Indonesia is the latest government to propose a  legal framework to coerce social media platforms, apps, and other online service providers to accept local jurisdiction over their content and users’ data policies and practices. And in many ways, its proposal is the most invasive of human rights. 

This rush of national regulations started with Germany’s 2017 “NetzDG” law, which compels internet platforms to remove or block content without a court order and imposes draconian fines on companies that don’t proactively submit to the country's own content-removal rules. Since NetzDG entered into force, Venezuela, Australia, Russia, India, Kenya, the Philippines, and Malaysia have followed with their own laws or been discussing laws similar to the German example. 

NetzDG, and several of its copycats, require social media platforms with more than two million users to appoint a local representative to receive content takedown requests from public authorities and government access to data requests. NetzDG also requires platforms to remove or disable content that appears to be “manifestly illegal” within 24 hours of notice that the content exists on their platform. Failure to comply with these demands subjects companies to draconian fines (and even raises the specter of blocking of their services). This creates a chilling effect on free expression: platforms will naturally choose to err on the side of removing gray area content rather than risk the punishment. 

Indonesia’s NetzDG variant—dubbed MR5—is the latest example. It entered into force in November 2020, and, like some others, goes significantly further than its German inspiration. In fact, the Indonesian government is exploring new lows in harsh, intrusive, and non-transparent Internet regulation. The MR5 regulation, issued by the Indonesian Ministry of Communication and Information Technology (Kominfo), seeks to tighten the government’s grip over digital content and users’ data. 

MR5 Comes Amid Difficult Times In Indonesia

The MR5 regulation also comes at a time of increased conflict, violence, and human rights abuses in Indonesia: at the end of 2020, the UN High Commissioner for Human Rights raised concern about the escalating violence in Papua and West Papua and shed light on reports about “intimidation, harassment, surveillance, and criminalization of human rights defenders for the exercise of their fundamental freedoms.” According to APC, the Indonesian government has used hate speech laws, envisioned to protect minority and vulnerable groups, to silence dissent and people critical of the government. 

These provisions are not only a serious threat to Indonesians’ free expression rights, they are also a major compliance challenge for Private ESOs

MR5 further exacerbates the challenging situation of freedom of expression in Indonesia this year and in the future, according to Ika Ningtyas, Head of the Freedom of Expression Division at the Southeast Asia Freedom of Expression Network (SAFEnet). She told EFF: 

The Ministry's authority, in this case, Kominfo, is increasing capacity so it can judge and decide whether the content is appropriate or not. We're very concerned that MR5 will be misused to silence groups criticizing the government. Independent branches of government have been excluded, making it unlikely that this regulation will include transparent and fair mechanisms. MR5 can be followed by other countries, especially in Southeast Asia. Regional and global solidarity is needed to reject it.

Business enterprises have a responsibility to respect human rights law. The UN Special Rapporteur on Free Expression has already reminded States that they “must not require or otherwise pressure the private sector to take steps that unnecessarily or disproportionately interfere with freedom of expression, whether through laws, policies, or extralegal means.” The Special Rapporteur also pointed out that any measures to remove online content must be based on validly enacted law, subject to external and independent oversight, and demonstrate a necessary and proportionate means of achieving one or more aims under Article 19 (3) of the ICCPR.

We join SAFEnet in urging the Indonesian government to bring its legislation into full compliance with international freedom of expression standards. 

Below are some of MR5’s most harmful provisions.

Forced ID Registration To Operate in Indonesia

MR5 obliges every “Private Electronic System Operator” (or “Private ESO”) to register and obtain an ID certificate issued by the Ministry before people in Indonesia start accessing its services or content. A “Private ESO” includes any individual, business entity or the community that operates “electronic systems” for users within Indonesia, even if the operators are incorporated abroad. Private ESOs subject to this obligation are any digital marketplace, financial services, social media and content sharing platforms, cloud service providers, search engines, instant messaging, email, video, animation, music, film and games, or any application which collects, processes, or analyzes users’ data for electronic transactions within Indonesia. 

Registration must take place by mid-May 2021. Under MR5, Kominfo will sanction non-registrants by blocking their services. Those Private ESOs who decide to register must provide information granting access to their “system” and data to ensure the effectiveness in the “monitoring and law enforcement process.” If a registered Private ESO disobeyed the MR5 requirements, for example, by failing to provide the “direct access” to their systems (Article 7 (c)), it can be punished in various ways, ranging from a first warning to temporary blocking to full blocking and a final revocation of its registration. Temporary or full blocking of a site is a general ban of a whole site, an inherently disproportionate measure, and therefore an impermissible limitation under Article 19 (3) of the UN’s International Covenant on Civil and Political Rights (ICCPR). When it comes to general blocking, the Council of Europe has recommended that public authorities should not, through general blocking measures, deny access by the public to information on the Internet, regardless of frontiers. The United Nations and three other special mandates on freedom of expression explain that “[m]andatory blocking of entire websites, IP addresses, ports, network protocols or types of uses (such as social networking) is an extreme measure – analogous to banning a newspaper or broadcaster – which can only be justified in accordance with international standards, for example where necessary to protect children against sexual abuse.” 

