TOTAL NUMBER OF SECURITY INCIDENTS REPORTED (2018-2023): 6,787,410,968

Play Video

About DBNMS

On 22 April 2022, the National Privacy Commission, through its Compliance and Monitoring Division, launched the Data Breach Management System (DBNMS) for the easier and more convenient submission of personal data breach notifications and Annual Security Incident Reports by Personal Information Controllers and Processors. The System allows more effective issuance of Orders as well as real-time update and reflection of the status of the submissions. It also allows a more efficient manner of compliance by Data Subjects which eliminates the submission of inaccurate data breach notifications through its self-evaluation tool. The data gathered from the DBNMS are used by the Commission in its policy and standards development, awareness campaign, and other privacy-related advocacies of the Commission.

505

Total Personal Data Breach
Notification from January 2022
to 23 January 2024: 505 PDBNs

SECURITY INCIDENT / DATA BREACH / PERSONAL DATA BREACH

TOP 3 GENERAL CAUSES OF DATA BREACHES

Human Error

Accidental Email (44)

Loss of Documents (34)

Loss of Equipment (14)   

Misdelivered Documents (5)

Misuse of Resources (10)

Negligence (59)

Undertrained Staff (12)

Others (24)

202

Reports

211

Reports

Malicious Attacks

Hacking-Cloud (9)

Hacking-Database (18)  

Hacking-Email Account (5)           

Hacking-Infrastructure (10)

Hacking-Man-In-The-Middle (2)

Hacking-Others (18)

Hacking-Phishing (8)      

Hacking-SQL Injection (4)

Hacking-Server (12)

Hacking-Website (19)    

Malware-Ransomware (46)

Malware-Trojan Horse (0)            

Malware-Virus (6)           

Phishing (3)       

Smishing (2)      

Social Engineering (1)    

Theft (23)

Others (25)

Malicious Attacks / Human Error

Misuse of Resources (2)

Phishing (5)

Smishing (1)

Social Engineering (7)

Unauthorized Disclosure (8)

Hacking Database (3)

Stolen Device (4)

Negligence (2)

Insider Threat (1)

Undertrained Staff (2)

Others (6)

41

Reports

Top 5 Sectors reporting Data Breach Notifications January 2023 to 24 January 2024

GOVERNMENT (55)

FINANCIAL SERVICE ACTIVITIES (46)

RETAIL/TRADE (27)

HEALTHCARE FACILITIES (20)

EDUCATION (22)

Top 5 Sectors Reporting Security Incidents in 2023

HOTELS AND ACCOMMODATION (29)

FINANCIAL SERVICE ACTIVITIES (71

HEALTHCARE FACILITIES (22)

REAL ESTATE (88)

OFFICE ADMINISTRATIVE, OFFICE SUPPORT AND OTHER BUSINESS SUPPORT (21)

HOW CAN THE DBNMS HELP YOU?

Faster and more accurate development of data-driven policies for Personal Information Controllers and Processors, and data subjects

PERSONAL INFORMATION CONTROLLERS AND PROCESSORS

  • Faster, easier, and more efficient submission of data breach notifications and Annual Security Incident Reports
  • More accurate submission of data breach notifications through its self-evaluation tool

DATA SUBJECTS

  • Awareness of data subjects on the common causes of data breaches and the sectors and how to protect themselves against these incidents

TESTIMONIALS

VIDEO TESTIMONIALS

Play Video
Play Video
Play Video
Play Video
Play Video
Play Video

BUILT USING THE PRIVACY BY DESIGN APPROACH

  • Proactive not Reactive; Preventative not Remedial - In its initial stages, the DBNMS was built with the idea of preventing or mitigating privacy and security risks.

 

  • Privacy as the Default Setting – The DBNMS has its privacy preserving options turned on by default. Users need not worry about the need to configure the DBNMS to enable privacy preserving features because user privacy is implemented upon signup and during the use of the System.

 

  • Privacy Embedded into Design – While designing the DBNMS, the NPC’s Compliance and Monitoring Division conducted Privacy Impact Assessments (“PIA”) to determine the data flows and data inventory of the system to ensure that the DBNMS shall respect the following principles of the Data Privacy Act of 2012 - Proportionality, Integrity, and Legitimate Purpose. It also integrated features to ensure the security of the personal data that will be processed by the System.

 

  • Full Functionality — Positive-Sum, not Zero-Sum – During its development, the NPC ensured to harmonize and preserve both the privacy measures and proposed functionalities of the DBNMS. During its implementation, the need for additional features was also determined to be added. Since the PIA was conducted during the design phase, adding features without compromising the privacy measures can be made without issues.

 

  • End-to-End Security — Lifecycle Protection – One of the requirements that was emphasized during the planning stage is that every major stage of the development should undergo a security assessment. This is to ensure that all possible vulnerabilities will be addressed even before the completion of the DBNMS. In addition, several PIAs were conducted during its development to ensure that none of the privacy measures were neglected or removed from the system. Finally, prior to its deployment, a Vulnerability Assessment and Penetration Test (“VAPT”) was conducted by a recognized VAPT provider.

 

  • Visibility and Transparency – Keep it Open – Following best practices, a Just-in-Time (“JIT”) Privacy Notice pops up during sign up. This Privacy Notice is designed to be easily read and understood. Users are also given the option to read the full Notice by clicking on the link in the JIT version or at the bottom every page of the DBNMS to ensure that they are informed about how their personal data is processed and protected, as well as how to contact the Commission’s Data Protection Officer (“DPO”) in case of any concern.

 

 

  • Respect for User Privacy – Keep it User-Centric-Users of the DBNMS are empowered to exercise their privacy rights in the System. Aside from the security and privacy safeguards in place and the integration of privacy into the design of the system, users can also modify, edit, and delete their personal data. In addition, the contact details of the DPO are provided for any privacy-related concern while the email address of the DBNMS administrator is provided for other DBNMS concerns.

DBNMS LAUNCH

HOW TO USE DBNMS

All Breach Notifications and Annual Security Incident Reports (Annual Security Incident Report (“ASIR”) shall be submitted through the Data Breach Notification Management System (“DBNMS”) online platform (https//dbnms.privacy.gov.ph) . To guide you in navigating the DBNMS, please watch the videos through the links below:
1. How to create DBNMS account
2. How to submit a Personal Data Breach Notification report
3. How to comply with the required documents and information
4. How to submit an Annual Security Incident Report