by the public, such as social media, communication apps, video-sharing services, online games, and e-commerce platforms, are in principle, classified as electronic system operators and are therefore required to comply with these provisions.

 

Along with the increasing use of digital services by children, there is a need to establish regulations that specifically address child protection in the digital space. A significant development then occurred through the provisions of Article 16A of the ITE Law, which requires electronic system operators to provide protection to children when using the digital products, services, and features they provide. This provision also mandates the government to further regulate the governance of child protection in the operation of electronic systems. To implement these provisions, the government issued GR 17/2025. This regulation was an important step forward because, for the first time, it specifically regulated the obligations of electronic system operators to protect children as users of digital services. GR 17/2025 introduced various obligations, including assessing the risk level of services, verifying user age, controlling access to certain services, and applying the principle of “child protection by design” in the design and development of electronic systems.

 

The technical implementation provisions were subsequently further regulated through MOC 9/2026. This regulation stipulated the risk classification of electronic system operators, age verification procedures, risk mitigation mechanisms for children, and various administrative obligations that electronic system operators must fulfill. These developments indicate that digital regulation in Indonesia has undergone a significant shift. Whereas previous regulations focused more on the validity of electronic transactions and system security, current regulations also prioritize child protection as a crucial aspect of digital platform governance. Consequently, electronic system operators are no longer solely responsible for the technical aspects of service delivery but are also accountable for protecting users, particularly children, from various risks arising in the digital space. This development subsequently became the foundation for the establishment of the concept of digital platform responsibility in child protection, which will be discussed in the following section.

 

The Concept of Digital Platform Liability

The development of digital technology has changed the role of digital platforms in modern society. While in the early development of the internet, digital platforms were viewed as intermediaries that merely provided a means of communication and information exchange among users, today digital platforms play a far more active role in forming user experiences. Through algorithms, content moderation, personal data management, and various features that influence user interactions, digital platforms no longer merely provide technological infrastructure; they also help determine how information is distributed and consumed by users. This shift in role has fostered the view that digital platforms can no longer be regarded as entirely neutral parties. In many situations, platforms have greater capacity than users to identify, control, and mitigate various risks arising from the use of digital services. Consequently, various legal systems are beginning to hold digital platforms accountable for certain responsibilities regarding user security and safety. In the digital law literature, this approach is often associated with the concept of “duty of care” the obligation to take reasonable steps to prevent or minimize risks that can reasonably be foreseen as arising from a particular activity or service. In the context of digital platforms, this concept requires platform operators to identify, prevent, and mitigate risks that may arise from the design, features, or governance of the services they provide.

 

The application of this concept becomes even more important when it comes to child users. Unlike adults, children generally do not yet have the fully developed ability to understand digital risks, manage their personal data, or assess the long-term impact of their activities in the digital space. As a result, children are more vulnerable to various risks arising from the use of social media and other digital services. These risks do not always stem from the actions of third parties. In some cases, risks can also arise from the characteristics of the services designed by the digital platforms themselves, such as content recommendation systems, unlimited interaction features, notification mechanisms that encourage continuous user engagement, and the practice of mass collection of user data. Therefore, protecting children in the digital space requires more than just focusing on user behavior; it must also consider how digital services are designed and operated.

 

Regulatory developments in various countries indicate a paradigm shift in the regulation of digital platforms. Previously, responsibility was largely placed on users; however, the emerging approach now begins to hold platform operators jointly responsible for managing and mitigating risks arising from the digital services they provide. Nevertheless, this responsibility is not absolute. Platforms are not required to eliminate all possible risks, but are obligated to take reasonable, appropriate, and proportionate measures to prevent or reduce foreseeable risks. A similar approach is beginning to emerge in Indonesia’s legal framework through Article 16A of the ITE Law, GR 17/2025, and MOC 9/2026. Through these regulations, the protection of children in the digital space is no longer positioned solely as the responsibility of the state and the family, but also becomes part of the obligations of electronic system operators. Thus, digital platforms are required to take an active role in creating a safe digital environment that aligns with the best interests of children. Based on these developments, the concept of digital platform liability is essentially a form of legal adaptation to changes in the characteristics of information technology. The greater a platform’s ability to influence user behavior and control the digital environment it creates, the greater the demand for the platform to share responsibility for protecting users—particularly children, as the most vulnerable group in the digital ecosystem.

