SECURITY OF PERSONAL INFORMATION
A. Right to be Informed: The right to know if your
(a) Proactive Protection: Controllers must adopt
personal data is being processed, including any use
organizational, physical, and technical measures to
of automated decision-making or profiling.
stop unauthorized access, modification, or unlawful
B. Right to Object: The right to refuse the processing of
processing.
your data—especially for direct marketing or automated
(b) Comprehensive Safety: Controllers must defend
profiling—and the right to be notified of any changes to
personal data against both natural disasters (e.g., loss)
your information so you can withhold consent.
and human threats (e.g., fraud, contamination).
C. Right to Access allows data subjects to demand details
(c) Security Determination Factors: Tailoring security
on how their data is processed, stored, and shared.
to risk, data nature, organization size, best practices,
Right to Access
and cost. 1. Content: Access to actual data processed.
(1) Network Safeguards: Protecting against
2. Source: Where data was collected.
unauthorized access or system interference.
3. Recipients: Who received the data.
4. Manner: Method of processing.
(2) Security Policy: A documented strategy for 5. Reason: Why data was shared.
processing personal data. 6. Automation: Logic behind automated, impactful decisions.
(3) Vulnerability Management: Identifying, mitigating,
7. Log: Dates of last access/modification.
and preventing security breaches.
8. Controller ID: Identity of the responsible party.
(4) Monitoring and Incident Response: Regular d. Right to Rectification
checking for breaches and taking corrective actions. The right to dispute errors and have them immediately
corrected by the controller. If corrected, the controller must
(d) Third-Party Compliance: Requiring third parties to
ensure both old/new data are accessible, and notify
implement the same data security measures.
previous recipients of the correction upon request.
(e) Confidentiality Obligation: Employees/agents E. Right to Erasure or Blocking allows data subjects to
must maintain strict confidentiality of non-public demand the suspension, removal, or destruction of their
personal information, an obligation that persists even personal data from a controller's system. This right, based
after employment ends or position changes. on the NPC Advisory No. 2021-01, is exercised upon proof
(f) Breach Notification: Controllers must promptly of issues like unlawful processing or inaccurate data, with
notify the Commission and data subjects of notification to third parties holding the data.
This right may be exercised upon discovery
unauthorized access to sensitive data that poses a real and substantial proof of any of the following:
risk of harm, outlining the breach and mitigation steps, (a) Inaccurate/Illicit Data: Data is outdated, false,
with delayed notification only for investigation or incomplete, or illegally obtained.
security restoration. (b) Unauthorized Use: Data is used for purposes not
consented to.
(c) Irrelevance: Data is no longer necessary for the
original collection purpose.
RIGHTS OF DATA SUBJECTS
(d) Withdrawn Consent: Data subject objected to 2. Confidentiality Obligation: Ensure all employees or
processing with no overriding legal ground. agents authorized to process the data are bound by
(e) Prejudicial Info: Data is harmful to the subject confidentiality agreements.
(unless exempted by law/press freedom). 3. Security & Compliance: Implement proper security
(f) Unlawful Processing: The processing activity measures (technical/organizational) and comply with
violates privacy laws. all Data Privacy Act rules and Commission
(g) Violation of Rights: The controller or processor issuances.
breached the data subject’s rights. 4. Controlled Subcontracting: Do not hire another
processor without the controller's consent, ensuring
Third-Party Notification:
sub-processors meet the same high-level data
The personal information controller (PIC) may notify
protection standards.
third parties who previously received the data to also
block or erase it. 5. Support Data Subject Rights: The processor must
implement technical/organizational measures to help the
OUTSOURCING AND SUBCONTRACTING
controller respond to data subject rights requests (e.g.,
AGREEMENTS
access, rectification).
Subcontract of Personal Data
6. Ensure Regulatory Compliance: The processor must
Personal Information Controllers (PICs) may
assist in adhering to the Data Privacy Act (DPA), NPC
outsource data processing but must use contracts or
regulations, and other laws, based on the nature of
safeguards to guarantee data security, integrity, and
processing.
privacy compliance. The PIC retains responsibility for
7. Data Return or Deletion: Upon contract completion, the
preventing unauthorized use, ensuring the processor
processor must, at the controller's choice, delete or return
adheres to the Data Privacy Act, and maintaining
all personal data and delete existing copies, unless law
compliance with commission regulations.
requires storage.
Agreements for Outsourcing
Processing by a personal information processor 8 Documentation & Audit Cooperation: Processor must
shall be governed by a contract or other legal act
that binds the personal information processor to provide all necessary data to prove compliance and submit to
the personal information controller.
audits/inspections by the controller or its representative.
