0% found this document useful (0 votes)
14 views27 pages

Law 3

Republic Act No. 10173, known as the Data Privacy Act of 2012, aims to protect individual personal information in both government and private sectors while promoting the free flow of information. It establishes the National Privacy Commission and defines key terms such as consent, data subject, and personal information, outlining the rights of data subjects and the responsibilities of personal information controllers and processors. The Act also includes provisions for exemptions, extraterritorial application, and the protection of journalists and their sources.

Uploaded by

emnems231
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views27 pages

Law 3

Republic Act No. 10173, known as the Data Privacy Act of 2012, aims to protect individual personal information in both government and private sectors while promoting the free flow of information. It establishes the National Privacy Commission and defines key terms such as consent, data subject, and personal information, outlining the rights of data subjects and the responsibilities of personal information controllers and processors. The Act also includes provisions for exemptions, extraterritorial application, and the protection of journalists and their sources.

Uploaded by

emnems231
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 27

REPUBLIC ACT No.

10173 (b) Consent of the data subject refers to any


freely given, specific, informed indication of
AN ACT PROTECTING INDIVIDUAL
will, whereby the data subject agrees to the
PERSONAL INFORMATION IN
collection and processing of personal
INFORMATION AND
information about and/or relating to him or
COMMUNICATIONS SYSTEMS IN
her. Consent shall be evidenced by written,
THE GOVERNMENT AND THE
electronic or recorded means. It may also be
PRIVATE SECTOR, CREATING FOR
given on behalf of the data subject by an
THIS PURPOSE A NATIONAL
agent specifically authorized by the data
PRIVACY COMMISSION, AND FOR
subject to do so.
OTHER PURPOSES
(c) Data subject refers to an individual
whose personal information is processed.
CHAPTER I
Data subject
GENERAL PROVISIONS
It refers to an individual whose personal,
SEC. 1. Short Title- This Act shall be sensitive personal, or privileged information
known as the "Data Privacy Act of 2012", is processed.

SEC. 2. Declaration of Policy- It is the (d) Direct marketing refers to


policy of the State to protect the communication by whatever means of any
fundamental human right of privacy, of advertising or marketing material which is
communication while ensuring free flow of directed to particular individuals.
information to promote innovation and
(e) Filing system refers to any act of
growth. The State recognizes the vital role
information relating to natural or juridical
of information and communications
persons to the extent that, although the
technology in nation-building and its
information is not processed by equipment
inherent obligation to ensure that personal
operating automatically in response to
information in information and
instructions given for that purpose, the set is
communications systems in the government
structured, either by reference to individuals
and in the private sector are secured and
or by reference to criteria relating to
protected.
individuals, in such a way that specific
SEC. 3. Definition of Terms- Whenever information relating to a particular person is
used in this Act, the following terms shall readily accessible.
have the respective meanings hereafter set
(f)Information and Communications System
forth:
refers to a system for generating, sending,
(a) Commission shall refer to the National receiving, storing or otherwise processing
Privacy Commission created by virtue of electronic data messages or electronic
this Act. documents and includes the computer
system or other similar device by or which
data is recorded, transmitted or stored and information including, but not limited to, the
any procedure related to the recording, collection, recording, organization, storage,
transmission or storage of electronic data, updating or modification, retrieval,
electronic message, or electronic document. consultation, use, consolidation, blocking,
erasure or destruction of data.
(g) Personal information refers to any
information whether recorded in a material
form or not, from which the identity of an
Note:
individual is apparent or can be reasonably
and directly ascertained by the entity Processing may be performed through
holding the information, or when put automated means, or manual processing, if
together with other information would the personal data are contained or are
directly and certainly identify an individual. intended to be contained in a filing system.
(h) Personal information controller refers to (k) Privileged information refers to any and
a person or organization who controls the all forms of data which under the Rules of
collection, holding, processing or use of Court and other pertinent laws constitute
personal information, including a person or privileged communication.
organization who instructs another person or
(1) Sensitive personal information refers
organization to collect, hold, process, use,
to personal information:
transfer or disclose personal information on
1. About an individual’s race,
his or her behalf. The term excludes:
ethnic origin, marital status,
(1) A person or organization who age, color, and religious,
performs such functions as instructed philosophical or political
by another person or organization; affiliations.
and 2. About an individual’s health,
education, genetic or sexual
(2) An individual who collects,
life of a person, or to any
holds, processes or uses personal
proceeding for any offense
information in connection with the
committed or alleged to have
individual's personal, family or
been committed by such
household affairs.
person, the disposal of such
(i) Personal information processor refers to proceedings, or the sentence
any natural or juridical person qualified to of any court in such
act as such under this Act to whom a proceedings;
personal information controller may 3. Issued by government
outsource the processing of personal data agencies peculiar to an
pertaining to a data subject. individual which Includes,
but not limited to, social
(j)Processing refers to any operation or any
security numbers, previous or
set of operations performed upon personal
current health records,
licenses or its denials, access to, personal data transmitted, stored,
suspension or revocation, and or otherwise processed.
tax returns; and
4. Specifically established by an
executive order or an act of Profiling
Congress to be kept
It refers to any form of automated
classified.
processing of personal data consisting of the
use of personal data to evaluate certain
personal aspects relating to a natural person,
Data processing systems
in particular to analyze or predict aspects
It refers to the structure and procedure by concerning that natural person’s
which personal data is collected and further performance at work, economic situation,
processed in an information and health, personal preferences, interests,
communications system or relevant filing reliability, behavior, location or movements.
system, including the purpose and intended
output of the processing.
Public authority
It refers to any government entity created by
Data sharing
the Constitution or law, and vested with law
It is the disclosure or transfer to a third party enforcement or regulatory authority and
of personal data under the custody of a functions.
personal information controller or personal
information processor. In the case of the
latter, such disclosure or transfer must have Security incident
been upon the instructions of the personal
It is an event or occurrence that affects or
information controller concerned. The term
tends to affect data protection, or may
excludes outsourcing, or the disclosure or
compromise the availability, integrity and
transfer of personal data by a personal
confidentiality of personal data. It includes
information controller to a personal
incidents that would result to a personal data
information processor.
breach, if not for safeguards that have been
put in place.3
Personal data
It refers to all types of personal information. SEC. 4. Scope- This Act applies to the
processing of all types of personal
Personal data breach
information and to any natural and juridical
It refers to a breach of security leading to the person involved in personal information
accidental or unlawful destruction, loss, processing including those personal
alteration, unauthorized disclosure of, or information controllers and processors who,
although not found or established in the (c) Information relating to any
Philippines, use equipment that are located discretionary benefit of a financial
in the Philippines, or those who maintain an nature such as the granting of a
office, branch or agency in the Philippines license or permit given by the
subject to the immediately succeeding government to an individual,
paragraph: Provided, That the requirements including the name of the individual
of Section 5 are complied with. and the exact nature of the benefit;
(d) Personal information processed for
journalistic, artistic, literary or
This Act does not apply to the following: research purposes;
(e) Information necessary in order to
(a) Information about any individual
carry out the functions of public
who is or was an officer or employee
authority which includes the
of a government institution that
processing of personal data for the
relates to the position or functions of
performance by the independent,
the individual, including:
central monetary authority and law
1) The fact that the individual is or was
enforcement and regulatory agencies
an officer or employee of the
of their constitutionally and
government institution;
statutorily mandated functions.
2) The title, business address and office
Nothing in this Act shall be
telephone number of the individual;
construed as to have amended or
3) The classification, salary range and
repealed Republic Act No. 1405,
responsibilities of the position held
otherwise known as the Secrecy of
by the individual; and
Bank Deposits Act; Republic Act No.
4) The name of the individual on a
6426, otherwise known as the
document prepared by the individual
Foreign Currency Deposit Act; and
in the course of employment with the
Republic Act No. 9510, otherwise
government;
known as the Credit Information
System Act (CISA);
(b) Information about an individual who
(f) Information necessary for banks and
is or was performing service under
other financial institutions under the
contract for a government institution
jurisdiction of the independent,
that relates to the services performed,
central monetary authority or
including the terms of the contract,
Bangko Sentral ng Pilipinas to
and the name of the Individual given
comply with Republic Act No. 9510,
in the course of the performance of
and Republic Act No. 9160, as
those services;
amended, otherwise known as the
Anti-Money Laundering Act and
other applicable laws; and
(g) Personal information originally performing a service under
collected from residents of foreign contract for a government
jurisdictions in accordance with the institution, but only in so far
laws of those foreign jurisdictions, as it relates to such service,
including any applicable data privacy including the name of the
laws, which is being processed in the individual and the terms of
Philippines. his or her contract;

