
Press Release: For Immediate Release
Jakarta, December 14, 2018
Digital signature providers in Indonesia can no longer operate without proper oversight. The Ministry of Communication and Information Technology (Kemkominfo) is now more closely monitoring digital signature providers through Ministerial Regulation No. 11 of 2018 on the Implementation of Electronic Certification, which was issued on September 6, 2018. This ministerial regulation sets forth fifteen requirements that digital signature and electronic certificate providers must meet to be recognized as registered companies by the Minister of Communication and Information Technology, including:
Previously, digital signature providers were also required to be registered as Electronic System Operators (PSE) as stipulated in Government Regulation No. 82 of 2012 concerning the Operation of Electronic Systems and Transactions. Only after both of these regulations have been complied with is the institution deemed trustworthy to issue legally valid digital signatures.
“Digital signature providers that are not registered are essentially producing illegal digital signature products,” said Riki Arif Gunawan, Director of Information Technology Application Control at the Ministry of Communication and Information Technology (Kemkominfo).
The digital signature provider, Privy Identitas Digital, became the first private digital signature provider to meet all the requirements of Ministry of Communication and Information Technology Regulation No. 11/2018 and was recognized by Kemkominfo as a registered electronic certificate provider (PsRE) effective December 7, 2018.
Kemkominfo granted this recognition after PrivyID met a number of requirements, including having systems for the issuance, management, protection, and verification of electronic certificates. PrivyID also had to pass electronic system testing and information security analysis, consisting of stress tests, load tests, and penetration tests. In the stress test conducted to assess system capacity, PrivyID was able to handle one hundred transactions per second with satisfactory results.
“As Kominfo intensifies its oversight of digital signature providers, the public and the industry no longer need to worry about the security and validity of digital signatures. This is because registered digital signatures and electronic certificates, such as PrivyID, can guarantee legal certainty should a dispute reach the court level,” said Marshall Pribadi, CEO & Founder of PrivyID.
To date, PrivyID has 2.1 million digital signature users, with an average of 179,000 documents digitally signed each month via the PrivyID platform. PrivyID’s clients range from large corporations such as Telkom Indonesia, CIMB Niaga, Bank Mandiri, Bussan Auto Finance, Kredit Plus, Adira Finance, and Bank BRI to startups and small and medium-sized enterprises (SMEs) like Awan Tunai, Klik Acc, Kerjasama.com, ITX, and Sewa Kamera.
PrivyID is the only private digital signature provider that has met the requirements set forth by the ITE Law, Government Regulation No. 82 of 2012 on the Implementation of Electronic Systems and Transactions, and Ministry of Communication and Information Technology Regulation No. 11 of 2018 on the Implementation of Electronic Certification. PrivyID is also the first Indonesian startup to obtain ISO/IEC 27001:2013-compliant information security certification.