TOTAL NUMBER OF SECURITY INCIDENTS REPORTED: 559,804,889
About DBNMS
On April 20, 2022, the National Privacy Commission (NPC) held its virtual launching of the Data Breach Notification Management System (DBNMS), a user-friendly interface that facilitates easy tracking and faster submission of Personal Data Breach Notifications and Annual Security Incident Reports. The DBNMS is a standardized and automated system, making it easier for personal information controllers (PICs) to submit Personal Data Breach Notification as required by NPC Circular No. 16-03 and Annual Security Incident Reports. The DBNMS addresses the limitations of manual submission and processing, as well as increases public transparency by allowing PICs to access pertinent and real-time information on their data breach notification. To use the DBNMS, head to https://dbnms.privacy.gov.ph. or click here.
401
Total Personal Data Breach
Notification from Jan 2022 to Present
TOP 3 GENERAL CAUSES OF DATA BREACHES
Human Error
Accidental Email (37)
Loss of Documents (29)
Loss of Equipment (12)
Misdelivered Documents (5)
Misuse of Resources (7)
Negligence (44)
Undertrained Staff (12)
Others (18)
164
Reports
Malicious Attacks
Hacking-Cloud (8)
Hacking-Database (13)
Hacking-Email Account (5)
Hacking-Infrastructure (6)
Hacking-Man-In-The-Middle (1)
Hacking-Others (20)
Hacking-Phishing (2)
Hacking-SQL Injection (4)
Hacking-Server (8)
Hacking-Website (15)
Malware-Ransomware (29)
Malware-Trojan Horse (0)
Malware-Virus (5)
Phishing (2)
Smishing (2)
Social Engineering (1)
Theft (19)
140
Reports
Malicious Attacks/Human Error
Connection Error (9)
Hardware Failure (2)
System Error (6)
System Misconfiguration (4)
21
Reports
Top 5 Sectors reporting Data Breach Notifications January-June 2023
GOVERNMENT (36)
FINANCIAL SERVICE ACTIVITIES (29)
RETAIL/TRADE (23)
REAL ESTATE (12)
PROFESSIONAL SCIENTIFIC AND TECHNICAL SERVICES (12)
Top 5 Sectors Reporting Security Incidents in 2023
FINANCIAL SERVICES ACTIVITIES (267)
REAL STATE (179)
RETAIL/TRADE (139)
MANUFACTURING/PRODUCTION (130)
UTILITIES (128)
HOW CAN THE DBNMS HELP YOU?
Faster and more accurate development of data-driven policies for Personal Information Controllers and Processors, and Data Subjects
PERSONAL INFORMATION CONTROLLERS AND PROCESSORS
Faster, easier, and more efficient submission of data breach notifications and Annual Security Incident Reports
More accurate submission of data breach notifications through its self-evaluation tool
DATA SUBJECTS
Awareness of data subjects on the specific causes of data breaches and the affected sectors
TESTIMONIALS
“We wish to congratulate the National Privacy Commission (the “Commission”) in launching and implementing its Data Breach Notification Management System (“DBNMS”). Personal data breaches are among the top concerns of Personal Information Controllers (“PICs”), especially considering the severe impact it has on the data subjects and the business. Hence, having a system to facilitate the swift submission of critical breach-related information is certainly a boon, as it permits the Commission to quickly and efficiently respond to such reports. Moreover, by making breach notifications less daunting through an organized, accessible, and easy to understand portal, the Commission, through the DBNMS, encourages entities of all sizes to comply—regardless of whether they’re an organization with robust resources dedicated to privacy management or an individual professional processing personal data. At any rate, we believe that the DBNMS is a testament to the Commission’s desire to be a partner to the PICs and a stalwart defender of the Filipinos’ privacy rights. Once again, we congratulate the Commission on this pivotal achievement.”
