0% found this document useful (0 votes)
32 views5 pages

Codals Data Privacy

Uploaded by

idk idk
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
32 views5 pages

Codals Data Privacy

Uploaded by

idk idk
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 5

Rule I.

Preliminary Provisions operation or set of operations on personal data


involving under a logical framework or automated
Section 1. Title. These rules and regulations shall be instructions
known as the Implementing Rules and Regulations
of Republic Act No. 10173 known as the Data a. Act refers to the Data Privacy Act.
Privacy Act of 2012, or the “Rules.”
b. Breach is a security incident that leads to
Section 2. Policy. These rules and regulations unlawful or unauthorized processing of personal,
further enforce the Data Privacy Act and adopts sensitive or privileged information, or that
generally accepted international principles and otherwise compromises the availability, integrity or
standards for data protection, safeguarding the confidentiality of personal data processed under the
fundamental right of every individual to privacy control of a personal information controller.
while supporting the free flow of information for
innovation, growth and national development. c. Commission refers to the National Privacy
These rules and regulations recognize the vital role Commission created by virtue of the Data Privacy
of information and communications technology in Act. (Dug Christopher B. Mah is the new Deputy Privacy
Commissioner of the National Privacy Commission (NPC),
nation-building and enforce the State’s inherent effective March 2022.)
obligation to ensure that personal data in
information and communications systems in the d. Consent of the da ta subject refers to any freely
government and in the private sector are secured given, specific, informed indication of will,
and protected. whereby the data subject agrees tothe collection and
processing of his or her personal, sensitive or
Section 3. Definitions. Whenever used in these privileged information. Consent shall be evidenced
Rules, the following terms shall have the respective by written, electronic or recorded means. It may
meanings hereafter set forth: also be given on behalf of a data subject by a lawful
*security incident – an event or occurrence that representative or an agent specifically authorized by
affects or tends to affect data protection, or that may the data subject to do so.
compromise the availability, integrity and e. Data subject refers to an individual whose
confidentiality of personal data, including those personal, sensitive or privileged information is
incidents that would have resulted to a security processed.
breach if not for safeguards in place
f. Direct marketing refers to communication by
*data sharing – the disclosure or transfer of personal whatever means of any advertising or marketing
data under custody of a natural or juridical person material which is directed to particular individuals.
or other entity involved in the processing of
personal data to a third party, excludes outsourcing g. Filing system refers to any set of information
or instructions to personal information processor relating to natural or juridical persons to the extent
that, although the information is not processed by
*data processing systems – the structure and equipment operating automatically in response to
procedure by whichpersonal data is collected and instructions given for that purpose, the set is
further processed in an information and structured, either by reference to individuals or by
communications system or relevant filing system, reference to criteria relating to individuals, in such a
including the purpose and intended output of the way that specific information relating to a particular
processing person is readily accessible.
*automatic processing systems – the use of h. Information and Communications System refers
information and communications system to perform to a system for generating, sending, receiving,
storing or otherwise processing electronic data m. Processing refers to any operation or any set of
messages or electronic documents and includes the operations performed upon personal data including,
computer system or other similar device by or but not limited to, the collection, recording,
which data is recorded, transmitted or stored and organization, storage, updating or modification,
any procedure related to the recording, transmission retrieval, consultation, use, consolidation, blocking,
or storage of electronic data, electronic message, or erasure or destruction of data.
electronic document.
n. Privileged information refers to any and all forms
i. Personal data refers, to personal information, of data which under the Rules of Court and other
sensitiveinformation and privileged information, pertinent laws constitute privileged communication.
collectively, which are in an information and
communications system, or relevant filing system, o. Sensitive personal information refers to personal
or intended to form part of the same. Personal data information:
is the term used when referring to personal 1. About an individual’s race, ethnic origin, marital
information, sensitive personal information and status, age, color, and religious, philosophical or
privileged information collectively. political affiliations;
j. Personal information refers to any information 2. About an individual’s health, education, genetic
whether recorded in a material form or not, from or sexual life of a person, or to any proceeding for
which the identity of an individual is apparent or any offense committed or alleged to have been
can be reasonably and directly ascertained by the committed by such person, the disposal of such
entity holding the information, or when put together proceedings, or the sentence of any court in such
with other information would directly and certainly proceedings;
identify an individual.
3. Issued by government agencies peculiar to an
k. Personal information controller refers to a natural individual which includes, but not limited to, social
or juridical person or any other body who controls security numbers, previous or current health
the processing of personal data or instructs another records, licenses or its denials, suspension or
to process personal data on his or her behalf. The revocation, and tax returns; and
term excludes:
4. Specifically established by an executive order or
1. A natural or juridical person or any other body an act of Congress to be kept classified.
who performs such functions on behalf of another;
or

2. A natural person who processes personal data in


connection with his or her personal, family or
household affairs. There is control if the natural or
juridical person or any other body decides on what
information is collected, or the purpose or extent of
processing.

