Sie sind auf Seite 1von 14

01

DPO Forum
U P D AT E S F R O M T H E N AT I O N A L P R I VA C Y C O M M I S S I O N
Table of Contents A message
A message from the Privacy Commissioner 3

A quick look back on June and July 2017 4


from the Privacy
Roadshow Updates 6

The Case Facts of the BPI Data Breach


and its Implications in Data Privacy
8 Commissioner
DPO of the Month 10

The World on Privacy 12

Preparing for GDPR Compliance 14 I am delighted to welcome you to the private organizations can best protect just let us know. Your comments
first issue of the Data Privacy Forum, and uphold data subject rights. and feedback would also be much
a bimonthly newsletter for the Data appreciated. This would help us ensure
Best Practices for DPOs & Privacy-Minded Organizations 16 Protection Officer (DPO) community In this and future editions, we shall that this newsletter serves the DPO
in the Philippines, published in PDF touch on NPC decisions, advisories community in the best way possible.
Updates from the Compliance and Monitoring Division 18 format by the National Privacy and other public discussions, which We also encourage you to share the
Commission (NPC). we believe practicing DPOs will find information here with your colleagues
instructive in further understanding and contacts who may be interested
Updates from the Privacy Policy Office 19 Available via email to DPOs like you, their role as data privacy champion. in DPO-related concerns.
who are registered with the NPC, this We shall also feature DPOs of the
newsletter is aimed at keeping you month, tips, trends to watch for, as As always, if there is anything the NPC
Registered Organizations 20 on track of the latest updates and well as NPC guidelines, updates, can do to help in your job as DPO, do
emerging issues in the data privacy announcements and other related not hesitate to get in touch with us.
Upcoming DPO Events 22 front, thus help you in getting your news.
organization on top of its compliance Thank you.
obligations. I hope you enjoy reading each issue of
Data Privacy Forum.
The DPO Newsletter is produced by the National Privacy Commissions Public Information and Assistance Data Privacy Forum is envisioned to
Division, with the contributions of its Privacy Policy Office, Compliance and Monitoring Division, serve as a medium for the continuing This publication is for you, so if you Raymund Enriquez Liboro
and Complaints and Investigations Division. conversation on how public and have a suggestion for an article Privacy Commissioner and Chairman

2 privacy.gov.ph privacy.gov.ph 3
A quick look back
JUNE - JULY 2017 EVENT HIGHLIGHTS

Throughout the
months of June
and July 2017,
representatives from
the National Privacy
Commission served
as speakers and
resource persons for
the Conduct of the Privacy Impact
Assessment

15 June
Adamson University Awareness on
the DPA
FOI Conference with the Presidential
Communications Operations Office
Department of Health Office for
Health Service Development Cluster
Orientation on the DPA and its
Implementing Rules and Regulations
Banco De Oro Orientation
on the DPA
Launching
Securities and Exchange
Commission Executive-Level Briefing
on the DPA

27 June
Tondo Medical Center Lecture on
the DPA
Armed Forces of the Philippines
Cyber Security Summit

28 June
National ICT Summit
Office of the President Information
01
12 July
2017 Annual Home Development
Mutual Fund Lawyers Conference:
The Lawyer as an Advocate of Data
Privacy

