1. DATA PRIVACY ORIENTATION
DATA PRIVACY ORIENTATION
TECHNOLOGY SUPPORT SERVICES UNIT
REPUBLIC ACT 10173
DATA PRIVACY ACT OF 2012
An Act Protecting Individual Personal Information in Information and Communications Systems in Government and the Private Sector, Creating for this Purpose a National Privacy Commission, and for Other Purposes.
TWO-FOLD MANDATE
TWO-FOLD MANDATE
It is the policy of the state to protect:
-
the interest of privacy of individuals
-
to ensure free flow of information promote innovation and growth
NATIONAL PRIVACY COMMISSION
An independent body mandated to administer and implement the DPA and its IRR.
FUNCTIONS
-
Rule making
-
Advisory
-
Public education
-
Compliance & monitoring
-
Complaints & investigation
-
Enforcement

KEY TERMS
DATA SUBJECT
An individual whose personal information, sensitive personal information, or privileged information is being processed.
PROCESSING
-
collection
-
recording
-
organization
-
storage, updating or modification
-
retrieval,
-
blocking
-
erasure or destruction of data
PERSONAL INFORMATION CONTROLLER (PIC)
A natural or juridical person, or any other body who controls the processing of personal information or instructs another to process personal data on its behalf.
PERSONAL INFORMATION PROCESSOR (PIP)
A natural or juridical person, or any other body to whom a PIC may outsource or instruct the processing of personal information.
DATA PROTECTION OFFICER (DPO)
Personal information controllers (PIC) and personal information processors (PIP) are required to appoint or designate a data protection officer (DPO). The DPO will ensure the compliance of the organization to the DPA.
PERSONAL INFORMATION
Refers to any information from which:
(a) the identity of an individual is apparent
(b) can be reasonably and directly ascertained by the entity holding the information
(c) when put together with other information would directly and certainly identify an
Individual
SENSTIVE PERSONAL INFORMATION
-
race
-
ethnic origin
-
marital status
-
age
-
color
-
religious, philosophical or political affiliations
-
health, education, genetic or sexual life
SENSTIVE PERSONAL INFORMATION
-
Proceeding for any offense committed or alleged to have been committed by an individual
-
government-issued ID's (SSS, GSIS, Philhealth, Pag-IBIG, LTO)
-
bank/credit card numbers
-
website visited
-
materials downloaded
SENSTIVE PERSONAL INFORMATION
-
any other information reflecting preferences and behavior of an individual
-
grievance information
-
discipline information
-
LOA reason
-
license revocation
PRIVILEGED INFORMATION
-
Husband or wife cannot testify against one another without consent on any communication received by either in confidence
-
Attorney-client relationship
-
Physician-patient relationship
-
Minister/priest-person making the confession
-
Public officer given information in official confidence
DATA BREACH
Refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
TYPES OF DATA BREACHES
1) Availability breach - resulting from loss, accidental or unlawful destruction of personal data
2) Integrity breach - resulting from alteration of personal data
3) Confidentiality breach - resulting from the unauthorized disclosure of or access to personal data
PRIVACY ECO-SYSTEM

SCOPE OF APPLICATION
DPA applies to the processing of all types of personal information and to any natural and juridical person involved in personal information processing including those personal information controllers and processors who, although not found or established in the Philippines, use equipment that are located here in the Philippines, or those who maintain an office, branch or agency in the Philippines.
EXCEPTION
-
Information about any individual who is or was an officer or employee of a government institution that relates to the position or functions of the individual.
(b) Information about an individual who is or was performing service under contract for a government institution that relates to the services performed.
-
Information relating to any discretionary benefit of a financial nature such as
granting of a license or permit given by the government to an individual.
(d) Personal information processed for journalistic, artistic, literary or research purposes.
(e) information necessary in order to carry out the functions of public authority.
(f) Information necessary for banks and other financial institutions under the jurisdiction of the independent, central monetary authority or Bangko Sentral ng Pilipinas to comply with the R.A 9510 (CISA Law), and R.A 9160 (AMLA) and other applicable laws.
(g) Personal information originally collected from residents of foreign jurisdictions.
RIGHTS OF THE DATA SUBJECT
-
Right to Information
-
Right to Object
-
Right to Access
-
Right to Correct
-
Right to Erase
-
Right to Damages
-
Right to Data Portability
-
Right to file a Complaint
RIGHTS OF THE DATA SUBJECT

OBLIGATIONS OF A PIC
-
The PIC should collect personal information for specified and legitimate purposes determined and declared before, or as soon as reasonably practicable after collection.
-
The PIC should process accurate, relevant and up to date personal information
-
The PIC should retain personal information only for as long as necessary for the fulfillment of the purposes for which the data was obtained. The information should be kept in a form which permits identification of data subjects for no longer than necessary.
-
The PIC should process personal information fairly and lawfully, and in accordance with the rights of a data subject.
-
The PIC should collect and process personal information adequately and not excessively
-
The PIC must implement reasonable and appropriate organizational, physical, and technical measures intended for the protection of personal information.
DATA PRIVACY PRINCIPLES
-
TRANSPARENCY
-
LEGITIMATE PURPOSE
-
PROPORTIONALITY
TRANSPARENCY
A data subject must be aware of the nature, purpose, and extent of the processing of his or her personal data, including the risks and safeguards involved, the identity of personal information controller, his or her rights as a data subject, and how these can be exercised.
HOW IS TRANSPARENCY SHOWN?
-
PRIVACY NOTICE
-
Statement made to a data subject (Directed to external stakeholders)
-
PRIVACY POLICY
-
Internal statement (within the organization)
-
CONSENT
-
The data subject agrees to the collection and processing of P.I.
CONSENT
The data subject agrees to the collection and processing of personal information
-
freely given
-
specific
-
informed indicating of will
Evidence by written, electronic or recorded means
-
signature
-
opt-inbox/clicking an icon
-
sending a confirmation email
-
oral confirmation
DO YOU ALWAYS NEED CONSENT?
-
No. Consent is just one criterion for lawful processing of both personal and sensitive personal information.
-
Consent will not always be the most appropriate basis for processing personal data.
-
PICs should choose the lawful basis that most closely reflects the true nature of the relationship with the individual and the purpose of the processing.
LAWFUL PROCESSING
PERSONAL INFORMATION
Consent
Law and Regulation
Protect Life
Contract
Legal Obligation
Public Order and Safety
Legitimate Interest
SENSITIVEPERSONAL INFORMATION
Consent
Law and Regulation
Protect Life
Medical Treatment
Court Proceedings, Legal Claims
PROCESSING WHICH MAY NOT NEED CONSENT

LEGITIMATE PURPOSE
The processing of information shall be compatible with a declared and specified purpose, which must not be contrary to law, morals or public policy.
PROPORTIONALITY
The processing of information shall be adequate, relevant, suitable, necessary, and not excessive in relation to a declared and specified purpose.
SECURITY MEASURES
TYPES OF SECURITY MEASURES
1) Physical
2) Organizational
3) Technical
REASONS FOR THE MEASURES (CIA)
1) Confidentiality
2) Integrity
3) Availability
PENALTIES

SECURITY MEASURES
DATA PRIVACY GOLDEN RULE
IF YOU CAN'T PROTECT IT, DON'T COLLECT IT.