Data Privacy Act

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 28

DATA PRIVACY ACT

of 2012
Title:

• “An Act Protecting Individual Personal


Information and Communications Systems in the
Government and the Private Sector, Creating for
this Purpose The National Privacy Commission,
and for Other Purposes”
SCOPE
• DATA PROCESSING- any operation or any set of
operations performed upon personal information

• PERSONAL INFORMATION- any information


whether recorded in a material or not, from
which the identity of an individual is apparent or
can be reasonably and directly ascertained by the
entity holding the information, or when put
together with other information would directly
and certainly identify an individual
• INFORMATION AND COMMUNICATIONS SYSTEMS- a
system for generating, sending, receiving, storing
or otherwise processing electronic data messages,
electronic documents and includes the computer
system or other similar device by or which data is
recorded, transmitted or stored and any
procedure related to the recording, transmission
or storage of electronic data, electronic message,
and electronic document
• DATA SUBJECT- an individual whose personal
information is processed.
• Applies to the processing of all types of personal
information and to any enity involved in personal
information processing
• Applies even to acts done outside the Philippines
if they relate to personal information about a
Philippine citizen or resident Alien and the doer
of the act has a recognized link in the Philippines
EXCLUSIONS
Personal Information…
1. Relating to officers or employees of a
government institution relating to the position
and function of said individuals;
2. Relating to those performing service under
contract for a government institution;
3. Relating to any discretionary benefit of a
financial nature such as
4. Those processed for journalistic, artistic,
literary or research purposes
EXCLUSIONS

5. Those necessary for carry out the functions of


public authority;
6. Those necessary for banks and other financial
institutions;
7. Those originally collected from nonresidents in
accordance with the laws of their residence
GENERAL RIGHTS OF DATA SUBJECT

1. Right to Information
2. Right to Access
3. Right to Correct
4. Right to Remove
5. Right to Damages
6. Right to Data Portability

Note: Rights are transmissible


EXCEPTIONS (General Rights of the Data Subject)

1. The processed personal information are used


only for the needs of scientific and statistical
research and, on the basis of such, no activities
are carried out and no decisions are taken
regarding the data subject.
2. The Processing of personal information is
gathered for the purpose of investigations in
relation to any criminal, administrative or tax
liabilities of a data subject.
PROCESSING OF PERSONAL INFORMATION
• Personal Information must be:
1. Collected for specified and legitimate
purpose/s;
2. Processed fairly and lawfully;
3. Accurate, relevant and kept up to date;
incomplete data must be rectified,
supplemented, destroyed or their further
processing restricted;
4. Adequate and not excessive
PROCESSING OF PERSONAL INFORMATION
5. Retained only for as long as necessary for the
fulfillment of the purposes for which the ata was
obtained or for the establishment, exercise of
defense of legal claims, or for legitimate business
purposes, or as provided by law.
6. Kept in form which permits identification of
data subjects for no longer than is necessary for
the purposes for which the data were collected
and processed
PROCESSING OF PERSONAL INFORMATION
Criteria for Lawful Processing of Personal
Information - the processing shall be permitted
only if not otherwise prohibited by law, and when
at least one of the following conditions exists:
1.) The data subject has given his or her consent;
2.) The processing of personal information is
necessary and is related to the fulfillment of a
contract with the data subject or in order to take
steps at the request of the data subject prior to
entering int a contract;
PROCESSING OF PERSONAL INFORMATION
3.) The processing is necessary for compliance
with a legal obligation to which the personal
information controller is subject;
4.) The processing is necessary to protect vitally
important interests of the data subject;
5.) The processing is necessary in order to respond
to national emergency, to comply with the
requirements of public order and safety, or to
fulfill functions of public authority;
PROCESSING OF PERSONAL INFORMATION

6.) The processing is necessary for the purposes of


the legitimate interests pursued by the personal
information controller or by a third party or parties
to whom the data is dsclosed, except where such
interests are overridden by fundamental rights and
freedoms of the data subject which require
protection under the Phil. Constitution.
PROCESSING OF PERSONAL INFORMATION

PRIVILEGED INFORMATION-
refers to any and all forms of data which under
the Rules of Court and other pertinent laws
constitute privileged communication
PROCESSING OF PERSONAL INFORMATION
SENSITIVE PERSONAL INFORMATION-refers to personal
information:
1. About an individual’s race, ethnic origin, marital
status, age, color, and religious , philosophical or
political affiliations;
2. About an individual’s health, education, genetic or
sexual life, or to any proceeding for any offense
committed or alleged to have been committed by a
person, the disposal of such proceedings, or the
sentence of any court in such proceedings;
SENSITIVE PERSONAL INFORMATION

3. Issued by government agencies peculiar to an


individual;
4. Specifically established by an executive order or
an act of Congress to be kept classified.
PROCESSING OF PERSONAL INFORMATION

General Rule: The processing of sensitive personal


information and privileged information shall be
prohibited.

EXCEPTIONS:
1. The data subject has given his/her consent or
in the case of privileged information, all parties to
the exchange have given their consent prior to
processing
PROCESSING OF PERSONAL INFORMATION
2. The processing of the same is provided for by
existing laws and regulations
3. The processing is necessary to protect the life
and health of the data subject or another
person, and the data subject is not legally or
physically able to express his/her consent prior
to the processing;
4. The processing is necessary to achieve the
lawful and noncommercial objectives of public
organizations and their associations.
PROCESSING OF PERSONAL INFORMATION

5. The processing is necessary for purposes of


medical treatment
6. The processing concerns such personal
information as is necessary for the protection of
lawful rights and interests of natural or legal
persons in court proceedings, or the
establishment, exercise or defense of legal
claims, or when provided to government or
public authority.
SECURITY OF SENSITIVE PERSONAL
INFORMATION IN GOVERNMENT

• Responsibility of Heads of Agencies- information


must be secured with the most appropriate
standards as recommended by the National
Privacy Commission. Heads are responsible for
complying with the security requirements
Requirements of Access by Agency Personnel

a. ONLINE/ONSITE – no employee shall have access


unless the employee has received a security
clearance;
b. OFFSITE – information shall not be transported
or accessed offsite unless a request is approved
PERSONAL INFORMATION CONTROLLER

Refers to a aperson or organizations who


controls the collection, holding, or processing or
use of personal information, including a person or
org who instructs another person or org to collect,
hold, process, use, transfer or disclose personal
information on his or her behalf.
PERSONAL INFORMATION PROCESSOR

• Refers to an any natural or juridical person


qualified to act as such to whom a personal
information controller may outsource the
processing of personal data pertaining to a
data subject
Rights of Personal Information Controllers

1. Outsource the processing of personal


information

2. Invoke the defense of privileged communication


Obligations of Personal Information Controllers

1. Implement reasonable and appropriate organization,


physical and technical measures intended for the
protection of personal information against any accidental
or unlawful destruction, alteration and disclosure, as well
as against any other unlawful processing

2. Implement reasonable and appropriate measures to


protect personal information against natural dangers and
human dangers
PROHIBTED ACTS
1. Unauthorized Processing
2. Accessing and Providing Access Through Negligence
3. Improper Disposal
4. Processing for Unauthorized Purposes
5. Unauthorized Access or Intentional Breach
6. Concealment of Security Breaches
7. Malicious Disclosure
8. Unauthorized Disclosure
Thank You!!

You might also like