When a state-owned payment technology subsidiary starts appearing in conversations about VAT compliance, most finance teams assume something got mixed up. It did not. Presidential Regulation No. 68 of 2025, signed by President Prabowo Subianto and in force since 5 June 2025, deliberately placed a fintech company at the center of Indonesia’s newest tax collection mechanism, and understanding why requires stepping back from the mechanics of any single transaction to look at the gap the regulation was actually built to close. 

The Revenue Gap This Regulation Was Written to Close

The government’s own reasoning, as reflected in the regulation’s stated objectives, starts from a fairly narrow observation. A meaningful share of foreign digital transactions, exchanges of services, data, or information carried out over computer networks, the internet, or other electronic media, was generating VAT liability that existing collection channels were not consistently capturing. Rather than expanding an existing mechanism, the government built a second, parallel one.

Perpres 68/2025 sets out four objectives for the system it creates, formally named the Sistem Pemungutan Pajak atas Transaksi Digital Luar Negeri (SPP-TDLN):

  • Establishing a specialized collection system capable of reaching foreign digital transactions that existing mechanisms could not consistently capture
  • Improving the efficiency, effectiveness, and accountability of VAT collection on these transactions
  • Increasing fairness in tax collection and taxpayer compliance specifically around foreign digital transaction obligations
  • Increasing state revenue through better optimized collection on this transaction category

It is worth being precise about what kind of regulation this is. A Presidential Regulation sits above a Ministry of Finance Regulation in Indonesia’s legal hierarchy, and Perpres 68/2025 reads accordingly. At nine articles, it establishes the system, assigns the institution responsible for running it, and sets the financial and oversight arrangements around that assignment. It does not itself specify VAT rates, filing deadlines, or invoice formats. Those operational details were left to a follow-up Ministry of Finance regulation, issued roughly a year later specifically to implement this framework. Anyone reading Perpres 68/2025 expecting a compliance checklist is reading the wrong layer of the regulation.

Why a State-Owned Fintech Subsidiary, Not a Government Agency

The Selection Logic Behind PT Jalin Pembayaran Nusantara

The regulation actually reasons through this in two separate steps, and conflating them, as a first read tends to do, misses why the appointment is structured the way it is.

The first step, under Pasal 3(1), justifies assigning the role to a state-owned financial technology and payment systems subsidiary as a category, rather than to a government agency directly. Five considerations sit behind that policy choice: the urgency of getting SPP-TDLN operating quickly to lift state revenue, the need for a digital collection mechanism that reaches transactions abroad and is backed by adequate data and information, the need for specific technological capability that had to be available immediately, the sensitivity of transaction data confidentiality involved in running the system, and the fact that building it this way requires no upfront capital investment from the government itself.

The second step, under Pasal 3(3), is where PT Jalin Pembayaran Nusantara specifically gets named and authorized, on four further grounds: existing competence in financial technology and payment systems, demonstrated capacity to maintain transaction data confidentiality, adequate financial capability, and an assessment that Jalin meets the broader criteria set out in Pasal 3(1). The legal basis for routing this through a BUMN subsidiary at all traces back partly to Law No. 4 of 2023 on Financial Sector Development, alongside Indonesia’s Personal Data Protection Law, Law No. 27 of 2022, both cited directly in the regulation’s legal foundation given how central data handling is to the whole arrangement.

That two-step structure matters because it means Jalin was not simply the only available option. The regulation first decided what kind of entity should hold this role, then separately confirmed that Jalin specifically met the bar.

That last point matters more than it might first appear. Building a government-run technology platform capable of interfacing with global payment flows from scratch would have meant a multi-year procurement and budget cycle. Appointing an existing, technically capable state-owned entity and compensating it through a service fee arrangement sidesteps that timeline entirely.

What Jalin Is Actually Obligated to Do

Pasal 3(5) sets out seven obligations attached to Jalin’s role as Penyelenggara SPP-TDLN, described as a floor rather than a ceiling, “paling sedikit” (at least these):

  • Conducting sandboxing, the administrative and technical testing process, for any prospective partner
  • Ensuring the reliability and continuity of the system and technology, based on that sandboxing outcome
  • Actually carrying out the collection of tax on foreign digital transactions, not merely operating supporting infrastructure around it
  • Ensuring system security, including the confidentiality, integrity, and availability of the data involved
  • Providing the support, maintenance, and funding the system requires to keep running
  • Coordinating with the coordination team overseeing SPP-TDLN’s implementation
  • Complying with applicable statutory provisions and operational working guidelines

That third obligation is worth underlining, since it directly answers a question companies sometimes ask when they hear Jalin described as a system operator. This is not a passive infrastructure role. Jalin is explicitly obligated to carry out the actual tax collection itself, not merely to keep the pipes running for someone else to do it.

How Jalin Brings Its Own Partners Into the System

Jalin does not collect tax alone. Under Pasal 3(4) and Pasal 4 to 5, it is authorized to directly appoint what the regulation calls calon mitra, prospective partners, to help carry out the system’s implementation. Before any such party can formally operate, it goes through the same sandboxing process applied to Jalin itself: administrative review plus technical testing covering functionality, cyber security, scalability, and fit with the system’s underlying purpose.