R.A. 10173 and the Implementing Rules and 3. Information relating to a


Regulations shall not apply to the following benefit of a financial nature
specified information, only to the minimum conferred on an individual
extent of collection, access, use, disclosure upon the discretion of the
or other processing necessary to the purpose, government, such as the
function, or activity concerned: granting of a license or
permit, including the name of
a. Information processed for purpose of
the individual and the exact
allowing public access to
nature of the benefit:
information that fall within matters
Provided, that they do not
of public concern, pertaining to:
include benefits given in the
1. Information about any
course of an ordinary
individual who is or was an
transaction or as a matter of
officer or employee of the
right;
government that relates to his
or her position or functions,
including:
b. Personal information processed for
a) The fact that the individual is or was
journalistic, artistic or literary
an officer or employee of the
purpose, in order to uphold freedom
government;
of speech, of expression, or of the
b) The title, office address, and office
press, subject to requirements of
telephone number of the individual;
other applicable law or regulations;
c) The classification, salary range, and
responsibilities of the position held
c. Personal information that will be
by the individual; and
processed for research purpose,
d) The name of the individual on a
intended for a public benefit, subject
document he or she prepared in the
to the requirements of applicable
course of his or her employment with
laws, regulations, or ethical
the government.
standards;
2. Information about an
individual who is or was
d. Information necessary in order to person or body seeking exemption. In the
carry out the functions of public absence of proof, the applicable law shall be
authority, in accordance with a presumed to be R.A. 10173 and the Rules:
constitutionally or statutorily
mandated function pertaining to law
enforcement or regulatory function, Provided, that the non-applicability of R.A.
including the performance of the 10173 or the Rules do not extend to personal
functions of the independent, central information controllers or personal
monetary authority, subject to information processors, who remain subject
restrictions provided by law. Nothing to the requirements of implementing security
in this Act shall be construed as measures for personal data protection:
having amended or repealed Provided further, that the processing of the
Republic Act No. 1405, otherwise information provided in the preceding
known as the Secrecy of Bank paragraphs shall be exempted from the
Deposits Act; Republic Act No. requirements of R.A. 10173 only to the
6426, otherwise known as the minimum extent necessary to achieve the
Foreign Currency Deposit Act; and specific purpose, function, or activity.
Republic Act No. 9510, otherwise
known as the Credit Information
System Act (CISA); SEC. 5. Protection Afforded to Journalists
and Their Sources- Nothing in this Act
e. Information necessary for banks, shall be construed as to have amended or
other financial institutions under the repealed the provisions of Republic Act No.
jurisdiction of the independent, 53, which affords the publishers, editors or
central monetary authority or duly accredited reporters of any newspaper,
Bangko Sentral ng Pilipinas, and magazine or periodical of general circulation
other bodies authorized by law, to the protection from being compelled to reveal
extent necessary to comply with the source of any news report or information
Republic Act No. 9510 (CISA), appearing in said publication which was
Republic Act No. 9160, as amended, related in any confidence to such publisher,
otherwise known as the Anti-Money editor, or reporter.
Laundering Act, and other applicable
laws;
Protection afforded to Data Subjects
f. Personal information originally collected
from residents of foreign jurisdictions in a. The personal information controller
accordance with the laws of those foreign or personal information processor
jurisdictions, including any applicable data shall uphold the rights of data
privacy laws, which is being processed in subjects, and adhere to general data
the Philippines. The burden of proving the privacy principles and the
law of the foreign jurisdiction falls on the requirements of lawful processing
b. The burden of proving that R.A. What is Republic Act No. 53?
10173 and the Rules and Regulations
An Act to exempt the publisher, editor or
are not applicable to a particular
reporter of any publication from revealing
information falls on those involved
the source of published news or information
in the processing of personal data or
obtained in confidence.
the party claiming the non-
applicability. SEC. 6. Extraterritorial Application- This
c. In all cases, the determination of any Act applies to an act done or practice
exemption shall be liberally engaged in and outside of the Philippines by
interpreted in favor of the rights and an entity if:
interests of the data subject.
a) The act, practice or processing
relates to personal information about
a Philippine citizen or a resident;
Protection Afforded to Journalists and
b) The entity has a link with the
their Sources
Philippines, and the entity is
a. Publishers, editors, or duly processing personal information in
accredited reporters of any the Philippines or even if the
newspaper, magazine or periodical of processing is outside the Philippines
general circulation shall not be as long as it is about Philippine
compelled to reveal the source of any citizens or residents such as, but not
news report or information appearing limited to, the following:
in said publication if it was related in 1) A contract is entered in the
any confidence to such publisher, Philippines;
editor, or reporter. 2) A juridical entity unincorporated
b. Publishers, editors, or duly in the Philippines but has central
accredited reporters who are likewise management and control in the
personal information controllers or country; and
personal information processors 3) An entity that has a branch,
within the meaning of the law are agency, office or subsidiary in the
still bound to follow the Data Philippines and the parent or
Privacy Act and related issuances affiliate of the Philippine entity has
with regard to the processing of access to personal information; and
personal data, upholding rights of
their data subjects and maintaining c) ) The entity has other links in the
compliance with other provisions Philippines such as, but not limited
that are not incompatible with the to:
protection provided by Republic Act 1) The entity carries on business in
No. 53. the Philippines; and
2) The personal information was Philippine entity has access to
collected or held by an entity in the personal data;
Philippines. 5. An entity that carries on business in
the Philippines;
6. An entity that collects or holds
RA. 10173 and the Implementing Rules
personal data in the Philippines.
