Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

CPA REVIEW

REGULATORY FRAMEWORK FOR BUSINESS TRANSACTIONS ATTY. AGUILAR


DATA PRIVACY ACT NOV 2020

Republic Act 10173 or The Data Privacy Act 2012 f. Information necessary for banks and other financial
institutions under the jurisdiction of the
It is a comprehensive and strict privacy legislation to independent, central monetary authority or
protect the fundamental human right of every individual to Bangko Sentral ng Pilipinas to comply with
privacy while ensuring free flow of information to promote Republic Act No. 9510, and Republic Act No. 9160,
innovation, growth and national development. as amended, otherwise known as the Anti-Money
Laundering Act and other applicable laws; and
National Privacy Commission is created to administer and g. Personal information originally collected from
implement the provisions of this Act, and to monitor and residents of foreign jurisdictions in accordance
ensure compliance of the country with international with the laws of those foreign jurisdictions,
standards set for data protection. On September 9, 2016, the including any applicable data privacy laws, which
Implementing Rules and Regulations was put in effect thus is being processed in the Philippines
mandating all companies to comply.
Terms
Scope and Application Personal Information

The Data Privacy Act is applicable to any natural and refers to any information whether recorded in a material
juridical person or entity involved in processing of form or not, from which the identity of an individual is
personal information, with provided exceptions. The act apparent or can be reasonably and directly ascertained by
applies to the processing of the personal information of the entity holding the information, or when put together
Philippines citizens regardless of where they reside. The with other information would directly and certainly
law has extraterritorial application which is applicable not identify an individual.
only to businesses with offices in the Philippines but also
when equipment based in the Philippines is used for the Personal Information Controller
processing of personal information.
refers to a person or organization who controls the
Exclusions collection, holding, processing or use of personal
information, including a person or organization who
a. Information about any individual who is or was an instructs another person or organization to collect, hold,
officer or employee of a government institution that process, use, transfer or disclose personal information on
relates to the position or functions of the individual; his or her behalf, excluding:
b. Information about an individual who is or was
performing service under contract for a a. A person or organization who performs such
government institution that relates to the services functions as instructed by another person or
performed, including the terms of the contract, and organization; and
the name of the individual given in the course of b. An individual who collects, holds, processes or
the performance of those services; uses personal information in connection with the
c. Information relating to any discretionary benefit of individual’s personal, family or household affairs.
a financial nature such as the granting of a license
or permit given by the government to an Personal Information Processor
individual, including the name of the individual
and the exact nature of the benefit; Provided, that refers to any natural or juridical person qualified to act as
they do not include benefits given in the course of such under this Act to whom a personal information
an ordinary transaction or as a matter of right; controller may outsource the processing of personal data
d. Personal information processed for journalistic, pertaining to a data subject.
artistic, literary or research purposes, in order to
uphold freedom of speech, of expression, or of the Sensitive Personal Information – refers to personal
press, subject to requirements of other applicable information about:
law or regulations a. About an individual’s race, ethnic origin, marital
e. Information necessary in order to carry out the status, age, color, and religious, philosophical or
functions of public authority which includes the political affiliations;
processing of personal data for the performance by b. About an individual’s health, education, genetic or
the independent, central monetary authority and sexual life of a person, or to any proceeding for any
law enforcement and regulatory agencies of their offense committed or alleged to have been
constitutionally and statutorily mandated committed by such person, the disposal of such
functions. proceedings, or the sentence of any court in such
proceedings;

Page 1 of 4
c. Issued by government agencies peculiar to an
individual which includes, but not limited to, social shall be disposed or discarded in a
security numbers, previous or current health secure manner that would prevent
records, licenses or its denials, suspension or further processing, unauthorized
revocation, and tax returns; and, access, or disclosure to any other party
d. Specifically established by an executive order or an or the public, or prejudice the interests
act of Congress to be kept classified. of the data subjects.

General Data Privacy Principles Any Personal data originally collected for a
authorized declared, specified, or legitimate
further purpose may be processed further for
Collection Consent is required prior to the collection processing historical, statistical, or scientific
must be for and processing of personal data. When shall have purposes, and, in cases laid down in
a declared, consent is required, it must be time-bound adequate law, may be stored for longer periods,
specified, in relation to the declared, specified and safeguards.
and legitimate purpose. Consent given may be Personal data which is aggregated or
legitimate withdrawn. kept in a form which does not permit
purpose. identification of data subjects may be
Data subject must be provided specific kept longer than necessary for the
information regarding the purpose and declared, specified, and legitimate
extent of processing, including, where purpose.
applicable, the automated processing of
his or her personal data for profiling, or shall not be retained in perpetuity in
processing for direct marketing, and data contemplation of a possible future use
sharing. yet to be determined

