0% found this document useful (0 votes)
9 views3 pages

Penalties For Data Privacy Breach

The document outlines various penalties for unauthorized processing, accessing, and disposal of personal and sensitive personal information, with imprisonment terms ranging from six months to seven years and fines from Php100,000.00 to Php4,000,000.00. It specifies penalties for negligence, unauthorized purposes, intentional breaches, concealment of security breaches, malicious disclosures, and unauthorized disclosures. Additionally, a combination of offenses can result in increased penalties, emphasizing the importance of data privacy compliance.

Uploaded by

Js Si
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views3 pages

Penalties For Data Privacy Breach

The document outlines various penalties for unauthorized processing, accessing, and disposal of personal and sensitive personal information, with imprisonment terms ranging from six months to seven years and fines from Php100,000.00 to Php4,000,000.00. It specifies penalties for negligence, unauthorized purposes, intentional breaches, concealment of security breaches, malicious disclosures, and unauthorized disclosures. Additionally, a combination of offenses can result in increased penalties, emphasizing the importance of data privacy compliance.

Uploaded by

Js Si
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 3

DEFENITIONS AND PENALTIES FOR DATA PRIVACY BREACH

SEC. 25. Unauthorized Processing of Personal Information and Sensitive


Personal Information. – (a) The unauthorized processing of personal
information shall be penalized by imprisonment ranging from one (1) year to
three (3) years and a fine of not less than Five hundred thousand pesos
(Php500,000.00) but not more than Two million pesos (Php2,000,000.00)
shall be imposed on persons who process personal information without the
consent of the data subject, or without being authorized under this Act or
any existing law.

(b) The unauthorized processing of personal sensitive information shall be


penalized by imprisonment ranging from three (3) years to six (6) years and
a fine of not less than Five hundred thousand pesos (Php500,000.00) but not
more than Four million pesos (Php4,000,000.00) shall be imposed on persons
who process personal information without the consent of the data subject, or
without being authorized under this Act or any existing law.

SEC. 26. Accessing Personal Information and Sensitive Personal Information


Due to Negligence. – (a) Accessing personal information due to negligence
shall be penalized by imprisonment ranging from one (1) year to three (3)
years and a fine of not less than Five hundred thousand pesos
(Php500,000.00) but not more than Two million pesos (Php2,000,000.00)
shall be imposed on persons who, due to negligence, provided access to
personal information without being authorized under this Act or any existing
law.

(b) Accessing sensitive personal information due to negligence shall be


penalized by imprisonment ranging from three (3) years to six (6) years and
a fine of not less than Five hundred thousand pesos (Php500,000.00) but not
more than Four million pesos (Php4,000,000.00) shall be imposed on persons
who, due to negligence, provided access to personal information without
being authorized under this Act or any existing law.

SEC. 27. Improper Disposal of Personal Information and Sensitive Personal


Information. – (a) The improper disposal of personal information shall be
penalized by imprisonment ranging from six (6) months to two (2) years and
a fine of not less than One hundred thousand pesos (Php100,000.00) but not
more than Five hundred thousand pesos (Php500,000.00) shall be imposed
on persons who knowingly or negligently dispose, discard or abandon the
personal information of an individual in an area accessible to the public or
has otherwise placed the personal information of an individual in its
container for trash collection.

(b) The improper disposal of sensitive personal information shall be


penalized by imprisonment ranging from one (1) year to three (3) years and
a fine of not less than One hundred thousand pesos (Php100,000.00) but not
more than One million pesos (Php1,000,000.00) shall be imposed on persons
who knowingly or negligently dispose, discard or abandon the personal
information of an individual in an area accessible to the public or has
otherwise placed the personal information of an individual in its container for
trash collection.

SEC. 28. Processing of Personal Information and Sensitive Personal


Information for Unauthorized Purposes. – The processing of personal
information for unauthorized purposes shall be penalized by imprisonment
ranging from one (1) year and six (6) months to five (5) years and a fine of
not less than Five hundred thousand pesos (Php500,000.00) but not more
than One million pesos (Php1,000,000.00) shall be imposed on persons
processing personal information for purposes not authorized by the data
subject, or otherwise authorized under this Act or under existing laws.

The processing of sensitive personal information for unauthorized purposes


shall be penalized by imprisonment ranging from two (2) years to seven (7)
years and a fine of not less than Five hundred thousand pesos
(Php500,000.00) but not more than Two million pesos (Php2,000,000.00)
shall be imposed on persons processing sensitive personal information for
purposes not authorized by the data subject, or otherwise authorized under
this Act or under existing laws.

SEC. 29. Unauthorized Access or Intentional Breach. – The penalty of


imprisonment ranging from one (1) year to three (3) years and a fine of not
less than Five hundred thousand pesos (Php500,000.00) but not more than
Two million pesos (Php2,000,000.00) shall be imposed on persons who
knowingly and unlawfully, or violating data confidentiality and security data
systems, breaks in any way into any system where personal and sensitive
personal information is stored.

SEC. 30. Concealment of Security Breaches Involving Sensitive Personal


Information. – The penalty of imprisonment of one (1) year and six (6)
months to five (5) years and a fine of not less than Five hundred thousand
pesos (Php500,000.00) but not more than One million pesos
(Php1,000,000.00) shall be imposed on persons who, after having knowledge
of a security breach and of the obligation to notify the Commission pursuant
to Section 20(f), intentionally or by omission conceals the fact of such
security breach.

SEC. 31. Malicious Disclosure. – Any personal information controller or


personal information processor or any of its officials, employees or agents,
who, with malice or in bad faith, discloses unwarranted or false information
relative to any personal information or personal sensitive information
obtained by him or her, shall be subject to imprisonment ranging from one
(1) year and six (6) months to five (5) years and a fine of not less than Five
hundred thousand pesos (Php500,000.00) but not more than One million
pesos (Php1,000,000.00).

SEC. 32. Unauthorized Disclosure. – (a) Any personal information controller


or personal information processor or any of its officials, employees or agents,
who discloses to a third party personal information not covered by the
immediately preceding section without the consent of the data subject, shall
he subject to imprisonment ranging from one (1) year to three (3) years and
a fine of not less than Five hundred thousand pesos (Php500,000.00) but not
more than One million pesos (Php1,000,000.00).

(b) Any personal information controller or personal information processor or


any of its officials, employees or agents, who discloses to a third party
sensitive personal information not covered by the immediately preceding
section without the consent of the data subject, shall be subject to
imprisonment ranging from three (3) years to five (5) years and a fine of not
less than Five hundred thousand pesos (Php500,000.00) but not more than
Two million pesos (Php2,000,000.00).

SEC. 33. Combination or Series of Acts. – Any combination or series of acts


as defined in Sections 25 to 32 shall make the person subject to
imprisonment ranging from three (3) years to six (6) years and a fine of not
less than One million pesos (Php1,000,000.00) but not more than Five million
pesos (Php5,000,000.00).

You might also like

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy