Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

13 February 2020

Coffee Bean & Tea Leaf


Eastwood Mall Branch

Gentlemen:

I write to inform you that there was a privacy breach possibly committed by one of your
employees.

I am a regular customer of Coffee Bean & Tea Leaf (“CBTL” for brevity) particularly in
your branch at Eastwood Mall.

As a regular customer, I am a holder of CBTL Swirl Card with Swirl Card No:
____________ where I disclosed my personal information upon registration.

Recently, I was informed that my name was disclosed to a certain person where I have
personal issues with. I was shocked to know that such person was able to get hold of my
name despite my anonymity on all of my social media accounts. Thereafter, I did some
investigation and found out that such person, whom I have personal issues with, is a
friend of one of your employees. Then I realized that once I order in your store and present
my Swirl Card, my name will reflect at the cashier monitor and will be printed in the receipt.
Then I confronted the other half of the person that I have personal issues with and that
other half person confirmed that it was Mr. X, one of your employees, who disclosed my
name.

In this regard, I wish to remind you that pursuant to Republic Act No. 10173 otherwise
known as Data Privacy Act of 2012, “The personal information controller must
implement reasonable and appropriate organizational, physical and technical
measures intended for the protection of personal information against any
accidental or unlawful destruction, alteration and disclosure, as well as against any
other unlawful processing”, that “Each personal information controller is responsible for
personal information under its control or custody” and any Malicious Disclosure of
personal information is prohibited under the said law.

Here, CBTL Management, as the personal information controller, must ensure that the
personal information of its customers, obtained through registration in your Swirl Card
System, must be free from any accidental and unlawful disclosure, by and through its
employees and any Malicious Disclosure of personal information may be a violation of
the provisions of the Data Privacy Act.
I will no longer disclose the name of your employee. I would just like to inform you that
any repetition of this will prompt me to do all the necessary in order to protect my privacy.

Thank you and best regards,

Customer

You might also like