 

Challenges in Implementing Child Protection Regulations in the Digital Space

Although Indonesia already has a legal framework that specifically regulates the protection of children in the digital space through Article 16A of the ITE Law, GR 17 /2025, and MOC 9/2026, the effectiveness of these regulations still has various challenges. The cross-border nature of the digital space, rapid technological advancements, and the complexity of the relationship between digital platforms and users mean that the success of child protection depends not only on the existence of regulations but also on the effectiveness of their implementation. One of the main challenges relates to user age verification mechanisms. GR 17/2025 and MOC 9/2026 require electronic system operators to implement age-based categorization and mechanisms that ensure service access aligns with users’ age categories. However, in practice, children can still access digital services by using inappropriate identities or accounts belonging to others. On the other hand, overly strict age verification measures also have the potential to raise personal data protection concerns, as they require the collection of additional identity information. This situation shows that age verification is not only a legal issue but also a technical issue that must balance child protection and user privacy.

 

The next challenge relates to oversight of the algorithms and content recommendation systems used by digital platforms. In addition to potentially displaying age-inappropriate content, these algorithms can also encourage excessive use of the services by continuously presenting content based on users’ preferences. In the context of children, this can affect behavioral patterns, mental health, and social development. However, monitoring algorithms is not easy because their operations are generally proprietary, dynamic, and highly technical. The cross-border nature of digital platforms also poses unique challenges. Most platforms used by the Indonesian public are global companies headquartered abroad, while user data may be stored across various different jurisdictions. These conditions cause obstacles in oversight and law enforcement, meaning that child protection in the digital space cannot rely solely on national legal approaches but also requires international cooperation and cross-jurisdictional coordination. Furthermore, the effectiveness of child protection in the digital space is also significantly influenced by the public’s level of digital literacy. Regulations essentially only provide a general protective framework, whereas children’s interactions with digital technology take place within family and community environments. Therefore, parental supervision and guidance continue to have an important role in ensuring that children use digital technology safely and responsibly.

 

Another challenge is the government’s capacity for oversight and law enforcement. Although GR 17/2025 has granted the authority to monitor, evaluate, conduct compliance audits, and impose sanctions on electronic system operators, the effectiveness of these authorities depends heavily on institutional readiness, human resources, and the government’s ability to keep pace with rapidly evolving technology. In many cases, technological advancements often outpace regulatory developments and oversight capacity. Thus, while comprehensive regulations are an important step, they are not sufficient on their own to ensure effective child protection in the digital space. The success of implementation ultimately depends on the ability of digital platforms to consistently fulfill their obligations, the effectiveness of government oversight, and the improvement of the public’s digital literacy. Therefore, future regulatory development must be accompanied by strengthened oversight capacity, enhanced international cooperation, and the development of technologies that support child protection objectives within an ever-evolving digital ecosystem.

 

Regulatory Frameworks in Other Countries

Child protection in the digital space has become a global issue that has prompted various countries to establish specific regulations for digital platforms. Although they take different approaches, there is a common trend toward expanding platforms’ responsibilities in identifying, preventing, and mitigating risks faced by child users. In the United Kingdom, child protection in the digital space is strengthened through the Online Safety Act 2023, which requires digital service providers to conduct risk assessments and take proportionate measures to protect users, particularly children from various forms of harmful content and activities. This approach emphasizes preventive risk management before violations occur.

 

Meanwhile, the European Union, through the Digital Services Act (DSA), is strengthening the responsibilities of digital platforms, especially those with a very large user base to identify and mitigate systemic risks arising from digital services. The DSA also promotes more transparency regarding the content recommendation systems and moderation practices used by platforms.

 

In the United States, child protection has evolved through an approach focused on privacy and personal data protection. The Children’s Online Privacy Protection Act (COPPA) restricts the collection, use, and disclosure of personal data from children under the age of 13 without parental consent. This approach shows that child protection in the digital space is not only about content safety but also about the protection of personal data.

 

Australia has also developed various child protection policies by strengthening the role of the eSafety Commissioner and implementing various online safety policies. In recent years, Australia has actively promoted the implementation of age verification and restrictions on children’s access to certain digital services as part of efforts to enhance child safety in the digital space.

 

Compared to these developments, Indonesia’s approach as outlined in Article 16A of the ITE Law, GR 17/2025, and MOC 9/2026 is aligns with global trends. Indonesia has begun adopting a risk-based approach, mandating user age verification, and introducing the principle of “child protection by design” in the operation of electronic systems. This indicates that child protection is no longer viewed solely as the responsibility of individuals or families, but also as part of the governance of digital platforms. Nevertheless, experiences from various countries show that the success of child protection in the digital space does not depend solely on the existence of regulations. Challenges such as the effectiveness of age verification, algorithm transparency, personal data protection, and law enforcement against global platforms remain issues faced by many countries. Therefore, child protection in the digital space requires a balance between technological innovation, the protection of user rights, and the responsibility of digital platforms.

