0% found this document useful (0 votes)
140 views6 pages

Notes On Data Privacy Act

(1) The document summarizes key aspects of the Philippines' Data Privacy Act, including its policy goals of protecting privacy and ensuring free flow of information, as well as definitions of personal information, sensitive personal information, and the roles of controllers and processors. (2) Personal information refers to any recorded information that can directly or indirectly identify a person. Sensitive personal information includes information about an individual's race, health, religion, and criminal proceedings. (3) The Act applies to all who process personal data in the Philippines or of Filipinos abroad. Personal information controllers are responsible for personal data collection and processing, while processors carry out these functions on controllers' instructions.

Uploaded by

Rad Isnani
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
140 views6 pages

Notes On Data Privacy Act

(1) The document summarizes key aspects of the Philippines' Data Privacy Act, including its policy goals of protecting privacy and ensuring free flow of information, as well as definitions of personal information, sensitive personal information, and the roles of controllers and processors. (2) Personal information refers to any recorded information that can directly or indirectly identify a person. Sensitive personal information includes information about an individual's race, health, religion, and criminal proceedings. (3) The Act applies to all who process personal data in the Philippines or of Filipinos abroad. Personal information controllers are responsible for personal data collection and processing, while processors carry out these functions on controllers' instructions.

Uploaded by

Rad Isnani
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 6

Notes on Data Privacy Act Simply state: Information or combination

From the Lecture of Prof. Sergio Ceniza of information that will likely identify the
Jurists Bar Review Center 6/16/2019 person.
Prepared by Harradier P. Isnani

Pls note: Some portions skipped by Sensitive Personal Information


Prof. Ceniza are indicated as such, but
please read them anyway. SEC. 3. Definition of Terms
.
Declaration of Policy (l) Sensitive personal information refers
to personal information:
SEC. 2. Declaration of Policy. – It is the
policy of the State to protect the (1) About an individual’s race, ethnic
fundamental human right of privacy, of origin, marital status, age, color, and
communication while ensuring free flow religious, philosophical or political
of information to promote innovation and affiliations;
growth. The State recognizes the vital
role of information and communications (2) About an individual’s health,
technology in nation-building and its education, genetic or sexual life of a
inherent obligation to ensure that person, or to any proceeding for any
personal information in information and offense committed or alleged to have
communications systems in the been committed by such person, the
government and in the private sector are disposal of such proceedings, or the
secured and protected. sentence of any court in such
proceedings;
Probable question (PQ): What is the
Policy of the Data Privacy Act (DPA)? - Health status of patients in
hospitals cannot be released by
hospital staff.
Personal Information - Inmates in Bureau of Corrections
without political rights: BuCor
SEC. 3. Definition of Terms. may not reveal information about
inmates because it is also
(g) Personal information refers to any covered by DPA
information whether recorded in a
material form or not, from which the (3) Issued by government agencies
identity of an individual is apparent or peculiar to an individual which includes,
can be reasonably and directly but not limited to, social security
ascertained by the entity holding the numbers, previous or current health
information, or when put together with records, licenses or its denials,
other information would directly and suspension or revocation, and tax
certainly identify an individual. returns; and

- Should be a combination of - Building security requiring visitors


certain information that will to enter name, address, etc. in
identify the person (e.g. name + the security logbook constitutes
picture) data breach since the next
- Without consent of the person, visitors would easily gain access
release of information will to such information.
constitute data breach. - In the same light, when building
- The person who owns the security requires visitors to
information is called the Data surrender their IDs, the security
Subject. personnel must handle and
secure the IDs properly to ensure
PQ: What is personal information? prying eyes are not able to easily
Answer(A): No need to cite verbatim to gain access to all the information.
provision above. In one complaint filed before the

1
NPC, the security guard merely disclose personal information on his or
attached the IDs to a clip and her behalf. The term excludes:
placed them on the table in a
disorganized manner. In this (1) A person or organization who
case, there is a data breach. performs such functions as instructed by
(Not an SC case, but NPC ruling) another person or organization; and

(4) Specifically established by an (2) An individual who collects, holds,


executive order or an act of Congress to processes or uses personal information
be kept classified. in connection with the individual’s
personal, family or household affairs.

