BSI Secures ISO Certification for Privacy Information Management System
PT Bank Syariah Indonesia (Persero) Tbk (BSI) has achieved the global standard ISO/IEC 27701:2025 certification regarding the Privacy Information Management System (PIMS) for its services on the BYOND by BSI super app and customer care operations.
BSI Deputy President Director, Bob T. Ananta, emphasised that the company ensures customer data privacy governance operates with high, measurable, and sustainable security standards. According to him, this achievement is not merely about regulatory compliance, but a fundamental mandate to maintain public trust.
“Being the first bank to achieve the ISO/IEC 27701:2025 certification is both a significant achievement and a responsibility for BSI,” Bob stated in a press release in Jakarta on Thursday.
He added that for the company, protecting personal data is a direct reflection of implementing Sharia values in maintaining customer trust. “Superior services must be built upon a foundation of security, transparency, and absolute respect for customer privacy,” Bob remarked.
Technically, the implementation of ISO/IEC 27701:2025 on the BYOND by BSI service ensures that all data management follows a ‘privacy-by-design’ approach. The system is designed with strict access controls, privacy risk mitigation, and continuous monitoring.
In the customer care sector, identity verification and the fulfilment of data subject rights now operate in accordance with international practices.
Bob explained that customer data security is an essential part of the company’s work culture, known as EMAS (Empathy, Serving, Enthusiastic, with All Our Heart). He noted that the commitment to ‘Serving with All Our Heart’ is implemented not only through friendliness, empathy, and speed at branch offices but also through rigorous digital protection in cyberspace.
BSI Director of Compliance & Human Capital, Arief Adhi Sanjaya, stated that this certification marks the beginning of a more massive escalation of data protection within BSI. He added that the ISO/IEC 27701:2025 certification is not the finish line, but rather a strategic step to continue strengthening privacy governance and information security across the entire BSI service ecosystem.
“Moving forward, we will continue to enhance our human resource capabilities and expand the culture of data protection across all lines of the organisation,” said Arief.