"ACBA BANK" Open Joint Stock Company, emphasizing the security and protection of customers' personal data, the reliability of the services provided, as well as increasing the level of the information security system, was re-certified in 2021 by the Italian company INTERNATIONAL TECHNICAL ALLIANCE S.R.L. (ITA S.r.l.) in accordance with the international standard for information security ISO/IEC 27001:2013.
Compliance with the international standard testifies to the implementation of the principles adopted by the Bank, which are aimed at improving effective management, increasing the efficiency of the data processing and control process, as well as applying information security principles in relations with partners.
By the way, "ACBA BANK" Open Joint Stock Company was the first in the banking system of the Republic of Armenia to receive the ISO/IEC 27001 information security standard certificate on September 11, 2012.
"ACBA BANK" OJSC has received a high-level international Payment Card Industry Data Security Standard (PCI DSS) security certificate.
This certification confirms that all data used in our card operations, including the storage, processing and destruction of sensitive cardholder data, as well as all related activities, are carried out in accordance with international best practices.
PCI DSS is one of the highest international standards for data security in the payment and settlement system, and compliance with it indicates a high level of ensuring the confidentiality, integrity and availability of card data, as well as the company’s responsible and systematic approach to information security and cybersecurity.
The ACBA BANK GROUP Privacy Policy sets forth the general principles governing the protection, collection, processing, and storage of personal data and information constituting a banking secret. The objective of the Policy is to ensure the protection of the legitimate interests of our clients, employees, and stakeholders through a robust data protection system, in compliance with the requirements of domestic and international legislation. This document is intended to mitigate privacy risks and to foster a culture of information security and responsible governance within the Group.