15 July
Lyceum Polytechnic University
of Manila Total Quality Instruction
Development Program

19 July
Professional Regulation
Commission (PRC) Seminar-Workshop
and Communication Technology
a number of local and 1 June 16 June Month Celebration 04 July
20 July
Globe Telecom Inc. Seminar ASEAN 2017 Dialogues DPA Compliance and the Fight
international events. on the DPA 29 June Against Cybercrime Conference Data Privacy Asia with the Contact
Center Association of the Philippines
19 June Internet and Mobile Marketing Harophil Seminar on the DPA
Got an event you would like to invite 6 June Securities and Exchange Association of the Philippines General 05 July
us to? Interested in having us over to PhilEXIM Seminar on the DPA Commission Awareness on the DPA Membership Meeting Information Security Officers Group
21 July
discuss more about the Data Privacy NEDA Orientation on the Privacy and Conduct of a Privacy Impact Philippine National Bank Briefing on 2017: Keep Information Security
#CyberSafePH: CICC Cyber
Act (DPA)? Send us an e-mail Impact Assessment Assessment the DPA Secured
Semirara Mining and Power Corp. Security Caravan
at info@privacy.gov.ph. Bureau of Jail Management and
7 June 20 June Penology 2nd Quarter Management Privacy Impact Assessment Seminar-
TESDA Planners Conference Workshop 27 July
The Big Story Live Interview on the Conference Panel Discussion during the 19th
BPI Breach Lina Group of Companies Presidents founding anniversary of National
8 June and Senior Management Forum on 06 July
House of Representatives DLSU CEShout: Online PrivaCIV Telehealth Center
22 June Data Privacy Awareness
Information and Communications Department of Health Policy and Department of Tourism Seminar on Protection
Technology Committee Technical Administrations Executive Course the DPA and the NPC Memorandum
Working Group Meeting House of Representatives Circulars 10 July
Committee on Banks and Financial Commission on Audit Orientation
14 June Intermediaries Meeting 30 June on the DPA and its Implementing
Office of the President Knowledge Philippine Export-Import Credit Rules and Regulations
Sharing Exercise: Laying down the 23 June Agency Workshop on Conducting a 11 July
foundations of Data Privacy Department of Information and Privacy Impact Assessment Cloud Security Alliance
Aboitiz Equity Ventures (AEV) Communications Technology Project Cyber Insurance Roadshow Summit 2017
DPA Awareness and Workshop on

4 privacy.gov.ph privacy.gov.ph 5
PrivaMoves Roadshows
OVER THE PAST FEW MONTHS, representatives
from the NPC have gone to several key cities across
the country to talk about compliance with the Data
Privacy Act and awareness on information privacy.

26 January, Cebu City


- In coordination with the Cebu
Educational Development
ICT Association of Dumaguete,
National ICT Confederation of the
Philippines, and Globe Business
and Industry, National ICT
Confederation of the Philippines,
and the Local Government of
Data Privacy Compliance Caravan
Data Privacy Awareness Campaign
During the DICT Cybersecurity Caravan

01 aM oves
Where do you

v
#Pri
Foundation Technology, the - 56 Participants Albay think Priva should
Department of Information and - 40 Participants go to next?
Communications Technology, and 16 May, Iloilo City For invites, call
the Cebu Provincial Capitol - In coordination with the 27July, Davao City (02)565-9623
- 78 Participants Department of Information and - In coordination with the or e-mail us at
Communications Technology Department of Information and info@privacy.
01 March, Cagayan de Oro City - 120 Participants Communications Technology, gov.ph.
- In coordination with the the Cybercrime Invesigation and
Department of Information and 21 July, Dagupan City Coordination Center, and Ateneo
Communications Technology - In coordination with the de Davao University
- 100 Participants Department of Information and - 668 Participants
Communications Technology
03 March, Butuan City - 100 Participants 29 July, Zamboanga City
- In coordination with the - In coordination with the
Department of Information and 21 July, Quezon City Department of Information and
Communications Technology - In coordination with the Communications Technology
- 93 Participants Department of Information and - 370 Participants
Communications Technology and
24 March, Zamboanga City the Cybercrime Invesigation and 11 August, Cagayan De Oro City
- In coordination with the Coordination Center - In coordination with the
Department of Information and - 1,200 Participants Department of Information and
Communications Technology Communications Technology,
- 213 Participants 25 July, Legazpi City National Telecommunications
- In coordination with the Commission, Palo Alto Networks,
13 May, Dumaguete City Department of Information and FireEye Singapore Private Ltd, and
- In coordination with the Communications Technology, IECEP-Northern Mindanao Chapter
Department of Information and the Albay ICT Association, Inc., - 2,219 Participants
Communications Technology, the Albay Chamber of Commerce

6 privacy.gov.ph privacy.gov.ph 7
BREACH RECAP

The Case Facts of the BPI Data


Breach and its implications
on Data Privacy
BPI first became aware of the
glitch on or around 5:00 a.m.,
when customers calling their
customer relations hotlines reported
problems with their accounts. The
customer service reports referred
to discrepancies in the account
balances of BPI and BPI Family
Bank current and savings account
depositors. Despite having been
so alerted, customers were able to
withdraw a total of P46 million.

