You are on page 1of 6

Data Privacy Act of 2012 entity has access to personal information; and

(c) The entity has other links in the Philippines


Right to Privacy such as, but not limited
➢ The right to be let alone - the most to:
comprehensive of rights and the right most (1) The entity carries on business in the
valued by civilized men. Philippines; and
(2) The personal information was collected or
Right to Information Privacy held by an entity
in the Philippines.
➢ The individual’s ability to control the flow of
information concerning or describing him, A. Personal vs. Sensitive Personal
which however must be overbalanced by Information
legitimate public concerns. To deprive an
individual of his power to control or determine Personal Information
whom to share information of his personal ➢ refers to any information whether recorded
details would deny him of his right to his own in a material form or not, from which the
personhood. identity of an individual is apparent or can
be reasonably and directly ascertained by
National Privacy Commission the entity holding the information, or when put
➢ The Regulatory Body task “to administer together with other information would
and implement the provisions of [the Data directly and certainly identify an
Privacy Act], and to monitor and ensure individual.
compliance of the country with
international standards set for data protection” {Example of Personal Information -
 Name
State Policy on Data Privacy  Home Address
➢ “It is the policy of the State to protect the  Business Address
fundamental human right of privacy, of  Email Address
communication while ensuring the free flow of  Telephone Number - Work
information to promote innovation and  Telephone Number – Home }
growth.”
Sensitive Personal Information
Extraterritorial Application
➢ The [Data Privacy Act] applies to an act ➢ refers to personal information:
done or practice engaged in and outside of the
Philippines by an entity if: (1) About an individual’s race, ethnic origin,
(a) The act, practice or processing relates to marital status, age, color, and religious,
personal information about a Philippine citizen philosophical or political affiliations;
or a resident;
(b) The entity has a link with the Philippines, (2) About an individual’s health, education,
and the entity is processing personal genetic or sexual life of a person, or to any
information in the Philippines or even if the proceeding for any offense committed or
processing is outside the Philippines as long alleged to have been committed by such
as it is about Philippine citizens or residents person, the disposal of such proceedings, or
such as, but not limited to, the following: the sentence of any court in such proceedings;
(b)
(1) A contract is entered in the Philippines; (3) Issued by government agencies peculiar
(2) A juridical entity unincorporated in the to an individual which includes, but not limited
Philippines but has to, social security numbers, previous or
central management and control in the country; current health records, licenses or its
and denials, suspension or revocation, and tax
(3) An entity that has a branch, agency, office returns; and
or subsidiary in
the Philippines and the parent or affiliate of the (4) Specifically established by an executive
Philippine
order or an act of Congress to be kept
classified. (1) A person or organization who performs
such functions as instructed by another
{Examples of Sensitive Personal Information - person or organization; and
 Date of Birth
 Marital Status (2) An individual who collects, holds,
 Color, Race or Ethnic Origin processes or uses personal information in
 Religion (Religious beliefs or affiliations) connection with the individual’s personal,
 Education family or household affairs.
 Photo
 Biometrics {Examples of PICs processing personal data
 Political Association needed for their day to day activities -
 Philosophical Beliefs/Orientation Mercury Drugs through their Suki Card, SM
 Health through SM Advantage Card, Jollibee
 Sexual life/preference/practice Group through Happy Plus Card, All Banks, All
 Offence committed or alleged to have been Insurance Companies, Travel
committed, the disposal of such Agencies, Hospitals, and All Government
proceedings, or the sentence of any court in entities.}
such proceedings
 Issued by government agencies peculiar to Personal Information Processor (PIP)
an individual
• Unique identifiers ➢ refers to any natural or juridical person
• Previous or current health records qualified to act as such under this Act to whom
• Licenses or its denials, suspension or a personal information controller may
revocation outsource the processing of personal data
• Tax returns } pertaining to a data subject.
*Privilege Information {Examples of PIPs Mail Service Providers,
➢ refers to any and all forms of data which Outsource Companies for purposes as
under the Rules of Court and other pertinent needed by the Principal Company, IT Service
laws constitute privileged communication. Provider etc.}

B. Scope Processing Exempt from the Coverage of


the Data Privacy Act
[The Data Privacy Act of 2012] applies to the
processing of all types of personal ➢ This Act does not apply to the following:
information and to any natural and juridical
person involved in personal information (a) Information about any individual who is or
processing including those personal was an officer or employee of a
information controllers and processors who, government institution that relates to the
although not found or established in the position or functions of the individual,
Philippines, use equipment that are located in including:
the Philippines, or those who maintain an
office, branch (1) The fact that the individual is or was an
or agency in the Philippines. officer or employee of the
government institution;
Personal Information Controller (PIC)
(2) The title, business address and office
➢ refers to a person or organization who telephone number of the individual;
controls the collection, holding, processing or
use of personal information, including a person (3) The classification, salary range and
or organization who instructs another person responsibilities of the position held by the
or organization to collect, hold, process, use, individual; and
transfer or disclose personal information on his
or her behalf. (4) The name of the individual on a document
The term excludes:
prepared by the individual in the course of
employment with the government; C. Processing of Personal Information

