Notes On Data Privacy Act
Notes On Data Privacy Act
adopt generally accepted international principles and standards for personal data
protection.
SCOPE OF APPLICATION
The Act and these Rules apply to the processing of personal data
by any natural and juridical person in the government or private sector.
Extraterritorial Application. –
dThis Act applies to an act done or practice engaged in and outside of the Philippines
by an entity if:
(a) The act, practice or processing relates to personal information about a Philippine
citizen or a resident;
(b) The entity has a link with the Philippines, and the entity is processing personal
information in the Philippines or even if the processing is outside the Philippines as long
as it is about Philippine citizens or residents such as, but not limited to, the following:
(1) A contract is entered in the Philippines;
(2) A juridical entity unincorporated in the Philippines but has central management and
control in the country; and
(3) An entity that has a branch, agency, office or subsidiary in the Philippines and the
parent or affiliate of the Philippine entity has access to personal information; and
(c) The entity has other links in the Philippines such as, but not limited to:
(1) The entity carries on business in the Philippines; and
(2) The personal information was collected or held by an entity in the Philippines.
Rule Making. The Commission shall develop, promulgate, review or
amend rules and regulations for the effective implementation of the Act. This
includes:
for such to be lawful it must comply with any of the following conditions
a. The data subject must have given his or her consent prior to the
collection, or as soon as practicable and reasonable;
Compliance Officers.
Data Protection Policies.
Records of Processing Activities.
Management of Human Resources.
Right to be informed.
Right to Access.
Right to rectification.
-data subject has the right to dispute the
inaccuracy or error in the personal data and have the personal information
controller correct it immediately and accordingly
Right to Erasure or Blocking.
-he right to
suspend, withdraw or order the blocking, removal or destruction of his or her
personal data from the personal information controller’s filing system.
however such right may only be exercised upon proof of the following:
Commission
Data Subject
notification is required when it involves sensitive personal information
or such information may be used to enable identity fraud
personal information controller or the Commission believes that such unauthorized
acquisition is likely to give rise to a real risk of serious harm to any affected data
subject.
Breach Report
1. personal information controller shall notify the Commission by
submitting a report
2.report shall also include the name of a designated
representative of the personal information controller, and his or her contact
details.
3. All security incidents and personal data breaches shall be documented
through written reports
PENALTIES
A penalty of imprisonment ranging from one (1) year to three (3) years
and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not
more than Two million pesos (Php2,000,000.00) shall be imposed on persons who
process personal information without the consent of the data subject, or without
being authorized under the Act or any existing law.
penalty of imprisonment ranging from three (3) years to six (6) years
and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not
more than Four million pesos (Php4,000,000.00)
imposed on persons who process sensitive personal information without the consent of
the data subject, or without being authorized under the Act or any existing law.
Malicious disclosure
concealment of security breach
unauthorized disclosure
Combination or Series of Acts