Data Privacy Overview, things to understand

AthenaLyn1 13 views 59 slides Oct 09, 2024
Slide 1
Slide 1 of 59
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32
Slide 33
33
Slide 34
34
Slide 35
35
Slide 36
36
Slide 37
37
Slide 38
38
Slide 39
39
Slide 40
40
Slide 41
41
Slide 42
42
Slide 43
43
Slide 44
44
Slide 45
45
Slide 46
46
Slide 47
47
Slide 48
48
Slide 49
49
Slide 50
50
Slide 51
51
Slide 52
52
Slide 53
53
Slide 54
54
Slide 55
55
Slide 56
56
Slide 57
57
Slide 58
58
Slide 59
59

About This Presentation

DPA


Slide Content

Khane Samala-Raza
Public Information & Assistance DivisionPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
What is the right to privacy?
the right to be let alone— the most
comprehensive of rights and the right
most valued by civilized men
[Brandeis J, dissenting in Olmstead v. United
States, 277 U.S. 438 (1928)]PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHY IS IT
IMPORTANT?PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFINGPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFINGPROPERTY OF THE NATIONAL PRIVACY COMMISSION

PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
DPA sections
SECTION
1 - 6
Definitions
and General
Provisions
SECTION
7 -10
SECTION
11 -21
SECTION
22 -24
SECTION
25 -37
National
Privacy
Commission
Rights of Data
Subjects
and Obligations
of Personal
Information
Controllers and
Processors
Provisions
specific to
Government
PenaltiesPROPERTY OF THE NATIONAL PRIVACY COMMISSION

PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
PERSONAL
INFORMATIONPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
SENSITIVE
PERSONAL
INFORMATIONPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
PRIVILEGED
INFORMATIONPROPERTY OF THE NATIONAL PRIVACY COMMISSION

PRIVILEGED INFORMATION
Data received within the context
of a protected relationship
Husband and Wife Priest and Penitent
Attorney and Client Doctor and PatientPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
PERSONAL
DATAPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
DATA
SUBJECTPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
PERSONAL
INFORMATION
CONTROLLERPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
PERSONAL
INFORMATION
PROCESSORPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
DATA
PROCESSING
SYSTEMPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
KEY TERMS
DATA
SHARINGPROPERTY OF THE NATIONAL PRIVACY COMMISSION

under the DATA PRIVACY ACT PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
OBLIGATION 1: Adhere to
data privacy principles
TRANSPARENCY
LEGITIMATE PURPOSE
PROPORTIONALITYPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
OBLIGATION 2: Uphold
data subject rights
INFORMATION
OBJECT
ACCESS
CORRECT
ERASE
DAMAGES
DATA PORTABILITY
FILE A COMPLAINTPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
OBLIGATION 3: Implement
security measures
ORGANIZATIONAL
TECHNICAL
PHYSICALPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFINGPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
CIRCULARS
NPC Circular 16-01 –Security of
Personal Data in Government
Agencies
NPC Circular 16-02 –Data
Sharing Agreements Involving
Government Agencies
NPC Circular 16-03 –Personal
Data Breach Management
NPC Circular 16-04 –Rules of
Procedure
NPC Circular 17-01 –Registration of
Data Processing Systems
NPC Circular 17-01 Appendix 1 –
Registration of Data Processing
Systems Appendix 1PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ADVISORIES
NPC Advisory No. 2017-01 –Designation of Data
Protection Officers
NPC Advisory No. 2017-02 –Access to Personal
Data Sheets of Government Personnel
NPC Advisory No. 2017-03 –Guidelines on Privacy
Impact Assessments PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
PENALTIES
Access due to negligence 1yto 3y 3y to 6y 500k to 4m
Unauthorized processing 1y to 3y 3y to 6y 500k to 4m
Unauthorized purposes 18m to 5y 2y to 7y 500k to 2m
Improper disposal 6m to 2y 3y to 6y 100k to 1m
Intentional breach 1y to 3y 500k to 2m
PUNISHABLE ACT JAIL TERM FINE (PESOS)PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
PENALTIES
Concealing breach 18m to 5y 500k to 1m
Malicious disclosure 18m to 5y 500k to 1m
Unauthorized disclosure 1y to 3y 3y to 5y 500k to 2m
Combination of acts 3y to 6y 1m to 5m
PUNISHABLE ACT JAIL TERM FINE (PESOS)PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
5 PILLARS OF DATA PRIVACY
ACCOUNTABILITY & COMPLIANCE
Appoint a Data
Protection Officer
Conduct a Privacy
Impact Assessment
Create a Privacy
Management Program
Implement Data Privacy
and Security Measures
Be ready in case of a
Data Breach
1
2
PROGRAMPROGRAM3
4
5
REPORTREPORTPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFINGPROPERTY OF THE NATIONAL PRIVACY COMMISSION