(b) Information about an individual who is or ➢ The processing of personal information shall
was performing service under contract for a be allowed, subject to compliance with the
government institution that relates to the requirements of this Act and other laws
services performed, including the terms of the allowing disclosure of information to the public
contract, and the name of the individual given and adherence to the principles of
in the course of the performance of those transparency, legitimate purpose and
services; proportionality

(c) Information relating to any discretionary


benefit of a financial nature such as the ❖ Transparency
granting of a license or permit given by the
government to an individual, including the ➢ The data subject must be aware of the
name of the individual and the exact nature of nature, purpose and extent of the
the benefit; processing of his or her personal data.

(d) Personal information processed for ➢ Including the risks and safeguards
journalistic, artistic, literary or research involved the identity of personal
purposes; information controller, his or her rights as a
data subject, and how these can be
(e) Information necessary in order to carry out exercised. Any information and
the functions of public authority communication relating to the processing of
personal data should be easy to access and
which includes the processing of personal data understand, using clear and plain language.
for the performance by the independent,
central monetary authority and law ❖ Legitimate Purpose
enforcement and regulatory agencies of their
constitutionally and statutorily mandated ➢ Processing of information shall be
functions. Nothing in this Act shall be compatible with a declared and specified
construed as to have amended or repealed purpose which must not be contrary to law,
Republic Act No. 1405, otherwise known as morals or public policy.
the Secrecy of Bank Deposits Act; Republic
Act No. 6426, otherwise known as the Foreign ❖ Proportionality
Currency Deposit Act; and Republic Act No.
9510, otherwise known as the Credit ➢ The processing of information shall be
Information System Act (CISA); adequate, relevant, suitable, necessary and
not excessive in relation to a declared and
(f) Information necessary for banks and other specified purpose.
financial institutions under the jurisdiction of
the independent, central monetary authority or Personal data shall be processed only if the
Bangko Sentral ng Pilipinas to comply with purpose of the processing could
Republic Act No. 9510, and Republic Act No. not reasonably be fulfilled by other means.
9160, as amended, otherwise known as the
Anti-Money Laundering Act and other Criteria for Lawful Processing of Personal
applicable laws; and Information
The processing of personal information shall
(g) Personal information originally collected be permitted only if not otherwise
from residents of foreign jurisdictions in prohibited by law, and when at least one of the
accordance with the laws of those foreign following conditions exists:
jurisdictions, including any applicable
data privacy laws, which is being processed in (a) The data subject has given his or her
the Philippines. consent;
(b) The processing of personal information is
necessary and is related to the fulfillment of physically able to express his or her consent
a contract with the data subject or in order to prior to the processing;
take steps at the request of the data subject (c) The processing is necessary to achieve the
prior to entering into a contract; lawful and non-commercial objectives of public
(c) The processing is necessary for organizations and their associations: Provided,
compliance with a legal obligation to which That such processing is only confined and
the personal information controller is subject; related to the bona fide members of these
(d) The processing is necessary to protect organizations or their associations: Provided,
vitally important interests of the data subject, further, That the sensitive personal information
including life and health; are not transferred to third parties: Provided,
(e) The processing is necessary in order to finally, That consent of the data subject was
respond to national emergency, to comply obtained prior to processing;
with the requirements of public order and
safety, or to fulfill functions of (e) The processing is necessary for purposes
public authority which necessarily includes of medical treatment, is carried out by a
the processing of personal data for the medical practitioner or a medical treatment
fulfillment of its mandate; or institution, and an adequate level of
protection of personal information is ensured;
(f) The processing is necessary for the or
purposes of the legitimate interests pursued
by the personal information controller or by a (f) The processing concerns such personal
third party or parties to whom the data is information as is necessary for the protection
disclosed, except where such interests are of lawful rights and interests of natural or legal
overridden by fundamental rights and persons in court proceedings, or the
freedoms of the data subject which require establishment, exercise or defense of legal
protection under the Philippine Constitution. claims, or when provided to government or
public authority.
Criteria for Lawful Processing of Sensitive
Personal Information (and Privileged Consent of the Data Subject
Information)
➢ Refers to any freely given, specific,
The processing of sensitive personal informed indication of will, whereby the data
information and privileged information shall be subject agrees to the collection and processing
prohibited, except in the following cases: of personal information about and/or relating to
him or her.
(a) The data subject has given his or her
consent, specific to the purpose prior to the ➢ Consent shall be evidenced by written,
processing, or in the case of privileged electronic or recorded means.
information, all parties to the exchange have
given their consent prior to processing; ➢ It may also be given on behalf of the data
(b) The processing of the same is provided for subject by an agent specifically
by existing laws and regulations: authorized by the data subject to do so.

