You are on page 1of 13

DATA PRIVACY GUIDANCE:

CONTACT TRACING
Khane Samala Raza
OIC-Director IV, Data Security & Compliance Office
DP Council – Retail Meeting
COMPLIANCE CHECK
§Prompted by citizen reports

§Aims to facilitate the safe gradual re-opening


of the economy

§Focused on contact tracing as a personal


data processing activity

51st APPA FORUM JURISDICTION REPORT: EDUCATION ©2019 NPC


CONCERNS
§Unsecure processing – logbooks, unsecure
drop box, etc.
§Repurposing (marketing)
§Overcollection
§Baseless retention period
§Lack of transparency / no privacy notice

51st APPA FORUM JURISDICTION REPORT: EDUCATION ©2019 NPC


Legitimate purpose
Proportionality

DS Rights
Transparency

Security measures
PROPORTIONALITY
§Personal data collected

§Method or technology used

§Retention period
PROPORTIONALITY
TRANSPARENCY
o Personal data collected
Enumerates the personal data collected such as name, contact info, etc.

o Purpose
Declares the specific purpose(s) of the personal data processing

o Basis for processing


Declares the criteria for lawful processing used

o How data is collected


Specifies the manner of collection; E.g. physical forms, online forms, etc.

o How data is used


Explains the primary & secondary uses of the data
TRANSPARENCY
o How data is stored
Specifies the manner of storage & retention period

o If data is disclosed/shared
Specifies info on data transmission to other parties

o To whom data is disclosed/shared


Specifies the recipients within & outside the org, including the description, basis & purpose of sharing

o How data is disposed


Specifies the manner of disposal

o Risks involved
Specifies risks at any stage of the processing
TRANSPARENCY
o How data is protected
Enumerate organizational, physical & technical security measures to address risks

o Methods utilized for automated access


Includes description & extent of automated access, if any

o Identity of PIC
Specifies the name of PIC

o DPO Contact details


Specifies the Email, landline, mobile number or other contact info of the DPO

o Rights as data subjects


Specifies info on how to exercise applicable rights specified
§ Collect what is only necessary &
allowed under relevant gov’t
issuances

§ Do not process beyond the


declared, specified & legitimate
purpose

§ Retain data only for a limited


period as specified in
government issuances (30 days)
§ Be transparent, have a Privacy
Notice

§ Devise a reasonable way to


collect data that prevents
accidental & unauthorized
viewing

§ Encourage data subjects to


provide accurate info by
assuring that their data are
protected
§ Anticipate & manage risks

§ Train staff to handle & protect


collected data

§ Implement access controls

§ Establish a disciplinary process

§ Dispose data securely

§ Have mechanisms for the


exercise of rights
Thank you!

You might also like