You are on page 1of 14

DATA PRIVACY ACT

ILLUSTRATION: A passenger of a bus took a picture


Commission - shall refer to the National Privacy
of the conductor which he found to be cute. Can the
Commission created by virtue of this Act.
passenger be considered a personal information
Consent of the data subject - refers to any freely given, controller?
specific, informed indication of will, whereby the data
subject agrees to the collection and processing of
personal information about and/or relating to him or her. ANSWER: No, because the processing of personal
Consent shall be evidenced by written, electronic or information (the picture which bears the face and can
recorded means. It may also be given on behalf of the be used to identify the data subject) is only for
data subject by an agent specifically authorized by the personal affairs.
data subject to do so.
Data subject - refers to an individual whose information SCOPE:
is processed.
Applicability:
Direct marketing - refers to communication by
whatever means of any advertising or marketing 1) The processing of all types of personal
material which is directed to particular individuals. information and
Filing system - refers to any act of information relating 2) To any natural and juridical person involved in
to natural or juridical persons to the extent that, although personal information processing including those
the information is not processed by equipment operating personal information controllers and processors
automatically in response to instructions given for that who, although not found or established in the
purpose, the set is structured, either by reference to Philippines, use equipment that are located in the
individuals or by reference to criteria relating to Philippines, or those who maintain an office, branch
individuals, in such a way that specific information or agency in the Philippines subject to the
relating to a particular person is readily available. immediately succeeding paragraph.
Information and Communication System - refers to a Does not apply to:
system for generating, sending, receiving, storing or 1) Information about any individual who is or was an
otherwise processing electronic data messages or officer or employee of a government institution
electronic documents and includes the computer system that relates to the position or functions of the
or other similar device by which data is recorded, individual, including:
transmitted, or stored and any procedure related to the
recording, transmission or storage of electronic data, a) The fact that the individual is or was an officer
electronic message, or electronic document. of employee of the government institution;

Personal information controller - refers to a person or b) The title, business address and office telephone
organization who controls the collection, holding, number of the individual;
processing or use of personal information, including a c) The classification, salary range, and
person or organization who instructs another person or responsibilities of the position held by the
organization to collect, hold, process, use, transfer or individual; and
disclose personal information on his or her behalf. The
d) The name of the individual on a document
term excludes:
prepared by the individual in the course of
1) A person or organization who performs such employment with the government;
functions as instructed by another person or
2) Information about an individual who is or was
organization; and
performing service under contact for a
2) An individual who collects, holds, processes or uses government constitution that relates to the services
personal information in connection with the performed, including the terms of the contract, and
individual’s personal, family or household affairs. the name of the individual given in the course of the
Personal information processor - refers to any natural performance of those services;
or juridical person qualified to act as such under this Act 3) Information relating to any discretionary benefit of
to whom a personal information controller may a financial nature such as the granting of a license
outsource the processing of personal data pertaining to or permit given by the government to an individual,
a data subject. including the name of the individual and the exact
nature of the benefit;
ILLUSTRATION: The Human Resource Department,
headed by the Executive Vice President for HR, is 4) Personal information processed for journalistic,
tasked to collect information from applicants who may artistic, literary or research purposes;
eventually be hired and join the company according to 5) Information necessary in order to carry out the
the directives of the Board of Directors. In this case, functions of public authority which includes the
the EVP for HR is the Personal Data Processor processing of personal data for the performance by
because he/she processes the information only through the independent, central monetary authority and law
the directives of the BOD, the latter being the Personal enforcement and regulatory agencies of their
Data Controller. constitutionally and statutorily mandated functions.
No amendments or repeal to the following laws: Functions of the National Privacy Commission: The
Data Privacy commission was created to administer and
a) RA no. 1405 Secrecy of Bank Deposit Act
implement the provisions of the Data Privacy Act and to
b) RA no. 6426 Foreign Currency Deposit Act monitor and ensure compliance of the country with
c) RA no. 9510 Credit Information System Act international standards set for data protection. Its
functions include:
6) Information necessary for banks and other
financial institutions under the jurisdiction of the 1) Ensure compliance of personal information
independent, central monetary authority or BSP to controllers with the provisions of this Act;
comply with the CISA and RA 9160 as amended, 2) Receive complaints, institute investigations,
otherwise known as AMLA and other applicable facilitate or enable settlement of complaints through
laws. the use of alternative dispute resolution processes,
7) Personal information originally collected from the adjudicate, award indemnity on matters affecting
residents of foreign jurisdictions in accordance any personal information, prepare reports on
with the laws of those foreign jurisdictions, disposition of complaints and resolution of any
including any applicable data privacy laws, which is investigation it initiates, and, in cases it deems
being processed in the Philippines. appropriate, publicize any such report: Provided,
That in resolving any complaint or investigation
(except where amicable settlement is reached by the
Protection Afforded to Journalists and Their Sources: parties), the Commission shall act as a collegial
No amendment or repeal of RA no. 53, which affords body. For this purpose; the Commission may be
the publishers, editors or duly accredited reporters of given access to personal information that is subject
any newspaper, magazine or periodical of general of any complaint and to collect the information
