DP Orientation
DP Orientation
In the Q1 of 2021 - 6 accounts were leaked per second worldwide. 2021 Q1 - 43,169,912
In Q1 of 2022 - 2 internet users have their data leaked. (Surfshark) 2022 Q1 - 18,174,132
Public awareness and knowledge on the Data Privacy Act (DPA) grew from 13% in 2017 to
25% in 2021 (NPC, Feb. 2022)
Data Privacy by the Numbers
STOP WALKING ON DATA PRIVACY IS
EGGSHELLS!! ABOUT:
1
People, not Places
2
Personal Choice
3 4
Control, not Secrecy The Right to be Left
Alone
WHAT IS THE DPA?
Fully titled, “An Act Protecting Individual Personal Information in Information and
Communications Systems in the Government and the Private Sector, Creating for this
Purpose a National Privacy Commission, and for Other Purposes” the DPA aims to
protect the fundamental human right of privacy, of communication while ensuring the
free flow of information to promote innovation and growth.
KEY DPA ACTORS
PERSONAL INFORMATION
CONTROLLER (PIC)
RIGHTS OF DATA
SUBJECT
• Right to be Informed
• Right to Access
• Right to Object
• Right to Rectification
• Right to Erasure or Blocking
• Right to Damages
• Right to Data Portability
• Right to File A Complaint
TYPES OF DATA/ INFORMATION
PRIVILEGED
PERSONAL SENSITIVE INFORMATION
INFORMATION (PI) PERSONAL
INFORMATION (SPI)
***SEC. 12. Criteria for Lawful Processing of Personal Information. – ***SEC. 13. Sensitive Personal Information and Privileged Information. – The processing of
The processing of personal information shall be permitted only if not sensitive personal information and privileged information shall be prohibited, except in the cases:
otherwise prohibited by law, and when at least one of the conditions
exists:
DATA PROCESSING
CRITERIA FOR CRITERIA FOR LAWFUL
LAWFUL PROCESSING PROCESSING OF SPI
OF PI
• Consent • Consent
• Contract with the individual • Existing laws & regulations
• Vital interests/Life & health • Life & health
• Legal obligation • Processing by non-stock, non-
• National emergency / public profit orgs
order & safety, as prescribed by • Medical treatment
law • Lawful rights & interests in court
• Constitutional or statutory proceedings/legal claims
mandate of a public authority
• Legitimate interests of the PIC
or third parties
OBLIGATIONS OF PICs
1. The PIC should collect personal information for specified and legitimate purposes determined and
declared before, or as soon as reasonably practicable after collection.
2. The PIC should collect and process personal information adequately and not excessively.
3. The PIC should process personal information fairly and lawfully, and in accordance with the rights
of a data subject.
4. The PIC should process accurate, relevant and up to date personal information.
5. The PIC should retain personal information only for as long as necessary for the fulfillment of the
purposes for which the data was obtained. The information should be kept in a form which permits
identification of data subjects for no longer than is necessary.
6. The PIC must implement reasonable and appropriate organizational, physical and technical
measures intended for the protection of personal information.
General Data Privacy Principles
THANK YOU!
Data Protection Office
Notre Dame of Kidapawan College
[email protected]