THE
DATA PROTECTION OFFICERPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHAT IS A DPO?
Individual(s) accountable for
ensuring PICs / PIPs’
compliance with the DPA, its
IRR, NPC Issuances & other
applicable lawsPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHAT IS A COMPLIANCE OFFICER
FOR PRIVACY?
Individual(s) who perform some of
the functions of a DPO in
particular
cases:
§LGUs
§Gov’t agencies
§Private sector (subject to NPC approval)
§Analogous casesPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHY APPOINT A DPO?
üA legal requirement
üA cost-efficient solution to
achieve compliance &
accountability
üExtra beneficial for PICs/PIPs with
cross-border personal data
transfersPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHY BE A DPO?PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
GENERAL PRINCIPLES
•ResponsibilitylieswiththePICor
PIP,notwiththeDPO
•AutonomyoftheDPOorCOPin
theperformanceofduties
•Confidentialnatureofthe
positionPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
1.Monitorthe PIC’s or
PIP’s compliance
with the DPA, its
IRR, issuances by
the NPC & other
applicable laws and
policies. PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
2.Ensure the conduct
of Privacy Impact
Assessmentsrelative
to activities, measures, projects, programs, or systems of the PIC or PIP;PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
3.Advisethe PIC or
PIP regarding
complaints and/or
the exercise by data
subjects of their
rights
COMPLAINTPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
4.Ensure proper data breach
and security incident
managementby the PIC or
PIP, including the latter’s
preparation and submission to
the NPC of reports and other
documentation concerning
security incidents or data
breaches within the prescribed
period;
REPORTREPORTPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
5.Inform & cultivate
awarenesson privacy and
data protection within the organization of the PIC or
PIP, including all relevant
laws, rules and regulations
and issuances of the NPC;PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
6.Advocatefor the
development, review
and/or revision of policies,
guidelines, projects and/or
programs of the PIC or PIP
relating to privacy and
data protection, by
adopting a privacy by
design approach;
PROGRAMPROGRAMPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
7.Serveasthecontact
personofthePICorPIP
vis-à-vis datasubjects,the
NPCandotherauthorities
inallmattersconcerning
data privacyorsecurity
issuesorconcernsandthe
PICorPIP;PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
8.Cooperate, coordinate &
seek advice of the NPC
regarding matters concerning data privacy and security; and
LAWLAWPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS
9.Performotherduties&
tasksthatmay be
assignedbythePICorPIP
thatwillfurtherthe
interestofdata privacy
andsecurity&upholdthe
rightsofthedatasubjectsPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
ROLES AND FUNCTIONS (FOR COPs)
•Except for items (1) to (3), a COP shall
perform all other functions of a DPO
•assist the supervising DPO in the
performance of the latter’s functions.PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
SUBCONTRACTING THE
FUNCTIONS OF DPO/COP
•Outsourcing or
subcontracting of DPO
functions is allowed.
•DPO or COP must oversee
the performance of the
third-party service provider.
•DPO or COP shall remain
the contact personPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
SKILLS*
§Interpersonal &
communication skills
§Advanced org’l& privacy
program mgtskills
§Advanced leadership skills
*According to the Centre for Information Policy LeadershipPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
SKILLS*
§Data privacy strategy skills
§Business skills
§External engagement skills
*According to the Centre for Information Policy LeadershipPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
SUPPORTING THE DPO
§Top management
§Process owners
§Human resource
§Legal division
§IT
§Security
§Internal AuditPROPERTY OF THE NATIONAL PRIVACY COMMISSION

PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHO MUST
REGISTER?PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHO MUST
REGISTER?PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHO MUST
REGISTER?PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHY
SHOULD YOU
REGISTER?
PHOTO HERE
§A legal requirement
§Good for your brand
§Boosts compliance
readiness in several
waysPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
HOW TO
REGISTER?PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
PAPER DOCUMENTS - GOV’T
2 Original hard copies
§Certified true copy of the
Special/Office Order, or any
similar document, designating
or appointing the DPO of the
PIC or PIP; and
§Where applicable, a copy of
the charter of your agency, or
any similar document
identifying its mandate,
powers, and/or functions
REPORTREPORTPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
PAPER DOCUMENTS - PRIVATE
2 Original hard copies
§Duly-notarized Secretary’s Certificate authorizing the appointment or
designation of DPO, or any other document that demonstrates the validity
of the appointment or designation
§Certified true copy of any of the following documents, where applicable:
-Certificate of Registration (SEC Certificate, DTI Certification of Business
Name or Sole Proprietorship) or any similar document; and/or
-Franchise, license to operate, or any similar document.PROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFINGPROPERTY OF THE NATIONAL PRIVACY COMMISSION

DPO
BRIEFING
WHEN SHOULD YOU
REGISTER?
§PHASE II-8 March 2018
§Annually renewable w/in 2 months prior to, but not later
than 8 March
§Amendment or updates to be made w/in 2 months from
the date such changes take into effectPROPERTY OF THE NATIONAL PRIVACY COMMISSION
Tags