Personal Data Breach Response
Last updated: July 20, 2026
PlayKorte maintains a documented personal data breach response procedure aligned with Republic Act No. 10173 (Data Privacy Act of 2012) and NPC Circular 16-03. This page summarizes the commitments in that procedure.
What Counts as a Breach
We treat any of the following as a potential personal data breach and respond immediately:
- Unauthorized access to personal data.
- Accidental disclosure, deletion, or corruption of personal data.
- Loss or compromise of credentials, backups, or storage containing personal data.
- Notice from a third-party service provider that PlayKorte data may have been exposed.
What We Do
When we become aware of a potential breach, we:
- Contain it immediately — rotate credentials, revoke access, and isolate affected systems.
- Assess it — confirm what data was involved, how many people are affected, and the likely risk of harm.
- Notify — for notifiable personal data breaches, we notify the National Privacy Commission (NPC) and affected data subjects within seventy-two (72) hours from knowledge of the breach.
- Follow up — we issue updates to the NPC and affected data subjects when material new information is identified, and we document root cause and corrective actions after containment.
We preserve incident evidence throughout for legal, technical, and regulatory review.
Contact
- Data protection concerns: privacy@playkorte.com
- General support: support@playkorte.com
- National Privacy Commission: https://www.privacy.gov.ph · info@privacy.gov.ph