and Regulations apply to the processing of
personal data by any natural and juridical
person in the government or private sector.
CHAPTER II
They apply to an act done or practice
engaged in and outside of the Philippines if: THE NATIONAL PRIVACY
COMMISSION
a. The natural or juridical person
involved in the processing of The National Privacy Commission is an
personal data is found or established independent body mandated to administer
in the Philippines; and implement R.A. 10173, and to monitor
b. The act, practice or processing and ensure compliance of the country with
relates to personal data about a international standards set for personal data
Philippine citizen or Philippine protection.⁸
resident;
c. The processing of personal data is
being done in the Philippines; or SEC. 7. Functions of the National Privacy
d. .The act, practice or processing of Commission. To administer and implement
personal data is done or engaged in the provisions of this Act, and to monitor
by an entity with links to the and ensure compliance of the country with
Philippines, with due consideration international standards set for data
to international law and comity, such protection, there is hereby created an
as, but not limited to, the following: independent body to be known as the
1. Use of equipment located in the National Privacy Commission, which shall
country, or maintains an office, have the following functions:
branch or agency in the Philippines
a) Ensure compliance of personal
for processing of personal data;
information controllers with the
2. A contract is entered in the
provisions of this Act;
Philippines;
b) Receive complaints, institute
3. A juridical entity unincorporated in
investigations, facilitate or enable
the Philippines but has central
settlement of complaints through the
management and control in the
use of alternative dispute resolution
country;
processes, adjudicate, award
4. An entity that has a branch, agency,
indemnity on matters affecting any
office or subsidiary in the Philippines
personal information, prepare reports
and the parent or affiliate of the
on disposition of complaints and
resolution of any investigation it h) Publish a compilation of agency
initiates, and, in cases it deems system of records and notices,
appropriate, publicize any such including index and other finding
report: Provided, That in resolving aids;
any complaint or investigation i) Recommend to the Department of
[except where amicable settlement is Justice (DOJ) the prosecution and
reached by the parties), the imposition of penalties specified in
Commission shall act as a collegial Sections 25 to 29 of this Act;
body. For this purpose, the j) Review, approve, reject or require
Commission may be given access to modification of privacy codes
personal information that is subject voluntarily adhered to by personal
of any complaint and to collect the information controllers:
information necessary to perform its
Provided, That the privacy codes shall
functions under this Act;
adhere to the underlying data privacy
c) Issue cease and desist orders, impose
principles embodied in this Act: Provided,
a temporary or permanent ban on the
further, That such privacy codes may include
processing of personal information,
private dispute resolution mechanisms for
upon finding that the processing will
complaints against any participating
be detrimental to national security
personal information controller. For this
and public interest;
purpose, the Commission shall consult with
d) Compel or petition any entity,
relevant regulatory agencies in the
government agency or
formulation and administration of privacy
instrumentality to abide by its orders
codes applying the standards set out in this
or take action on a matter affecting
Act, with respect to the persons, entities,
data privacy;
business activities and business sectors that
e) Monitor the compliance of other
said regulatory bodies are authorized to
government agencies or
principally regulate pursuant to the law:
instrumentalities on their security
Provided, finally, That the Commission may
and technical measures and
review such privacy codes and require
recommend the necessary action in
changes thereto for purposes of complying
order to meet minimum standards for
with this Act:
protection of personal information
pursuant to this Act; k) Provide assistance on matters
f) Coordinate with other government relating to privacy or data protection
agencies and the private sector on at the request of a national or local
efforts to formulate and implement agency, a private entity or any
plans and policies to strengthen the person;
protection of personal information in l) Comment on the implication on data
the country; privacy of proposed national or local
g) Publish on a regular basis a guide to statutes, regulations or procedures,
all laws relating to data protection; issue advisory opinions and interpret
the provisions of this Act and other sensitive personal information
data privacy laws; maintained by government agencies,
m) Propose legislation, amendments or considering the most appropriate
modifications to Philippine laws on standard recognized by the
privacy or data protection as may be information and communications
necessary; technology industry, as may be
n) Ensure proper and effective necessary:
coordination with data privacy 2. Specifying electronic format and
regulators in other countries and technical standards, modalities and
private accountability agents, procedures for data portability, as
participate in international and may be necessary;
regional initiatives for data privacy 3. Issuing guidelines for organizational,
protection; physical, and technical security
o) Negotiate and contract with other measures for personal data
data privacy authorities of other protection, taking into account the
countries for cross-border application nature of the personal data to be
and implementation of respective protected, the risks presented by the
privacy laws; processing, the size of the
p) Assist Philippine companies doing organization and complexity of its
business abroad to respond to foreign operations, current data privacy best
privacy or data protection laws and practices, cost of security
regulations; and implementation, and the most
q) Generally, perform such acts as may appropriate standard recognized by
be necessary to facilitate cross- the information and communications
border enforcement of data privacy technology industry, as may be
protection. necessary;
4. Consulting with relevant regulatory
The National Privacy Commission shall
agencies in the formulation, review,
have the following functions:
amendment, and administration of
a. Rule Making privacy codes, applying the standards
set out in R.A 10173, with respect to
The Commission shall develop, promulgate,
the persons, entities, business
review or amend rules and regulations for
activities, and business sectors that
the effective implementation of R.A. 10173.
said regulatory bodies are authorized
This includes:
to principally regulate pursuant to
law;

