TOTAL NUMBER OF SECURITY INCIDENTS REPORTED: 559,804,889


About DBNMS

On April 20, 2022, the National Privacy Commission (NPC) held its virtual launching of the Data Breach Notification Management System (DBNMS), a user-friendly interface that facilitates easy tracking and faster submission of Personal Data Breach Notifications and Annual Security Incident Reports. The DBNMS is a standardized and automated system, making it easier for personal information controllers (PICs) to submit Personal Data Breach Notification as required by NPC Circular No. 16-03 and Annual Security Incident Reports. The DBNMS addresses the limitations of manual submission and processing, as well as increases public transparency by allowing PICs to access pertinent and real-time information on their data breach notification. To use the DBNMS, head to https://dbnms.privacy.gov.ph. or click here.





TOP 3 GENERAL CAUSES OF DATA BREACHES

Human Error

Accidental Email (37)
Loss of Documents (29)
Loss of Equipment (12)
Misdelivered Documents (5)
Misuse of Resources (7)
Negligence (44)
Undertrained Staff (12)
Others (18)

Malicious Attacks

Hacking-Cloud (8)
Hacking-Database (13)
Hacking-Email Account (5)
Hacking-Infrastructure (6)
Hacking-Man-In-The-Middle (1)
Hacking-Others (20)
Hacking-Phishing (2)
Hacking-SQL Injection (4)
Hacking-Server (8)
Hacking-Website (15)
Malware-Ransomware (29)
Malware-Trojan Horse (0)
Malware-Virus (5)
Phishing (2)
Smishing (2)
Social Engineering (1)
Theft (19)

Malicious Attacks/Human Error

Connection Error (9)
Hardware Failure (2)
System Error (6)
System Misconfiguration (4)

Top 5 Sectors reporting Data Breach Notifications January-June 2023

GOVERNMENT (36)
FINANCIAL SERVICE ACTIVITIES (29)
RETAIL/TRADE (23)
REAL ESTATE (12)
PROFESSIONAL SCIENTIFIC AND TECHNICAL SERVICES (12)


Top 5 Sectors Reporting Security Incidents in 2023

FINANCIAL SERVICES ACTIVITIES (267)
REAL STATE (179)
RETAIL/TRADE (139)
MANUFACTURING/PRODUCTION (130)
UTILITIES (128)



HOW CAN THE DBNMS HELP YOU?

Faster and more accurate development of data-driven policies for Personal Information Controllers and Processors, and Data Subjects

PERSONAL INFORMATION CONTROLLERS AND PROCESSORS

Faster, easier, and more efficient submission of data breach notifications and Annual Security Incident Reports

More accurate submission of data breach notifications through its self-evaluation tool


DATA SUBJECTS

Awareness of data subjects on the specific causes of data breaches and the affected sectors


TESTIMONIALS

VIDEOS

BUILT USING THE PRIVACY BY DESIGN APPROACH

Proactive not Reactive; Preventative not Remedial

In its initial stages, the DBNMS was built with the idea of preventing or mitigating privacy and security risks.

Privacy as the Default Setting

The DBNMS has its privacy preserving options turned on by default. Users need not worry about the need to configure the DBNMS to enable privacy preserving features, user privacy is implemented upon signup as well as during the use of the system. .

Privacy Embedded into Design

While designing the DBNMS, the Compliance and Monitoring Division conducted Privacy Impact Assessments to determine the data flows and data inventory of the system to ensure that the DBNMS shall respect the following principles of the Data Privacy Act of 2023: Proportionality, Integrity, and Legitimate Purpose.

Full Functionality — Positive-Sum, not Zero-Sum

During its development, it is ensured that both privacy measures and proposed functionalities of the DBNMS were preserved. In addition, during the use of the said system, it is determined that additional features needed to be added. Since PIA was conducted during the design phase, adding features without compromising the privacy measures can be made with issues.

End-to-End Security — Lifecycle Protection

One of the requirements that was emphasized during the planning stage is that every major stage of the development should undergo a security assessment. This is to ensure that all possible vulnerabilities will be addressed even before the completion of the DBNMS. In addition, during the development, a number of PIAs were conducted to ensure none of the privacy measures were neglected or removed from the system. Finally, prior to its deployment, a Vulnerability Assessment and Penetration Test is conducted by a recognized VAPT provider.

Visibility and Transparency – Keep it Open

Following best practices, a Just-in-Time (JIT) Privacy Notice pops up during sign up. This privacy notice is designed to be easily read and understood. In addition, users are also given the option to read the full privacy notice by clicking on the link in the said JIT privacy notice. Moreover, links to the full privacy notice are seen on every page of the DBNMS to ensure that users are informed about how their personal data is processed and protected as well as how to contact the DPO of the National Privacy Commission.

Respect for User Privacy – Keep it User-Centric

Users of the DBNMS are empowered to exercise their privacy rights in the DBNMS. Aside from the security and privacy safeguards that are in place as well as the integration of privacy that is embedded into the design of the system, users are able to modify, edit and delete their personal data. In addition, for any privacy related concerns, the Commission’s DPO can be reached through the email address found in the Privacy Policy of the DBNMS. Moreover, the DBNMS administrator can easily be reached through its email address.

Visibility and Transparency – Keep it Open

Following best practices, a Just-in-Time (JIT) Privacy Notice pops up during sign up. This privacy notice is designed to be easily read and understood. In addition, users are also given the option to read the full privacy notice by clicking on the link in the said JIT privacy notice. Moreover, links to the full privacy notice are seen on every page of the DBNMS to ensure that users are informed about how their personal data is processed and protected as well as how to contact the DPO of the National Privacy Commission.

HOW TO USE DBNMS

All Breach Notifications and Annual Security Incident Reports (Annual Security Incident Report (“ASIR”) shall be submitted through the Data Breach Notification Management System (“DBNMS”) online platform (https//dbnms.privacy.gov.ph) . To guide you in navigating the DBNMS, please watch the videos through the links below:
1. How to create DBNMS account
2. How to submit a Personal Data Breach Notification report
3. How to comply with the required documents and information
4. How to submit an Annual Security Incident Report