Provided, That such regulatory enactments Principle of Accountability


guarantee the protection of the sensitive
personal information and the privileged ➢ Each personal information controller is
information: Provided, further, That the consent responsible for personal information under its
of the data subjects are not required by law or control or custody, including information that
regulation permitting the processing of the have been transferred to a third party for
sensitive personal information or the privileged processing, whether domestically or
information; internationally, subject to cross-border
arrangement and cooperation.
(c) The processing is necessary to protect the
life and health of the data subject or another D. Rights of Data Subject
person, and the data subject is not legally or
when it is necessary for the performance of or
Data Subject in relation to a contract or service or when
➢ Refers to an individual whose personal necessary or desirable in the context of an
information is processed. employeremployee relationship, between the
collector and the data subject, or when the
Rights of Data Subject information is being collected and processed
The data subject is entitled to: as a result of legal obligation;

Right to Information Right to Access

➢ Be informed whether personal information ➢ Reasonable access to, upon demand, the
pertaining to him or her shall be, following:
are being or have been processed; (1) Contents of his or her personal information
that were processed;
➢ Be furnished the information indicated
hereunder before the entry of his or her (2) Sources from which personal information
personal information into the processing were obtained;
system of the personal information controller,
or at the next practical opportunity: (3) Names and addresses of recipients of the
personal information;
(1) Description of the personal information to
be entered into the system; (4) Manner by which such data were
processed;
(2) Purposes for which they are being or are to
be processed; (5) Reasons for the disclosure of the personal
information to recipients;
(3) Scope and method of the personal
information processing; (6) Information on automated processes where
the data will or likely to be made as the sole
(4) The recipients or classes of recipients to basis for any decision significantly affecting or
whom they are or may be disclosed; will affect the data subject;

(5) Methods utilized for automated access, if (7) Date when his or her personal information
the same is allowed by the data subject, and concerning the data subject were last
the extent to which such access is authorized; accessed and modified; and

(6) The identity and contact details of the (8) The designation, or name or identity and
personal information controller or its address of the personal
representative; information controller;

(7) The period for which the information will be Right to Rectification or Correction
stored; and ➢ Dispute the inaccuracy or error in the
personal information and have the personal
(8) The existence of their rights, i.e., to access, information controller correct it immediately
correction, as well as the right to lodge a and accordingly, unless the request is
complaint before the Commission. vexatious or otherwise unreasonable.

Any information supplied or declaration made ➢ If the personal information have been
to the data subject on these matters shall not corrected, the personal information
be amended without prior notification of data controller shall ensure the accessibility of both
subject: Provided, That the notification under the new and the retracted information and the
subsection (b) shall not apply should the simultaneous receipt of the new and the
personal information be needed pursuant to a retracted information by recipients thereof:
subpoena or when the collection and Provided, That the third parties who have
processing are for obvious purposes, including previously received such processed personal
information shall he informed of its inaccuracy
and its rectification upon reasonable request of Non Applicability of the Rights of Data
the data subject; Subject25

Right to Erasure or Blocking 1. Processed personal information are used


only for the needs of scientific and
➢ Suspend, withdraw or order the blocking, statistical research and, on the basis of such,
removal or destruction of his or her personal no activities are carried out and no
information from the personal information decisions are taken regarding the data subject.
controller’s filing system upon discovery and 2. Processing of personal information gathered
substantial proof that the personal information for the purpose of investigations in
are incomplete, outdated, false, unlawfully relation to any criminal, administrative or tax
obtained, used for unauthorized liabilities of a data subject.
purposes or are no longer necessary for the
purposes for which they were collected. In this
case, the personal information controller may
notify third parties who have previously
received such processed personal information;
and

Right to Damages

➢ Be indemnified for any damages sustained


due to such inaccurate, incomplete, outdated,
false, unlawfully obtained or unauthorized use
of personal information.

Right to Data Portability

➢ The data subject shall have the right, where


personal information is processed by electronic
means and in a structured and commonly used
format, to obtain from the personal information
controller a copy of data undergoing
processing in an electronic or structured
format, which is commonly used and allows for
further use by the data subject.

➢ The Commission may specify the electronic


format referred to above, as well as the
technical standards, modalities and procedures
for their transfer.

Transmissibility of Rights of the Data


Subject

➢ The lawful heirs and assigns of the data


subject may invoke the rights of the data
subject for, which he or she is an heir or
assignee at any time after the death of the data
subject or when the data subject is
incapacitated or incapable of exercising the
rights as enumerated in the immediately
preceding section.

You might also like