The incident caused the Cybercrime


Investigation and Coordination
it was determined that in the BPI
personal data breach, the root
of the problem was a batch run
that erroneously posted debits
and credits to a significant portion
of client accounts. These batch
programs are automated to run at
night to update balances based on
account movements. Because of
an erroneously processed request
from within BPI for all transactions
between April 27 to May 2, a
portion of the batch sequence that
updates current and savings account
balances was filled with erroneous
01
Circular No. 16-03 as a breach of
security leading to the accidental or
unlawful destruction, loss, alteration,
unauthorized disclosure of, or
access to, personal data transmitted,
stored, or otherwise processed.
A personal data breach may be:
(a) an availability breach resulting
from loss, accidental or unlawful
destruction of personal data; (2)
an integrity breach resulting from
alteration of personal data; and/or
(3) a confidentiality breach resulting
from the unauthorized disclosure
of or access to personal data. In an
Center (CICC) to convene with data. availability breach and in an integrity
representatives of the Philippine breach, as is the case here, there
National Police (PNP), the National Acting on the personal data breach, is no requirement that the data be
Bureau of Investigation (NBI), the BPI restored its system only after in the hands of third parties. The
Information Security Officers Group 36 hours, and after having suffered subsequent compliance check from
(ISOG), BPI, and this Commission. losses of P46 million. the Compliance and Management
At the meeting, the BPI CISO, Tony Division, using the 34-point
T. Reyes, informed CICC Chairman The incident gained the attention compliance check program, resulted
Rodolfo A. Salalima that the incident of national news media as well. The in a 12-page Compliance Order
was due to an internal system glitch. resulting Congressional hearings that highlighted opportunities for
saw Deputy Commissioner Ivy improvement and mandatory actions
Following this meeting, the NPC Patdu categorically characterize the that we ordered to better protect
took the lead in investigating incident as a personal data breach, the personal data of BPI clients.
the root of the problem. After a over the denial earlier made by BPI.
meeting with ranking BPI officers,
and from the investigation of DICT It is to be remembered that personal
Assistant Secretary Allan Cabanlong, data breaches are defined in NPC

IN THE MIDDLE OF JUNE 2017, an internal process (data retrieval


error) involving the production data of the current and savings
account database at the Bank of the Philippine Islands (BPI) caused
a massive data breach that affected a majority of its users using its
online account management facility.

8 privacy.gov.ph privacy.gov.ph 9
until December that I was tasked to
take over the creation of the Data
Privacy Office, which I now head.
February 1 is the official start date
of the Data Privacy Office and my
appointment as the head of it. Thats
the evolution of how data privacy
was tackled in the PLDT Group, and
the running mantra since then really is
that we need to start now. We need
to move forward inch by inch with a
very clear vision of where we need to
go.

What do you think is the biggest


challenge to building a culture
and any customer should expect, and
all of this really boils down to trust. So
I think our contribution, as the data
privacy office of PLDT, is basically
ensuring that the millions and millions
of customer data that we have, we
protect.

You have been working on Data


Privacy for over a year now. Do you
have any words of advice for aspiring
DPOs?

Im actually quite surprised that,


according to Commissioner Liboro, a
lot of people are struggling with data
01
just a by the way. Its not easy, but
its also not unreasonable.

Where do you see privacy and DPOs


in the Philippines 10 years from now?

