Indonesian Political, Business & Finance News

KAI assures customer digital data remains safe and protected

| Source: ANTARA_ID Translated from Indonesian | Technology
KAI assures customer digital data remains safe and protected
Image: ANTARA_ID

PT Kereta Api Indonesia (Persero) has assured that customers’ digital data remains safe, protected, and maintained through system strengthening, the application of international standards, and sustainable data protection governance. “KAI continues to strengthen the security and confidentiality of customer data in line with the increasingly widespread use of digital travel services,” said KAI Vice President of Corporate Communication Anne Purba in a statement in Jakarta on Tuesday. The strengthening covers data protection policies, system security, access control, cyber incident handling, and providing clear information to customers regarding the use of their data. According to her, digitalisation has made the travel process increasingly easy, from schedule searches, ticket purchases, and payments to travel management and the boarding process. This development must be accompanied by responsible data management. “Customers entrust a certain amount of information to KAI when using digital services. We maintain that trust through system strengthening, governance, worker competence, and data protection mechanisms that are continuously evaluated,” she said. This step is in line with the spirit of the 81st Anniversary of the Republic of Indonesia, ‘Indonesia Berdaulat, Adil, dan Makmur’ (Sovereign, Just, and Prosperous Indonesia). In economic development and digital services, sovereignty also relates to the nation’s ability to manage technology and safeguard public information responsibly. Based on KAI’s internal data, during January–June 2026, as many as 5,555,134 long-distance train customers used the Face Recognition Boarding Gate. This facility simplifies the boarding process because the customer’s identity can be verified through facial data linked to the travel ticket. “Registered customers no longer need to show a boarding pass, e-boarding pass, or ID card to officers when passing through the Face Recognition Boarding Gate,” she explained. The use of Face Recognition is optional. Customers who choose this service must give consent when registering via Access by KAI, the Check-in Counter machine at the station, or Customer Service. “Customer consent is an important part of the Face Recognition service. Customers can still use other available boarding mechanisms if they do not register their facial data,” Anne stated. Throughout the first semester of 2026, Access by KAI served 17,009,374 ticket transactions for mainline and local trains. This figure is equivalent to 76.34 per cent of all transactions through the sales channels for these two services. In terms of customer volume, 24,544,468 mainline and local train customers obtained tickets through Access by KAI in the January–June 2026 period. This number is equivalent to 73.68 per cent of the customer volume through all sales channels for the two services. KAI applies the ISO 27001 international standard Information Security Management System. This standard serves as a reference in managing information security risks, regulating access to data, and maintaining the confidentiality, integrity, and availability of information. Governance strengthening is also carried out through the establishment of a Computer Security Incident Response Team (CSIRT). This team is tasked with handling, coordinating, and responding if a cyber security incident is discovered. KAI has also appointed a Data Protection Officer (DPO), an official who oversees the implementation of company policies and compliance in data protection. Based on the 2025 Sustainability Report, KAI’s information technology governance maturity level reached approximately level 3.8. In addition to organisational strengthening, KAI conducts regular vulnerability assessments and system security testing. These checks aim to find potential gaps in applications and digital infrastructure so they can be addressed before disrupting services or posing risks to customer information. Customer data management is carried out with reference to Law Number 27 of 2022 concerning Personal Data Protection and the company’s internal policies. KAI also continues to educate workers on information security, access management, and responsibility in processing data. “For KAI, safeguarding the customer’s journey also means safeguarding the information entrusted to the company,” said Anne.

View JSON | Print