Submit incident
Documented

Worldcoin Scanned Indonesian Eyes Under a License That Wasn't Its Own

January 1, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1999View source ↗
LinkedInX

What happened

In May 2025, Indonesia's Ministry of Communication and Digital suspended Worldcoin's operating permit, ending the company's iris-scanning identity verification operations in the country. The suspension followed public complaints and police reports about suspicious activity connected to Worldcoin's World ID service, which asked users to submit biometric iris data in exchange for a digital identity credential and cryptocurrency.

What the investigation found was specific. Worldcoin's local representative, PT Terang Bulan Abadi, was running electronic services without the required electronic system provider license. Rather than obtaining its own registration, the entity had been operating under a certificate belonging to a separate legal entity, PT Sandina Abadi Nusantara. Using another company's registration to provide digital services is a direct violation of Indonesian law, and authorities suspended the permit while police opened a parallel inquiry into whether the data collection practices themselves broke Indonesian statute.

The biometric dimension makes the regulatory failure significantly more serious. Worldcoin was not collecting ordinary personal data. It was scanning irises, a uniquely identifying physical characteristic that cannot be changed, reissued, or revoked once captured and stored. Participants were required to submit that data to access the service at all. Whether consent was meaningfully informed, and whether the data was collected by an entity with legal standing to hold it, remains unanswered in any public disclosure by the company.

Indonesia is not the first country to reach this conclusion. Kenya suspended Worldcoin over privacy and security concerns, and Portugal banned the project for ninety days over citizen privacy risks. A pattern of entry-first, compliance-later operations across multiple jurisdictions points to a structural posture rather than isolated oversight failures. The Indonesia case is particularly clear as an example because the license problem was not a gray area: the operating entity had no valid registration of its own, and it had borrowed one from a company with no apparent connection to the services being offered.

The gap the Indonesian case exposes is one that regulators in every market face when a cross-border technology company collects irreversible biometric data through a local intermediary. There is no provable record of what system processed the iris scans, under whose authorization, or where that data was transmitted after collection. Verification depended entirely on the company's own disclosures, which arrived only after a suspension order forced the issue. A verifiable chain of custody for who held the license, what data was collected under it, and where it went would have made this violation legible long before the public complaints that finally triggered a response.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
Worldcoin Scanned Indonesian Eyes Under a License That Wasn't Its Own
2025