circulation protection from being compelled to reveal necessary to perform its functions under this Act:
the source of any news report or information appearing 3) Issue cease and desist orders, impose a temporary or
in said publication which was related to any confidence permanent ban on the processing of personal
to such publisher, editor, or reporter. information, upon finding that the processing will
be detrimental to national security and public
interest;
Extraterritorial Application: The Data Privacy Act
applies to an act done or practice engaged in and outside 4) Compel or petition any entity, government agency
of the Philippines by an entity if: or instrumentality to abide by its orders or take
action on a matter affecting data privacy;
1) The act, practice or processing related to personal
information about a Philippine citizen or a resident; 5) Monitor the compliance of other government
agencies or instrumentalities on their security and
2) The entity has a link with the Philippines, and the technical measures and recommend the necessary
entity is processing personal information in the action in order to meet minimum standards for
Philippines or even if the processing is outside the protection of personal information pursuant to this
Philippines as long as it is about Philippine citizens Act;
or residents such as, but not limited to, the
following: 6) Coordinate with other government agencies and the
private sector on torts to formulate and implement
a) A contract is entered in the Philippines; plans and policies to strengthen the protection of
b) A juridical entity unincorporated in the personal information in the country;
Philippines but has central management and 7) Publish on a regular basis a guide to all laws
control in the country; and relating to data protection;
c) An entity that has a branch, agency, office or 8) Publish a compilation of agency system of records
subsidiary in the Philippines and the parent or and notices, including index and other finding aids;
affiliate of the Philippine entity has access to
personal information; and 9) To recommend to the Department of Justice (DOJ)
the prosecution and imposition of penalties provided
3) The entity has other links in the Philippines such as, under the Act;
but not limited to:
10) Review, approve, reject or require modification of
a) The entity carries on business in the privacy codes voluntarily adhered to by a personal
Philippines; and information controller. Provided, That the privacy
b) The personal information was collected or held codes shall adhere to the underlying data privacy
by an entity in the Philippines principles embodied in this Act. Provided, further,
That such privacy codes may include private dispute
resolution mechanisms for complaints against any
participating personal information controller. For
this purpose, the Commission shall consult with
relevant regulatory agencies in the formulation and
The National Privacy Commission ministration of privacy codes applying the standards
set out in this Act, with respect to the persons,
entities, business activities and business sectors that shall be filled in the same manner in which the original
said regulatory bodies are authorized to principally appointment was made.
regulate pursuant to the law: Provided, finally, That
the Commission may review such privacy codes and
require changes thereto for purposes of complying Qualifications of The Privacy Commissioner:
with the Data Privacy Act; 1) At least thirty-five (35) years of age;
11) Provide assistance on matters relating to privacy or 2) Of good moral character, unquestionable integrity
data protection at the request of a national or local and known probity, and
agency, a private entity or any person;
3) A recognized expert in the field of information
12) Comment on the implication on data privacy of technology and data privacy
proposed national or local statutes, regulations or
procedures, issue advisory opinions and interpret The Deputy Privacy Commissioners must be recognized
the provisions of this Act and other data privacy experts in the field of information technology and data
laws; privacy.
13) Propose legislation, amendments or modifications Acts done in good faith: The Privacy Commissioner, the
to Philippine laws on privacy or data protection as Deputy Privacy Commissioners, or any person acting on
may be necessary; their behalf or under their direction, shall not be civilly
liable for acts done in good faith in the performance of
14) Ensure proper and effective coordination with data their duties.
privacy regulators in other countries and private
accountability agents, participate in international However, he or she shall be liable for willful or
and regional initiatives for data privacy protection; negligent acts done by him or her which are contrary to
law, morals, public policy and good customs even if he
15) Negotiate and contract with other data privacy or she acted under orders or instructions of superiors. In
authorities of other countries for cross-border case a lawsuit is filed against such official on the subject
application and implementation of respective of the performance of his or her duties, where such
privacy laws; performance is lawful, he or she shall be reimbursed by
16) Assist Philippine companies doing business abroad the Commission for reasonable costs of litigation.
to respond to foreign privacy or data protection laws
and regulations;
The Secretariat: Majority of the members of the
17) Generally perform such acts as may be necessary to Secretariat must have served for at least five (5) years in
facilitate cross-border enforcement of data privacy any agency of the government that is involved in the
protection. processing of personal information including, but not
limited to, the following offices: SSS, GSIS, LTO, BIR,
PhilHealth, COMELEC, DFA, DOJ, and Philpost.
Confidentiality: The Commission shall ensure at all
times the confidentiality of any personal information
that comes to its knowledge and possession. PROCESSING OF PERSONAL INFORMATION
Processing refers to any operation or any set of
Organizational Structure of the Commission: The operations performed upon personal information
Commission shall be attached to the Department of including, but not limited to:
Information and Communications Technology (DICT) 1) Collection
and shall be headed by a Privacy Commissioner, who 2) Recording
shall also act as Chairman of the Commission. 3) Organization
The Privacy Commissioner shall enjoy the benefits, 4) Storage
privileges and emoluments equivalent to the rank of 5) Updating or Modification
Secretary. 6) Retrieval
7) Consultation
The Privacy Commissioner shall be assisted by two (2) 8) Use
Deputy Privacy Commissioners, one to be responsible 9) Consolidation
for Data Processing Systems and one to be responsible 10) Blocking
for Policies and Planning. 11) Erasure; or
They shall enjoy the benefits, privileges and 12) Destruction of Data
emoluments to the rank of Undersecretary.

