Philippines Data Privacy Act
IRR Rule XI: Registration and compliance requirements – Philippines Data Privacy Act

Philippines Data Privacy Act R.47: IRR section 47: registration of personal data processing systems

A controller or processor must register its personal data processing systems with the Commission where it employs at least two hundred fifty persons, or, with fewer, where the processing is likely to pose a risk to the rights and freedoms of data subjects, is not occasional, or includes sensitive personal information of at least one thousand individuals (the Act's section 24 threshold for government contractors). The registration contains the name, address and contact details of the controller or processor and its representative; the purposes and whether processing is under an outsourcing or subcontracting agreement; the categories of data subjects and data; the recipients or categories of recipients; proposed transfers of personal data outside the Philippines; a general description of privacy and security measures; a brief description of the data processing system; a copy of all policies on data governance, privacy and information security; attestation to related certifications; and the name and contact details of the compliance or data protection officer, updated immediately on change. NPC Circular 17-01 sets the procedure.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in IRR Rule XI: Registration and compliance requirements – Philippines Data Privacy Act

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.