A general ban of a Private ESO platform will also not be compatible with Article 15 (3) of the UN’s International Covenant on Economic, Social and Cultural Rights (ICESCR), which states that individuals have a right to “take part in cultural life” and to “enjoy the benefits of scientific progress and its applications.” The UN has identified “interrelated main components of the right to participate or take part in cultural life: (a) participation in, (b) access to, and (c) contribution to cultural life." They explained that access to cultural life also includes a “right to learn about forms of expression and dissemination through any technical medium of information or communication.” 

Moreover, while a State party can impose restrictions on freedom of expression, these may not put in jeopardy the right itself, which a general ban does. The UN Human Rights Committee has said that the “relation between right and restriction and between norm and exception must not be reversed.” And Article 5, paragraph 1 of the ICCPR, states that “nothing in the present Covenant may be interpreted as implying for any State … any right to engage in any activity or perform any act aimed at the destruction of any of the rights and freedoms recognized in the Covenant.”

Forced Appointment of a Local Contact Person

Tech companies have come under increasing criticism for decisions to flout and ignore local laws or treat non-U.S. countries with attitudes that lack understanding of the local context. In that sense, a local point of contact can be a positive step. But forcing the appointment of a local contact is a complex decision that can make companies vulnerable to domestic legal actions, including potential arrest and criminal charges of their local contact as has happened in the past. With a local representative, platforms will also find it much harder to resist arbitrary orders and can be vulnerable to domestic legal action, including potential arrest and criminal charges. MR5 compels everyone whose digital content is used or accessed within Indonesia to appoint a local point of contact based in Indonesia and who would be responsible to respond to content removal or personal data access orders. 

Regulations Requiring Take Down of Content and Documents Deemed “Prohibited by the Government”

Article 13 of the MR5 forces Private ESOs (except cloud providers) to take down prohibited information and/or documents. Article 9(3) defines prohibited information and content as anything that violates any provision of Indonesia’s laws and regulations, or creates “community anxiety” or “disturbance in public order.” Article 9 (4) grants the Ministry, a non-independent authority, unfettered discretion to define this vague notion of “community anxiety” and “public disorder.” It also forces these Private ESOs to take down anything that would “inform ways or provide access” to these prohibited documents.

Laws must provide sufficient guidance to those charged with their execution to enable them to ascertain what sorts of expression are properly restricted and what sorts are not. 

This language is extremely concerning. Compelling Private ESOs to ensure that they are not “informing ways'' or “providing access” to prohibited documents and information, in our interpretation, would mean that if a user of a Private ESO platform or site decides to publish a tutorial on how to circumvent prohibited information or content (for example, by explaining how to use VPN to bypass access blocking), such a tutorial itself could be considered prohibited information. Use of a VPN itself could be considered prohibited information. (The Communications Minister has told Internet users in Indonesia to stop using Virtual Private Networks, which he claims allow users to hide from authorities and put users’ data at risk.)

While maintaining public order may in some circumstances be considered a legitimate aim, this provision could be used to justify limitations to freedom of expression. Any restrictions in the name of public order must be prescribed by law, be necessary and proportionate, and be the least restrictive means of realizing that legitimate aim. Moreover, as the Human Rights Committee stated, States' restrictions on the exercise of freedom of expression may not put in “jeopardy the right itself.” To comply with the “Prescribed by Law” requirement, they must not only be formulated with sufficient precision to enable an individual to regulate their conduct, but they must also be made accessible to the public. And they must not confer unfettered discretion for the restriction of freedom of expression on those charged with their execution. 

Article 9(3) includes within  “prohibited content and information” any speech that violates Indonesian law and regulations. GR71, a regulation one level higher than MR5, and the later Law No. 11 of 2008 on Electronic Information and Transactions, both use similar vague language without offering any further definition or elucidation. For example, Law No. 11 of 2008 defines “Prohibited Acts” as any person knowingly and without authority distributing and/or transmitting and/or causing to be accessible any material thought to violate decency; promote gambling; insult or defame; extort; spread false news resulting in consumer losses in electronic transactions; cause hatred based on ethnicity, religion, race, or group; or contain threats of violence. We see a similar systematic problem with the definition of “community anxiety” and “public order,” which fails to comply with the requirements of Article 19 (3) of the ICCPR. 

Additionally, Indonesia’s criminal code considers blasphemy a crime—even though outlawing "blasphemy" is incompatible with international human rights law. The United Nations Human Rights Committee has clarified that laws that prohibit displays of lack of respect for a religion or other belief systems, including blasphemy laws, are incompatible with the ICCPR. When it comes to defamation law, the UNHRC states that any law be crafted with care to ensure it does not stifle freedom of expression. The laws should allow for the defense of truth and should not be applied to other expressions that are not subject to verification. Likewise, the UNHRC has stated that “laws that penalize the expression of opinions about historical facts are incompatible with the obligations that the ICCPR imposes on States parties to respect for the right to freedom of opinion and expression.” Criminal defamation law has been widely criticized by UN Special Rapporteurs on Free Expression for hindering free expression. Yet under this new law, any speech that violates Indonesian law is deemed prohibited.

