Worldcoin Scanned Indonesian Eyes Under a License That Wasn't Its Own
What happened
In May 2025, Indonesia's Ministry of Communication and Digital suspended Worldcoin's operating permit, ending the company's iris-scanning identity verification operations in the country. The suspension followed public complaints and police reports about suspicious activity connected to Worldcoin's World ID service, which asked users to submit biometric iris data in exchange for a digital identity credential and cryptocurrency.
What the investigation found was specific. Worldcoin's local representative, PT Terang Bulan Abadi, was running electronic services without the required electronic system provider license. Rather than obtaining its own registration, the entity had been operating under a certificate belonging to a separate legal entity, PT Sandina Abadi Nusantara. Using another company's registration to provide digital services is a direct violation of Indonesian law, and authorities suspended the permit while police opened a parallel inquiry into whether the data collection practices themselves broke Indonesian statute.
The biometric dimension makes the regulatory failure significantly more serious. Worldcoin was not collecting ordinary personal data. It was scanning irises, a uniquely identifying physical characteristic that cannot be changed, reissued, or revoked once captured and stored. Participants were required to submit that data to access the service at all. Whether consent was meaningfully informed, and whether the data was collected by an entity with legal standing to hold it, remains unanswered in any public disclosure by the company.
Indonesia is not the first country to reach this conclusion. Kenya suspended Worldcoin over privacy and security concerns, and Portugal banned the project for ninety days over citizen privacy risks. A pattern of entry-first, compliance-later operations across multiple jurisdictions points to a structural posture rather than isolated oversight failures. The Indonesia case is particularly clear as an example because the license problem was not a gray area: the operating entity had no valid registration of its own, and it had borrowed one from a company with no apparent connection to the services being offered.
The gap the Indonesian case exposes is one that regulators in every market face when a cross-border technology company collects irreversible biometric data through a local intermediary. There is no provable record of what system processed the iris scans, under whose authorization, or where that data was transmitted after collection. Verification depended entirely on the company's own disclosures, which arrived only after a suspension order forced the issue. A verifiable chain of custody for who held the license, what data was collected under it, and where it went would have made this violation legible long before the public complaints that finally triggered a response.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.