revenue_memorandum_circular RMC No. 66-2023RMC No. 66-2023 2023-06-09

RMC No. 66-2023 — Circularizes the criminal penalties for violation of provisions of Republic Act (RA) No. 10173 or the Data Privacy Act of 2012 and administrative penalties for violation of Information and Communication Technology (ICT) Security Infrastructure System under Revenue Memorandum Order (RMO) No. 67-2010

REPUBLIC OF THE PHILIPPINES

BUREAU OF INTERNALREVENUE DEPARTMENT OF FINANCE Quezon City JUN D 9 2073

Revenue MEMiOranduM CIrCuLar no. 66-2023

SUBJECT: Circuiarizing the Criminal Penalties for Violation of Provisions of

under Revenue Memorandum Crder (RMO) No. 67-2010 Republic Act (RA) No. 10173 or the Data Privacy Act of 2012 and Communicatior Technology (IC"T) Security Infrastructure System Administrative Penalties for Violation of Inforrnation and

TO: All Internal Revenue Employees,Officials and Others Concerned

To afford full protection to a person's right to privacy and ensure that personal

penalties provided under Chapter VIii of the Data Privacy Act of 2012 and Information implemented by Revenue Memorandum Order (RMO) No. 67-2010 shall be imposed information and sensitive personal information are clisclosed only as permitted under existing laws, this Circular is hereby issued to remind all revenuers that in case of unauthorized access, or leaks or premature disclosure of said information;the and Communication Technology (ICT) Security Infrastructure Offenses, as

PENALTIES UNDER THE DATA PRIVACY ACT OF 2012

KIND OF INFORMATION AFFECTED OFFENSE INFORMATION PERSONAL SENSITIVE PERSONAL INFORMATION

Processing Due to Negligence. Accessing Information Unauthorized from 1year to 3years P500K to P2.0Million fine of not less than Imprisonment AND firie of not less than P500Kto from 3years to6years inprisonment P4.0.Million AND.

(knowingly or negligently Improper Disposal dispose, discard, or

individual in an area accessible to the public or has otherwise placed the personal information of an individual in its abandon the personal information of an fine of not less than P100Kto 500K from 6 moriths Imprisonment to2years AND fine of not less than P100K to from 1 yearto 3years Imprisonment P1.0 Million AND

container for trash collection).

BUREAU OF INTERNAL REVENUE NNNTITN Q:45 JUN o 9 2023 0 3

RECORDS MGT.DIVISION CST

KIND OF INFORMATION AFFECTED OFFeNSE INFORMATION PERSONAL SENSITIVE PERSONAL INFORMATION

Unauthorized Purposes Processing for from 1 year micnths P500K to P1.0Million fine of not less than Imprisonment to 5 years AND from 2years to7years P500K to P2.0Million fine of not less than Imprisonnent AND

Unauthorized Access breaking in any way into system storage) or Intentional Breach confidentiality and security systems, (violating data fineof rioless than P500K to P2.0 Million nprisonment from 1year to 3 years TAND

personal information Security Breaches involving sensitive C:oncealment of mprisonme finotrolossthanPi0oK to P1.0 Million from lyear 6months to5years ANDR

by PIPPIC,or its agents, employees Malicious Disclosure Imprisoriment froniyear6 months to5vears finofhotesthan P500K to Pl0 Million HANDE

Disclosure Unauthorized from 1 year to 3vears P500K.to P1.0 Million fine of not less thar Imprisonment AND finie ofnot less than P500Kto from 3years tol5years Imprisonment PTDMilion HAND!

of acts Combination or series findof not leasthan P10 Mllion to P5.0 Milion mprist ren1 It from 3 years to 6 years AND

mentioned actions. (Sec. 35, RA 10173) for the preceding offenses shall be imposed when the personal information of at least one hundred (100) persons is harmed, affected or irivolved as the result of the above Note that the maximum penalty in the scale of penaities respectively provided

as defined in the Administrative Code of the Philippines in the exercise of his or her duties, an accessory penalty consisting in the disgualification to occupy public office for a term double the term of criminal penalty imposed shall he applied. (Sec. 36, RA 10173) When the offender or the persor responsible for the offense is a public officer Page 2 of 6 BUREAU OF INTERNALREVENUE NNTIIYTN JUN 0 9'2023( .45 DM

RECORDS MGT.DIVISION JUJ JUJU

administrative case/s if the offender is al public official and employee. The penalties imposed are without prejudice to the filing of appropriate

I PeNAltieS For ict SecuRIty INFrAStruCtuRE OFFEnSeS uNder REVENUE MEMORANDUM ORDER (RMO) NO. 67-2010

