Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
x------------------------------------------------x
ORDER
THIS ORDER is being issued under the power of this Commission to
compel any entity to abide by its orders on a matter of data privacy, in relation
to a data breach report submitted by Betita Cabilao Casuela Sarmiento for and
in behalf of Cathay Pacific (“Cathay”).
5th floor, Ang Kiukok Hall, PICC Complex, Pasay City, Metro Manila 1308
URL: http://privacy.gov.ph Email Address: info@privacy.gov.ph
Order
In re: Cathay Pacific Airways, Ltd.
CID BN No. 18-198
Page 2 of 4
x-------------------------------------------------x
The law also provides that when there is a failure to notify this
Commission, or when the Commission determines that there is an
unreasonable delay to the notification, there is a presumption that there is a
1 National Privacy Commission, Personal Data Breach Management, Circular No. 16-03, §11.
2 Id.
3 National Privacy Commission, Personal Data Breach Management, Circular No. 16-03, §17-
A.
4 Id.
Order
In re: Cathay Pacific Airways, Ltd.
CID BN No. 18-198
Page 3 of 4
x-------------------------------------------------x
failure to notify.5 When such a failure or delay exists, this Commission may
investigate further the circumstances surrounding the data breach, including
the failure to report or any undue delay.6
The failure to report such a data breach in a timely manner may require
this Commission to fulfill its mandate to ensure compliance of personal
information controllers with the provisions of the Data Privacy Act. 7Philippine
law imposes criminal liability on persons who, after having knowledge of a
security breach and of the obligation to notify the Commission under
Philippine law, intentionally or by omission conceals the fact of such security
breach.8
5 National Privacy Commission, Personal Data Breach Management, Circular No. 16-03, §20.
6 National Privacy Commission, Personal Data Breach Management, Circular No. 16-03, §21.
7 An Act Protecting Individual Personal Information in Information and Communications
Systems in the Government and the Private Sector, Creating for this Purpose a National
Privacy Commission, and for Other Purposes [DATA PRIVACY ACT OF 2012], Republic Act No.
10173, §7(a)
8 DATA PRIVACY ACT OF 2012, §30.
9 National Privacy Commission, Personal Data Breach Management, Circular No. 16-03,
§17.D.3.
10 National Privacy Commission, Personal Data Breach Management, Circular No. 16-03,
§17.D.
Order
In re: Cathay Pacific Airways, Ltd.
CID BN No. 18-198
Page 4 of 4
x-------------------------------------------------x
1. EXPLAIN within ten (10) days why Cathay should have this
Commission overcome the presumption that there has been a failure
to timely notify this Commission about the occurrence of a data
breach requiring such timely notification giving rise to criminal
liability on the part of the responsible officers of Cathay; and
2. SUBMIT within five (5) days further information on the measures
taken to address the breach.
SO ORDERED.
GILBERT V. SANTOS
Director IV
Legal and Enforcement Office