1. Recommending organizational,
5. Proposing legislation, amendments
physical and technical security
or modifications to Philippine laws
measures for personal data
on privacy or data protection, as may
protection, encryption, and access to
be necessary;
person, including the enforcement of
6. Ensuring proper and effective rights of data subjects; and
coordination with data privacy 4. . Assisting Philippine companies
regulators in other countries and doing business abroad to respond to
private accountability agents, and data protection laws and regulations.

7. Participating in international and c. Public Education


regional initiatives for data privacy
The Commission shall undertake necessary
protection.
or appropriate effots to inform and educate
the public of data privacy, data protection,
and fair information rights and
b. Advisory
responsibilities. This includes:
The Commission shall be the advisory body
1. Publishing, on a regular basis, a
on matters affecting protection of personal
guide to all laws relating to data
data. This includes:
protection;
2. Publishing a compilation of agency
system of records and notices,
1. Commenting on the implication on
including index and other finding
data privacy of proposed national or
aids, and
local statutes, regulations or
3. Coordinating with other government
procedures, issuing advisory
agencies and the private sector on
opinions, and interpreting the
efforts to formulate and implement
provisions of R.A. 10173 and other
plans and policies to strengthen the
data privacy laws;
protection of personal data in the
2. Reviewing, approving, rejecting, or
country.
requiring modification of privacy
codes voluntarily adhered to by
personal information controllers,
d. Compliance and Monitoring
which may include private dispute
resolution mechanisms for The Commission shall perform compliance
complaints against any participating and monitoring functions to ensure effective
personal information controller, and implementation of R.A. 10173, the Rules,
which adhere to the underlying data and other Issuances. This includes:
privacy principles embodied in R.A.
1. Ensuring compliance by
10173 and the Rules;
personal information
3. Providing assistance on matters
controllers with the
relating to privacy or data protection
provisions of R.A. 10173;
at the request of a national or local
2. Monitoring the compliance of
agency, a private entity or any
all government agencies or
instrumentalities as regards a. Receiving complaints and
their security and technical instituting investigations
measures, and recommending regarding violations of R.A.
the necessary action in orde 10173, the Rules, and other
to meet minimum standards issuances of the Commission,
for protection of personal including violations of the
data pursuant to R.A. 10173; rights of data subjects and
3. Negotiating and contracting other matters affecting
with other data privacy personal data;
authorities of other countries b. Summoning witnesses, and
for cross-border application requiring the production of
and implementation of evidence by a subpoena
respective privacy laws; duces tecum for the purpose
4. Generally performing such of collecting the information
acts as may be necessary to necessary to perform its
facilitate cross-border functions under R.A. 10173:
enforcement of data privacy Provided, that the
protection; and Commission may be given
5. Managing the registration of access to personal data that is
personal data processing subject of any complaint;
systems in the country, c. Facilitating or enabling
including the personal data settlement of complaints
processing system of through the use of alternative
contractors and their dispute resolution processes,
employees entering into and adjudicating on matters
contracts with government affecting any personal data;
agencies that involves and
accessing or requiring d. Preparing reports on the
sensitive personal disposition of complaints and
information of at least 1,000 the resolution of any
individuals. investigation it initiates, and,
in cases it deems appropriate,
e. Complaints and Investigations publicizing such reports.
The Commission shall adjudicate on
complaints and investigations on matters
affecting personal data: Provided, that in
f. Enforcement
resolving any complaint or investigation,
except where amicable settlement is reached
by the parties, the Commission shall act as a
The Commission shall perform all acts as
collegial body. This includes:
may be necessary to effectively implement
R.A. 10173, the Rules and Regulations, and Administrative Issuances
its other issuances, and to enforce its Orders,
The Commission shall publish or issue
Resolutions or Decisions, including the
official directives and administrative
imposition of administrative sanctions, fines,
issuances, orders, and circulars, which
or penalties. This includes:
include:
1. Issuing compliance or enforcement
a. Rules of procedure in the exercise of
orders;
its quasi-judicial functions, subject to
2. Awarding indemnity on matters affecting the suppletory application of the
any personal data, or rights of data subjects; Rules of Court;
b. Schedule of administrative fines and
3. Issuing cease and desist orders, or
penalties for violations of R.A.
imposing a temporary or permanent ban on
10173, the Rules, and issuances or
the processing of personal data, upon finding
Orders of the Commission, including
that the processing will be detrimental to
the applicable fees for its
national security or public interest, or if it is
administrative services and filing
necessary to preserve and protect the rights
fees;
of data subjects;
c. Procedure for registration of data
4. Recommending to the Department of processing systems, and notification;
Justice (DOJ) the prosecution of crimes and and
imposition of penalties specified in R.A. d. Other administrative issuances
10173; consistent with its mandate and other
functions. 10
5. Compelling or petitioning any entity,
government agency, or instrumentality, to
abide by its orders or take action on a matter
SEC. 8. Confidentiality- The Commission
affecting data privacy; and
shall ensure at all times the confidentiality of
6. Imposing administrative fines for any personal information that comes to its
violations of R.A. 10173, the Rules and knowledge and possession.
Regulations, and other issuances of the
Commission.
Members, employees, and consultants of the
Commission shall ensure at all times the
confidentiality of any personal data that
come to their knowledge and possession:
Provided, that such duty of confidentiality
g. Other functions. shall remain even after their term,
employment, or contract has ended.11
The Commission shall exercise such other
functions as may be necessary to fulfill its
mandate under R.A. 10173.⁹
SEC. 9. Organizational Structure of the or she shall be liable for willful or negligent
Commission- The Commission shall be acts done by him or her which are contrary
attached to the Department of Information to law, morals, public policy and good
and Communications Technology (DICT) customs even if he or she acted under orders
and shall be headed by a Privacy or instructions of superiors: Provided, That
Commissioner, who shall also act as in case a lawsuit is filed against such official
Chairman of the Commission. The Privacy on the subject of the performance of his or
Commissioner shall be assisted by two (2) her duties, where such performance is
Deputy Privacy Commissioners, one to be lawful, he or she shall be reimbursed by the
responsible for Data Processing Systems and Commission for reasonable costs of
one to be responsible for Policies and litigation.
Planning. The Privacy Commissioner and
the two (2) Deputy Privacy Commissioners
shall be appointed by the President of the Note:
Philippines for a term of three (3) years, and
Qualified employees of the Commission
may be reappointed for another term of three
shall be covered by Republic Act No. 8349,
(3) years. Vacancies in the Commission shall
which provides a magna carta for scientists,
be filled in the same manner in which the
engineers, researchers, and other science
original appointment was made. The Privacy
and technology personnel in the
Commissioner must be at least thirty-five
government.12
(35) years of age and of good moral
character, unquestionable integrity and
known probity, and a recognized expert in
SEC. 10. The Secretariat- The Commission
the field of information technology and data
is hereby authorized to establish a
privacy. The Privacy Commissioner shall
Secretariat. Majority of the members of the
enjoy the benefits, privileges and
Secretariat must have served for at least five
emoluments equivalent to the rank of