Well, Im optimistic that everyones


going to embrace what digital
promises business here in the
Philippines, and privacy should go
hand-in-hand with that if you look at
it from a transformation standpoint.
Security is a pillar, customer
experience is also a pillar, and the
DPA affects both. So if we seek
growth in that area, then privacy is

DPO of the Month:


protective of privacy in the privacy. Thats because when we saw part and parcel of it all, something
Philippines, and what role do you the IRR, we thought it was crystal that is baked into our processes from
think DPOs play in combatting these clear. Its so clear, in fact, that its a the very beginning, up to the finished
challenges? little scary, because there is very little products and services.
room for interpretation.
I think its all about raising the level of As for DPOs in the Philippines, I think

Leah Camilla R. Besa-Jimenez


consciousness of the value that data I think other people might be anyone working in data privacy,
provides, both as a consumer the overanalyzing it, when I think its especially during this stage
value my data brings to a company really a choice of seeing it in either a because its all about setting up, and
and as a business person the positive or negative light. You can see really evaluating a lot of processes
value the company sees in the data it as a negative, because its another would be highly marketable.
AS THE CHIEF DATA PRIVACY OFFICER of the PLDT Data Privacy Office, I actually was of the customer. As to how to build layer that you need to comply with. But more than that, I think theres
with Smart, doing customer value a culture of data privacy, will I still be But if you think about it again, if actually a great opportunity for
Group of Companies, Leah has a lot on her hands management. That means a lot of alive in the time its actually there? the objective is excellent customer them, particularly in the context of
and that is an understatement. We sat down with her data, so of course we were one of the (Laughs). Commissioner Liboro said in experience and making sure your Southeast Asia, in carving the way
first to panic and ask ourselves what DPO3, that the TelCos are vanguards customers trust you, then the DPA for a more enhanced framework
for an afternoon to talk about her experiences thus far the law and the IRRs implications of data privacy, and its true when is a part of that. It has to be a given, something like the GDPR in
in data privacy, and where she sees it in the were for business. you think about it, because we not just something that is imposed Europe, but from the perspective
handle so much data. So my offices by the government. Its good that of emerging markets here in the
Philippines in the years to come. Between then and now is really just contribute to it, I think, is not just to its imposed by the government, of region. Because the Philippines is one
a lot of assessment of the various ensure compliance, but to establish course, and the sanctions only give of the first countries in the ASEAN
Please tell us briefly about yourself, with the role of Chief Data Privacy businesses, beginning with Smart. good governance for the data that more teeth to the act and provide to embrace data privacy, I feel that
and how you first became involved Officer of the PLDT Group officially in Then sometime in September or we have. Because the way we see more urgency to get things done. the country stands a good chance
with data privacy and protection. February of this year, but we started October, we were asked to apply the it, protecting data is equivalent to of spearheading the best practices
the work on data privacy as early as framework we were using for Smart, making sure that we provide the best For any digital company, security and in the region. That would be an
Well, how much time do you have? July of 2016, when we received the which we had then tested already, to customer experience, which any privacy really have to be baked in, its interesting move for the NPC, di ba?
(Laughs.) The short story is, I started draft of the IRR. Before I was in the the rest of the PLDT group. It wasnt company would consider a priority part of everything you do, and is not Lets see!

10 privacy.gov.ph privacy.gov.ph 11
The World on Privacy
On Ransomware

As of press time, the world has


barely begun to recover from the
effects of WannaCry and Petya
global ransomware attacks that
have infected nearly half a million
PCs worldwide. Although not an
entirely new phenomenon, the
attacks have only gotten more
advanced and more vicious over
the years, with ransomware costing
institutions an estimated 1B dollars
in 2016 alone.
Google as part of a project testing
an alert, diagnosis, and detection
system for acute kidney injury, it
Deep Mind accessed this data in
a manner that UKs National Data
Guard Dame Fiona Caldicott called
legally inappropriate.

The resolution filed by the UK


Information Commissioners Office
was accepted by both camps,
and better, more privacy-minded
agencies have instituted meaningful
protections to prevent the misuse of
the technology.