General Data Privacy Principles: The processing of


Term and Vacancy: The Privacy Commissioner and the personal information shall be allowed, subject to:
two (2) Deputy Privacy Commissioners shall be 1) Compliance with the requirements of the Data
appointed by the President of the Philippines for a term Privacy Act and other laws allowing disclosure of
of three (3) years and may be reappointed for another information to the public and
term of three (3) years. Vacancies in the Commission
2) Adherence to the following principles:
1. Principle of Proportionality: The processing of incomplete data must be rectified, supplemented,
Personal data shall be adequate, relevant, suitable, destroyed or then further processing restricted;
necessary, and not excessive in relation to a 4) Adequate and not excessive in relation to the
declared and specified purpose. Personal data shall purposes for which they are collected and
be processed by the Company only if the purpose of processed;
processing could not be reasonably be fulfilled by
other means 5) Retained only for as long as necessary for the
fulfillment of the purpose for which the data was
2. Principle of Legitimate Purpose: The processing obtained or for the establishment, exercise or
of personal data by the company shall be defense of legal claims, or for legitimate business
compatible with a declared and specified purpose purposes, or a provided by law; and
which must not be contrary to law, morals, or public
policy 6) Kept in a form which permits identification of data
subjects for no longer than is necessary for the
3. Principle of Transparency: The Data Subject must purposes for which the data were collected and
be aware of the nature, purpose, and extent of the processed: Provided, That personal information
Processing of his or her Personal Data by the collected for other purposes may lie processed for
company, including the risks and safeguards historical, statistical or scientific purposes, and in
involved, the identity of persons and entities cases laid down in law may be stored for longer
involved in processing his or her Personal Data, his periods: Provided, further, That adequate
or her rights as a Data Subject, and how these can safeguards are guaranteed by said laws authorizing
be exercised. Any information and communication their processing.
relating to the Processing of Personal Data should
be easy to access and understand, using clear and The personal information controller must ensure
plain language. implementation of personal information processing
principles set out herein.

ILLUSTRATION: A customer wants to apply for a


loyalty rewards card. The customer service CRITERIA FOR LAWFUL PROCESSING OF
representative asks the customer to fill-out a form PERSONAL INFORMATION
which includes information for blood type and The processing of personal information shall be
political affiliation. Can the company collect such permitted only if no otherwise prohibited by law, and
information? when at least one of the following conditions exists:
ANSWER: No, because of the principle of 1. The data subject has given his or her consent;
proportionality. Information relating to blood type and
political affiliation may be considered as going beyond 2. The processing of personal information is necessary
the necessary information necessary for the purpose of and is related to the fulfillment of a contract with
processing which is his application for a loyalty the data subject or in order to take steps at the
rewards card. request of the data subject prior to entering into a
contract;
3. The processing is necessary for compliance with a
PERSONAL INFORMATION, whether recorded in a legal obligation to which the personal information
material form or not, are those from which the identity controller is subject;
of an individual:
4. The processing is necessary to protect vitally
1. is apparent, or important interests of the data subject, including life
2. can be reasonably and directly ascertained by the and health;
entity holding the information, or 5. The processing is necessary in order to respond to
3. when put together with other information would national emergency, ho comply with the
directly and certainly identify an individual requirements of public order and safety, or to fulfill
functions of public authority which necessarily
Examples: include the Data Owner's Name, Home includes the processing of personal data for the
address and Phone number fulfillment of its mandate: or
Personal information must be: 6. The processing is necessary for the purposes of the
1) Collected for specified and legitimate purposes legitimate interests pursued by the personal
determined and declared before, as soon as information controller or by a third party or parties
reasonably practicable after collection, and later to whom the data is disclosed, except where such
processed in a way compatible with such declared, interests are overridden by fundamental rights and
specified and legitimate purposes only; freedoms of the data subject which require
protection under the Philippine Constitution.
2) Processed fairly and lawfully;
3) Accurate, relevant and, where necessary for
purposes for which is to be used the processing of
personal information, kept up to date; inaccurate or
PRIVILEGED INFORMATION this refers to any and b) That the sensitive personal information is not
all forms of data which under the Rules of Court and transferred to their parties; and
other pertinent laws constitute privileged c) That consent of the data subject was obtained
communication. prior to processing
Examples include: 5. The processing is necessary for purposes of medical
1) Attorney-client privileged information treatment, is carried out by a medical practitioner or
a medical treatment institution, and an adequate
2) Doctor-patient privileged information
level of protection of personal information is
3) Marital privilege communication ensured; or
4) Priest-confessor privileged information 6. The processing concerns such personal information
as is necessary for the protection of lawful rights
and interests of natural or legal persons in court
SENSITIVE PERSONAL INFORMATION proceedings, or the establishment, exercise or
This refers to personal information: defense of legal claims, or when provided to
government or public authority.
1. About an individual's race, ethnic origin, marital
status, age, color, and religious, philosophical or
political affiliations; ILLUSTRATION: A doctor logs in the symptoms and
2. About an individual's health, education, genetic or medications prescribed of a particular client. Is the
sexual life of a person, or to any proceeding for any doctor allowed to collect and process such
offense committed or alleged to have been information?
committed by such person, the disposal of such ANSWER: Yes. Because it would fall on the medical
proceedings, or the sentence of any court in such exception which is performed by a medical
proceedings; practitioner.
3. Issued by government agencies peculiar to an ILLUSTRATION: The employee is being required to
individual which includes, but not limited to, social provide his SSS, PAGIBIG, PhilHealth numbers to the
security numbers, previous or current health employer. Can the employer lawfully collect such
records, licenses or its denials, suspension or information?
revocation, and tax returns; and
ANSWER: Yes, because the processing of the same,
4. Specifically established by an executive order or an even though they are sensitive personal information is
act of Congress to be kept classified. provided for by existing laws and are necessary for the
Sensitive Personal Information and Privileged company to comply with existing laws and regulations.