(5) years in any agency of the government
Secretary. The Deputy Privacy
that is involved in the processing of personal
Commissioners must be recognized experts
information including, but not limited to, the
in the field of information and
following offices: Social Security System
communications technology and data
(SSS), Government Service Insurance
privacy. They shall enjoy the benefits,
System (GSIS), Land Transportation Office
privileges and emoluments equivalent to the
(LTO), Bureau of Internal Revenue (BIR),
rank of Undersecretary.
Philippine Health Insurance Corporation
(PhilHealth), Commission on Elections
(COMELEC), Department of Foreign
The Privacy Commissioner, the Deputy
Affairs (DFA), Department of Justice (DOJ),
Commissioners, or any person acting on
and Philippine Postal Corporation
their behalf or under their direction, shall not
(Philpost).
be civilly liable for acts done in good faith in
the performance of their duties, However, he
Personal information must be:
The Commission is authorized to establish a a. Collected for specified and
Secretariat, which shall assist in the legitimate purposes determined and
performance of its functions. The Secretariat declared before, or as soon as
shall be headed by an Executive Director reasonably practicable after
and shall be organized according to the collection, and later processed in a
following offices: way compatible with such declared,
specified and legitimate purposes
a. Data Security and Compliance
only;
Office;
b. Processed fairly and lawfully;
b. Legal and Enforcement Office;
c. Accurate, relevant and, where
c. Finance and Administrative Office;
necessary for purposes for which it is
d. Privacy Policy Office; and
to be used the processing of personal
e. Public Information and Assistance
information, kept up to date;
Office.
inaccurate or incomplete data must
Majority of the members of the be rectified.
Secretariat, in so far as practicable, must d. Supplemented, destroyed or their
have served for at least 5 years in any further processing restricted; d)
agency of the government that is involved in Adequate and not excessive in
the processing of personal data including, relation to the purposes for which
but not limited to, the following offices: they are collected and processed;
Social Security System (SSS), Government e. Retained only for as long as
Service Insurance System (GSIS), Land necessary for the fulfillment of the
Transportation Office (LTO), Bureau of purposes for which the data was
Internal Revenue (BIR), Philippine Health obtained or for the establishment,
Insurance Corporation exercise or defense of legal claims,
or for legitimate business purposes,
or as provided by law; and
CHAPTER III f. Kept in a form which permits
identification of data subjects for no
PROCESSING OF PERSONAL
longer than is necessary for the
INFORMATION
purposes for which the data were
SEC. 11. General Data Privacy collected and processed: Provided,
Principles- The processing of personal That personal information collected
information shall be allowed, subject to for other purposes may be processed
compliance with the requirements of this Act for historical, statistical or scientific
and other laws allowing disclosure of purposes, and in cases laid down in
information to the public and adherence to law may be stored for longer periods:
the principles of transparency, legitimate Provided, further, That adequate
purpose and proportionality.
safeguards are guaranteed by said specified purpose. Personal data shall be
laws authorizing their processing. processed only if the purpose of the
processing could not reasonably be fulfilled
The personal Information controller must
by other means. 14
ensure implementation of personal
information processing principles set out
herein.
GENERAL PRINCIPLES IN
COLLECTION, PROCESSING AND
RETENTION
PRINCIPLES OF TRANSPARENCY,
LEGITIMATE PURPOSE AND The processing of personal data shall adhere
PROPORTIONALITY to the following general principles in the
collection, processing, and retention of
The processing of personal data shall be
personal data:
allowed subject to adherence to the
principles of transparency, legitimate I. Collection must be for a
purpose, and proportionality. declared, specified, and
legitimate purpose
I. Transparency
1. Consent is required prior to
The data subject must be aware of the the collection and processing
nature, purpose, and extent of the processing of personal data, subject to
of his or her personal data, including the exemptions provided by R.A.
risks and safeguards involved, the identity of 10173 and other applicable
personal information controller, his or her laws and regulations. When
rights as a data subject, and how these can consent is required, it must be
be exercised. Any information and time-bound in relation to the
communication relating to the processing of declared. Specified and
personal data should be easy to access and legitimate purpose. Consent
understand using clear and plain language. given may be withdrawn.
2. The data subject must be
II. Legitimate purpose
provided specific information
The processing of information shall be regarding the purpose and
compatible with a declared and specified extent of processing,
purpose which must not be contrary to law, including, where applicable,
morals, or public policy. the automated processing of
his or her personal data for
profiling or processing for
III. Proportionality direct marketing, and data
sharing,
The processing of information shall be
3. Purpose should be
adequate, relevant, suitable, necessary, and
determined and declared
not excessive in relation to a declared and
before, or as soon as for declared, specified and
reasonably practicable, after legitimate purpose, kept up to
collection. date.
4. Only personal data that is 2. Inaccurate or incomplete data
necessary and compatible must be rectified,
with declared specified, and supplemented, destroyed or
legitimate purpose shall be their further processing
collected. restricted.
IV. Personal Data shall not be
II. Personal data shall be retained longer than necessary
processed fairly and lawfully 1. Retention of personal data
1. Processing shall uphold the rights of shall only for as long as
the data subject, including the right necessary:
to refuse, withdraw consent, or a) For the fulfillment of the declared,
object. It shall likewise be specified, and legitimate purpose, or
transparent, and allow the data when the processing relevant to the
subject sufficient information to purpose has been terminated:
know the nature and extent of b) For the establishment, exercise or
processing. defense of legal claims; or
2. Information provided to a data c) For legitimate business purposes,
subject must always be in clear ans which must be consistent with
plain language to ensure that they are standards followed by the applicable
easy to understand and access. industry or approved by appropriate
3. Processing must be in a manner government agency.
compatible with declared, specified,
and legitimate purpose.
4. Processed personal data should be V. Any authorized further processing shall
adequate, relevant, and limited to have adequate safeguards
what is necessary in relation to the
1. Personal data originally
purposes for which they are
collected for a declared,
processed.
specified, or legitimate
5. Processing shall be undertaken in a
purpose may be processed
manner that ensures appropriate
further for historical,
privacy and security safeguards.
statistical, or scientific
purposes, and, in cases laid
down in law, may be stored
for longer periods, subject to
III. Processing should ensure data
implementation of the
quality
appropriate organizational,
1. Personal data should be
physical, and technical
accurate and where necessary
security measures required by 2. Data sharing for commercial purposes,
R.A. 10173 in order to including direct marketing, shall be covered
safeguard the rights and by a data sharing agreement.
freedoms of the data subject.
a. The data sharing agreement shall
2. Personal data which is
establish adequate safeguards for
aggregated or kept in a form
data privacy and security, and uphold
which does not permit
rights of data subjects.
identification of data subjects
b. The data sharing agreement shall be
may be kept longer than
subject to review by the
necessary for the declared,
Commission, on its own initiative or
specified, and legitimate
upon complaint of data subject.
purpose.
3. Personal data shall not be
retained in perpetuity in
3.The data subject shall be provided with the
contemplation of a possible
following information prior to collection or
future use yet to be
before data is shared:
determined. 15
a) Identity of the personal information