A. "The agreement must specify the processing's
subject, duration, nature, and purpose; the data types 9. Legal Obligation Alert: Processor must immediately
and subjects involved; the controller’s rights and duties; inform the controller if any instruction violates the Data
and the processing location." Privacy Act, Rules, or NPC issuances.
B. The contract or other legal act shall stipulate, in
REGISTRATION AND COMPLIANCE REQUIREMENTS
particular, that the personal information processor
shall: Enforcement of the Data Privacy Act.: Pursuant to the mandate of
the Commission to administer and implement the Act, and to ensure
1. Strict Instruction Following: Process data only
the compliance of personal information controllers with its
based on documented instructions from the
obligations under the law, the Commission requires the following:
controller, including authorized international
transfers.
a. Registration of personal data processing systems operating in 9. Certifications: Proof of data-related certifications (e.g., ISO).
the country that involves accessing or requiring sensitive personal
10. DPO Information: Name and contact details of the Data
information of at least one thousand (1,000) individuals, including
Protection Officer (must be updated immediately).
the personal data processing system of contractors, and their
b. The procedure for registration shall be in accordance
personnel, entering into contracts with government agencies; with these Rules and other issuance of the Commission.
b. Notification of automated processing operations where the Notification of Automated Processing Operations:
processing becomes the sole basis of making decisions that would Companies must notify the National Privacy Commission (NPC)
when using automated systems as the sole basis for decisions
significantly affect the data subject;
that significantly affect individuals. This ensures transparency
and oversight when technology, rather than humans, makes
c. Annual report of the summary of documented security
impactful decisions about data subjects.
incidents and personal data breaches;
d. Compliance with other requirements that may be provided in a. The notification shall include the following information:
other issuances of the Commission.
1. Purpose of processing;
Registration of Personal Data Processing Systems:
2. Categories of personal data to undergo processing;
Entities with fewer than 250 employees are exempt from
3. Category or categories of data subject;
NPC data processing registration, unless they process
4. Consent forms or manner of obtaining consent;
sensitive data of 1,000+ individuals, engage in non-
5. The recipients or categories of recipients to whom the
occasional processing, or handle data posing risks to subject
data are to be disclosed;
rights. Those meeting these thresholds must register via
6. The length of time the data are to be stored;
the NPC Registration System.
7. Methods and logic utilized for automated processing;
a. The contents of registration shall include
8. Decisions relating to the data subject that would be
1. Identity Details: Names and contact info of the PIC/PIP,
made on the basis of processed data or that would
their representative, and the Head of Agency.
significantly affect the rights and freedoms of data subject;
2. Processing Purpose: Why data is processed and if it and
involves outsourcing/subcontracting. 9. Names and contact details of the compliance or data
protection officer.
3. Data & Subject Description: Categories of data subjects
and the types of personal data being processed. b. No decision with legal effects concerning a data subject
shall be made solely on the basis of automated processing
4. Data Recipients: Who receives or has access to the data.
without the consent of the data subject.
5. Cross-border Transfers: Details of data transfers outside
Review by the Commission:
the Philippines.
Under Rule XI, Section 49 of the Implementing Rules and
6. Security Measures: Summary of technical, physical, and
Regulations of the Data Privacy Act, the National Privacy
organizational security policies.
Commission (NPC) may review the following areas of data
7. System Description: A brief overview of the data processing, either on its own or through a data subject's
processing system. complaint:
8. Data Policies: Copies of Data Governance, Privacy, and
Information Security policies.
1. Regulatory Compliance: Checking if a personal
information controller (PIC) or processor (PIP) follows the
Data Privacy Act, its rules, and NPC issuances.
2. Security Measures: Evaluating whether a PIC or PIP has
established adequate safeguards to protect data privacy and
maintain security.
3. Contractual Agreements: Reviewing data sharing,
outsourcing, or similar contracts, including how they are
actually implemented.
4. Government Access: Examining any off-site or online
access to sensitive personal data in the government that has
been authorized by an agency head.
5. Processing for Research, Public Functions, or
Commerce (e): Data may be processed for scientific
research, government functions, or commercial activities,
provided there are adequate safeguards and the processing
is necessary for a legitimate purpose.
6. Reported Violations of Rights and Freedoms (f): The
National Privacy Commission (NPC) is mandated to
investigate and adjudicate any reported breaches or
complaints regarding the unauthorized use of data or
violations of a data subject's rights.
7. Effective Implementation and Administration (g): This
grants the NPC the broad authority to issue rules, circulars,
and other measures necessary to fully administer and
enforce the DPA and its regulations across both public and
private sectors.