Scope (i) Personal information processor refers


to any natural or juridical person
SEC. 4. Scope. – This Act applies to the qualified to act as such under this Act to
processing of all types of personal whom a personal information controller
information and to any natural and may outsource the processing of
juridical person involved in personal personal data pertaining to a data
information processing including those subject.
personal information controllers and
processors who, although not found or - In a setting where the employer
established in the Philippines, use company provides for an HMO
equipment that are located in the coverage for its employee, the
Philippines, or those who maintain an employee provides the employer
office, branch or agency in the the necessary personal
Philippines information which the employer
then transmits to the HMO
- If the person is holding on to provider.
sensitive or personal information, o The employee is the Data
they are covered by the law for as Subject. He owns the
long as the information comes personal information.
into (Prof. used the term reside) o The employer is the
the Philippines. Controller because it
- Whether those information are controls the flow of data.
being used inside or outside of The controller is given the
the Philippines, they are still duty and obligation to
covered by the law. Even if the handle the data with care
source of information is outside of and confidence.
the Philippines, if it comes into o The HMO is the processor.
the Philippines and the breach o If the database of the HMO
happens in the Philippines, there is hacked, the data subject
is a violation of the DPA. has a cause of action
o Common application: BPO against both the controller
Industry and processor – the
processor for mishandling
the data, and the
Controller and Processor controller, for having the
ultimate responsibility to
SEC. 3. Definition of Terms make sure that the
processor will handle the
(h) Personal information controller refers information in the strictest
to a person or organization who controls confidence with utmost
the collection, holding, processing or care.
use (CHPU) of personal information, o The processor, at the time
including a person or organization who of discovery of the breach,
instructs another person or organization must inform both the data
to collect, hold, process, use, transfer or subject and the NPC within
2
72 hours of such breach. (d) Personal information processed for
Otherwise, it would be journalistic, artistic, literary or research
liable for failure to make a purposes;
report.
(e) Information necessary in order to
carry out the functions of public authority
Exclusions from the Coverage of the which includes the processing of
Law personal data for the performance by
the independent, central monetary
This act does not apply to the following: authority and law enforcement and
regulatory agencies of their
(a) Information about any individual who constitutionally and statutorily mandated
is or was an officer or employee of a functions.
government institution that relates to the
position or functions of the individual, - E.g. Information submitted to
including: AMLC of Covered Transaction
Report
(1) The fact that the individual is
or was an officer or employee (f) Information necessary for banks and
of the government institution; other financial institutions under the
(2) The title, business address jurisdiction of the independent, central
and office telephone number monetary authority or Bangko Sentral ng
of the individual; Pilipinas to comply with Republic Act
(3) The classification, salary No. 9510, and Republic Act No. 9160,
range and responsibilities of as amended, otherwise known as the
the position held by the Anti-Money Laundering Act and other
individual; and applicable laws; and
(4) The name of the individual on
a document prepared by the (g) Personal information originally
individual in the course of collected from residents of foreign
employment with the jurisdictions in accordance with the laws
government; of those foreign jurisdictions, including
any applicable data privacy laws, which
(b) Information about an individual who is being processed in the Philippines.
is or was performing service under
contract for a government institution that
relates to the services performed, Processing of Personal Information
including the terms of the contract, and
the name of the individual given in the SEC. 11. General Data Privacy
course of the performance of those Principles. – The processing of personal
services; information shall be allowed, subject to
compliance with the requirements of this
- E.g. Name of contractor in a Act and other laws allowing disclosure of
DPWH project written on a poster information to the public and adherence
near the site of the project to the principles of transparency,
legitimate purpose and proportionality.
(c) Information relating to any Personal information must be:
discretionary benefit of a financial nature
such as the granting of a license or
permit given by the government to an (a) Collected for specified and legitimate
individual, including the name of the purposes determined and declared
individual and the exact nature of the before, or as soon as reasonably
benefit; practicable after collection, and later
processed in a way compatible with
- E.g. Award to a contractor under such declared, specified and legitimate
the government’s Build Build purposes only;
Build program

