On 19 November 2016, the National Privacy Commission's Personal Data Breach Management Circular (NPC CIRCULAR 16-03) was implemented. The circular outlines guidelines for managing personal data breaches, focusing on prevention, incident response, and notification procedures. It mandates the creation and implementation of a Security Incident Management Policy by personal information controllers or processors, including the establishment of a data breach response team with clear responsibilities and the implementation of security measures to prevent breaches. Additionally, it requires incident response policies for timely discovery, assessment, and notification to the Commission and affected data subjects.
Original source