Information: The processing of sensitive personal ILLUSTRATION: A card dealer is asking a potential
information and privileged information shall be buyer to fill-out a form which includes the name,
prohibited, except in the following cases: credit card details (as mode of payment) address and
1) The data subject has given his or her consent, racial origin of the buyer. Can the car dealer legally
specific to the purpose prior to the processing, or in process the same?
the case of privileged information, all parties to the ANSWER: As to the mare, and address, yes, since the
exchange have given their consent prior to processing of the same is necessary and is related to
processing; the fulfillment of a contract with the data subject or in
2) The processing of the same is provided for by order to take steps at the request of the data subject
existing laws and regulations, provided: prior to entering into a contract.
a) Such regulatory enactments guarantee the As to the credit card details, being sensitive personal
protection of the sensitive personal information information, consent must first be obtained to lawfully
and the privileged information; and process the same.
b) The consent of the data subject is not required As to the racial origin, no, since it violates the
by law or regulation permitting the processing principle of proportionality, even if the data subject
of the sensitive personal information or the gives his consent.
privileged information;
3. The processing is necessary to protect the life and Subcontract of Personal Information: A personal
health of the data subject or another person, and the information controller may subcontract the processing of
data subject is not legally or physically able to personal information.
express his or her consent prior to the processing;
The personal information controller shall be responsible
4. The processing is necessary to achieve the lawful for ensuring that proper safeguards are in place to
and noncommercial objectives of public ensure:
organizations and their associations: provided:
1) The confidentiality of the personal information
a) That such processing is only confined and processed,
related to their, fie members of these
organizations or their associations;
2) Prevent its use for unauthorized purposes, and f) The identity and contact details of the
generally, personal information controller or its
representative;
3) Comply with the requirements of the Data Privacy
Act and other laws for processing of personal g) The period for which the information will be
information. stored; and
The personal information processor shall comply with h) The existence of their rights, i.e., to access,
all the requirements of the Data Privacy Act and other correction, as well as the right to lodge a
applicable laws. complaint before the Commission.
2. Right to Object - The data subject shall have the
right to object to the processing of his or her
Extension of Privileged Communication: Personal
personal data, including processing for direct
information controllers may invoke the principle of
marketing, automated processing or profiling.
privileged communication over privileged information
that they lawfully control or process. Subject to existing 3. Right to Withhold Consent - The data subject
laws and regulations, any evidence gathered on shall be notified and given an opportunity to
privileged information is inadmissible. withhold consent to the processing in case of
changes or any amendment to the information
ILLUSTRATION: Examples of Personal Information
supplied or declared to the data subject in the
(PI), Sensitive Personal Information (SPI) or Privileged
preceding paragraph.
Information (Privileged)
Amendment of information: Any information supplied or
Information TYPE
declaration made to the data subject on these matters
Gender SPI shall not be amended without prior notification of the
School graduated from and date SPI data subject. Except: the notification shall not apply
graduated should the personal information be needed pursuant to a
subpoena or when the collection and processing are for
E-mail address PI obvious purposes, including when it is necessary for the
Laptop’s IP address PI performance of or in relation to a contract of service or
when necessary or desirable in the context of an
Bank Account Number SPI employer- employee relationship, between the collector
Home Address PI and the data subject, or when the information is being
collected and processed as a result of legal obligation.
Income tax Return SPI
4. Right to Access - The data subject has reasonable
Location tracked using an app PI access to, upon demand, the following:
Court cases filed against the individual SPI a) Contents of his or her personal information that
Disclosures made to an auditor Prvlgd were processed;
b) Sources from which personal information were
obtained;
Rights of the Data Subject:
c) Names and addresses of recipients of the
1. Right to Informed Consent - The data subject personal information;
shall be informed whether personal information
pertaining to him or her shall be, are being or have d) Manner by which such data were processed;
been processed; e) Reasons for the disclosure of the personal
The following information must be provided before the information to recipients;
entry of the personal information into the processing f) Information on automated processes where
system, or at the next practical opportunity: the data will or likely to be made as the sole
a) Description of the personal information to be basis for any decision significantly affecting or
entered into the system; will affect the data subject;

b) Purposes for which they are being or are to be g) Date when his or her personal information
processed; concerning the data subject were last accessed
and modified; and
c) Scope and method of the personal information
processing; h) The designation, or name or identity and
address of the personal data controller
d) The recipients or classes of recipients to
whom they are or may be disclosed; 5. Right to Correction - The data subject shall have
the right to dispute the inaccuracy or error in the
e) Methods utilized for automated access, if the personal information and have the personal
same is allowed by the data subject, and the information controller correct it immediately and
extent to which such access is authorized; accordingly, unless the request is vexatious or
otherwise unreasonable.
If the personal information has been corrected, the
personal information controller shall ensure the
accessibility of both the new and retracted information
and the simultaneous receipt of new and retracted
information by recipients thereof: Provided, That the
third parties have previously received such processed
personal information shall be informed of its inaccuracy SECURITY OF PERSONAL INFORMATION
and its rectification upon reasonable request of the data Security of Personal Information:
subject;
1. The personal information controller must implement
6. Right to Erasure - the data subject shall have the reasonable and appropriate organizational, physical
right to suspend, withdrawal or order the blocking, and technical measures intended for the protection
removal or destruction of his or her personal of personal information against any accidental or
information from the personal information unlawful destruction, alteration and disclosure,
controller’s filing system upon discovery and as well as against any other unlawful processing.
substantial proof that the personal information is
incomplete, outdated, false, unlawfully obtained, 2. The personal information controller shall implement
used for unauthorized purposes or are no longer reasonable and appropriate measures to protect
necessary for the purposes for which they were personal information against natural dangers such
collected. In this case, the personal information as accidental loss or destruction, and human dangers
controller may notify third parties who have such as unlawful access, fraudulent misuse,
previously received such processed personal unlawful destruction, alteration and contamination.
information; 3. The determination of the appropriate level of
7. Right to Damages - The data subject shall be security must take into account (1) the nature of
indemnified for any damages sustained due to such the personal information to be protected, (2) the
inaccurate, incomplete, outdated, false unlawfully risks represented by the processing, (3) the size of
obtained or unauthorized use of personal the organization and complexity of its operations,
information. (4) current data privacy best practices and (5) the
cost of security implementation.