GENERAL PRINCIPLES FOR DATA
controllers or personal information
SHARING
processors that will be given access
Further Processing of Personal Data to the personal data;
collected from a party other than the Data b) Purpose of data sharing:
Subject shall be allowed under any of the c) Categories of personal data
following conditions: concerned;
d) Intended recipients or categories of
A. Data sharing shall be allowed when it is
recipients of the personal data;
expressly authorized by law: Provided, that
e) Existence of the rights of data
there are adequate safeguards for data
subjects, including the right to access
privacy and security, and processing adheres
and correction, and the right to
to principle of transparency, legitimate
object; and
purpose and proportionality.
f) Other information that would
B. Data Sharing shall be allowed in the sufficiently notify the data subject of
private sector if the data subject consents the nature and extent of data sharing
to data sharing, and the following conditions and the manner of processing.
are complied with:
4)Further processing of shared data shall
1. Consent for data sharing shall be required adhere to the data privacy principles laid
even when the data is to be shared with an down in R.A. 10173, the Rules, and
affiliate or mother company, or similar other issuances of the Commission.
relationships:
C. Data collected from parties other b) The processing of personal
than the data subject for purpose of information is necessary and is
research shall be allowed when the related to the fulfillment of a contract
personal data is publicly available, or with the data subject or in order to
has the consent of the data subject take steps at the request of the data
for purpose of research: Provided, subject prior to entering into a
that adequate safeguards are in place, contract;
and no decision directly affecting the c) The processing is necessary for
data subject shall be made on the compliance with a legal obligation to
basis of the data collected or which the personal information
processed. The rights of the data controller is subject:
subject shall be upheld without d) The processing is necessary to
compromising research integrity. protect vitally important interests of
D. Data sharing between government the data subject, including life and
agencies for the purpose of a public health;
function or provision of a public e) The processing is necessary in order
service shall be covered by a data to respond to national emergency, to
sharing agreement. comply with the requirements of
public order and safety, or to fulfill
functions of public authority which
1. Any or all government agencies, necessarily includes the processing
party to the agreement, shall comply of personal data for the fulfillment of
with R.A. 10173, the Rules and its mandate; or
Regulations, and all other issuances f) The processing is necessary for the
of the Commission, including putting purposes of the legitimate interests
in place adequate safeguards for data pursued by the personal information
privacy and security. controller or by a third party or
2. The data sharing agreement shall be parties to whom the data is disclosed,
subject to review of the Commission, except where such interests are
on its own initiative or upon overridden by fundamental rights
complaint of data subject. 16 and freedoms of the data subject
which require protection under the
SEC. 12. Criteria for Lawful Processing
Philippine Constitution.
of Personal Information- The processing of
personal information shall be permitted only
if not otherwise prohibited by law, and when
SEC. 13. Sensitive Personal Information
at least one of the following conditions
and Privileged Information– The
exists:
processing of sensitive personal information
a) The data subject has given his or her and privileged information shall be
consent; prohibited, except in the following cases:
a) The data subject has given his or her an adequate level of protection of
consent, specific to the purpose prior personal information is ensured; or
to the processing, or in the case of f) The processing concerns such
privileged information, all parties to personal information as is necessary
the exchange have given their for the protection of lawful rights
consent prior to processing; and interests of natural or legal
b) The processing of the same is persons in court proceedings, or the
provided for by existing laws and establishment, exercise or defense of
regulations: Provided, That such legal claims, or when provided to
regulatory enactments guarantee the government or public authority.
protection of the sensitive personal
information and the privileged
SEC. 14. Subcontract of Personal
information: Provided, further, That
Information- A personal information
the consent of the data subjects are
controller may subcontract the
not required by law or regulation
processing of personal information:
permitting the processing of the
Provided, That the personal information
sensitive personal information or the
controller shall be responsible for
privileged information;
ensuring that proper safeguards are in
c) The processing is necessary to
place to ensure the confidentiality of the
protect the life and health of the data
personal information processed, prevent
subject or another person, and the
its use for unauthorized purposes, and
data subject is not legally or
generally, comply with the requirements
physically able to express his or her
of this Act and other laws for processing
consent prior to the processing:
of personal information. The personal
d) The processing is necessary to
information processor shall comply with
achieve the lawful and
all the requirements of this Act and other
noncommercial objectives of public
applicable laws.
organizations and their associations:
Provided, That such processing is
only confined and related to the bona
SEC. 15. Extension of Privileged
fide members of these organizations
Communication. Personal information
or their associations: Provided,
controllers may invoke the principle of
further, That the sensitive personal
privileged communication over privileged
information are not transferred to
information that they lawfully control or
third parties: Provided, finally, That
process. Subject to existing laws and
consent of the data subject was
regulations, any evidence gathered on
obtained prior to processing:
privileged information is inadmissible.
e) The processing is necessary for
purposes of medical treatment
carried out by a medical practitioner
or a medical treatment institution and
When the Commission inquires upon SEC. 16. Rights of the Data Subject- The
communication claimed to be privileged, the data subject is entitled to:
personal information controller concerned
(a) Be informed whether personal
shall prove the nature of the communication
information pertaining to him or her
in an executive session. Should the
shall be, are being, or have been
communication be determined as privileged,
processed;
it shall be excluded from evidence, and the
(b) Be furnished the information
contents thereof shall not form part of the
indicated hereunder before the entry
records of the case: Provided, that where the
of his or her personal information
privileged communication itself is the
into the processing system of the
subject of a breach, or a privacy concern or
personal information controller, or at
investigation, it may be disclosed to the
the next practical opportunity:
Commission but only to the extent necessary
for the purpose of investigation, without
1) Description of the personal
including the contents thereof in the
information to be entered into the
records.17
system;
2) Purposes for which they are being or
are to be processed;
Note:
3) Scope and method of the personal
Section 7 of Republic Act No. 9372, information processing:
otherwise known as the “Human Security 4) The recipients or classes of recipients
Act of 2007”, is hereby amended to include to whom they are or may be
the condition that the processing of personal disclosed;
data for the purpose of surveillance, 5) Methods utilized for automated
interception, or recording of access, if the same is allowed by the
communications shall comply with the Data data subject, and the extent to
Privacy Act, including adherence to the whichh such access is authorized;
principles of transparency, proportionality, 6) The identity and contact details of
and legitimate purpose. 18 the personal information controller
or its representative;
7) The period for which the information
will be stored; and
8) The existence of their rights, i.e., to
access, correction, as well as
the right to lodge a complaint before the
CHAPTER IV Commission.