Benjamin Franklin once famously


said that he who sacrifices liberty
for security deserves neither.
While this may be is true, the global
discourse on the sacrifices we
make for innovation, development,
and ease of interconnectivity is
now becoming mainstreamized.
solutions are in development for the What information is to be used,
Google project. Across the Atlantic, and how, and to what extent?
however, rages a fiercer legal battle These are questions that should
01
While there is no foreseeable end over data protection and privacy in ignite meaningful conversations
to these attacks, there are some the face of police surveillance and and it must begin with personal
steps your organization can take counterterrorism measures. information controllers and
to avoid or alleviate the effects of processors, whose legal obligations
ransomware. Data, as experts and The New York Police Department include transparency with the
observers say, is now the new oil; has been sued for refusing to information they collect and
it thus makes sense that individuals release information about its use process.
and groups across the globe will of facial recognition software,
be willing to do anything, legally predictive policing software, x-ray This is where privacy by design
or otherwise, to get their hands on vans, and mosque-raking programs comes in, guided by your Privacy
it. Therefore, it even makes more that violate the privacy of thousands Impact Assessments and outlined
sense for institutions to invest in of individuals, most especially in your Privacy Manuals and privacy
data protection and data privacy. minority communities in the City of and data protection measures.
New York. This has been the status
quo despite existing Freedom of
The price of innovation Information Laws, but the absence The final countdown:
of regulations governing police use 10 months to GDPR
Last month, Googles Deep Mind of facial recognition software has
ran into legal trouble after obtaining raised eyebrows and tensions in The EU Global Data Protection THE GLOBAL PRIVACY SUMMIT, attended by
data from the Royal Free NHS the city, especially among those Regulation is set to officially kick privacy professionals and agencies worldwide,
Foundation Trust in the United versed in Privacy Law. Research in by 25 May 2018. Ready or not, was held last April in Washington, DC. Among the
Kingdom without the consent of its indicates that roughly half of institutions all over the globe have topics discussed were trends in privacy impact
patients. While the health institution American adults are enrolled in face to comply. Is your organization assessments, principles of privacy by design,
had passed its patients data to recognition networks, but very few ready? and GDPR implementation.

12 privacy.gov.ph privacy.gov.ph 13
GUIDANCE AND RECOMMENDATIONS

Preparing for GDPR


Compliance
Scope

Accountability and
governance

Consent
EU GDPR

Personal data any information relating to an


identified or identifiable person. [Art. 4(1)]

Controllers generally must:


Implement appropriate technical and
organizational measures to demonstrate
GDPR compliance and build in privacy by
default and design. [Arts. 5(2), 24, 25]
Undertake compulsory data protection
impact assessments. [Art. 35]
Appoint data protection officers. [Art. 37]

Consent must be:


Freely given, specific, informed, and
unambiguous indication of data subjects
agreement to processing
Through statement or clear affirmative
action. [Art. 4(11)]
01
DPA

Personal Information, Sensitive Personal


Information, and Privileged Information. [Sec.
4(g), (l) and (k)]

PICs and PIPs generally must:


Implement organizational, physical, and
technical security measures. [Sec. 20]
Conduct a Privacy Impact Assessment
for each program or process that involves
personal data [see, Sec. 20 and Sec. 4, NPC
Circular No. 16-01]
Appoint data protection officer/s [Sec.
21(b)]

Consent must be:


Freely given, specific, informed indication of
will that the data subject agrees to processing
Evidenced by written, electronic or
recorded means. [Sec. 3(b)}

THE EU GENERAL DATA PROTECTION REGULATION (GDPR) Data Breach


Notification
Mandatory by controllers and processors
(exceptions apply) within 72 hours of
Mandatory by PIC within 72 hours from
knowledge or reasonable belief of occurrence
is a new regulation that will harmonize data protection laws across EU, becoming aware of the breach [Art. 33-34] of the breach (exceptions apply) [Sec. 20(f)]

replacing existing national data protection rules. Although it will not take effect
Rights Expanded individual rights include: Same rights of the data subject except right
until May 25, 2018, it is critical that preparation for compliance commence early Right to erasure. (Art. 17) to restriction (Sec. 16-18)
Right to restriction of processing. (Art. 18)
to effectively implement the new obligations imposed. Right to data portability. (Art. 20) Rights are also transmissible (Sec. 17)
Right to object. (Art. 21)