3
(b) Processed fairly and lawfully; contract with the data subject or in order to take
steps at the request of the data subject prior to
entering into a contract;
(c) Accurate, relevant and, where (c) The processing is necessary for compliance
necessary for purposes for which it is to with a legal obligation to which the personal
be used the processing of personal information controller is subject;
information, kept up to date; inaccurate (d) The processing is necessary to protect vitally
or incomplete data must be rectified, important interests of the data subject, including
life and health;
supplemented, destroyed or their further (e) The processing is necessary in order to
processing restricted; respond to national emergency, to comply with
the requirements of public order and safety, or
- E.g. Smartphone apps are not to fulfill functions of public authority which
allowed to ask for TIN Number necessarily includes the processing of personal
data for the fulfillment of its mandate; or
(f) The processing is necessary for the purposes
(d) Adequate and not excessive in of the legitimate interests pursued by the
relation to the purposes for which they personal information controller or by a third party
are collected and processed; or parties to whom the data is disclosed, except
where such interests are overridden by
fundamental rights and freedoms of the data
(e) Retained only for as long as subject which require protection under the
necessary for the fulfillment of the Philippine Constitution.
purposes for which the data was
obtained or for the establishment, SEC. 13. Sensitive Personal Information
exercise or defense of legal claims, or and Privileged Information. – The
for legitimate business purposes, or as processing of sensitive personal
provided by law; and information and privileged information
shall be prohibited, except in the
(f) Kept in a form which permits following cases:
identification of data subjects for no
longer than is necessary for the (a) The data subject has given his or her
purposes for which the data were consent, specific to the purpose prior to
collected and processed: Provided, That the processing, or in the case of
personal information collected for other privileged information, all parties to the
purposes may lie processed for exchange have given their consent prior
historical, statistical or scientific to processing;
purposes, and in cases laid down in law
may be stored for longer PQ: Whether or not consent is
periods: Provided, further, That necessary.
adequate safeguards are guaranteed by A: In every step of the way,
said laws authorizing their processing. consent is necessary in the
The personal information controller must processing of personal
ensure implementation of personal information. (It is for this reason
information processing principles set out that when a client opens an
herein. account with a bank, the fine print
in the contract includes giving of
- Ultimate responsibility for consent to the sharing of
ensuring that sensitive information given to all
information of the data subject units/departments of the bank.)
rests with the controller PQ: Can the data processor or
controller share your information
The following provisions were skipped by Prof. without your consent?
Ceniza (not discussed but included in his slides):
SEC. 12. Criteria for Lawful Processing of
A: No. Exception: Unqualified
Personal Information.  – The processing of consent such as that explained in
personal information shall be permitted only if the previous question.
not otherwise prohibited by law, and when at
least one of the following conditions exists: Skipped:
(a) The data subject has given his or her (b) The processing of the same is provided for
consent; by existing laws and regulations: Provided, That
(b) The processing of personal information is such regulatory enactments guarantee the
necessary and is related to the fulfillment of a protection of the sensitive personal information