l. Personal information processor refers to any


natural or juridical person or any other body to
whom a personal information controller may
outsource or instruct the processing of personal data
pertaining to a data subject.
Rule II. Scope of Application not extend to the personal information controllers or
processors, which process the same or other
Section 4. Scope. The Data Privacy Act and these personal data, in a manner or for a purpose that is
Rules apply to the processing of personal, sensitive not specifically provided in this section.
or privileged information, in the government or
private sector, under any of the following a. The Act and these Rules shall not be used to
conditions: restrict access to information that fall within matters
of public concern, and for this purpose shall not
a. The natural or juridical person involved in the apply to:
processing of personal data is found or established
in the Philippines. 1. Information about any individual who is or was
an officer or employee of a government institution
b. The act, practice or processing relates to personal that relates to the position or functions of the
data about a Philippine citizen or Philippine individual, including:
resident.
(a)The fact that the individual is or was an officer or
c. The processing of personal data is being done in employee of the government institution;
the Philippines.
(b)The title, business address and office telephone
d. The act, practice or processing of personal data is number of the individual;
done or engaged in by an entity with links to the
Philippines, which include: (c) The classification, salary range and
responsibilities of the position held by the
1. Use of equipment located in the country, or individual; and
maintains an office, branch or agency in the
Philippines for processing of personal data; (d)The name of the individual on a document
prepared by the individual in the course of
2. A Contract entered in the Philippines; employment with the government.
3. A Juridical entity unincorporated in the 2. Information about an individual who is or was
Philippines but has central management and control performing service under contract for a government
in the country; institution only in so far as it relates to the services
4. An entity that has a branch, agency, office or performed, including the terms of the contract, and
subsidiary in the Philippines and the parent or the name of the individual given in the course of the
affiliate of the Philippine entity has access to performance of those services;
personal data; or 3. Information relating to a benefit of a financial
5. An entity that carries on business in the nature conferred on an individual upon the
Philippines discretion of government, such as the granting of a
license or permit, including the name of the
6. An entity collects and holds personal data in the individual and the exact nature of the benefit,
Philippines. Provided further, that the information is provided that benefits given in the course of an
not specifically excluded in the succeeding section. ordinary transaction or as a matter of right are not
discretionary benefits under these Rules.
Section 5. Non-applicability. The Data Privacy Act
does not apply to specific categories of information, b. The Act and these Rules do not apply to personal
to the extent of allowable collection, access, use, information processed for journalistic, artistic or
disclosure or other processing, laid down in the literary purpose,
succeeding paragraphs. The non-applicability does
undertaken with view to publication or exhibition, regulatory function, including the performance of
subject to the functions

requirements of fair and true reporting and other of the independent, central monetary authority. The
applicable public

law or regulations. Any natural or juridical person authority must process the information, mindful of
or other the rights of

body who shall process the same personal the individual data subject to privacy and security,
information for any and subject

purpose other than journalistic, artistic or literary to other restrictions provided by law. If processing
expression, is by an

shall be covered by the Act and these Rules. information processor, the responsibility of the
public authority
c. The Act and these Rules do not apply to personal
information as personal information controller remains. Nothing
in this Act
that will be processed for purpose of scientific and
statistical shall be construed as to have amended or repealed
Republic
research only within the limits provided by Section
37 of these Act No. 1405, otherwise known as the Secrecy of
Bank Deposits
Rules. Any other research shall be covered by the
Act, these Act; Republic Act No. 6426, otherwise known as
the Foreign
8
Currency Deposit Act; and Republic Act No. 9510,
Rules and other issuances of the Commission, to the otherwise
end that
known as the Credit Information System Act
research purposes will be supported without (CISA).
compromising
e. The Act and these Rules do not apply to
privacy and security of personal data. information necessary
d. The Act and these Rules do not apply to for banks and other financial institutions under the
information necessary jurisdiction
in order to carry out functions of public authority of the independent, central monetary authority or
only to the Bangko
extent of collection and further processing Sentral ng Pilipinas to comply with Republic Act
consistent with a No. 9510, and
constitutionally or statutorily mandated function Republic Act No. 9160, as amended, otherwise
pertaining to known as the
national security, law enforcement, taxation and
other
Anti-Money Laundering Act and other applicable
laws. Banks

and financial institutions involved in processing of


personal

data shall be covered by the act and these Rules


where the

information collected and processed to comply with


law will be

subjected to processing for other purpose.

f. The Rules shall not apply to personal information


originally

collected from residents of foreign jurisdictions in


accordance

with the laws of those foreign jurisdictions,


including any

applicable data privacy laws, which is being


processed in the

Philippines, with regard to its collection. The Act


and these

Rules shall apply to processing performed in the


Philippines,

taking into account the law of the foreign


jurisdiction with

regard to collection. The burden of proving the law


of the

foreign jurisdiction falls on the person or body


seeking

exemption. In the absence of proof, the applicable


law shall be

presumed to be that of the Philippines.

You might also like