Some Philippine businesses covered Personal information controllers There are similarities with the Overseas transfer of May be transferred outside the EU in limited Recognized under the DPA; PICs still
by the Data Privacy Act of 2012 and processors who are outside GDPR and the DPA. You would personal data circumstances including: responsible for personal data whose
(DPA) may need to comply with the EU but are covered by the GDPR note that the DPA is largely based To countries that provide an adequate level processing is outsourced or transferred
of data protection internationally [see: Sec. 6 and 21, DPA; Sec.
GDPR if they: will generally have to appoint on the 1995 EU Directive, which
Where standard data protection clauses or 50, IRR)
a representative established in is the predecessor of the GDPR. approved binding corporate rules that enable
have an establishment in the an EU Member State, subject to For additional resources and transfers within a corporate group apply
EU (regardless of whether they exceptions. The representative is information, you may review the Approved codes of conduct or certification
in place. [Chapter V]
process personal data in the EU) or the point of contact for supervisory following European Commission,
do not have an establishment authorities and individuals in the Reform of EU data protection rules
in the EU, but offer goods or EU on all issues related to data and the Article 29 working group Registration of No requirement but must maintain internal Required for PICs and PIPs who meet the
Data Processing Systems records of processing activities [Art. 30] criteria [Sec. 46-47, IRR]
services, or monitor the behavior of processing. GDPR guidance.
individuals in the EU.
Sanctions Administrative fines of up to 20 million Both fine and imprisonment for [Sec.
euros or 4% of annual worldwide turnover, 25-37]
whichever is higher. [Art. 83]

14 privacy.gov.ph privacy.gov.ph 15
Best Practices for DPOs
and Privacy-Minded
Organizations
NPC CIRCULAR 16-01, which discusses the security of personal data
in government agencies, mandates all organizations in the public sector
to establish a control framework to address the risks identified
upon the conduct of a privacy impact assessment.
With the continuing rise of data
privacy awareness, public and
private organizations across the
globe are now strengthening their
respective control frameworks with
more stringent security measures
over who can view or access the
personal data it stores.

In most organizations, access to


information is usually determined
in accordance with an employees
013. Privacy Notices

An indispensable part of any


organizations privacy management
program is the posting of a privacy
notice to its data subjects. The
to ensure the protection of the functions. This means that if the privacy notice serves to inform
personal data they process. The personal data is not relevant or clients of what personal data will
Section 6 of NPC Circular 16-01 following describe security measures necessary in the performance of an be collected and why, how long
defines the control framework as considered to be best practices as employees core functions, then he the personal data will be retained,
a comprehensive enumeration implemented by PICs across the or she should not have access to which organizations the personal
of the measures intended to board: any personal data, regardless of his data will be shared with, and how
address the risks, including or her position in the organizational the personal data will be disposed
organizational, physical and hierarchy. of, among others. The privacy
technical measures to maintain Nature of the personal data Risks represented by the
1. Security Clearances notice posted on the PICs website
to be protected processing, the size of the
the availability, integrity and or office premises promotes the
organization and complexity
confidentiality of personal data of its operations As an organizational measure, the 2. Access Control Systems data processing principles of
and to protect the personal data issuance of security clearances by transparency, legitimate purpose
against natural dangers such as the Human Resources Department Setting up an access control system and proportionality, because they
accidental loss or destruction, of a PIC is considered not only a best is considered an effective security inform the data subjects how and
and human dangers such as practice, but also a requirement for measure for any public or private why their personal data is being
unlawful access, fraudulent government agencies as per Section organization that processes personal processed by the PICs. Also, it lifts
misuse, unlawful destruction, 9 of NPC Circular 16-01. data, as it allows the effective the veil of ambiguity in the terms by
alteration and contamination. recording of when, where, and by which a data subject and personal
Security clearances ensure that whom an organizations data centers information controller transact,
A control framework shall take into Current data privacy Cost of security only duly authorized personnel are accessed. As a physical measure, because the data subjects are made
account, among others, the items best practices implementation
are allowed to process personal this is usually manifested in the to better understand the PICs
illustrated to the right. data collected and stored by the form of biometrics technology as functions in relation to their personal
organization, while allowing the an entry/exit point in offices where data.
organization to have more control personal data is being processed.

