Philippines: Implemented National Privacy Commission Circular 2023-06 on Security of Personal Data in the Government and Private Sector

Compare with different regulatory event:

Description

Implemented National Privacy Commission Circular 2023-06 on Security of Personal Data in the Government and Private Sector

On 30 March 2024, the National Privacy Commission (NPC) Circular 2023-06 Security of Personal Data in the Government and Private Sector entered into force. The Circular provides updated requirements for the security of personal data processed by personal information controllers (PICs) or personal information processors (PIPs). The requirements include the designation and registration of a data protection officer, the registration of data processing systems, conducting privacy impact assessments (PIAs), implementing a privacy management program, training personnel periodically on privacy and data protection policies, and compliance with the orders of the NPC. Furthermore, personal data must be stored as long as deemed necessary and appropriate based on best practices and industry standards. Lastly, PICs and PIPs must implement a business continuity plan that mitigates potential disruptive events. The plan must include personal data backups, restoration, business impact assessment, and a crisis communications plan.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-12-01
adopted

On 1 December 2023, the National Privacy Commission (NPC) adopted Circular 2023-06, Security of Per…

2024-03-30
in force

On 30 March 2024, the National Privacy Commission (NPC) Circular 2023-06 Security of Personal Data …