Secure collection
Personal or company documents shall be requested only through an approved form using encrypted HTTPS connections, defined access permissions, and a documented review process.
Responsible Digital Operations
How PFA approaches website security, protects submitted information, and helps visitors use online services safely.
Personal or company documents shall be requested only through an approved form using encrypted HTTPS connections, defined access permissions, and a documented review process.
Access shall be limited to authorized people with a legitimate business need and removed when responsibilities change. Administrative accounts shall use strong authentication.
Records shall be kept only for approved purposes and retention periods, then securely deleted, anonymized, or disposed of according to policy and applicable obligations.
Website software, integrations, user access, backups, and hosting shall be reviewed and maintained according to risk, including timely updates and recovery planning.
For visitors and applicants
The membership form stores submissions as private administrator-only records. Uploaded documents are held in protected storage and are available through permission-checked download links. An alert is sent to PFA's designated application mailbox; administrators can disable file attachments if mailbox limits require notifications to contain only the secure review link.
Suspected unauthorized access, disclosure, loss, alteration, or misuse shall be escalated promptly through PFA’s internal incident process. Reports shall describe the issue without attaching personal data unless a protected channel has been provided.
Do not test, scan, exploit, disrupt, or access data without written authorization. If you believe you found a security issue, report it privately through PFA’s official contact channel and allow reasonable time for investigation before public disclosure.
The Philippine National Privacy Commission explains that organizations processing personal data shall implement reasonable and appropriate organizational, physical, and technical measures. See the NPC’s Data Security guidance.