RIGHTS OF THE DATA SUBJECT


Any information supplied or declaration 8) The designation, or name or identity
made to the data subject on these matters and address of the personal
shall not be amended without prior information controller;
notification of data subject: Provided, That
the notification under subsection (b) shall
not apply should the personal information be (d) Dispute the inaccuracy or error in the
needed pursuant to a subpoena or when the personal information and have the
collection and processing are for obvious personal information controller
purposes, including when it is necessary for correct it immediately and
the performance of or in relation to a accordingly, unless the request is
contract or service or when necessary or vexatious or otherwise unreasonable.
desirable in the context of an employer. If the personal information have been
Employee relationship, between the corrected, the personal information
collector and the data subject, or when the controller shall ensure the
information is being collected and processed accessibility of both the new and the
as a result of legal obligation; retracted information and the
simultaneous receipt of the new and
the retracted information by
(c) Reasonable access to, upon demand, recipients thereof: Provided, That the
the following: third parties who have previously
1) Contents of his or her personal received such processed personal.
information that were processed; Information shall be informed of its
2) Sources from which personal inaccuracy and its rectification upon
information were obtained; reasonable request of the data
3) Names and addresses of recipients of subject;
the personal information: (e) Suspend, withdraw or order the
4) Manner by which such data were blocking, removal or destruction of
processed: his or her personal information from
5) Reasons for the disclosure of the the personal information controller’s
personal information to recipients; filing system upon discovery and
6) Information on automated processes substantial proof that the personal
where the data will or likely to be information are incomplete,
made as the sole basis for any outdated, false, unlawfully obtained,
decision significantly affecting or used for unauthorized purposes or
will affect the data subject; are no longer necessary for the
7) Date when his or her personal purposes for which they were
information concerning the data collected. In this case, the personal
subject were last accessed and information controller may notify
modified; and third parties who have previously
received such processed personal
information; and
e. The recipients or classes of recipients
to whom the personal data are or
(f) Be indemnified for any damages
may be disclosed,
sustained due to such inaccurate,
f. Methods utilized for automated
incomplete, outdated, false,
access, if the same is allowed by the
unlawfully obtained or unauthorized
data subject, and the extent to which
use of personal information.
such access is authorized, including
meaningful information about the
logic involved, as well as the
RIGHTS OF THE DATA SUBJECT
significance and the envisaged
The data subject is entitled to the following consequences of such processing for
rights: the data subject:
g. The identity and contact details of
the personal data controller or its
a. Right to be informed representative;
1. The data subject has a right to be h. The period for which the information
informed whether personal data will be stored, and
pertaining to him or her shall be, are i. The existence of their rights as data
being, or have been processed, subjects, including the right to
including the existence of automated access, correction, and object to the
decision-making and profiling processing, as well as the right to
2. The data subject shall be notified and lodge a complaint before the
furnished with information indicated Commission.
hereunder before the entry of his or
her personal data into the processing b. Right to object
system of the personal information The data subject shall have the
controller, or at the next practical right to object to the processing of
opportunity: his or her personal data, including
a. Description of the personal data to be processing for direct marketing,
entered into the system; automated processing or profiling.
b. Purposes for which they are being or The data subject shall also be
will be processed, including notified and given an opportunity to
processing for direct marketing, withhold consent to the processing in
profiling or historical, statistical or case of changes or any amendment to
scientific purpose; the information supplied or declared
c. Basis of processing, when processing to the data subject in the preceding
is not based on the consent of the paragraph.
data subject,
d. Scope and method of the personal When a data subject objects or
data processing: withholds consent, the personal
information controller shall no
longer process the personal data, significantly affects or will affect
unless: the data subject:
1. The personal data is needed 7. Date when his or her personal
pursuant to a subpoena: data concerning the data subject
2. The collection and processing were last accessed and modified:
are for obvious purposes and
including when it is 8. The designation, name or
necessary for the identity, and address of the
performance of or in relation personal information controller.
to a contract or service to
which the data subject is a d. Right to rectification
party, or when necessary or
The data subject has the right to dispute
desirable in the context of an
the inaccuracy or error in the personal data
employer-employee
and have the personal information controller
relationship between the
correct it immediately and accordingly,
collector and the data subiect
unless the request is vexatious or otherwise
or
unreasonable. If the personal data has been
3. The information is being
corrected, the personal information
collected and processed as a
controller shall ensure the accessibility of
result of a legal obligation.
both the new and the retracted information
and the simultaneous receipt of the new and
c. Right to Access
