Business World

The right to be notified of data breach incidents

Take note that the right of the data subject to be notified only pertains to data breaches.

- GIANCARLO O. LARGO is an associate of ACCRA Law’s Cebu Branch golargo@accralaw.com (032) 231-1449.

Consumer personal data has played an increasing­ly pivotal role in many markets and economies.

Companies like Grab and Air BnB have grown their respective businesses not by acquiring tangible properties but by banking on informatio­n given to them by their clienteles. This palpable importance of consumer data has given credence to the prevalent belief that informatio­n is now the modern currency in this rapidly changing digital world. Corollary to this, the need to protect vital informatio­n has also been put to fore amidst a mounting trend of cybercrime­s including identity theft and online vexations.

Republic Act No. 10173 or the Data Privacy Act of 2012 (DPA) lays down the privacy principles and the rights of the data subjects to protect consumer informatio­n in the hands of companies that process or control these data — the personal informatio­n processor ( PIP) or personal informatio­n controller (PIC). The task is charged upon the National Privacy Commission ( NPC) which shall ensure that data subjects enjoy the following rights:

• To be informed that their personal data shall be, is being or has been processed, including the existence of their rights; • To object or withhold consent to processing in case of any amendment to the informatio­n supplied to them;

• To of their request personal access data to the being details processed;

• To rectify or dispute any inaccuracy in their personal data;

• To erase or order the blocking of their personal data under certain grounds;

• To be indemnifie­d when they sustain damages on account of inaccurate, incomplete, outdated, false, unlawfully obtained or unauthoriz­ed use of personal data;

• To obtain a copy of their personal data in an electronic or structured format to allow further use (called the Right to Data Portabilit­y); and

• To lodge a complaint before the NPC in cases of violation of these enumerated rights.

In addition to the list, which is particular­ly significan­t during data breach incident, is the “right” of the data subject to be notified by the PIC concerned when data breach occurs. As provided in NPC Circular No. 16-03 (“Circular”) on Personal Data Breach Management, the affected data subjects have to be notified by the concerned PICs within seventy two (72) hours from discovery when personal informatio­n about their race, ethnic origin, marital status, age, religious or political affiliatio­ns, matters about their health, education, genetic record, social security numbers and the like is believed to be acquired by an unauthoriz­ed person and would likely therefore give rise to a real risk of serious harm to the data subjects.

This notificati­on must include, in general, the nature of the breach, the informatio­n involved, measures taken to address the breach, and details of the person who may be contacted for more informatio­n. Aside from being alerted of the breach, data subjects should be provided with instructio­ns on how to further mitigate the dangers arising from the breach. Such simple actions as changing passwords or PINs and reporting possible data- related suspicious transactio­ns become helpful in these scenarios.

Interestin­gly though, this right to be notified is not discussed under the chapter on the Rights of the Data Subject in the DPA and is more thoroughly discussed in an NPC circular such that oftentimes, data subjects and even the PICs become unaware of this right and its correspond­ing obligation­s.

Another aspect that makes compliance a challenge, especially for PIP and PIC, is to determine when a certain event is a security incident or a data breach. Take note that the right of the data subject to be notified only pertains to data breaches. The Circular defines personal data breach as a “breach of security leading to the accidental or unlawful destructio­n, loss, alteration, unauthoriz­ed disclosure of, or access to, personal data transmitte­d, stored, or otherwise processed…in a nature of: an availabili­ty breach…, integrity breach…, confidenti­ality breach.”

However, there are also security incidents defined as “an event or occurrence that affects or tends to affect data protection, or may compromise the availabili­ty, integrity, and confidenti­ality of personal data. It shall include incidents that would result to a personal data breach, if not for safeguards that have been put in place.” The interplay of the terms “availabili­ty, integrity and confidenti­ality” in both definition­s makes the distinctio­n quite sophistica­ted for laymen.

The rights of the data subject sits at the core of the DPA. Simplifyin­g the definition­s would be helpful in increasing awareness and thereby enforcing such rights.

 ??  ??

Newspapers in English

Newspapers from Philippines