Main Text: RA 10173 and its IRR: https://privacy.gov.
ph/the-data-privacy-act-and-its-irr/
Read:
Definitions of Personal Information and Sensitive Personal Information
RJC v. DL, NPC 22-012, https://privacy.gov.ph/wp-content/uploads/2023/08/NPC-22-
012-2022.11.10-RJC-v.-DL-Decision.pdf
Processing of Personal Information
Basis of Processing:
Consent, https://privacy.gov.ph/wp-content/uploads/2023/11/NPC-Circular-No.-2023-
04_Guidelines-on-Consent_07Nov2023.pdf
Cases:
Pesopop, https://privacy.gov.ph/wp-content/uploads/2024/09/NPC-SS-21-008-
2023.09.26-O.pdf
VVC, https://privacy.gov.ph/wp-content/uploads/2023/05/NPC-19-134-VVC-v.-CJB-
Decision-2021.12.10.pdf
PLDT, https://privacy.gov.ph/wp-content/uploads/2023/05/01-NPC-18-010-RLA-v.-PLDT-
Enterprise-Decision.pdf
EU Case - EU Court of Justice clarifies concept of “informed consent” for collection of
personal data, https://www.lexology.com/library/detail.aspx?g=6cf3217e-e687-4b5d-
97f0-d2107e6ff7e7,
Orange Romania v.
ANSPDCP, https://curia.europa.eu/juris/document/document.jsf;jsessionid=721EB9E9B9
81B4BEFA31F12A7F05B524?
text=&docid=233544&pageIndex=0&doclang=en&mode=lst&dir=&occ=first&part=1&cid
=3704496
Legitimate Interest, https://privacy.gov.ph/wp-content/uploads/2024/01/NPC-Circular-
No.-2023-07_Guidelines-on-Legitimate-Interest_13-December-2023.pdf
Cases:
Victorias Milling, https://privacy.gov.ph/wp-content/uploads/2024/05/NPC-19-758-to-
NPC-19-1846-2023.06.30-MCD-_-JJD-v-Victorias-Milling-Company-et-al-Decision-
FinalP.pdf
Shopee, https://privacy.gov.ph/wp-content/uploads/2024/05/NPC-21-167-2022.09.22-
MAF-v.-Shopee-Decision-FinalP.pdf
EG v. JI, https://privacy.gov.ph/wp-content/uploads/2023/09/NPC-21-111-EG-v.-JI-RO-
and-RR.pdf
Rights of the Data Subject, https://privacy.gov.ph/the-right-to-be-informed/ and click to
the right for the other rights; Rule VIII, IRR
Data Controller v. Data Processor,
Security Measures for the Protection of Personal Data; Rules VI, X IRR
Data Breach Notification, Rule IX
Accountability and Penalties, Rule XIII
Ex. Facebook post having personal data, ok?
What is the purpose, consent? What kind of info? Do u have legitimate purpose.
It doesn’t mean that public posts u have the right to process data.
If it’s sensitive info,
1. Data
2. Consent?
3. Legitimate purpose?