When Can Directors Face Prison for Data Breaches?

When Can Directors Face Prison for Data Breaches?

Introduction

Corporate data breaches can expose personal information, disrupt operations, and cause serious harm to data subjects. Although a corporation is generally treated as a separate juridical person, directors and other responsible officers may face personal criminal liability when their participation, gross negligence, or deliberate concealment satisfies the requirements of the Data Privacy Act of 2012.

The risk is not created merely by the occurrence of a cyberattack. Personal criminal liability depends on the specific offense, the officer’s participation or gross negligence, the officer’s knowledge, and the presence of the statutory conditions for prosecution. Board membership alone does not automatically result in imprisonment.

Governing Law on Corporate Data Privacy Liability

The principal statute is Republic Act No. 10173, or the Data Privacy Act of 2012 (DPA). It regulates the processing and protection of personal information and imposes duties on personal information controllers, personal information processors, and responsible officers.

Under Section 34 of the DPA, when the offender is a corporation, partnership, or other juridical person, the penalty may be imposed on the responsible officers who participated in the offense or who, through gross negligence, allowed the offense to be committed. This provision creates a direct route to personal criminal liability, but it does not make every director automatically liable for an act of the corporation.

The same principle is reflected in the implementing rules, which provide that, in criminal acts, the person who committed the unlawful act or omission may be recommended for prosecution. Where the offender is a juridical person, responsible officers who participated in, or by gross negligence allowed, the commission of the crime may likewise be recommended for prosecution under the IRR of Republic Act No. 10173.

What Conduct Can Result in Imprisonment?

Several data privacy offenses may expose responsible corporate officers to imprisonment. The most relevant for serious cybersecurity incidents are unauthorized access, concealment of a reportable security breach, and other offenses committed through the unauthorized or negligent handling of personal information.

Concealing a Security Breach

Section 30 of the DPA penalizes the concealment of security breaches involving sensitive personal information. The penalty is imprisonment of one year and six months to five years and a fine of ₱500,000 to ₱1,000,000.

The offense requires the coexistence of three conditions:

  • A personal data breach occurred;
  • The breach was one that required notification to the National Privacy Commission; and
  • The person, knowing of the breach and the obligation to notify the Commission, intentionally or by omission concealed the breach.

These requirements were identified by the National Privacy Commission in NPC SS 22-001 and NPC SS 22-008, Decision dated May 5, 2021. The concealed incident must be a breach that falls within the mandatory notification requirement; not every security event automatically constitutes the crime.

Accordingly, a director may face criminal exposure if the evidence shows that the director knew of a qualifying breach, knew that notification was required, and intentionally or negligently failed to disclose the breach to the Commission. Knowledge of a general cybersecurity weakness, without proof of knowledge of an actual reportable breach, may be insufficient for Section 30 liability.

Unauthorized Access or Intentional Breach

Section 29 of the DPA punishes a person who knowingly and unlawfully breaks into a system where personal or sensitive personal information is stored, in violation of data confidentiality and security. The penalty is imprisonment of one year to three years and a fine of ₱500,000 to ₱2,000,000.

The elements identified by the NPC include:

  • The system stores personal or sensitive personal information;
  • The accused breaks into the system; and
  • The accused knowingly and unlawfully breaks into the system in a manner that violates its confidentiality and security.

These elements were discussed in NPC 18-109, Decision dated May 5, 2021. Authorized access by a processor acting within the scope of its assigned role does not, by itself, establish unauthorized access or intentional breach.

A director would therefore not ordinarily be liable under Section 29 merely because the director sits on the board or failed to understand a technical system. Personal liability would require proof that the director personally committed, authorized, participated in, or legally allowed the unlawful access under the circumstances contemplated by Section 34.

How Gross Negligence Can Create Personal Liability

Gross negligence is more than an ordinary mistake, poor business judgment, or a failure to achieve perfect cybersecurity. It involves a serious failure to exercise the degree of care expected from a responsible officer under circumstances where the risk of harm was apparent.

In the data privacy setting, circumstances that may support a finding of gross negligence include the following:

  • Ignoring repeated warnings of a serious and continuing vulnerability;
  • Failing to implement basic access controls, authentication, monitoring, or encryption despite known risks;
  • Allowing unrestricted access to sensitive personal information without a legitimate business need;
  • Failing to investigate credible reports of unauthorized access; and
  • Refusing to activate an incident-response and breach-notification process after learning of a qualifying incident.

The relevant inquiry is not whether the board personally wrote software or configured a server. The inquiry is whether the directors or responsible officers had authority over the organization’s data-security measures and, despite known risks, allowed unlawful conduct or a qualifying breach to occur through a serious failure of supervision.

In NPC 19-910, Decision dated 2021, the NPC emphasized that responsible corporate officers may incur liability not only when they personally perform the prohibited act, but also when their managerial position gave them the power and responsibility to prevent it and they failed to exercise appropriate supervision.

Why Board Membership Alone Is Not Enough

The DPA does not impose automatic criminal liability on every director whenever a company suffers a data breach. Section 34 requires a connection between the officer and the offense through participation or gross negligence that allowed the offense to occur.

The NPC has also recognized the importance of evidence. In NPC SS 21-023, Decision dated March 4, 2024, the Commission stated that administrative liability cannot rest on mere allegations or presumptions. The complainant must establish the factual basis for the alleged violation, and a phishing attack directed at account holders does not automatically prove that the bank’s system was compromised or that the bank acted negligently.

