0% found this document useful (0 votes)
13 views4 pages

Data Privacy Notes

The document outlines the rights of data subjects regarding their personal information, including the right to be informed, object, access, rectify, erase, and withdraw consent. It emphasizes the responsibilities of personal information controllers and processors to implement security measures, ensure compliance with data protection laws, and maintain confidentiality. Additionally, it details requirements for outsourcing, subcontracting, and registration of data processing systems to uphold data privacy standards.

Uploaded by

jocelynong2006
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views4 pages

Data Privacy Notes

The document outlines the rights of data subjects regarding their personal information, including the right to be informed, object, access, rectify, erase, and withdraw consent. It emphasizes the responsibilities of personal information controllers and processors to implement security measures, ensure compliance with data protection laws, and maintain confidentiality. Additionally, it details requirements for outsourcing, subcontracting, and registration of data processing systems to uphold data privacy standards.

Uploaded by

jocelynong2006
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

SECURITY OF PERSONAL INFORMATION

 A. Right to be Informed: The right to know if your


 (a) Proactive Protection: Controllers must adopt
personal data is being processed, including any use
organizational, physical, and technical measures to
of automated decision-making or profiling.
stop unauthorized access, modification, or unlawful
 B. Right to Object: The right to refuse the processing of
processing.
your data—especially for direct marketing or automated
 (b) Comprehensive Safety: Controllers must defend
profiling—and the right to be notified of any changes to
personal data against both natural disasters (e.g., loss)
your information so you can withhold consent.
and human threats (e.g., fraud, contamination).
C. Right to Access allows data subjects to demand details
 (c) Security Determination Factors: Tailoring security
on how their data is processed, stored, and shared.
to risk, data nature, organization size, best practices,
Right to Access
and cost. 1. Content: Access to actual data processed.

(1) Network Safeguards: Protecting against


2. Source: Where data was collected.

unauthorized access or system interference.


3. Recipients: Who received the data.

4. Manner: Method of processing.


(2) Security Policy: A documented strategy for 5. Reason: Why data was shared.
processing personal data. 6. Automation: Logic behind automated, impactful decisions.

(3) Vulnerability Management: Identifying, mitigating,


7. Log: Dates of last access/modification.

and preventing security breaches.


8. Controller ID: Identity of the responsible party.

(4) Monitoring and Incident Response: Regular d. Right to Rectification

checking for breaches and taking corrective actions. The right to dispute errors and have them immediately

corrected by the controller. If corrected, the controller must


 (d) Third-Party Compliance: Requiring third parties to
ensure both old/new data are accessible, and notify
implement the same data security measures.
previous recipients of the correction upon request.

 (e) Confidentiality Obligation: Employees/agents E. Right to Erasure or Blocking allows data subjects to

must maintain strict confidentiality of non-public demand the suspension, removal, or destruction of their

personal information, an obligation that persists even personal data from a controller's system. This right, based

after employment ends or position changes. on the NPC Advisory No. 2021-01, is exercised upon proof

 (f) Breach Notification: Controllers must promptly of issues like unlawful processing or inaccurate data, with

notify the Commission and data subjects of notification to third parties holding the data.
This right may be exercised upon discovery
unauthorized access to sensitive data that poses a real and substantial proof of any of the following:

risk of harm, outlining the breach and mitigation steps,  (a) Inaccurate/Illicit Data: Data is outdated, false,

with delayed notification only for investigation or incomplete, or illegally obtained.

security restoration.  (b) Unauthorized Use: Data is used for purposes not

consented to.

 (c) Irrelevance: Data is no longer necessary for the

original collection purpose.

RIGHTS OF DATA SUBJECTS


 (d) Withdrawn Consent: Data subject objected to 2. Confidentiality Obligation: Ensure all employees or

processing with no overriding legal ground. agents authorized to process the data are bound by

 (e) Prejudicial Info: Data is harmful to the subject confidentiality agreements.

(unless exempted by law/press freedom). 3. Security & Compliance: Implement proper security

 (f) Unlawful Processing: The processing activity measures (technical/organizational) and comply with

violates privacy laws. all Data Privacy Act rules and Commission

 (g) Violation of Rights: The controller or processor issuances.

breached the data subject’s rights. 4. Controlled Subcontracting: Do not hire another

processor without the controller's consent, ensuring


Third-Party Notification:
sub-processors meet the same high-level data
 The personal information controller (PIC) may notify
protection standards.
third parties who previously received the data to also

block or erase it.  5. Support Data Subject Rights: The processor must

implement technical/organizational measures to help the


OUTSOURCING AND SUBCONTRACTING
controller respond to data subject rights requests (e.g.,
AGREEMENTS
access, rectification).
Subcontract of Personal Data
 6. Ensure Regulatory Compliance: The processor must
Personal Information Controllers (PICs) may
assist in adhering to the Data Privacy Act (DPA), NPC
outsource data processing but must use contracts or
regulations, and other laws, based on the nature of
safeguards to guarantee data security, integrity, and
processing.
privacy compliance. The PIC retains responsibility for
 7. Data Return or Deletion: Upon contract completion, the
preventing unauthorized use, ensuring the processor
processor must, at the controller's choice, delete or return
adheres to the Data Privacy Act, and maintaining
all personal data and delete existing copies, unless law
compliance with commission regulations.
requires storage.
Agreements for Outsourcing