8. Right to Data Portability - The right of the data
subject to obtain from the personal information
controller a copy of data, where personal Subject to guidelines as the Commission may issue from
information is processed: time to time, the measures implemented must include:
a) by electronic means and a. Safeguards to protect its computer network against
b) in a structured and commonly used format accidental, unlawful or unauthorized usage or
interference with or hindering of their functioning
or availability;
The Commission may specify the electronic format b. A security policy with respect to the processing of
referred to above, as well as the technical standards, personal information;
modalities and procedures for their transfer.
c. A process for identifying and accessing
reasonably foreseeable vulnerabilities in its
Transmissibility of Rights of the Data Subject - The computer networks, and for taking preventive
lawful heirs and assigns of the data subject may invoke corrective and mitigating action against security
the rights of the data subject for which he or she is an incidents that can lead to a security breach; and
heir or assignee at any time after the death of the data d. Regular monitoring for security breaches and a
subject or when the data subject is incapacitated or process for taking preventive, corrective and
incapable of exercising the right as enumerated above. mitigating action against security incidents that can
lead to a security breach.
Non-Applicability of Rights - The above rights of a data 4. The personal information controller must further
subject are not applicable: ensure that third parties processing personal
information on its behalf shall implement the
1) If the processed personal information is used only security measures required by this provision.
for the needs of scientific and statistical research
and, on the basis of such, no activities are carried 5. The employees, agents or representatives of a
out and no decisions are taken regarding the data personal information controller who are involved in
subject: Provided, That the personal information the processing of personal information shall operate
shall be held under strict confidentiality and shall be and hold personal information under strict
used only for the declared purpose; and confidentiality if the personal information is not
intended for public disclosure. This obligation shall
2) To processing of personal information gathered for continue even after leaving the public service,
the purpose of investigations in relation to any transfer to another position or upon termination of
criminal, administrative or tax liabilities of a data employment or contractual relations.
subject.
6. The personal information controller shall promptly SECURITY OF SENSITIVE PERSONAL
notify the Commission and affected data subjects INFORMATION IN GOVERNMENT
when sensitive personal information or other Responsibility of Heads of Agencies - All sensitive
information that may, under the circumstances, be personal information maintained by the government,
used to enable identity fraud are reasonably its agencies and instrumentalities shall be assured, as far
believed to have been acquired by an as practicable, with the use of the most appropriate
unauthorized person, and the personal information standard recognized by the information and
controller or the Commission believes that such communications technology industry, and is
unauthorized acquisition is likely to give rise to a recommended by the Commission.
real risk of serious harm to any affected data
subject.
Notification to the Commission - The notification shall The head of each government agency or
at least describe the nature of the breach, the sensitive instrumentality shall be responsible for complying
personal information possibly involved, and the with the security requirements mentioned while the
measures taken by the entity to address the breath Commission shall monitor the compliance and may
Notification may be delayed only to the extent necessary recommend the necessary action in order to satisfy the
to determine e scope of the breach, to prevent further minimum standards.
disclosures, or to restore reasonable integrity to the
information and communications system
Requirements Relating to Access by Agency Personnel
a. In evaluating if notification is unwarranted, the to Sensitive Personal Information:
Commission may take into account compliance by
the personal information controller with this 1. On-site and Online Access - Except as may be
provision and existence of good faith in the allowed through guidelines to be issued by the
acquisition of personal information. Commission, no employee of the government shall
have access to sensitive personal information on
b. The Commission may exempt a personal government property or through online facilities
information controller from the notification where, unless the employee has received a security
in its reasonable judgment, such notification would clearance from the head of the source agency.
not be in the public interest or in the interests of the
affected data subjects. 2. Off-site Access - Unless otherwise provided in
guidelines to be issued by the Commission,
c. The Commission may authorize postponement of sensitive personal information maintained by an
notification where it may hinder the progress of a agency may not be transported or accessed from
criminal investigation related to a serious breach. a location of government property unless a request
Period to Report - If there is likelihood of risk to for such transportation or access is submitted
individuals, the data processor must report data breaches and approved by the head of the agency in
within 72 hours. accordance with the following guidelines:
a) Deadline for Approval or Disapproval - in
the case of any request submitted to the head of
ACCOUNTABILITY FOR TRANSFER OF an agency, such head of the agency shall
PERSONAL INFORMATION approve or disapprove the request within two
Principle of Accountability - Each personal information (2) business days after the date of submission
controller is responsible for personal information under of the request.
its control or custody, including information that has In case there is no action by the head of the agency,
been transferred to a third party for processing, whether then such request is considered disapproved;
domestically or internationally, subject to cross-border
arrangement and cooperation. b) Limitation to 1,000 Records - If a request is
approved, the head d the agency shall limit the
1) The personal information controller is accountable access to not more than one thousand (1,000)
for complying with the requirements of the Data records at a time; and
Privacy Act and shall use contractual or other
reasonable means to provide a comparable level of c) Encryption - Any technology used to store,
protection while the information is being processed transport or acres sensitive personal information
by a third party. for purposes of off-site acres approved under
this subsection shall be secured by the use of
2) Data Protection Officer: The personal information the most secure encryption standard
controller shall designate an individual or recognized by the Commission
individuals who are accountable for the
organization's compliance with the Data Privacy
Act. The identity of the individual(s) so designated Applicability to Government Contractors - In entering
shall be made known to any data subject upon into any contract that may involve accessing or requiring
request. sensitive personal information from one thousand
(4,000) or more individuals, an agency shall require a
contractor and its employees to register their
personal information processing system with the
Commission in accordance with the Data Privacy Act data confidentiality and security data systems,
and to comply with the other provisions of said Act in breaks in any way into any system where personal
the same manner as agencies and government employees and sensitive personal information is stored. Penalty
comply with such requirements. shall be imprisonment of 1 year to 3 years and a fine
of P500,000 to P2,000,000.
