RMC No. 66-2023 — Circularizes the criminal penalties for violation of provisions of Republic Act (RA) No. 10173 or the Data Privacy Act of 2012 and administrative penalties for violation of Information and Communication Technology (ICT) Security Infrastructure System under Revenue Memorandum Order (RMO) No. 67-2010
REPUBLIC OF THE PHILIPPINES
BUREAU OF INTERNALREVENUE DEPARTMENT OF FINANCE Quezon City JUN D 9 2073
Revenue MEMiOranduM CIrCuLar no. 66-2023
SUBJECT: Circuiarizing the Criminal Penalties for Violation of Provisions of
under Revenue Memorandum Crder (RMO) No. 67-2010 Republic Act (RA) No. 10173 or the Data Privacy Act of 2012 and Communicatior Technology (IC"T) Security Infrastructure System Administrative Penalties for Violation of Inforrnation and
TO: All Internal Revenue Employees,Officials and Others Concerned
To afford full protection to a person's right to privacy and ensure that personal
penalties provided under Chapter VIii of the Data Privacy Act of 2012 and Information implemented by Revenue Memorandum Order (RMO) No. 67-2010 shall be imposed information and sensitive personal information are clisclosed only as permitted under existing laws, this Circular is hereby issued to remind all revenuers that in case of unauthorized access, or leaks or premature disclosure of said information;the and Communication Technology (ICT) Security Infrastructure Offenses, as
PENALTIES UNDER THE DATA PRIVACY ACT OF 2012
KIND OF INFORMATION AFFECTED OFFENSE INFORMATION PERSONAL SENSITIVE PERSONAL INFORMATION
Processing Due to Negligence. Accessing Information Unauthorized from 1year to 3years P500K to P2.0Million fine of not less than Imprisonment AND firie of not less than P500Kto from 3years to6years inprisonment P4.0.Million AND.
(knowingly or negligently Improper Disposal dispose, discard, or
individual in an area accessible to the public or has otherwise placed the personal information of an individual in its abandon the personal information of an fine of not less than P100Kto 500K from 6 moriths Imprisonment to2years AND fine of not less than P100K to from 1 yearto 3years Imprisonment P1.0 Million AND
container for trash collection).
BUREAU OF INTERNAL REVENUE NNNTITN Q:45 JUN o 9 2023 0 3
RECORDS MGT.DIVISION CST
KIND OF INFORMATION AFFECTED OFFeNSE INFORMATION PERSONAL SENSITIVE PERSONAL INFORMATION
Unauthorized Purposes Processing for from 1 year micnths P500K to P1.0Million fine of not less than Imprisonment to 5 years AND from 2years to7years P500K to P2.0Million fine of not less than Imprisonnent AND
Unauthorized Access breaking in any way into system storage) or Intentional Breach confidentiality and security systems, (violating data fineof rioless than P500K to P2.0 Million nprisonment from 1year to 3 years TAND
personal information Security Breaches involving sensitive C:oncealment of mprisonme finotrolossthanPi0oK to P1.0 Million from lyear 6months to5years ANDR
by PIPPIC,or its agents, employees Malicious Disclosure Imprisoriment froniyear6 months to5vears finofhotesthan P500K to Pl0 Million HANDE
Disclosure Unauthorized from 1 year to 3vears P500K.to P1.0 Million fine of not less thar Imprisonment AND finie ofnot less than P500Kto from 3years tol5years Imprisonment PTDMilion HAND!
of acts Combination or series findof not leasthan P10 Mllion to P5.0 Milion mprist ren1 It from 3 years to 6 years AND
mentioned actions. (Sec. 35, RA 10173) for the preceding offenses shall be imposed when the personal information of at least one hundred (100) persons is harmed, affected or irivolved as the result of the above Note that the maximum penalty in the scale of penaities respectively provided
as defined in the Administrative Code of the Philippines in the exercise of his or her duties, an accessory penalty consisting in the disgualification to occupy public office for a term double the term of criminal penalty imposed shall he applied. (Sec. 36, RA 10173) When the offender or the persor responsible for the offense is a public officer Page 2 of 6 BUREAU OF INTERNALREVENUE NNTIIYTN JUN 0 9'2023( .45 DM
RECORDS MGT.DIVISION JUJ JUJU
administrative case/s if the offender is al public official and employee. The penalties imposed are without prejudice to the filing of appropriate
I PeNAltieS For ict SecuRIty INFrAStruCtuRE OFFEnSeS uNder REVENUE MEMORANDUM ORDER (RMO) NO. 67-2010
ACTS COMMItTED OFFENSE Penalty
G Disciosure of sensitive infornation Gross Neglect Of Dismissal from
Unsecured Super User and other any event or incident of violations and/or without management approval powerful accounts Disclosure of user ID and password without consent Failure to disclose to proper authorities security breaches discovered by and/or made known to him/her Other Analogous cases Duty service on the first offense
G Unauthorized access to operating Unauthorized access to database Unauthorized user access to BIR Offices Unauthorized alterations to system Unauthorized access to the network system objects and files Grave Misconduct service on the first Dismissal from offense
0 Unauthorized access to application systems Unauthorized access to machines (PCs)
3 and data transmitting applications or data) Unauthorized copying of BIR software Instaliation of unauthorized software Unauthorized access to external storage servers, peripherais, etc., holdirig or
media (flash drives, optical-media. etc.