Data Protection Officer
DITO Telecommunity
"I would like to congratulate the National Privacy Commission (NPC) and the Compliance and Monitoring Division (CMD) for the successful development and implementation of the Data Breach Notification Management System (DBNMS). The DBNMS serves as the pioneering platform of NPC applying privacy-by-design and privacy engineering in its software development lifecycle. The system’s rapid response during breach reporting, detailed breach analysis, and interactive communication capabilities have proven very useful for personal information controllers in the country."
Regional Data Protection Officer, Director
APAC Chief Privacy Office
CITI
“I wish to congratulate the National Privacy Commission (NPC) on the inclusion of your program, Data Breach Notification Management System (DBNMS), as a nominee in the Global Privacy Assembly Awards.
The DBNMS, a user-friendly interface that facilitates easy tracking and faster submission of Personal Data Breach Notifications (PDBN) and Annual Security Incident Reports (ASIR), is a laudable initiative of the NPC to make its processes more efficient through digitization. The system addresses the limitations of manual submission and processing and increases public transparency as it allows personal information controllers (PICs) to access pertinent and real-time information on their data breach notification.
This is a good example of harnessing the benefits of emerging technologies to better serve the people. The program’s inclusion in the Global Privacy Assembly Awards is a testament to its noteworthiness. I hope it will be the eventual winner. Congratulations and more power to the National Privacy Commission!"
Undersecretary for Public Affairs and Foreign Relations
Department of Information and Communications Technology
"DBMNS is very convenient for us users (DPOs). The platform allows us to easily connect with the National Privacy Commission (NPC) and the interface is user friendly and easy to use, especially in complying with the Annual Security Incident Report, with just a few clicks of a button you can easily comply with the annual reportorial requirement. With the DBNMS, complying with the requirements of the National Privacy Commission feels just like a breeze!""
Data Protection Officer
Far Eastern University - Dr. Nicanor Reyes Medical Foundation (FEU-NRMF)
"Using the Data Breach Notification Management System (DBNMS) of the National Privacy Commission has truly transformed my role as a Data Protection Officer. It guides me through the complex process of complying with the reportorial requirements of the Data Privacy Act of 2012 especially with the submission of the Annual Security Incident Reports. With just a few clicks, I can efficiently comply.
This system also ensures that I stay on the right side of the law by helping me meet legal requirements for reportorial requirements. It's a sigh of relief knowing I can avoid fines and keep our organization's reputation intact with God’s help.
Beyond its legal benefits, the system has elevated our data protection practices. This proactive approach helps prevent future breaches and strengthens our overall data protection strategy. Being a Data Protection Officer has never been so empowering, thanks to this user-friendly and efficient system that supports our commitment to privacy and security."
DPO -La Verdad Christian College, Inc./DPO -MCGI
“The NPC Data Breach Management Notification System is a breakthrough project for the NPC. Since its launch in 2022, Organizations and Agencies were able to not only easily report a breach in compliance with the law, but as well as help their own Data Privacy teams in assessing security incidents through self-assessment. Having an automated system for reporting data breach helps organizations keep track of security incidents as part of good governance practice and helps protect data subjects in getting timely notification when needed. This initiative has definitely been a welcome innovation and receipt of efficient and ethical public service.”
DPO – Security Bank
“I am very proud that the Data Breach Notification Management System (DBNMS) of the National Privacy Commission has been shortlisted as a candidate for the Best in Innovation Awards Category of the Global Privacy Assembly.
The implementation of this new DBNM system made one of the compliance and monitoring requirements of an organization easy and real time. The mandatory requirement to submit annual security incident and data breach is now online and can be done anytime, anywhere and with any computer device. This supports the new work arrangements of DPOs who have been on work-from-home or flexible work arrangements during the pandemic up to this time. The system which also provided real-time reporting of data breach which falls under mandatory reporting is an efficient tool provided by NPC to receive on real-time reports, provide immediate feedback to the DPO’s registered email address, through the same system. Communication is between the NPC and the DPO who reported a data breach is through the system, thus we both just have to look at one system.
The system is easy to use, as it provides the list of security incidents and data breaches which may be encountered, thus we, DPOs can use such as our reference in monitoring our incidents and breach on a regular basis, and not just on an annual basis.
As a DPO, this system is one of the innovative tools provided by the NPC, and we would like to commend this and the NPC. We strongly commend the DBNMS to merit the award “Best in Innovation,” as it is well-deserved.
Congratulations to the NPC!”
Group Data Protection Officer
San Miguel Corporation
VIDEOS
BUILT USING THE PRIVACY BY DESIGN APPROACH
Proactive not Reactive; Preventative not Remedial
In its initial stages, the DBNMS was built with the idea of preventing or mitigating privacy and security risks.
Privacy as the Default Setting
The DBNMS has its privacy preserving options turned on by default. Users need not worry about the need to configure the DBNMS to enable privacy preserving features, user privacy is implemented upon signup as well as during the use of the system. .
Privacy Embedded into Design
While designing the DBNMS, the Compliance and Monitoring Division conducted Privacy Impact Assessments to determine the data flows and data inventory of the system to ensure that the DBNMS shall respect the following principles of the Data Privacy Act of 2023: Proportionality, Integrity, and Legitimate Purpose.
Full Functionality — Positive-Sum, not Zero-Sum
During its development, it is ensured that both privacy measures and proposed functionalities of the DBNMS were preserved. In addition, during the use of the said system, it is determined that additional features needed to be added. Since PIA was conducted during the design phase, adding features without compromising the privacy measures can be made with issues.
End-to-End Security — Lifecycle Protection
One of the requirements that was emphasized during the planning stage is that every major stage of the development should undergo a security assessment. This is to ensure that all possible vulnerabilities will be addressed even before the completion of the DBNMS. In addition, during the development, a number of PIAs were conducted to ensure none of the privacy measures were neglected or removed from the system. Finally, prior to its deployment, a Vulnerability Assessment and Penetration Test is conducted by a recognized VAPT provider.
Visibility and Transparency – Keep it Open
Following best practices, a Just-in-Time (JIT) Privacy Notice pops up during sign up. This privacy notice is designed to be easily read and understood. In addition, users are also given the option to read the full privacy notice by clicking on the link in the said JIT privacy notice. Moreover, links to the full privacy notice are seen on every page of the DBNMS to ensure that users are informed about how their personal data is processed and protected as well as how to contact the DPO of the National Privacy Commission.
Respect for User Privacy – Keep it User-Centric
Users of the DBNMS are empowered to exercise their privacy rights in the DBNMS. Aside from the security and privacy safeguards that are in place as well as the integration of privacy that is embedded into the design of the system, users are able to modify, edit and delete their personal data. In addition, for any privacy related concerns, the Commission’s DPO can be reached through the email address found in the Privacy Policy of the DBNMS. Moreover, the DBNMS administrator can easily be reached through its email address.
Visibility and Transparency – Keep it Open
Following best practices, a Just-in-Time (JIT) Privacy Notice pops up during sign up. This privacy notice is designed to be easily read and understood. In addition, users are also given the option to read the full privacy notice by clicking on the link in the said JIT privacy notice. Moreover, links to the full privacy notice are seen on every page of the DBNMS to ensure that users are informed about how their personal data is processed and protected as well as how to contact the DPO of the National Privacy Commission.
DBNMS LAUNCH
HOW TO USE DBNMS
All Breach Notifications and Annual Security Incident Reports (Annual Security Incident Report (“ASIR”) shall be submitted through the Data Breach Notification Management System (“DBNMS”) online platform (https//dbnms.privacy.gov.ph) . To guide you in navigating the DBNMS, please watch the videos through the links below:
1. How to create DBNMS account
2. How to submit a Personal Data Breach Notification report
3. How to comply with the required documents and information
4. How to submit an Annual Security Incident Report