Processing by a personal information processor 8 Documentation & Audit Cooperation: Processor must
shall be governed by a contract or other legal act
that binds the personal information processor to provide all necessary data to prove compliance and submit to
the personal information controller.
audits/inspections by the controller or its representative.
A. "The agreement must specify the processing's

subject, duration, nature, and purpose; the data types 9. Legal Obligation Alert: Processor must immediately

and subjects involved; the controller’s rights and duties; inform the controller if any instruction violates the Data

and the processing location." Privacy Act, Rules, or NPC issuances.

B. The contract or other legal act shall stipulate, in


REGISTRATION AND COMPLIANCE REQUIREMENTS
particular, that the personal information processor

shall: Enforcement of the Data Privacy Act.: Pursuant to the mandate of

the Commission to administer and implement the Act, and to ensure


1. Strict Instruction Following: Process data only
the compliance of personal information controllers with its
based on documented instructions from the
obligations under the law, the Commission requires the following:
controller, including authorized international

transfers.
a. Registration of personal data processing systems operating in 9. Certifications: Proof of data-related certifications (e.g., ISO).

the country that involves accessing or requiring sensitive personal


10. DPO Information: Name and contact details of the Data
information of at least one thousand (1,000) individuals, including
Protection Officer (must be updated immediately).
the personal data processing system of contractors, and their
b. The procedure for registration shall be in accordance
personnel, entering into contracts with government agencies; with these Rules and other issuance of the Commission.

b. Notification of automated processing operations where the Notification of Automated Processing Operations:
processing becomes the sole basis of making decisions that would Companies must notify the National Privacy Commission (NPC)
when using automated systems as the sole basis for decisions
significantly affect the data subject;
that significantly affect individuals. This ensures transparency
and oversight when technology, rather than humans, makes
c. Annual report of the summary of documented security
impactful decisions about data subjects.
incidents and personal data breaches;

d. Compliance with other requirements that may be provided in a. The notification shall include the following information:

other issuances of the Commission.


1. Purpose of processing;
Registration of Personal Data Processing Systems:
2. Categories of personal data to undergo processing;
Entities with fewer than 250 employees are exempt from
3. Category or categories of data subject;
NPC data processing registration, unless they process
4. Consent forms or manner of obtaining consent;
sensitive data of 1,000+ individuals, engage in non-
5. The recipients or categories of recipients to whom the
occasional processing, or handle data posing risks to subject
data are to be disclosed;
rights. Those meeting these thresholds must register via
6. The length of time the data are to be stored;
the NPC Registration System.
7. Methods and logic utilized for automated processing;
a. The contents of registration shall include
8. Decisions relating to the data subject that would be
1. Identity Details: Names and contact info of the PIC/PIP,
made on the basis of processed data or that would
their representative, and the Head of Agency.
significantly affect the rights and freedoms of data subject;

2. Processing Purpose: Why data is processed and if it and

involves outsourcing/subcontracting. 9. Names and contact details of the compliance or data

protection officer.
3. Data & Subject Description: Categories of data subjects

and the types of personal data being processed. b. No decision with legal effects concerning a data subject

shall be made solely on the basis of automated processing


4. Data Recipients: Who receives or has access to the data.
without the consent of the data subject.

5. Cross-border Transfers: Details of data transfers outside


Review by the Commission:
the Philippines.

Under Rule XI, Section 49 of the Implementing Rules and


6. Security Measures: Summary of technical, physical, and
Regulations of the Data Privacy Act, the National Privacy
organizational security policies.
Commission (NPC) may review the following areas of data

7. System Description: A brief overview of the data processing, either on its own or through a data subject's

processing system. complaint:

8. Data Policies: Copies of Data Governance, Privacy, and

Information Security policies.


1. Regulatory Compliance: Checking if a personal

information controller (PIC) or processor (PIP) follows the

Data Privacy Act, its rules, and NPC issuances.

2. Security Measures: Evaluating whether a PIC or PIP has

established adequate safeguards to protect data privacy and

maintain security.

3. Contractual Agreements: Reviewing data sharing,

outsourcing, or similar contracts, including how they are

actually implemented.

4. Government Access: Examining any off-site or online

access to sensitive personal data in the government that has

been authorized by an agency head.

5. Processing for Research, Public Functions, or

Commerce (e): Data may be processed for scientific

research, government functions, or commercial activities,

provided there are adequate safeguards and the processing

is necessary for a legitimate purpose.

6. Reported Violations of Rights and Freedoms (f): The

National Privacy Commission (NPC) is mandated to

investigate and adjudicate any reported breaches or

complaints regarding the unauthorized use of data or

violations of a data subject's rights.

7. Effective Implementation and Administration (g): This

grants the NPC the broad authority to issue rules, circulars,

and other measures necessary to fully administer and

enforce the DPA and its regulations across both public and

private sectors.

You might also like