Philippines Data Privacy Act
Chapter VII: Security of sensitive personal information in government – Philippines Data Privacy Act

Philippines Data Privacy Act 23: Access by agency personnel to sensitive personal information: on-site, online and off-site

Except as the Commission's guidelines allow, no government employee may access sensitive personal information on government property or through online facilities without a security clearance from the head of the source agency; sensitive personal information may not be transported or accessed from a location off government property unless a request is submitted to and approved by the head of the agency, who must approve or disapprove within two business days (silence is disapproval), must limit approved access to not more than one thousand records at a time, and must ensure that any technology used to store, transport or access the information off-site is secured with the most secure encryption standard recognised by the Commission.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Chapter VII: Security of sensitive personal information in government – Philippines Data Privacy Act

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.