6) Concealment of Security Breaches Involving
Sensitive Personal Information - any person who,
UNLAWFUL ACTS AND PENALTIES later having knowledge of a security breach and of
1) Unauthorized Processing - any person who the obligation to notify the Commission,
processes personal information without the consent intentionally or by omission conceals the fact of
of the data subject, or without being authorized such security breach. The penalty shall be
under the Data Privacy Act or any existing law. imprisonment of 1 year and 6 months to 5 years and
Penalties: a fine of P500,000 to P1,000,000.

Type of Info Imprisonment Fine 7) Malicious Disclosure - Any personal information


controller or personal information processor or any
Personal of its officials, employees or agents, who, with
1 to 3 years P500,000 - P2M
Information malice or in bad faith, discloses unwarranted or
Sensitive Personal false information relative to any personal
3 to 6 years P500,000 - P4M information or personal sensitive information
Information
obtained by him or her. The penalty shall be
imprisonment of 1 year and 6 months to 5 years and
2) Access - any person who, due to negligence, a fine of P500,000 to P1,000,000.
provided access to personal information without 8) Unauthorized Disclosure - Any personal
being authorized under the Data Privacy Act or any information controller or personal information
existing law. Penalties: processor or any of its officials, employees p agents,
Type of Info Imprisonment Fine who discloses to a third party personal or sensitive
personal information, not covered by Malicious
Personal Disclosure above, without the consent of the data
1 to 3 years P500,000 - P2M
Information subject. The penalties:
Sensitive Personal Type of Info Imprisonment Fine
3 to 6 years P500,000 - P4M
Information
Personal
1 to 3 years P500,000 - P1M
Information
3) Improper Disposal - any person who knowingly or Sensitive Personal
negligently disposes, discards or abandons the 3 to 5 years P500,000 - P2M
Information
personal information of an individual in an area
accessible to the public or has otherwise placed the
personal information of an individual in its 9) Combination or Series of Acts - any combination or
container for trash collection. Penalties: series of acts as defined in above shall make the
Type of Info Imprisonment Fine person subject to imprisonment of 3 years to 6 years
and a fine of P1,000,000 to P5,000,000.
Personal 6 months to 2 P100,000 -
Information years P500,000
Sensitive Personal Extent of Liability:
1 to 3 years P100,000 - P1M
Information 1. Juridical Persons - If the offender is a corporation,
partnership or any juridical person, the penalty shall
be imposed upon the responsible officers, as the
4) Processing for Unauthorized Purpose - processing case may be, who participated in by their gross
personal information for purposes not authorized by negligence, allowed the commission of the crime. If
the data subject, or otherwise authorized under this the offender is a juridical person, the court may
Act or under existing laws. Penalties: suspend or revoke any of its rights under the Data
Type of Info Imprisonment Fine Privacy Act.
Personal 1 year and 6 2. Alien - if the offender is an alien, he or she shall, in
Information months to 3 P500,000 - P1M addition to the penalties above, be deported
years without further proceedings after serving the
penalties prescribed.
Sensitive Personal
2 to 7 years P500,000 - P2M 3. Large-Scale - the maximum penalty in the scale of
Information
penalties respectively provided shall be imposed
when the personal information of at least one
5) Unauthorized Access or Intentional Breach - any hundred (100) persons is harmed, affected or
person who knowingly and unlawfully, or violating
involved as the result of the above-mentioned a. Anita only
actions. b. Anita and Bonnie only
c. Anita and Cassie only
4. Public Official or Employee - If the offender is a
d. Bonnie and Cassie only
public official or employee and he or she is found
guilty of Improper Disposal of Personal information
and Sensitive Personal Information and Processing 5) Winnie, a personal information processor, is
of personal Information and Sensitive Personal charged with violation of the Data Privacy Act. The
Information for Unauthorized Persons, he or she violation consists of two acts. First, Winnie revealed
shall, in addition to the penalties prescribed, suffer the salary range of Sally, an Administrative Officer
perpetual or temporary absolute disqualification III at the Department of Finance, Second, Winnie,
from office, as the case may be. in publishing her research, disclosed the ages and
5. Offense Committed by Public Officer - When the sexes of the respondents to her survey. Is Winnie
offender or the person responsible for the offense is liable for violation of the Data Privacy Act?
a public officer as defined in the Administrative a. No
Code of the Philippines in the exercise of his or her b. Yes, but only as to the first act
duties, an accessory penalty consisting in the c. Yes, but only to the second act
disqualification to occupy public office for a term d. Yes, on both acts
double the term of criminal penalty imposed shall
he applied.
6. Restitution - Restitution for any aggrieved party 6) Which of the following statements is true regarding
shall be governed by the provisions of the New news sources of journalists?
