Indonesian Political, Business & Finance News

KAI Strengthens Customer Data Security with ISO 27001 and Cyber Response Team

| Source: ANTARA_ID Translated from Indonesian | Technology
KAI Strengthens Customer Data Security with ISO 27001 and Cyber Response Team
Image: ANTARA_ID

PT Kereta Api Indonesia (Persero) is strengthening the security and confidentiality of customer data in line with the expanding use of its digital travel services. Vice President of Corporate Communication KAI, Anne Purba, stated that digitalisation has simplified the travel process, from schedule searches and ticket purchases to payments, travel management, and boarding. ‘Customers entrust a number of pieces of information to KAI when using digital services. We safeguard that trust by reinforcing systems, governance, worker competence, and data protection mechanisms, all of which are continuously evaluated,’ Anne said. According to KAI’s 2025 Sustainability Report, the growth of digital technology brings risks of cyber security threats, software vulnerabilities, and potential misuse of personal data. Consequently, the security and confidentiality of customer data have become a primary focus in managing KAI’s digital services. The company’s data protection policy is communicated through the Privacy Policy section in Access by KAI, informing customers about the types of data managed, the purposes of its use, retention periods, and procedures for requesting data deletion. This initiative aligns with the spirit of the 81st Independence Day of the Republic of Indonesia, linking digital sovereignty to the responsible management of technology and public information. KAI internal data shows that in the first half of 2026, 5,555,034 long-distance train customers used the Face Recognition Boarding Gate. The feature streamlines boarding by verifying customer identity through facial data linked to their travel ticket. Customers who opt into this service must provide consent during registration via Access by KAI, Check-in Counter machines at stations, or through Customer Service officers. The facial recognition data, including names, national identity numbers, and facial photos, is stored within KAI’s system infrastructure and is automatically deleted after one year. Customers may also request earlier deletion. The scope of digital service usage is reflected in Access by KAI, which had 30,449,049 registered users as of 30 June 2026, with 9,058,935 active users. During the first semester of 2026, the application processed 17,009,374 ticket transactions for mainline and local trains, representing 76.34% of total transactions across all sales channels. In terms of passenger volume, 24,544,468 customers obtained their tickets through the app, equivalent to 73.68% of the total. Anne noted that the extensive use of the application demonstrates that digital services have become integral to the customer journey. KAI has implemented an Information Security Management System based on the international ISO 27001 standard, which serves as a reference for managing information security risks, controlling data access, and ensuring confidentiality, integrity, and availability. Governance has been further strengthened by establishing a Computer Security Incident Response Team (CSIRT) to handle, coordinate, and respond to cyber security incidents. The company has also appointed a Data Protection Officer (DPO) to oversee the implementation of data protection policies and compliance. KAI conducts regular vulnerability assessments and security testing of its applications and digital infrastructure to identify potential gaps before they can disrupt services or pose risks to customer information. Customer data management is carried out in accordance with Law Number 27 of 2022 on Personal Data Protection and internal company policies.

View JSON | Print