KAI Vice President of Corporate Communication Anne Purba said that digitization has made train travel services more practical. Starting from finding schedules, buying tickets, paying, managing trips, to boarding processes can now be done digitally.
According to him, these facilities must go hand in hand with responsibility in maintaining information entrusted by customers to the company.
"Customers entrust a number of information to KAI when using digital services. We maintain this trust through strengthening systems, governance, employee competence, and data protection mechanisms that are constantly evaluated," Anne said in an official statement, Tuesday, August 4.
This commitment is also reflected in the 2025 Sustainability Report. In the report, KAI assessed that the development of digital technology brings challenges in the form of increased cyber security risks, software vulnerabilities, to the potential misuse of personal data. Therefore, the company places information security as one of the main focuses in the development of digital services.
As a form of transparency, KAI also provides a Privacy Policy on the Access by KAI application. Through this information, customers can find out what type of data is managed, its purpose of use, storage period, and data deletion mechanism if necessary.
The Face Recognition service itself allows customers to board without having to show a boarding pass or ID card. The system will verify the identity through facial data that has been connected to the travel ticket.
Anne emphasized that the use of this technology is entirely voluntary. Customers can only use the service after giving consent through the Access by KAI application, Check-in Counter machines at stations, and Customer Service officers.
"Customer approval is an important part of the Face Recognition service. Customers can still use other boarding mechanisms available if they do not register their facial data," he said.
Data used in the registration process includes name, National Identification Number (NIK), and face photo. All data is stored in KAI's system infrastructure and is used specifically for Face Recognition Boarding Gate operations.
KAI also applies a time limit for data storage. Face Recognition registration will be stored for one year before being automatically deleted. Customers can also request early deletion of data through the Access by KAI application and Customer Service at the station.
The increasing use of Face Recognition is inseparable from the increasing use of KAI's digital services. As of June 30, 2026, the Access by KAI application has 30,449,049 registered users with 9,058,935 active users and a total download of 41,011,320 times.
In Semester I-2026, the application recorded 17,009,374 transactions of Main and Local Train tickets or about 76.34 percent of all transactions of these two services. Meanwhile, as many as 24,544,468 customers obtained tickets through Access by KAI, equivalent to 73.68 percent of the total customers who bought tickets through all sales channels.
According to Anne, the high use of Access by KAI shows that digital services have now become an important part of customer travel, ranging from ticket purchases, schedule changes, trip cancellations, e-boarding pass access, Face Recognition registration, to various other services in the KAI Group ecosystem.
"The wider the use of digital services, the greater the responsibility of KAI in maintaining the system and customer data. Ease of service must go hand in hand with security, transparency, and respect for customer rights," he explained.
To strengthen information security, KAI implements the ISO 27001 international standard Information Security Management System. The company also formed a Computer Security Incident Response Team (CSIRT) to handle cyber security incidents and appointed a Data Protection Officer (DPO) to ensure that the implementation of data protection policies is in accordance with regulations.
In addition, KAI periodically conducts vulnerability checks and system security testing to identify potential gaps in applications and digital infrastructure. All customer data management refers to Law Number 27 of 2022 concerning the Protection of Personal Data and the company's internal policies.
"KAI will continue to strengthen technology, governance, and incident handling readiness in line with the development of digital services. For KAI, maintaining customer travel also means maintaining information that has been entrusted to the company," concluded Anne.
The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)