Civil Code. a. Journalists are compelled to reveal the source of
any news report.
b. Journalists, by order of a competent court, are
MULTIPLE CHOICE QUESTIONS compelled to reveal the source of any news
1) It refers to communication by whatever means of report.
any advertising or marketing material which is c. Journalists are compelled to reveal details
directed to particular individuals. regarding sources of any news report except
those classified as sensitive personal
a. Direct Marketing
information.
b. Direct Communication
d. Journalists are not compelled to reveal the
c. Direct Advertising
source of any news report.
d. Direct Infringement

7) Which of the following is not included in the


2) It refers to a person or organization who controls the
application of the Data Privacy Act?
collection, holding, processing or use of personal
information, including a person or organization who I. Information about an individual who is or was
instructs another person or organization to collect, performing service under contract for a banking
hold, process, use, transfer or disclose personal institution that relates to the services performed
information on his or her behalf II. Information necessary for banks and other
a. Personal Information Collector financial institutions to comply with the Anti-Money
b. Personal Information Controller Laundering Act
c. Personal Information Manager a. I only.
d. Personal Information Repository b. II only.
c. I and II only.
d. Neither I nor II.
3) It refers to an individual whose personal
information is processed.
a. Personal Information Provider 8) Which of the following statements is true regarding
b. Personal Information Holder a personal information controller outside the
c. Data Subject Philippines?
d. Data Person a. A personal information controller outside the
Philippines is not covered by the Data Privacy
Act if the personal information pertains to
4) Anita obtains the addresses of her customers for her
Philippine citizens
food business, so that she may be able to deliver her
b. A personal information controller outside the
goods efficiently. Bonnie obtains the names and age
Philippines is not covered by the Data Privacy
of her students as part of her record-keeping as
Act if the personal information pertains to
adviser of the class. Cassie obtains emails and
Philippine residents
phone numbers of her friends to save on her phone.
c. A personal information controller inside the
Who among them is a personal information
Philippines is not covered by the Data Privacy
controller?
Act if the personal information pertains to non-
residents 14) This principle provides that the Processing of
d. A personal information controller outside Personal Data by the Company shall be compatible
the Philippines is covered by the Data with a declared and specified purpose which must
Privacy Act if the personal information not be contrary to law, morals, or public policy.
pertains to residents or citizens
a. Principle of Transparency
b. Principle of Compatibility
9) The National Privacy Commission is an agency c. Principle of Legitimate Purpose
attached to: d. Principle of Adherence
a. Department of National Defense
b. Commission on Human Rights 15) Kris joined the raffle draw of Barry’s Supermarket
c. Department of Information and in the hopes of winning a 42” Smart TV. Kris
Communications Technology indicated her mobile phone number and email
d. Department of Privacy address in the form given for the raffle entry. The
form looked simple for Kris. It just contained empty
fields to be filled out, the logo of Barry’s
10) All of the following are qualifications of the Privacy
Supermarket, and the grand prizes to be won.
Commission except:
However, to her surprise, Kris soon received
a. At least thirty-five (35) years of age multiple promotions from different brands asking
b. A resident of the Philippines for at least two her to buy products at a discount. Her email inbox
(2) years soon became spammed as well with unwanted
c. Of good moral character, unquestionable promotion. Is there a data privacy principle
integrity and known probity violated?
d. A recognized expert in the field of information
a. None
technology and data privacy
b. Yes. The Principle of Proportionality was
violated
11) Which of the following acts performed upon c. Yes. The Principle of Legitimate Purpose was
personal information constitute processing? violated
d. Yes. The Principle of Transparency was
I. Collection violated.
II. Storage
III. Retrieval
IV. Erasure 16) Which of the following best defines the term
a. I and III only “personal information”?
b. II and IV only a. Those which the data subject would normally
c. I, II, and III only and reasonably regard as private in nature
d. I, II, III, and IV b. Those from which the identity of an
individual is apparent or can be reasonably
and directly ascertained
12) This principle provides that the Processing of c. Those from which the identity of an individual
Personal data shall be adequate, relevant, suitable, can be subject to identity theft
necessary, and not excessive in relation to a d. Those which the personal information
declared and specified purpose. controller would regard as having economic
a. Principle of Proportionality value
b. Principle of Legitimate Purpose
c. Principle of Relevance
d. Principle of Reasonable Extent 17) Statement 1: There can be no lawful processing of
personal information without the consent of the data
subject.
13) This principle provides that the Data Subject must Statement 2: If the processing is necessary for
be aware of the nature, purpose, and extent of the compliance with a legal obligation to which the
Processing of his or her Personal Data by the personal information controller is subject, then such
Company, including the risks and safeguards is considered as lawful processing by the Data
involved, the identity of persons and entities Privacy Act.
involved in processing his or her Personal Data, his
or her rights as a Data Subject, and how these can a. Only Statement 1 is true.
be exercised. b. Only Statement 2 is true.
c. Both statements are true.
a. Principle of Proportionality d. Both statements are not true.
b. Principle of Informed Consent
c. Principle of Awareness
d. Principle of Transparency
18) All of the following are privileged information, 23) Statement 1: A data subject shall have the right to
except: be informed of the purpose for which his personal
information is being taken.
a. Attorney-client privileged information
b. Doctor-patient privileged information Statement 2: A data subject shall have the right to
c. Priest-confessor privileged information be informed of the duration for which his personal
d. Bank-client privileged information information will be stored by the personal
information controller.
a. Only Statement 1 is true
b. Only Statement 2 is true
19) Which of the following is classified as sensitive c. Both statements are true
personal information? d. Both statements are not true
a. List of Facebook friends
b. Tax Returns
24) Which of the following is false regarding the rights
c. Credit card information
of a data subject?
d. Passwords
a. A data subject shall have the right to object to
the processing of his o her personal data,
20) Which of the following is not classified as sensitive including processing for direct marketing
personal information? automated processing or profiling
a. Bank account number b. A data subject can no longer object to the
b. Political affiliation processing of his data once he has given it to
c. High school grades a personal information processor.
d. Social security numbers c. A data subject can choose which personal
information will be subject to processing,
withholding from processing those which he
21) Mr. X was admitted to a hospital. He is suffering chooses otherwise.
from difficulty in breathing, high fever, and fatigue. d. If a personal information controller changes the
His symptoms are quickly worsening. The doctor purpose for which the personal information of
asked his wife as to previous admissions, but the the data subject is to be processed, the data
wife had no idea. Instead, the wife informed the subject may withhold consent.
doctor that he was previously admitted at BCD
Hospital, and they have the health records of Mr. X.