Forcing Private Companies To Proactively Monitor 

MR5 also obliges Private ESOs (except cloud providers) to ensure that their service, websites or platforms do not contain and do not facilitate the dissemination of such prohibited information or documents. Private ESOs are then required to ensure that their system does not carry prohibited content or information, which will in practice require a general monitoring obligation, and the adoption of content filters. Article 9 (6) imposes disproportionate sanctions, including a general blocking of systems for those who fail to ensure there is no prohibited content and information in their systems. 

We join SafeNet in urging the Indonesian government to bring its legislation into full compliance with international freedom of expression standards

These provisions are not only a serious threat to Indonesians’ free expression rights, they are also a major compliance challenge for Private ESOs. If the Ministry gets to determine what information is “prohibited,” a Private ESO would be hard-pressed to proactively ensure its system does not contain that information or facilitate its dissemination even before a specific takedown.

According to Ika Ningtyas, Head of the Freedom of Expression Division at the Southeast Asia Freedom of Expression Network (SAFEnet), leaving it up to the Ministry will allow it to censor content containing criticism of public policies and some discussion of LGBT rights or activities or the ongoing Papua conflict.

Who Decides What Is Prohibited? 

MR5 empowers an official with the Orwellian title “Minister for Access Blocking” to coordinate the prohibited information that will be blocked. Blocking requests may originate with Indonesian law enforcement agencies, courts, the Ministry of Information, or concerned members of the public. (The courts can issue “instructions” to the Access Blocking Minister, while other government entities send requests that the Minister can evaluate. Individuals’ requests related to pornography or gambling can be sent directly to the Access Blocking Minister, while those related to other matters are addressed first to the Ministry of Information.) The Minister then emails platform operators with orders to block particular things, which they are expected to obey within 24 hours—or only 4 hours for “urgent” requests. “Urgent” requests include  terrorism; child pornography; or content causing “unsettling situations for the public and disturbing public order.” If a Private ESO (with the exception of a cloud provider) does not comply, it may receive warnings, fines, and eventually have its services blocked in Indonesia—even if the prohibited information was legal under international human rights law.

It requires time to understand the local context and complexity of the cases, and to assess such government orders. Careful assessments are particularly needed when it comes to material that relates to minority groups and movements, regardless of the context in which the complaint is raised—copyright, defamation, blasphemy, or any of the categories MR5 describes as harmful or causing. Laws must provide sufficient guidance to those charged with their execution to enable them to ascertain what sorts of expression are properly restricted and what sorts are not. 

Even the use of copyright law as a cudgel by the state to censor dissent is not hypothetical. According to  Google’s Transparency Report on Government requests: 

We received a request through our copyright complaints submission process from an Indonesian Consul General who requested that we remove six YouTube videos. Outcome: We did not remove the videos, which appeared to be critical of the Consulate.

Forcing User-Generated Content Platforms to Become Government Enforcers

MR5 Articles 11, 16(11), and 16(12) enlist user-generated content platforms (like Youtube, Twitter, TikTok or any local sites that distribute user generated content) as content enforcers by threatening them with legal liability for their users’ expression unless they agree to help monitor the content of communication in various ways specified by the Indonesian government. Under Article 11, a User Generated Content Private ESO must ensure that prohibited information and documents are not transmitted or distributed digitally through their services, and must disclose subscriber information revealing who uploaded such information for the purpose of supervision by administrative agencies (Trade Agency) and law enforcement, and must perform access blocking (takedowns) on prohibited content. 

User-Generated Content Private ESOs who fail to remove prohibited information and/or documents are subject to an administrative sanction based on the provisions of the law and regulations concerning Non-Tax State Revenue (Article 16 (11)).

The Minister can force ISPs to block access to the Social Media Private ESO and/or can impose a fine that would accumulate every 24 or 4 hours until compliance, up to a maximum of 3 times (i.e. the fine can be multiplied up to 3 times, over a total of 4x3 = 12 hours for emergency cases such as terrorism, requiring a turnaround time of 4 hours), or 24x3=72 hours for other “normal” cases. The result: if changes aren’t made within 12 or 72 hours, on top of owing 3 times the fine, the Private ESO could find itself blocked. ((Article 16 (11)(12)).

MR5 Regulation Should be Repealed

We join SafeNet in urging the Indonesian government to repeal MR5 for its incompatibility with international freedom of expression law and standards. Companies should not remove content that is inconsistent with the permissible limitation test. General blocking measures as sanctions, in our opinion, are always inconsistent with Article 19 of the ICCPR. Companies should legally challenge such general blocking orders. They should also fight back strategically under any pressure from the Indonesian government.