PIA360 ADMINISTRATION
Privacy Notice
This separate administration module processes only information necessary to manage authorized PIA360 access and demonstrate accountability: administrator and managed-user identifiers, corporate email addresses, display names, assigned roles, access state, MFA policy state, session-security metadata, authentication outcomes, and audit events.
Purpose and lawful governance
Information is used to authenticate authorized administrators, apply least-privilege access, manage PIA roles, revoke access, investigate security events, and maintain accountability under the Data Privacy Act of 2012, its IRR, and applicable NPC issuances.
Minimization and protection
The module does not require PIA assessment content or data-subject records. Passwords are not stored in plaintext. MFA seeds are encrypted. Session and network identifiers are protected with keyed hashes where implemented. Access is restricted, logged, and subject to retention and disposal controls approved by the accountable organization.
Rights and inquiries
Requests for access, correction, objection, erasure or blocking, portability, complaint handling, and other applicable data-subject rights follow the organization’s approved privacy and DPO process.