ACTS COMMItTED OFFENSE Penalty

G Disciosure of sensitive infornation Gross Neglect Of Dismissal from

Unsecured Super User and other any event or incident of violations and/or without management approval powerful accounts Disclosure of user ID and password without consent Failure to disclose to proper authorities security breaches discovered by and/or made known to him/her Other Analogous cases Duty service on the first offense

G Unauthorized access to operating Unauthorized access to database Unauthorized user access to BIR Offices Unauthorized alterations to system Unauthorized access to the network system objects and files Grave Misconduct service on the first Dismissal from offense

0 Unauthorized access to application systems Unauthorized access to machines (PCs)

3 and data transmitting applications or data) Unauthorized copying of BIR software Instaliation of unauthorized software Unauthorized access to external storage servers, peripherais, etc., holdirig or

media (flash drives, optical-media. etc.

Adding an unauthorized PC or other Unauthorized users gaining access to the system via logged-in workstations devices to the network Disclosure of user iD and password even with his/her consent

his/her identity on the internet or in any software, monitoring tool installed on any system or network Misrepresentation or falsification of Disruption of the operations of the BIR's technology systems Unauthorized disabling of hardware, BIR system or communications information and communication Page 3 of 6 BUREAUOEINtERNAL REVEnUE NaiiyN JUN o 9 2UZ3l &:45

RECOrdS MGT. DIVISION CJGA

ACtS CoMMIttED OFFENSE Penalty

e Abuse of access privileges

Unauthorized download, installation, storage or transmittal of software not Unauthorized probing or cracking of security mechanisms either at BIR or Iicensed to the BIR

external sites O Unauthorized establishment of internet

or other external network connections 0 Unauthorized setting-up of proxy servers

Other analogous cases

0 Unauthorized alterations (addition, Falsification of Dismissal from

A Other analogous cases modification, deletion) to printouts (reports, correspondences, etc.) ancl electronic files official documents service on the first offense

I DiSciPlinArY Action WitH THeir correspoNding PenALties UNDER RMO NO. 67-2010 AdditionAL circumstanCEs AS GrOuNDs For AdmIiNistRAtive

ACts CoMMitteD OFFense Penalty

andlor security breaches discovered by Other analogous cases Disciosure of sensitive information Unsecured superuser and without consent any event or incident of violations and/or made known to him/her without priormanagement approval powerful accounts Disclosure of user id and password Failure to disclose to proper authorities other Grave uisconduct service on the first Dismissal from offense

BUREAU OF INTERNAL REVENUE NnTTN Q:qE"p JUN 6 9 2OZ3 I

Page 4 of G RECOrdS MGt. DiViSION GUGT

ACtS CoMMIttED OFFeNse Penalty

Unauthorized access to the operating Unauthorized user access to BIR Unauthorized access to the database. Unauthorized alterations (addition, offices system Gross Negiect Of Duty service on the first Dismissal from offense

and iogs Unauthorized access to the network Unauthorized access to application objects and files, application, data modification, deletion) to system

( Unauthorized access to machines systems

(PCs, servers, peripherals, etc.) holding or transmitting applications or data

Unauthorized disabling of hardware, etc.) and electronic files devices to the network Disclosure of user id and password any BIR system or communications BIR's information and communication Unauthorized copying of BiR software and data Installation of unauthorized software storage media (tape cartridges, flash etc.) Unauthorized users gaining access to the system via logged-in workstations Adding an unauthorized PC or other even with his/her consent : Misrepresentation or falsification of his/her identity on the internet or in Disruption of the operations of the technoiogy systems software, monitoring tool installed on Unauthorized access to printed output (reports, correspondences, Unauthorized access to external - drives, optical media, floppy disks, 1

Unauthorized probing or cracking of Unauthorized setting-up of proxy security mechanisms either at BiR or Unauthorized establishment of internet or other external network Unauthorized download, installation, licensed to the BIR connections any system or network Abuse of access privileges storage or transmittal of software not external sites BUREAU OF INTERNAL REVENUE servers TnTTIY

Page (5 of t) jUN'O g 2UZ3 aCS P0

records Mgt. division U U

ACtS COMMIttED OFFENSE PenaltY

Unauthorized alterations (addition, modification, deletion) to printouts pfficial documents FaIsification of service on the first Dismissal from

(reports, correspondences, etc.) and offense electronic files Other analogous cases

For your strict compliance.

Cor'nmissioner of Inte Romeo d. LumaGu, Jr. grnal Reveriue

L BUREAU OF INTERNAL REVENUE NnnTTY JUN 0 9 2023D} a:q5 p

Page 6 of G RECOrdS MGt. DIVISION e UJ

Want an analysis of this document?

Ask ASG Legal AI to summarize it, compare it with other rulings, or explain how it applies to your situation — it researches from this same library.