the retracted information by the intended
The data subject has the right to recipients thereof: Provided, That recipients
reasonable access to upon demand the or third parties who have previously
following: received such processed personal data shall
be informed of its inaccuracy and its
1. Contents of his or her personal
rectification, upon reasonable request of the
data that were processed:
data subject.
2. 2. Sources from which personal
data were obtained:
3. Names and addresses of e. Right to Erasure or Blocking
recipients of the personal data:
The data subject shall have the right to
4. Manner by which such data were
suspend, withdraw or order the blocking,
processed:
removal or destruction of his or her personal
5. Reasons for the disclosure of the
data from the personal information
personal data to recipients if any
controller’s filing system.
6. Information on automated
processes where the data will or 1. This right may be exercised upon
is likels to, be made as the sole discovery and substantial proof
basis for any decision that of any of the following:
a) The personal data is f. Right to damages
incomplete, outdated,
The data subiect shall be indemmfied for
false, or unlawfully
any damages sustained due in such
obtained:
inaccurate, incomplete, outdated, false,
b) The personal data is being
unlawfully obtained or unauthorized use of
used for purpose not
personal data, taking into account any
authorized by the data
violation of his or her rights and freedoms as
subject: el
data subiect.
c) The personal data is no
longer necessary for the
purposes for which they
SEC. 17. Transmissibility of Rights of the
were collected
Data Subject- The lawful heirs and assigns
d) The data subiect
of the data subject may invoke the rights of
withdraws consent or
the data subject for, which he or she is an
objects to the processing
heir or assignee at any time after the death of
and there is no other legal
the data subject or when the data subject is
ground or overriding
incapacitated or incapable of exercising the
legitimate interest for the
rights as enumerated in the immediately
processing
preceding section.
e) The personal data
concerns private SEC. 18. Right to Data Portability- The
information that is data subject shall have the right, where
presudicial to data personal information is processed by
subiect, unless justified electronic means and in a structured and
by freedom of speech. Of commonly used format, to obtain from the
expression or of the press personal information controller a copy of
or otherwise authorized data undergoing processing in an electronic
f) The processing Is or structured format, which is commonly
unlawful and used and allows for further use by the data
g) The personal information subject. The Commission may specify the
controller or personal electronic format referred to above, as well
information processor as the technical standards, modalities and
violated the rights of the procedures for their transfer.
data subiect

SEC. 19. Non-Applicability- The


2. The personal information
immediately preceding sections are
controller may notify third
not applicable if the processed
parties who have previously
personal information are used only
received such processed personal
for the needs of scientific and
information.
statistical research and, on the basis loss or destruction, and
of such, no activities are carried out human dangers such as
and no decisions are taken regarding unlawful access, fraudulent
the data subject: Provided, That the misuse, unlawful destruction,
personal information shall be held alteration and contamination.
under strict confidentiality and shall
be used only for the declared (c) The determination of the
purpose. Likewise, the immediately appropriate level of security
preceding sections are not applicable under this section must take
to processing of personal information into account the nature of the
gathered for the purpose of personal information to be
investigations in relation to any protected, the risks
criminal, administrative or tax represented by the
liabilities of a data subject. processing, the size of the
organization and complexity
CHAPTER V of its operations, current data
SECURITY OF PERSONAL privacy best practices and the
INFORMATION cost of security
implementation. Subject to
SEC. 20. Security of Personal guidelines as the Commission
Information. – may issue from time to time,
the measures implemented
(a) The personal information must include:
controller must implement
reasonable and appropriate 1) Safeguards to protect its computer
organizational, physical and network against accidental. Unlawful
technical measures intended or unauthorized usage or interference
for the protection of personal with or hindering of their functioning
information against any or availability;
accidental or unlawful 2) A security policy with respect to the
destruction, alteration and processing of personal information;
disclosure, as well as against
any other unlawful
processing. 3) A process for identifying and
accessing reasonably foreseeable
(b) The personal information vulnerabilities in its computer
controller shall implement networks, and for taking
reasonable and appropriate 4) Regular monitoring for security
measures to protect personal breaches and a process for taking
information against natural preventive, corrective and mitigating
dangers such as accidental
action against security incidents that
can lead to a security breach

(d) The personal information


controller must further ensure
that third parties processing
personal information on its
behalf shall implement the
security measures required by
this provision.
(e) The employees, agents or
representatives of a personal
information controller who
are involved in the processing
of personal information under
strict confidentiality if the
personal information are not
intended for public
disclosure. This obligation
shall continue even after
leaving the public service,
transfer to another position or
upon termination of
employment or contractual
relations.
(f) The personal information
controller shall promptly
notify the Commission and
affected data subjects when
sensitive personal

You might also like