DATA PRIVACY ORIENTATION

1. DATA PRIVACY ORIENTATION

DATA PRIVACY ORIENTATION

TECHNOLOGY SUPPORT SERVICES UNIT

REPUBLIC ACT 10173

DATA PRIVACY ACT OF 2012

An Act Protecting Individual Personal Information in Information and Communications Systems in Government and the Private Sector, Creating for this Purpose a National Privacy Commission, and for Other Purposes.

 

TWO-FOLD MANDATE

TWO-FOLD MANDATE

It is the policy of the state to protect:

  • the interest of privacy of individuals

  • to ensure free flow of information promote innovation and growth 

 

NATIONAL PRIVACY COMMISSION

An independent body mandated to administer and implement the DPA and its IRR.

FUNCTIONS

  • Rule making

  • Advisory

  • Public education

  • Compliance & monitoring

  • Complaints & investigation

  • Enforcement

 

KEY TERMS

DATA SUBJECT

An individual whose personal information, sensitive personal information, or privileged information is being processed.

 

PROCESSING

  • collection

  • recording

  • organization

  • storage, updating or modification

  • retrieval, 

  • blocking

  • erasure or destruction of data

 

PERSONAL INFORMATION CONTROLLER (PIC)

A natural or juridical person, or any other body who controls the processing of personal information or instructs another to process personal data on its behalf.

 

PERSONAL INFORMATION PROCESSOR (PIP)

A natural or juridical person, or any other body to whom a PIC may outsource or instruct the processing of personal information.

 

DATA PROTECTION OFFICER (DPO)

Personal information controllers (PIC) and personal information processors (PIP) are required to appoint or designate a data protection officer (DPO). The DPO will ensure the compliance of the organization to the DPA.

 

PERSONAL INFORMATION

Refers to any information from which:

         (a) the identity of an individual is apparent

         (b) can be reasonably and directly ascertained by the entity holding the information

         (c) when put together with other information would directly and certainly identify an

              Individual

 

SENSTIVE PERSONAL INFORMATION



  • race

  • ethnic origin

  • marital status

  • age

  • color 

  • religious, philosophical or political affiliations

  • health, education, genetic or sexual life


SENSTIVE PERSONAL INFORMATION

  • Proceeding for any offense committed or alleged to have been committed by an individual

  • government-issued ID's (SSS, GSIS, Philhealth, Pag-IBIG, LTO)

  • bank/credit card numbers

  • website visited

  • materials downloaded

 

SENSTIVE PERSONAL INFORMATION

  • any other information reflecting preferences and behavior of an individual

  • grievance information

  • discipline information

  • LOA reason

  • license revocation 

 

PRIVILEGED INFORMATION

  • Husband or wife cannot testify against one another without consent on any communication received by either in confidence

  • Attorney-client relationship

  • Physician-patient relationship

  • Minister/priest-person making the confession

  • Public officer given information in official confidence

 

DATA BREACH

Refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed. 

 

TYPES OF DATA BREACHES

1) Availability breach - resulting from loss, accidental or unlawful destruction of     personal data

2) Integrity breach - resulting from alteration of personal data

3) Confidentiality breach - resulting from the unauthorized disclosure of or access to     personal data










PRIVACY ECO-SYSTEM

 

SCOPE OF APPLICATION

DPA applies to the processing of all types of personal information and to any natural and juridical person involved in personal information processing including those personal information controllers and processors who, although not found or established in the Philippines, use equipment that are located here in the Philippines, or those who maintain an office, branch or agency in the Philippines. 

 

EXCEPTION

  1. Information about any individual who is or was an officer or employee of a government institution that relates to the position or functions of the individual.

 

(b)      Information about an individual who is or was performing service under contract for           a government institution that relates to the services performed.

 

  1.     Information relating to any discretionary benefit of a financial nature such as   

           granting of a license or permit given by the government to an individual.

 

(d) Personal information processed for journalistic, artistic, literary or research purposes.

 

(e) information necessary in order to carry out the functions of public authority.

 

(f) Information necessary for banks and other financial institutions under the jurisdiction of the independent, central monetary authority or Bangko Sentral ng Pilipinas to comply with the R.A 9510 (CISA Law), and R.A 9160 (AMLA) and other applicable laws.

 

(g) Personal information originally collected from residents of foreign jurisdictions.

 

RIGHTS OF THE DATA SUBJECT

  • Right to Information

  • Right to Object

  • Right to Access

  • Right to Correct

  • Right to Erase

  • Right to Damages

  • Right to Data Portability

  • Right to file a Complaint

 

RIGHTS OF THE DATA SUBJECT

 

OBLIGATIONS OF A PIC

  • The PIC should collect personal information for specified and legitimate purposes determined and declared before, or as soon as reasonably practicable after collection.

  • The PIC should process accurate, relevant and up to date personal information

  • The PIC should retain personal information only for as long as necessary for the fulfillment of the purposes for which the data was obtained. The information should be kept in a form which permits identification of data subjects for no longer than necessary.

  • The PIC should process personal information fairly and lawfully, and in accordance with the rights of a data subject.

  • The PIC should collect and process personal information adequately and not excessively

  • The PIC must implement reasonable and appropriate organizational, physical, and technical measures intended for the protection of personal information.

 

DATA PRIVACY PRINCIPLES

  1. TRANSPARENCY

  2. LEGITIMATE PURPOSE

  3. PROPORTIONALITY

 

TRANSPARENCY

A data subject must be aware of the nature, purpose, and extent of the processing of his or her personal data, including the risks and safeguards involved, the identity of personal information controller, his or her rights as a data subject, and how these can be exercised. 

 

HOW IS TRANSPARENCY SHOWN?

  • PRIVACY NOTICE

    • Statement made to a data subject (Directed to external stakeholders)

  • PRIVACY POLICY

    • Internal statement (within the organization)

  • CONSENT

    • The data subject agrees to the collection and processing of P.I.

CONSENT

The data subject agrees to the collection and processing of personal information

  • freely given

  • specific

  • informed indicating of will

Evidence by written, electronic or recorded means

  • signature

  • opt-inbox/clicking an icon

  • sending a confirmation email

  • oral confirmation

DO YOU ALWAYS NEED CONSENT?

  • No. Consent is just one criterion for lawful processing of both personal and sensitive personal information.

  • Consent will not always be the most appropriate basis for processing personal data.

  • PICs should choose the lawful basis that most closely reflects the true nature of the relationship with the individual and the purpose of the processing.

 

LAWFUL PROCESSING

PERSONAL INFORMATION

Consent

Law and Regulation

Protect Life

Contract

Legal Obligation

Public Order and Safety

Legitimate Interest

 

SENSITIVEPERSONAL INFORMATION

Consent

Law and Regulation

Protect Life

Medical Treatment

Court Proceedings, Legal Claims




PROCESSING WHICH MAY NOT NEED CONSENT

 

LEGITIMATE PURPOSE

The processing of information shall be compatible with a declared and specified purpose, which must not be contrary to law, morals or public policy.

 

PROPORTIONALITY

The processing of information shall be adequate, relevant, suitable, necessary, and not excessive in relation to a declared and specified purpose. 

 

SECURITY MEASURES

TYPES OF SECURITY MEASURES

1) Physical

2) Organizational

3) Technical

REASONS FOR THE MEASURES (CIA)

1) Confidentiality

2) Integrity

3) Availability

 

PENALTIES

 

SECURITY MEASURES

DATA PRIVACY GOLDEN RULE

IF YOU CAN'T PROTECT IT, DON'T COLLECT IT.