You are on page 1of 14

DATA PRIVACY AWARENESS

Personal Personal
DATA ECOSYSTEM Information Information
Controller Processor
Data Subject (PIC) (PIP)

provide outsources
personal data the
processing

• Personal Information Third


• Sensitive Personal Parties
Information
• Privilege Information
shares data sub-contracts
HISTORY

Mandatory Mandatory
Compliance Registration

Data Privacy Act Implementing Rules


(RA 10173) & Regulations
Privacy & Deputy Privacy National Privacy
Commissioners Commission Gov’t Agencies &
Private Companies

DICT Act of 2015


(RA 10844)

DICT

Sept 2017 –
2012 Mar 2016 May 2016 Aug 2016
Mar 2018

*DICT – Department of Information and Communications Technology


** Deadline of Registration:
Phase I: Registration of DPO – until September 9, 2017
Phase II: Registration of personal data processing systems – until March 8, 2018
TYPES OF DATA
Personal Sensitive personal Privileged
information information information
► Information, whether recorded ► Personal information whose leakage ► Anyand all forms of data
in a material form or not, from could impact the material well being of which under the Rules of
which the identity of an an individual (EU GDPR). Court or other pertinent laws
individual: constituted privileged
► Race, ethnic origin, marital status,
► is apparent, or communications. (IRR)
age, color, religious, philosophical or
► can be reasonably and political affiliation. ► Attorney-client privileged
directly ascertained by the ► Health, education, genetic or sexual information
entity holding the life, offenses committed or alleged, ► Doctor-patient privileged
information, or disposal of such, or sentences of any information
► when put together with court.
other information would ► Issued by any government agency
directly and certainly peculiar to an individual such as SSS
identify an individual (IRR) numbers, previous and current
► Name health records, licenses, denials,
► Home address suspension or revocation, and tax
returns.
► Phone number
► Specifically
established by an
executive order or an act of
Congress to be kept classified. (IRR)
KNOWLEDGE CHECK
DATA PI or SPI or N/A?

Gender (Male or Female) SPI


School graduated from
and year graduated SPI
A company’s contact
number N/A
E-mail addresses that is
only collected by PI
websites

Office or home address PI


RIGHTS OF DATA SUBJECT

Consent Object Access Correct

Erase Damages Data


Portability
What can
you do to
protect
your data?
ROLES OF DATA SUBJECT
Physical Security Technical Security
Do’s Do’s

• Secure storage of hardcopy • Do not share passwords with


documents by locking filing anyone, use of highly complex
cabinets and giving access only passwords)
to those authorized and • Encrypt sensitive attachments being
required to fulfill processing of sent through e-mail and send the
these documents password in a separate e-mail with a
• Secure destruction/disposal different subject
of hardcopy documents • Lock the home screen of the
• Control over printing of workstation when leaving it unattended
documents containing personal • Beware of phishing attacks
data • Always shut down and/or restart the
• Clear the workstation from computers to keep the operating
any documents containing systems and anti-virus software up
personal data. to date
• Refresh History if you’re using public
PHISHING

You might also like