Answer First
Primary Text
SIM Register.All PTEs shall maintain their own database containing information required under this Act. The database shall strictly serve as a SIM Register to be used by PTEs to process, activate or deactivate a SIM or subscription and shall not be used for any other purpose, unless otherwise provided under this Act. The successful submission and acceptance of the required registration form shall serve as the certification of registration by the end-user.
The registration required under this Act shall be implemented at no cost to the end-users.
In the recordkeeping of information, PTEs shall ensure that the end-users' data are secured and protected at all time. The PTEs shall comply with the minimum information security standards prescribed by the DICT consistent with internationally accepted cybersecurity standards and relevant laws, rules and regulations.
The DICT shall establish and perform an annual audit on PTEs' compliance with information security standards.
In case of any change in the information of the end-user, or the loss of the SIM, death of the end-user, or any request for deactivation, the end-user shall immediately inform the PTE through its facility established for such purpose:Provided,That in the case of death of an end-user, such fact shall be reported to the concerned PTE by the immediate family, relatives, or guardian.
In case of any change in the information of the end-user, the concerned PTE shall clearly note such change in its database.
In case of loss of the SIM, death of the end-user, or request for deactivation, the concerned PTE shall deactivate said SIM within twenty-four (24) hours from the report of the end-user, immediate family, relatives or guardian.
Provided,That regardless of any deactivation, the relevant data and information shall be retained by the PTE pursuant to the pertinent provisions of this Act, which is ten (10) years.
In case of a cyber-attack on the SIM Register, the incident shall be reported to the DICT within twenty-four (24) hours of detection.1a⍵⍴h!1
PTEs shall provide user-friendly reporting mechanisms for their respective end-users upon the latter's receipt of any potentially fraudulent text or call, and shall, upon due investigation, deactivate, either temporarily or permanently, the SIM used for the fraudulent text or call.
Use With Care
Definitions and exceptions often appear before or after this text.
Court decisions may interpret, limit, or apply this provision.
Confirm amendment, repeal, effectivity, and official publication.