 

For Indonesia, the regulatory developments that have taken place represent an important step in building a child protection system in the digital space. However, its effectiveness will depend heavily on the ability of the government, the public, and electronic system operators to consistently apply these principles in the day-to-day operation of digital services.

 

The Role of the Government, Parents, and Digital Platforms

Child protection in the digital space cannot, in essence, be the responsibility of any single party alone. The complexity of digital technology, the continuously evolving nature of platforms, and the diverse risks faced by children demonstrate that child protection requires the participation of the state, families, and digital platforms collectively. These three parties play complementary roles in creating a safe digital environment that supports children’s growth and development. The state plays a primary role in establishing a legal and policy framework that provides protection for children as users of digital services. The existence of Article 16A of the ITE Law, GR 17/2025, and MOC 9/2026 demonstrates the government’s efforts to align the national legal system with advancements in digital technology. However, the state’s role does not end with the formulation of regulations; it also includes oversight of compliance by electronic system operators, law enforcement, and the promotion of digital literacy among the public so they can understand the risks and security considerations associated with the use of digital technology.

 

On the other hand, parents remain an important role as the people closest to their children in daily life. Control and guidance regarding the use of social media, online games, and various other digital services cannot be entirely delegated to the state or digital platforms. In addition to providing control, parents also have a role in educating their children about the safe, responsible, and age-appropriate use of technology. An approach that emphasizes communication and guidance is generally more effective than purely repressive restrictions. Meanwhile, digital platforms, as operators of electronic systems, have the ability to control the design, features, and governance of services used by millions of users, including children. Therefore, platforms have a responsibility to identify and mitigate various risks that may arise from the services they provide. This responsibility can be fulfilled through the implementation of age verification, access controls for certain content, the development of recommendation systems that prioritize the best interests of children, and the application of the “child protection by design” principle in the development of digital services.

 

Ultimately, child protection in the digital space is a shared responsibility that requires synergy among the government, parents, and digital platforms. The government plays a role in formulating and enforcing regulations; parents provide supervision and education; while digital platforms are obligated to create services that are safe for children as users. The effectiveness of child protection will depend heavily on the ability of these three parties to consistently fulfill their roles and support each other. As the role of digital technology in daily life continues to grow, collaboration between the government, families, and digital platforms will be an important factor in ensuring that the digital space can be developed as a safe, healthy, and supportive environment that optimally supports children’s growth and development.

 

Conclusion

The development of digital technology has made the digital space an integral part of child development and daily life. While providing various benefits in the form of access to information, education, and social interaction, the digital space also presents various risks that require adequate legal protection. Therefore, child protection can no longer be limited to the physical environment but must encompass children’s various activities and interactions within the digital ecosystem. Regulatory developments in Indonesia through Article 16A of the ITE Law, GR 17/2025, and MOC 9/2026 indicate a shifting approach to child protection in the digital space. Child protection is no longer viewed solely as the responsibility of the state and the family, but has also become part of the obligations of electronic system operators. This approach aligns with global trends that increasingly hold digital platforms accountable for identifying, preventing, and mitigating risks faced by child users.

 

Nevertheless, the effectiveness of child protection in the digital space still faces various challenges, ranging from user age verification, algorithm transparency, and personal data protection to law enforcement against digital platforms operating across national borders. These conditions indicate that while comprehensive regulations are an important step, they are not sufficient on their own to ensure the effective implementation of child protection. Therefore, child protection in the digital space must be implemented through a collaborative approach involving the government, parents, and digital platforms. The government plays a role in formulating and enforcing regulations; parents provide supervision and education; while digital platforms are obligated to create services that are safe and oriented toward the best interests of children. Synergy among these three parties is a key factor in realizing a digital ecosystem that is safe, healthy, and supports children’s optimal growth and development.

 

Ultimately, technological advancements will continue to present new challenges that require adaptive legal responses. Therefore, strengthening the governance of the digital space must be an ongoing effort, with child protection remaining a high priority, so that technological progress can go hand in hand with the fulfillment and protection of children’s rights in the digital age.

We take processes apart, rethink, rebuild, and deliver them back working smarter than ever before.