The administrative criteria a prospective partner has to meet under Pasal 5(2)(a) run to ten specific points, and several of them go well beyond the generic technology and financial capacity checks a company might expect:

  • Possessing the specific technology needed to collect cross-border digital tax accurately and efficiently
  • Having global business reach along with a representative office in Indonesia
  • Demonstrating financial capability that satisfies cash flow requirements for both current and future cooperation agreements
  • Having already implemented, or currently implementing, a comparable digital transaction tax collection system generating revenue in at least one other country
  • Employing expert staff with at least three years of relevant experience in digital transaction tax collection
  • Carrying no sanctions or court judgments against the services it provides, including its management, within the preceding two years
  • Having no conflict of interest with officials or staff at relevant ministries or agencies, or with any other party involved in providing SPP-TDLN
  • Not originating from a country the Indonesian government does not recognize
  • Not appearing on any blacklist or under sanction from the Indonesian government
  • Not appearing on the blacklists maintained by the US Office of Foreign Assets Control (OFAC) or the US Securities and Exchange Commission (SEC)

Alongside that administrative review, Pasal 5(2)(b) requires a parallel technical test covering function, scalability, and performance; cyber security, governance risk compliance, and personal data protection; fit with the system’s stated purpose, verified through an isolated test environment; and monitoring, recording, analysis, and reporting procedures for the test results themselves. The two tracks, administrative and technical, run in parallel rather than sequentially, and Jalin reports the combined outcome to the coordination team for validation and recommendation before formally confirming a partner.

That OFAC and SEC reference is a notable detail on its own. A domestic Indonesian regulation explicitly importing US regulatory blacklists into its partner vetting criteria signals how seriously the drafters treated the cross-border financial exposure a partner in this system could create.

Before any of this sandboxing begins, Pasal 4 sets a simpler baseline: a prospective partner must be an Indonesian and or foreign legal entity with infrastructure and supporting systems capable of meeting the data, information, and specific technology requirements this system needs, reaching all the way to transactions abroad. Jalin tests candidates against that baseline first and reports the result to the coordination team before the fuller sandboxing process in Pasal 5 even starts.

This appointment track is the one that later surfaces, under the implementing Ministry of Finance regulation, as the designation of a bank or payment facilitator as a Pihak Lain, the party actually responsible for withholding VAT at the point of payment. Pasal 6(7) of this Perpres explicitly delegates the detailed procedure for VAT collection and Imbal Jasa payment to that Ministry of Finance regulation, confirming in the regulation’s own text that the operational mechanics were always meant to live one level down from this framework. Pasal 8(1) adds one more practical constraint worth knowing: SPP-TDLN’s implementation does not begin at all until Jalin has formally designated at least one partner under this process. The framework existing on paper and the system actually collecting anything from a transaction are, by the regulation’s own design, two different milestones.

Money Flows Through the System, Not Around It

A reasonable question follows from all of this. If a private, albeit state-owned, fintech company is sitting inside the tax collection chain, where does the money actually go, and does Jalin get to keep a share before the state sees it?

Under Pasal 6, the answer is structured deliberately to avoid that ambiguity. VAT collected through SPP-TDLN is state revenue and must be deposited into the state treasury account according to standing regulation, in full. Separately, Jalin receives a service fee, imbal jasa, for operating the system, but that fee follows its own approval chain. Jalin proposes a figure to the coordination team, the coordination team passes a recommendation to the Minister of Finance, and the Minister, or an appointed official, sets the final amount based on that recommendation. Payment of the fee is calculated with reference to the VAT actually remitted to the treasury, rather than deducted from it as a first-in-line cut.

Oversight Runs Through a Coordination Team, Not a Single Regulator

Rather than placing SPP-TDLN under a single ministry’s direct day-to-day supervision, the regulation establishes a coordination team under Pasal 7, appointed by presidential decision, referenced repeatedly across Pasal 3, 5, and 6 as the body that validates Jalin’s partner testing, recommends the service fee amount, and receives Jalin’s reporting. Under Pasal 8(2), that same team conducts periodic review and evaluation of the entire system’s implementation, not a one-time sign-off. The regulation itself does not break the coordination team down into named sub-committees, so any more granular structure beyond what is written here would need to come from the separate Presidential Decision establishing that team, a document distinct from Perpres 68/2025 itself.

What This Actually Means for Foreign Vendors and Their Indonesian Counterparties

For a company paying foreign vendors for digital services, Perpres 68/2025 by itself does not change a monthly VAT filing. What it did was authorize the system, the institution, and the appointment process that a subsequent Ministry of Finance regulation then used to define actual collection mechanics, VAT timing, calculation formulas, and reporting obligations for banks and payment providers designated under this framework.

That distinction matters when reading anything written about SPP-TDLN, including this article. Claims about specific VAT rates, remittance deadlines, or invoice formats belong to the implementing ministerial regulation, not to Perpres 68/2025 itself. For companies that already navigate Indonesia’s existing digital VAT collector regime, understanding how that older mechanism works is covered in a separate explainer on how VAT works in Indonesia for foreign companies, and the two systems now sit alongside each other rather than one replacing the other.

The broader pattern worth noticing is institutional rather than transactional. Indonesia’s tax administration has been steadily rebuilding how it identifies and administers non-standard taxpayer relationships this year, from redefined tax representative rules under PMK 44/2026 to marketplace withholding obligations under PMK 37/2025. Perpres 68/2025 fits that same pattern, expanding who sits inside the collection chain rather than changing what is owed. Whatever collection document eventually lands in a company’s hands as a result of this system, it still has to reconcile against the same Coretax-based crediting process, covered separately in a look at issuing and reconciling tax invoices under Coretax.

XPND’s tax compliance team tracks how each layer of this framework, the presidential regulation, the implementing ministerial rules, and whichever banks or payment providers eventually get designated under it, actually reaches a client’s own transactions, rather than treating the system as a single event that concluded when it was signed. A regulation establishing who is authorized to collect is not the same document as one explaining how much gets collected and when, and conflating the two is exactly where confident-sounding compliance advice tends to go wrong first.