Revenue Memorandum Circular · RMC
RMC No. 66-2023
To circularize the criminal penalties for violations of the provisions of Republic Act (RA) No. 10173 (Data Privacy Act of 2012) and the administrative penalties for violations of the Information and Communication Technology (ICT) Security Infrastructure System under Revenue Memorandum Order (RMO) No. 67-2010.
- Document type
- RMC
- Number
- 66
- Year
- 2023
- Text quality
- Not specified
Document text
Reference copy · verify against the official sourceRMC No. 66-2023 (June 9, 2023) circularizes the criminal penalties under the Data Privacy Act of 2012 (RA 10173) for offenses such as unauthorized processing, improper disposal, processing for unauthorized purposes, unauthorized access or intentional breach, concealment of security breaches, malicious disclosure, and unauthorized disclosure. Imprisonment and fine ranges differ depending on whether personal information or sensitive personal information is affected. The maximum penalty applies when the personal information of at least 100 persons is harmed, affected, or involved; public officers face an accessory penalty of disqualification from public office for a term double the criminal penalty imposed. The circular also refers to the administrative penalties for ICT Security Infrastructure offenses and additional circumstances under RMO No. 67-2010, stated in Sections II and III of the Circular.