The doctor called at BCD Hospital, and BCD 25) A data subject has the right to access:
Hospital disclosed the health records to the doctor. I. The address of the personal information
Is there any breach of the Data Privacy Act with the controller
disclosure? II. Sources from which his personal information
a. Yes, because Mr. X did not give her consent. were obtained
b. No, because Mr. X's wife, as his duly a. I only.
authorized representative, gave her consent for b. II only
the disclosure. c. Both I and II
c. Yes, because health records are considered as d. Neither I nor II
sensitive personal information.
d. No, because the processing of the personal
26) A data subject has the right to data portability. This
information is necessary for purposes of
means that-
medical treatment.
a. A data subject can transfer his data from one
personal information controller to another
22) Which of the following information can a business b. A data subject can obtain a copy of his
organization obtain without violating the Data personal information
Privacy Act? c. A data subject can change the purpose for
I. Tax Identification Number of its employees which his personal information will be
II. Medical records for employees who have processed
signified that they wish to avail of the health insurance d. A data subject can dictate the format in which
benefit of the .company his personal information will be stored
III. Names of customers for purposes of issuing
invoices and official receipts
27) Which of the following is true regarding the data
a. I only
subject's right to correction?
b. I and III only
c. I and II only a. The personal information controller shall
d. I, II, and III ensure the accessibility of both the new and
the retracted information
b. The data subject can exercise this right only these debtors’ assets and the settlement of their
once obligations. (Section 2)
c. The personal information controller has no
obligation to inform third persons who may
have obtained the data prior to correction of the NATURE OR PROCEEDINGS:
correction made by the data subject 1. In rem. Meaning it is a proceeding which binds the
d. The personal information controller is obligated whole world.
to delete the retracted information.
2. Jurisdiction over all persons affected shall be
acquired upon publication of the notice of
28) In the event that the personal information controller commencement in a newspaper of general
reasonably believe that sensitive personal circulation in the Philippines.
information has been acquired by unauthorized 3. Proceedings shall be summary and non-adversarial.
person, the personal information controller has the
obligation to:
a. Notify the affected data subjects PURPOSE:
b. Notify the National Privacy Commission 1) To encourage debtors and creditors to collectively
c. Notify all data subjects which the personal and realistically resolve and adjust competing
information claims and property rights through rehabilitation.
d. Notify both the affected data subjects and
the National Privacy Commission 2) If not feasible, to facilitate speedy and orderly
liquidation of debtor’s assets and the settlement of
their obligations.
29) The data processor must report data breaches to the
NPC within a period of:
DEBTORS are defined under the law are insolvent:
a. 24 hours
b. 48 hours 1. Sole proprietorship registered with the DTI;
c. 72 hours 2. Partnership registered with the SEC;
d. Five days
3. Corporations organized and existing under the laws
of the Philippines; or
30) A data privacy violation is considered to be large 4. Individual debtors which are natural persons who
scale if. are residents and citizens of the Philippines
a. the personal information of at least ten (10) Group of Debtors refer to:
persons is harmed
1) Financially related corporations - parent, subsidiary
b. the personal information of at least twenty (20)
or affiliates
persons is harmed
c. the personal information of at least one 2) Partnerships - more than 50% of which is owned by
hundred (100) persons is harmed the same person
d. the personal information of at least one 3) Single Proprietorship - owned by the same
thousand (1,000) persons is harmed individual
EXCLUDED DEBTORS: Banks, pre-need companies,
FINANCIAL REHABILITATION insurance companies, and government agencies or units
- governed by their respective special laws.
AND INSOLVENCY ACT
INSOLVENT shall refer to the financial condition of a
INTRODUCTION debtor that is
DECLARATION OF POLICY: It is the policy of the 1. Unable to pay its or his liabilities as they fall due; or
State  to encourage debtors, both juridical and natural
persons, and their creditors to collectively and 2. Has liabilities greater than its or his assets
realistically resolve and adjust competing claims and
property rights. In furtherance thereof, the State shall
CREDITORS include natural or juridical persons
ensure a timely, fair, transparent, effective and efficient
which has a claim against the debtor that arose on or
rehabilitation or liquidation of debtors. The
before the commencement date, which can either be
rehabilitation or liquidation shall be made with a view to
secured or unsecured.
ensure or maintain certainty and predictability in
commercial affairs, preserve and maximize the value of 1) Unsecured creditors are those whose claim or
the assets of these debtors, recognize creditor rights and portion thereof is neither secured, preferred nor
respect priority of claims, and ensure equitable treatment subordinated
of creditors who are similarly situated. When 2) Secured creditors are those whose claims are
rehabilitation is not feasible, it is in the interest of the secured by a lien (either by law, agreement or by
State to facilitate a speedy and orderly liquidation of judicial judgment) which legally entitles a creditor
to resort the property subject of alien Tor payment
or his claim. Example:
3)

You might also like