Philippines Data Privacy Act
Chapter V: Security of personal information – Philippines Data Privacy Act

Philippines Data Privacy Act 20(f): Notification of the Commission and affected data subjects of a personal data breach

The controller must promptly notify the Commission and affected data subjects when sensitive personal information, or other information that may under the circumstances be used to enable identity fraud, is reasonably believed to have been acquired by an unauthorized person and the controller or the Commission believes the acquisition is likely to give rise to a real risk of serious harm to any affected data subject. The notification must at least describe the nature of the breach, the sensitive personal information possibly involved and the measures taken to address it, and may be delayed only to the extent necessary to determine the scope of the breach, prevent further disclosures or restore reasonable integrity to the system; the Commission may find notification unwarranted taking compliance and good faith into account, exempt a controller where notification would not be in the public interest or the data subjects' interest, and authorise postponement where notification would hinder a criminal investigation. The IRR (sections 38 to 40) sets the clock at 72 hours from knowledge of, or reasonable belief in, a notifiable breach by the controller or the processor, adds the mitigation measures, the contact details of representatives and the assistance to data subjects to the contents, and allows on-site investigation by the Commission.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Chapter V: Security of personal information – Philippines Data Privacy Act

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.