This distinction is significant. A company may experience a cyberattack despite maintaining reasonable safeguards. Conversely, a company may face serious exposure where its officers knew of material weaknesses, failed to correct them, and then failed to report a qualifying breach.

When Does a Cybersecurity Failure Become a Criminal Case?

A severe cybersecurity vulnerability becomes a possible basis for criminal liability when the evidence establishes more than the existence of a technical weakness. The following circumstances are particularly important:

  • The affected system contained personal or sensitive personal information;
  • The responsible officers had actual knowledge, or circumstances clearly established their awareness, of the vulnerability or breach;
  • The officers had authority to allocate resources, impose controls, or direct the incident response;
  • The failure to act amounted to gross negligence rather than ordinary error or reasonable business judgment; and
  • The conduct satisfied the elements of a specific DPA offense, including the notification and knowledge requirements for concealment.

For concealment, the breach must also be one requiring notification to the NPC. The existence of a security incident, without more, does not establish the offense under Section 30.

Corporate Governance Duties Relevant to Data Security

Directors are expected to exercise reasonable care and prudence in performing their corporate responsibilities. In data-intensive businesses, this includes ensuring that the company has appropriate policies, personnel, systems, and controls for protecting personal information.

The board’s responsibilities may include approving a data-protection program, requiring periodic cybersecurity reports, ensuring that material vulnerabilities are addressed, and confirming that the company can investigate and report qualifying breaches within the required period.

The board may also be exposed where it delegates data processing to a contractor but abandons supervision entirely. Outsourcing does not eliminate the accountability of the personal information controller. The NPC recognized in NPC 21-122, Decision dated 2023 that outsourcing collection activities may be permitted when appropriate safeguards and accountability measures are maintained.

Mandatory Breach Notification

The DPA and its implementing rules require notification to the NPC when the legal conditions for mandatory reporting are present. The IRR generally requires notification within 72 hours from knowledge of, or reasonable belief in, a qualifying personal data breach.

Companies should not wait for a complete forensic investigation before beginning the notification assessment. The incident-response team should promptly determine whether the breach involves sensitive personal information, whether there is a real risk of serious harm, and whether the statutory and regulatory notification requirements have been triggered.

Failure to notify is not automatically the same as criminal concealment. For Section 30 liability, the prosecution must still establish a qualifying breach, a notification obligation, the officer’s knowledge of that obligation, and intentional or omission-based concealment.

Typical Scenarios

Scenario 1: The board receives repeated warnings but does nothing. If the board is repeatedly informed that sensitive personal information is exposed through an unpatched and widely known vulnerability, refuses to fund or require corrective measures, and a qualifying breach follows, the responsible directors may face allegations of gross negligence under Section 34.

Scenario 2: A phishing attack targets customers. A phishing incident alone does not establish that the company’s systems were compromised or that the company was negligent. The company’s liability depends on the evidence regarding its safeguards, the source of the exposure, and its response, consistent with NPC SS 21-023, Decision dated March 4, 2024.

Scenario 3: The company confirms a reportable breach but withholds it. If responsible officers know that a qualifying breach occurred and that notification is required, but deliberately suppress the information or omit notification to avoid regulatory scrutiny, the elements of concealment under Section 30 may be present.

Scenario 4: A director has no operational role and receives no notice. A nonexecutive director who had no knowledge of the incident, no participation in the relevant conduct, and no basis to know that a reportable breach existed would not ordinarily be criminally liable solely because of board membership.

Evidence Used to Assess Director Liability

Evidence relevant to personal criminal liability may include board minutes, cybersecurity committee reports, audit findings, incident-response records, internal emails, risk assessments, vendor contracts, penetration-test results, reports to senior management, and communications with the NPC.

Investigators may also examine whether the board received warnings, whether it approved or rejected security expenditures, whether it required corrective action, and whether it imposed a reporting structure capable of detecting and escalating breaches.

For this reason, accurate board minutes and documented follow-through are important. A general resolution declaring support for data privacy is less persuasive than records showing specific risk reviews, assigned responsibilities, deadlines, remediation, and verification.

Recommended Compliance Measures

  • Adopt a written data-security and breach-response policy aligned with the DPA and NPC issuances.
  • Require regular reports to the board concerning material vulnerabilities, incidents, remediation, and unresolved risks.
  • Maintain an incident-response team with clearly assigned legal, technical, communications, and compliance responsibilities.
  • Document the decision-making process when the company determines whether notification to the NPC or affected data subjects is required.
  • Review contracts and oversight procedures for data processors, contractors, cloud providers, and other third parties.

Directors should also avoid treating cybersecurity as solely an information-technology concern. Where the company processes large volumes of sensitive personal information, data security is a governance, compliance, and risk-management responsibility.

Conclusion

Directors may face imprisonment for a corporate data privacy breach when the evidence establishes the elements of a specific offense and shows that they participated in the unlawful conduct or, through gross negligence, allowed it to occur. The most direct warning concerns the concealment of a qualifying breach: the law requires a reportable personal data breach, knowledge of the notification obligation, and intentional or omission-based concealment.

A cyberattack alone does not establish criminal liability. The decisive issues are the nature of the information, the seriousness and foreseeability of the risk, the officer’s authority and knowledge, the adequacy of the company’s safeguards, and the quality of the response after discovery.

Boards should therefore treat cybersecurity warnings as formal governance matters, require documented remediation, preserve evidence of compliance, and ensure that breach-notification decisions are made promptly and on the basis of the DPA and applicable NPC rules.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH