ni Atty. Persida Rueda-Acosta @Magtanong Kay Attorney | Pebrero 18, 2023
Dear Chief Acosta
Ako ay may savings account sa isang bangko na nagkaroon ng mga hindi awtorisadong transaksyon, limang buwan na ang nakakaraan. Nang ito ay ipinagbigay-alam ko sa bangko, sinabihan ako na nagkaroon lamang ng problema ang kanilang data processing system na agad naman nilang naayos, at ang mga transaksyon sa aking account ay naiwasto rin kalaunan. Subalit, napag-alaman ko lamang kamakailan na ang data processing system ng nasabing bangko ay na-hack, anim na buwan na ang nakalilipas.
Ano ang tungkulin ng bangko sa ganitong pangyayari? –Pauline
Dear Pauline,
Ang batas na sasaklaw patungkol sa iyong katanungan ay ang Republic Act No. 10173 o mas kilala bilang “Data Privacy Act of 2012.” Nakasaad sa Sections 20 (f), at 30 ng batas na:
“Section 20. Security of Personal Information.
(f) The personal information controller shall promptly notify the Commission and affected data subjects when sensitive personal information or other information that may, under the circumstances, be used to enable identity fraud are reasonably believed to have been acquired by an unauthorized person, and the personal information controller or the Commission believes that such unauthorized acquisition is likely to give rise to a real risk of serious harm to any affected data subject. The notification shall at least describe the nature of the breach, the sensitive personal information possibly involved, and the measures taken by the entity to address the breach. Notification may be delayed only to the extent necessary to determine the scope of the breach, to prevent further disclosures, or to restore reasonable integrity to the information and communications system.
Section 30. Concealment of Security Breaches Involving Sensitive Personal Information. – The penalty of imprisonment of one (1) year and six (6) months to five (5) years and a fine of not less than Five hundred thousand pesos (P500,000) but not more than One million pesos (P1,000,000) shall be imposed on persons who, after having knowledge of a security breach and of the obligation to notify the Commission pursuant to Section 20(f), intentionally or by omission conceals the fact of such security breach.”
Kaugnay nito, nakasaad sa Section 38 ng Implementing Rules and Regulations (IRR) ng kaparehong batas na:
“Section 38. Data Breach Notification.
a. The Commission and affected data subjects shall be notified by the personal information controller within seventy-two (72) hours upon knowledge of, or when there is reasonable belief by the personal information controller or personal information processor that, a personal data breach requiring notification has occurred.”
Ayon sa mga nabanggit na probisyon ng batas, ang isang bangko, bilang personal information controller, ay may tungkulin na pangalagaan ang personal na impormasyon ng kanyang mga kliyente, at ang seguridad nito. Kaugnay nito, ang isang bangko ay inatasan ng batas na ipagbigay-alam sa Data Privacy Commission, at sa mga kliyente nito, ang anumang anomalya o breach of security na magaganap, kung saan ang personal na impormasyon ng huli ay maaaring makuha ng ibang tao. Ang paglabag sa nasabing tungkulin ay may kaakibat na kaparusahan, alinsunod sa mga nabanggit sa itaas. Kaya kung mapatutunayan na nagkaroon ng hack sa sistema ng iyong bangko at nakompromiso ang iyong mga personal na impormasyon, at hindi ito ipinagbigay-alam sa iyo ng nasabing bangko, maaari itong mapanagot sa batas.
Sana ay nabigyan namin ng linaw ang iyong katanungan. Ang payong aming ibinigay ay base lamang sa mga impormasyon na iyong inilahad at maaaring magbago kung mababawasan o madaragdagan ang mga detalye ng iyong salaysay.
Maraming salamat sa inyong patuloy na pagtitiwala.