Adding an unauthorized PC or other Unauthorized users gaining access to the system via logged-in workstations devices to the network Disclosure of user iD and password even with his/her consent
his/her identity on the internet or in any software, monitoring tool installed on any system or network Misrepresentation or falsification of Disruption of the operations of the BIR's technology systems Unauthorized disabling of hardware, BIR system or communications information and communication Page 3 of 6 BUREAUOEINtERNAL REVEnUE NaiiyN JUN o 9 2UZ3l &:45
RECOrdS MGT. DIVISION CJGA
ACtS CoMMIttED OFFENSE Penalty
e Abuse of access privileges
Unauthorized download, installation, storage or transmittal of software not Unauthorized probing or cracking of security mechanisms either at BIR or Iicensed to the BIR
external sites O Unauthorized establishment of internet
or other external network connections 0 Unauthorized setting-up of proxy servers
Other analogous cases
0 Unauthorized alterations (addition, Falsification of Dismissal from
A Other analogous cases modification, deletion) to printouts (reports, correspondences, etc.) ancl electronic files official documents service on the first offense
I DiSciPlinArY Action WitH THeir correspoNding PenALties UNDER RMO NO. 67-2010 AdditionAL circumstanCEs AS GrOuNDs For AdmIiNistRAtive
ACts CoMMitteD OFFense Penalty
andlor security breaches discovered by Other analogous cases Disciosure of sensitive information Unsecured superuser and without consent any event or incident of violations and/or made known to him/her without priormanagement approval powerful accounts Disclosure of user id and password Failure to disclose to proper authorities other Grave uisconduct service on the first Dismissal from offense
BUREAU OF INTERNAL REVENUE NnTTN Q:qE"p JUN 6 9 2OZ3 I
Page 4 of G RECOrdS MGt. DiViSION GUGT
ACtS CoMMIttED OFFeNse Penalty
Unauthorized access to the operating Unauthorized user access to BIR Unauthorized access to the database. Unauthorized alterations (addition, offices system Gross Negiect Of Duty service on the first Dismissal from offense
and iogs Unauthorized access to the network Unauthorized access to application objects and files, application, data modification, deletion) to system
( Unauthorized access to machines systems
(PCs, servers, peripherals, etc.) holding or transmitting applications or data
Unauthorized disabling of hardware, etc.) and electronic files devices to the network Disclosure of user id and password any BIR system or communications BIR's information and communication Unauthorized copying of BiR software and data Installation of unauthorized software storage media (tape cartridges, flash etc.) Unauthorized users gaining access to the system via logged-in workstations Adding an unauthorized PC or other even with his/her consent : Misrepresentation or falsification of his/her identity on the internet or in Disruption of the operations of the technoiogy systems software, monitoring tool installed on Unauthorized access to printed output (reports, correspondences, Unauthorized access to external - drives, optical media, floppy disks, 1
Unauthorized probing or cracking of Unauthorized setting-up of proxy security mechanisms either at BiR or Unauthorized establishment of internet or other external network Unauthorized download, installation, licensed to the BIR connections any system or network Abuse of access privileges storage or transmittal of software not external sites BUREAU OF INTERNAL REVENUE servers TnTTIY
Page (5 of t) jUN'O g 2UZ3 aCS P0
records Mgt. division U U
ACtS COMMIttED OFFENSE PenaltY
Unauthorized alterations (addition, modification, deletion) to printouts pfficial documents FaIsification of service on the first Dismissal from
(reports, correspondences, etc.) and offense electronic files Other analogous cases
For your strict compliance.
Cor'nmissioner of Inte Romeo d. LumaGu, Jr. grnal Reveriue
L BUREAU OF INTERNAL REVENUE NnnTTY JUN 0 9 2023D} a:q5 p
Page 6 of G RECOrdS MGt. DIVISION e UJ
Want an analysis of this document?
Ask ASG Legal AI to summarize it, compare it with other rulings, or explain how it applies to your situation — it researches from this same library.