What is the mandatory time frame for officially reporting a personal data breach to the Commission?
Controllers must notify the Commission and affected subjects within 72 hours upon discovering or reasonably believing a data breach occurred.
Controllers must notify the Commission and affected subjects within 72 hours upon discovering or reasonably believing a data breach occurred.
Data subjects can quickly dispute inaccurate personal data, compelling the controller to correct it immediately and officially inform third-party recipients.
Does a data subject have the right to correct inaccurate personal information? Read More »
Data portability actively allows subjects to obtain an electronic, structured copy of their processed personal data for their own further use.
What is the right to data portability? Read More »
Controllers must strictly implement organizational, physical, and technical security measures to securely protect personal data from natural and human-induced threats.
What are the obligations of a personal information controller regarding data security? Read More »
Employees handling personal data must maintain strict confidentiality, a vital obligation that completely persists even after their employment or contract legally ends.
Are employees who process personal data bound by confidentiality even after they resign? Read More »
Controllers must promptly notify the Commission and affected data subjects if unauthorized acquisition of sensitive data poses a risk of serious harm.
The personal information controller permanently remains entirely accountable for personal data even when it is actively transferred to a third-party processor.
Who is accountable for personal information transferred to a third party for processing? Read More »
Unauthorized processing of personal information is strictly punished by 1 to 3 years of imprisonment and a massive fine up to Php2,000,000.00.
What is the penalty for unauthorized processing of personal information? Read More »
For corporate offenders, the responsible officers are heavily penalized, and the court may legally suspend or completely revoke the corporation’s functional rights.
Data processing must strictly adhere to transparency, legitimate purpose, and proportionality, and data must be collected for specific and lawful purposes.