In the space of six months, three of Southeast Asia's largest digital markets have put binding children's online safety rules into force. Malaysia's Online Safety Act took effect on 1 January 2026. Indonesia's child protection regulation for digital platforms, known as PP Tunas, applied from 28 March 2026. Singapore made age assurance mandatory for app stores on 1 April 2026 and opened its Online Safety Commission on 29 June 2026. The Philippines is close behind, and Vietnam and Thailand are drafting. For international NGOs, UN agencies and any organisation serving children across the region, the question is no longer whether these rules matter, but how to meet five different versions of them with one standard.
What do Southeast Asia's new children's online safety laws have in common?
All three live regimes borrow from the same template: a duty on platforms to assess and reduce risks to children, minimum-age or age-assurance requirements for under-16s, a named regulator with licensing or enforcement powers, and codes of practice that spell out the detail. They differ in scope, in how far they reach beyond the largest platforms, and in how much they ask of the organisations that use those platforms to reach children.
Country by country
Singapore. The Infocomm Media Development Authority (IMDA) has regulated social media through a Code of Practice for Online Safety since 2023. Its Code of Practice for Online Safety for App Distribution Services took effect on 31 March 2025, and from 1 April 2026 the major app stores, including Apple, Google, Huawei, Samsung and Microsoft, must implement age assurance. Separately, the Online Safety (Relief and Accountability) Act 2025 created a new Online Safety Commission, operational since 29 June 2026, giving individuals a route to have harmful content removed and, in later phases, statutory torts against those responsible. Singapore's model is regulator-led and incremental. Its significance for the region is that so many organisations run their Asia-Pacific operations from there.
Malaysia. The Online Safety Act 2025 came into force on 1 January 2026 under the Malaysian Communications and Multimedia Commission (MCMC). Platforms with eight million or more users in Malaysia are treated as licensed application service providers and must comply with a Risk Mitigation Code and a Child Protection Code, both effective 1 June 2026. The Child Protection Code includes a ban on accounts for under-16s, with age verification through national identity documents or passports. Malaysia has gone furthest on hard age limits and identity-based verification, which raises its own child-rights questions about privacy and exclusion.
Indonesia. Government Regulation 17 of 2025, PP Tunas, took effect on 28 March 2026 under the Ministry of Communication and Digital Affairs (Komdigi). An implementing regulation restricts under-16 access to eight named platforms, with a grace period on penalties running to 27 March 2027. The six-month evaluation reported that around 28 million child accounts had been restricted, and the ministry publicly flagged at least one major platform as slow to comply. Indonesia has the largest child population of the three and the most explicit willingness to name non-compliant platforms.
The Philippines. No law is in force yet. A Senate committee has endorsed the Child Online Safety and Protection Act, which would set a minimum age of 16 for social media, and the government has signalled it wants the law enacted by the end of 2026. Organisations working in the Philippines should treat 2027 as the compliance year.
Vietnam and Thailand. Vietnam's Decree 147 has required parental registration of under-16 accounts since December 2024, and amendments drafted in September 2026 stop short of a ban but mandate parental supervision and default maximum privacy for children's accounts. Thailand is studying an under-16 restriction and rewriting its Child Protection Act. Both are direction-of-travel signals rather than deadlines.
The regional layer. ASEAN is finalising a Regional Plan of Action on child online protection for 2026 to 2030, with UNICEF's East Asia and Pacific Regional Office as technical partner. That plan will shape how the remaining member states legislate and how donors fund implementation.
What this means for organisations that serve children
These laws bind platforms. Organisations that work with children inherit their consequences in three ways.
First, the digital services you use to reach children are changing. Under-16 restrictions in Malaysia and Indonesia mean younger children will be pushed off mainstream platforms or into misreporting their age. Programmes that depend on those platforms for outreach, education or reporting channels need a plan for that shift.
Second, expectations are rising for everyone. Once a regulator has said that platforms must assess risk to children and design for their safety, donors, ministries and parents start asking the same of the organisations they fund and trust. A safeguarding policy that does not cover digital and AI risks reads as out of date.
Third, data about children is now a regulated asset across the region. Identity-based age verification in Malaysia and default privacy settings in Vietnam point the same way as Australia's Children's Online Privacy Code and Europe's rules: collect less, protect more, and be able to explain why you hold what you hold.
Five regimes, one standard
An organisation with children in several of these jurisdictions cannot run a compliance programme per country. It needs one child-safety standard, grounded in children's rights, that maps onto each regime. The UN Convention on the Rights of the Child and General Comment 25 on children's rights in the digital environment supply that standard. They also give you something the laws do not: a way to weigh protection against children's rights to participation, information and privacy, so that age limits and identity checks do not become a new source of harm.
In practice, a cross-jurisdiction readiness review asks the same questions in every country:
- Which digital services and AI systems touch the children we serve, directly or through partners?
- What does each applicable regime require of those services, and what evidence do we hold that the providers meet it?
- Where do our own practices on children's data, age assurance and reporting fall short of the strictest regime we operate in?
- What is the child-rights impact of complying, especially for children who will be excluded or pushed elsewhere?
- What do we change, in what order, and how do we show our working to donors and regulators?
Frequently asked questions
Do these laws apply to NGOs and schools, or only to platforms? The direct obligations fall on platforms and app stores. Organisations that use those services to reach children are affected indirectly, through changes in what children can access and through rising expectations from funders and authorities.
Which regime is the strictest? Malaysia, on paper: a statutory under-16 account ban with identity-based age verification and binding codes since 1 June 2026. Indonesia is the most active enforcer against named platforms. Singapore is the most incremental but reaches app stores and now provides individual relief through its Online Safety Commission.
What is the ASEAN Regional Plan of Action on child online protection? A five-year regional framework for 2026 to 2030, developed with UNICEF as technical partner, that sets shared priorities for member states on legislation, capacity and cooperation. It is the main route through which regional standards will reach the countries that have not yet legislated.
How does this compare with Europe and the UK? The EU Digital Services Act and the UK Online Safety Act set the template: risk assessment, safety by design and a regulator with real penalties. Southeast Asian regimes add harder minimum-age rules and, in some cases, identity-based verification. An organisation operating across both regions should build to the child-rights standard and map each regime onto it.
Where should an organisation start? Inventory the digital services and AI systems children use because of you, country by country. Identify the strictest applicable regime and use it as your floor. Assess the child-rights impact of the changes you make. Document all of it.
Regulatory details cited here are accurate as of September 2026 and should be checked against the relevant regulator before being relied on in a compliance decision.