KAI tightens customer data security with ISO 27001
KAI also has formed a cyber incident response team and assigned data protection officers for its digital services.
PT Kereta Api Indonesia (Persero) is tightening the security and confidentiality of customer data amid the growing use of digital travel services. The effort covers data protection policies, system safeguards, access controls, cyber incident handling, and clearer information for customers about how their data is used. KAI has implemented an Information Security Management System to ISO 27001 standards, formed a Computer Security Incident Response Team, prepared a Data Protection Officer, and carried out regular security testing. Its privacy policy is also displayed in the Access by KAI app so customers understand the types of data managed, the purpose of its use, the retention period, and how to request deletion of data.