Data Privacy Act Flashcards
(102 cards)
An act protecting individual personal information in information and communication systems in the government and the private sector, creating for this purpose a national privacy commission and for other purposes.
Republic Act No. 10173 known as the Data Privacy Act of 2012
Protects the right to privacy of an individual with regard to his personal data. It imposes upon any person processing personal data the obligation to implement security measures aimed at ensuring the confidentiality, integrity, and availability of an individual’s personal data.
The Data Privacy Act (Act)
DPA applies to:
Natural/juridical persons in government or private sectors processing personal data.
Processing of data about Philippine citizens or residents.
Entities with links to the Philippines.
Except:
Information related to government officials, contractors, public benefits, journalistic, artistic, literary, research purposes, etc.
Refers to any information whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information
Personal Information
When put together with other information would directly and certainly identify an individual.
Personal Information
About an individual’s race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;
Sensitive Information
About an individual’s health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such person, the disposal of such proceedings, or the sentence of any court in such proceedings
Sensitive Information
Issued by government agencies peculiar to an individual which includes, but not limited to, social security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns
Sensitive Information
The data subject must be aware of the structure, purpose, and extent of the processing of his or her personal data, including the risks and safeguards involved, the identity of the PIC, his or her rights as a data subject, and how these can be exercised.
Principle of Transparency
It mandates that the processing of information be compatible with a declared and specified purpose which must not be contrary to law, morals, or public policy.
Principle of Legitimate Purpose
It requires that the processing of information shall be adequate, relevant, suitable, necessary, and only to the minimum extent necessary to achieve declared, specified and legitimate purpose.
Principle of Proportionality
Refers to “an individual whose personal information is processed.”
Data Subjects
This may only be an individual or human being. The term does not extend to artificial persons such as partnerships, corporations, and other entities.
Data Subjects
The DPA grants various rights to individuals whose personal information is being processed
These rights empower you with control over your data and ensure transparency in how it’s handle.
Rights of Data Subjects
As a data subject, you have the right to be informed whether your personal data shall be, are being, or have been processed, including the existence of automated decision-making and profiling.
RIGHT TO BE INFORMED
The privacy notice to data subjects should include the following information;
The privacy notice to data subjects should include the following information;
2.Information regarding data transfers to other countries, where applicable, and reference to appropriate or suitable safeguards and the means by which by to obtain a copy of them or where they have been made available;
- The period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;
4.The existence of data subjects’ rights, such as the right to access, rectification, erasure, data portability, and the like;
- The right to lodge a complaint with a supervisory authority;
6.If applicable, information regarding automated decision making, including profiling.
The Data Subject Has A Right
(next slide)