EXPLANATION
EXPLANATION
The Data Privacy Act of 2012, also known as Republic Act No. 10173, is crucial for safeguarding personal
information in the Philippines. It establishes a framework for how both public and private sectors must handle
personal data, ensuring that individuals' rights to privacy are upheld. Understanding this law is essential for
compliance and for building a culture of respect for personal information.
WHAT IS A BREACH
Breaches can occur in various forms, from minor errors to significant security failures. It’s crucial for all
employees to be vigilant and report any potential breaches to the DPO immediately. Prompt action can
mitigate the impact of a breach and ensure that affected clients are notified in a timely manner, maintaining
trust and transparency.
KEY PRINCIPLES
The principles outlined here are critical for effective data protection. They serve as a framework for
organizations to follow, ensuring that personal information is handled responsibly and ethically. Each
principle plays a role in building trust with customers and protecting their rights in an increasingly digital
world.
1. Purpose Limitation - Personal data should be collected only for specific, clear, and
legitimate purposes, and should not be processed further in a way that is incompatible
with those purposes.
2. Data Minimization - Collect and retain only the data that is required for the specified
purposes.
3. Consent - is a clear, specific, informed agreement given freely by the data subject for
processing their personal data.
4. Security - Organizations are required to adopt suitable technical and organisational
measures to safeguard personal data against loss, misuse, or unauthorized access.
5. Transparency - Organizations must clearly explain their methods for collecting, using,
and managing personal data so individuals understand their practices.
6. Data Subjects Rights - The Data Privacy Act of 2012 (DPA) in the Philippines, or
Republic Act No. 10173, safeguards data subjects' rights, granting individuals control
over their personal information. These rights include being informed, accessing,
rectifying, erasing, and objecting to processing, among others.