4
and the privileged information: Provided, subject, the entity must inform the
further, That the consent of the data subjects data subject that it has the
are not required by law or regulation permitting
the processing of the sensitive personal information and that it is going to
information or the privileged information; process it.
(c) The processing is necessary to protect the
life and health of the data subject or another (b) Be furnished the information
person, and the data subject is not legally or indicated hereunder before the entry of
physically able to express his or her consent
prior to the processing; his or her personal information into the
(d) The processing is necessary to achieve the processing system of the personal
lawful and noncommercial objectives of public information controller, or at the next
organizations and their practical opportunity:
associations:  Provided,  That such processing is
only confined and related to the  bona (Skipped)
fide  members of these organizations or their 1) Description of the personal information to be
associations:  Provided, further,  That the entered into the system;
sensitive personal information are not (2) Purposes for which they are being or are to
transferred to third parties: Provided, be processed;
finally, That consent of the data subject was (3) Scope and method of the personal
obtained prior to processing; information processing;
(e) The processing is necessary for purposes of (4) The recipients or classes of recipients to
medical treatment, is carried out by a medical whom they are or may be disclosed;
practitioner or a medical treatment institution, (5) Methods utilized for automated access, if the
and an adequate level of protection of personal same is allowed by the data subject, and the
information is ensured; or extent to which such access is authorized;
(f) The processing concerns such personal (6) The identity and contact details of the
information as is necessary for the protection of personal information controller or its
lawful rights and interests of natural or legal representative;
persons in court proceedings, or the (7) The period for which the information will be
establishment, exercise or defense of legal stored; and
claims, or when provided to government or (8) The existence of their rights, i.e., to access,
public authority. correction, as well as the right to lodge a
complaint before the Commission.

Rights of the Data Subject (c) Reasonable access to, upon


demand, of the following:
1. Right to be informed
2. Right to object (Skipped)
3. Right to access (1) Contents of his or her personal information
that were processed;
4. Right to data portability (2) Sources from which personal information
5. Right to correct (rectification) were obtained;
6. Right to erasure or blocking (3) Names and addresses of recipients of the
7. Right to file a complaint personal information;
8. Right to damages (4) Manner by which such data were processed;
(5) Reasons for the disclosure of the personal
9. Transmissibility of Rights information to recipients;
(6) Information on automated processes where
PQ: Enumerate at least 3 or 5 rights the data will or likely to be made as the sole
(since J. Perlas-Bernabe asked to basis for any decision significantly affecting or
enumerate AMLA predicate crimes will affect the data subject;
(7) Date when his or her personal information
when she was merc. examiner in 2007) concerning the data subject were last accessed
and modified; and
SEC. 16. Rights of the Data Subject. – (8) The designation, or name or identity and
The data subject is entitled to: address of the personal information controller;

(a) Be informed whether personal (d) Dispute the inaccuracy or error in the
information pertaining to him or her shall personal information and have the
be, are being or have been processed; personal information controller correct it
immediately and accordingly, unless the
- If personal information is received request is vexatious or otherwise
by one entity from another, unreasonable. If the personal
without the consent of the data information have been corrected, the
personal information controller shall
5
ensure the accessibility of both the new
and the retracted information and the
simultaneous receipt of the new and the
retracted information by recipients
thereof: Provided, That the third parties
who have previously received such
processed personal information shall be
informed of its inaccuracy and its
rectification upon reasonable request of
the data subject;

(e) Suspend, withdraw or order the


blocking, removal or destruction of his or
her personal information from the
personal information controller’s filing
system upon discovery and substantial
proof that the personal information are
incomplete, outdated, false, unlawfully
obtained, used for unauthorized
purposes or are no longer necessary for
the purposes for which they were
collected. In this case, the personal
information controller may notify third
parties who have previously received
such processed personal information;
and

- Right is available even when


consent has been previously
given because the consent given
is not perpetual. It may be
withdrawn at will.

(f) Be indemnified for any damages


sustained due to such inaccurate,
incomplete, outdated, false, unlawfully
obtained or unauthorized use of
personal information.

SEC. 18. Right to Data Portability. – The


data subject shall have the right, where
personal information is processed by
electronic means and in a structured
and commonly used format, to obtain
from the personal information controller
a copy of data undergoing processing in
an electronic or structured format, which
is commonly used and allows for further
use by the data subject.

- Customer (data subject) may ask


telecommunications company to
forward personal information to
another telco (e.g from Smart to
Globe)

You might also like