Purpose should be determined and


declared before, or as soon as reasonably Transparency Data subject must be aware of the
practicable, after collection. nature, purpose, and extent of the
processing of his or her personal data,
Only personal data that is necessary and including the risks and safeguards
compatible with declared, specified, and involved, the identity of personal
legitimate purpose shall be collected. information controller, his or her rights
as a data subject, and how these can be
Personal Uphold the rights of the data subject, exercised.
data shall including the right to refuse, withdraw
be consent, or object. It shall likewise be Any information and communication
processed transparent and allow the data subject relating to the processing of personal
fairly and sufficient information to know the nature data should be easy to access and
lawfully. and extent of processing. understand, using clear and plain
language.
Information provided to a data subject must
always be in clear and plain language to
Legitimate Compatible with a declared and
ensure that they are easy to understand and
Purpose specified purpose which must not be
access.
contrary to law, morals, or public
Must be in a manner compatible with
policy.
declared, specified, and legitimate purpose.
Proportionality Adequate, relevant, suitable,
Should be adequate, relevant, and limited to necessary, and not excessive in relation
what is necessary in relation to the purposes to a declared and specified purpose.
for which they are processed
Personal data shall be processed only if
Undertaken in a manner that ensures the purpose of the processing could
appropriate privacy and security safeguards. not reasonably be fulfilled by other
means.
Personal Retention of personal data shall only for as
Data shall long as necessary:
not be (a) for the fulfillment of the declared,
retained specified, and legitimate purpose, or when
longer than the processing relevant to the purpose has
necessary. been terminated;
(b) for the establishment, exercise or defense
of legal claims; or
(c) for legitimate business purposes, which
must be consistent with standards followed
by the applicable industry or approved by
appropriate government agency.

Page 2 of 4
personal information are not transferred to third
Criteria for Lawful Processing of Personal Information parties: Provided, finally, That consent of the data
subject was obtained prior to processing;
The processing of personal information shall be permitted
only if not otherwise prohibited by law, and when at least e. The processing is necessary for purposes of medical
one of the following conditions exists: treatment, is carried out by a medical practitioner
or a medical treatment institution, and an adequate
a. The data subject has given his or her consent; level of protection of personal information is
b. The processing of personal information is ensured; or
necessary and is related to the fulfillment of a
contract with the data subject or in order to take f. The processing concerns such personal information
steps at the request of the data subject prior to as is necessary for the protection of lawful rights
entering into a contract; and interests of natural or legal persons in court
c. The processing is necessary for compliance with a proceedings, or the establishment, exercise or
legal obligation to which the personal information defense of legal claims, or when provided to
controller is subject; government or public authority.
d. The processing is necessary to protect vitally
important interests of the data subject, including Rights of the Data Subject
life and health;
e. The processing is necessary in order to respond to The personal information controller or personal
national emergency, to comply with the information processor shall uphold the rights of data
requirements of public order and safety, or to fulfill subjects, and adhere to general data privacy principles and
functions of public authority which necessarily the requirements of lawful processing. The data subject is
includes the processing of personal data for the entitled to the following rights:
fulfillment of its mandate; or
f. The processing is necessary for the purposes of the (a) Right to be informed
legitimate interests pursued by the personal (b) Right to object
information controller or by a third party or parties (c) Right to access
to whom the data is disclosed, except where such (d) Right to rectification
interests are overridden by fundamental rights and (e) Right to erasure or blocking
freedoms of the data subject which require (f) Right to damages
protection under the Philippine Constitution.
The rights shall not be applicable if the processed personal
data are used only for the needs of scientific and statistical
Processing of Sensitive Personal Information and research and, on the basis of such, no activities are carried
Privileged Information out and no decisions are taken regarding the data subject.
The rights are also not applicable to the processing of
General Rule: PROHIBITED personal data gathered for the purpose of investigations in
relation to any criminal, administrative or tax liabilities of a
Exceptions: data subject.
a. The data subject has given his or her consent,
specific to the purpose prior to the processing, or in Data Privacy and Security
the case of privileged information, all parties to the
exchange have given their consent prior to The law requires that any entity involved in data collection
processing; and processing must implement reasonable and
appropriate organizational, physical and technical
b. The processing of the same is provided for by measures intended for the protection of personal
existing laws and regulations: Provided, That such information against any accidental or unlawful destruction,
regulatory enactments guarantee the protection of alteration and disclosure, as well as against any other
the sensitive personal information and the unlawful processing.
privileged information: Provided, further, That the
consent of the data subjects are not required by law Data Breach Notification
or regulation permitting the processing of the
sensitive personal information or the privileged The entity shall promptly notify the Commission and the
information; affected data subject through a written or electronic report
within 72 hours upon knowledge of that a personal data
c. The processing is necessary to protect the life and breach has occurred. It is when sensitive information may
health of the data subject or another person, and the have been acquired by an unauthorized person to be used
data subject is not legally or physically able to for identity fraud and is likely to give rise to a real risk of
express his or her consent prior to the processing; serious harm to any affected data subject. The contents of
the notification must at least:
d. The processing is necessary to achieve the lawful (a) Describe the nature of the breach;
and noncommercial objectives of public (b) The personal data possibly involved;
organizations and their (c) The measures taken by the entity to address the
associations: Provided, That such processing is breach;
only confined and related to the bona fide members (d) The measures take to reduce the harm or negative
of these organizations or their consequence of the breach;
associations: Provided, further, That the sensitive

Page 3 of 4
(e) The representatives of the personal information
controller, including their contact details;
(f) Any assistance to be provided to the affected data
subjects.

Notification may be delayed only to the extent necessary to


determine the scope of the breach, to prevent further
disclosures, or to restore reasonable integrity to the
information and communications system.

Penalties

Who is liable for penalties?

Page 4 of 4

You might also like