16 privacy.gov.ph privacy.gov.ph 17
Updates from the
Compliance and Monitoring
Division
THE COMPLIANCE AND MONITORING DIVISION is the NPCs arm for ensuring
compliance of personal information controllers (PICs) and processors (PIPs) in the
Philippines to ensure the effective implementation of the Data Privacy Act of 2012. Its
main initiative for the first few years of the effectivity of the law and its Implementing
Updates from the
Privacy Policy Office

CONSIDERED AS THE KNOWLEDGE CENTER of the National Privacy Commission


01
(NPC) that establishes data privacy and protection rules and guidelines, the Privacy
Policy Office (PPO) spearheads the development of policies, advisory opinions,
and standpoints on proposed legislations affecting personal data. It also provides
Rules and Regulations is to create and develop the registration process for PICs and clarifications on the interpretation of the Data Privacy Act of 2012 (DPA) and its
PIPs. In this regard, this is the status of registration, by the numbers, as of 14 August: Implementing Rules and Regulations (IRR) and other data privacy issues and concerns.

Entity Actual Target Achieved Percentage 32 Advisory Opinions 2 Position Papers protection and privacy. Appropriate
These are made in response to Position papers provide comments and recommendations
NGAs 119 61 (Executive 42.62% (Executive inquiries from different stakeholders comprehensive discussion and have been provided for the
on a variety of topics. Most common recommendations on key issues following bills:
Offices) Offices)
of these are concerns on automated through the lens of personal data Filipino Identification System
Private Companies 194 - - processing and decision-making, protection, with two released Free Internet Access in Public
consent, data sharing, the Data recently: Areas
State Universities and Colleges 70 112 62.50% Protection Officer, and exemptions International Telecommunication
in relation to existing related laws, Union (ITU) Department of
Total 383 among others. Information and Communications Whats in the works for the PPO?
Technology (DICT) Big Data Pilot 1. Research on the use of CCTVs,
2 Advisories Study drones, and dashcams, and their
For the proper guidance of Online and Social Media privacy and data protection
The NPC has been active
concerned stakeholders, the Membership Accountability Act implication
in reminding the remaining offices
following advisories were produced 2. An advisory on Privacy Impact
and institutions to comply, as the
and made available: Comments on Proposed Assessment (PIA) Guidelines
deadline of registration is on 9
Designation of a Data Protection Legislation 3. A circular on the Registration of
September 2017.
Officer The NPC has been monitoring Data Processing System, or Phase
Access to Personal Data Sheet of proposed legislation and their Two of PIC registration with the
For more information, visit
Government Personnel implications on personal data NPC.
register.privacy.gov.ph.

18 privacy.gov.ph privacy.gov.ph 19
Registered Organizations
National Government
Agencies (NGAs) and
Government-Owned and
-Controlled Corporations
(GOCCs)

Anti-Money Laundering
Council
APO Production Unit, Inc.
Autonomous Region in
Muslim Mindanao
Bureau of Broadcast
Services
Bureau of Internal Revenue
Bureau of the Treasury
Central Board of
Assessment Appeals
Department of Budget and
Management
Governance Commission for
the Philippines
Clark Development
Corporation
Commission on Filipinos
Overseas
Cooperative Development
Authority
Department of Trade and
Industry
Deptartment of Information
and Communications
Technology
Design Center of the
Philippines
Insurance Commission
Land Bank of the Philippines
Light Railway Transits
Authority
Metro Rail Transit
Sugar Regulatory
Administration
Tourism Infrastructure and
Enterprise Zone Authority
Trade & Investment
Development Corporation
Council for the Welfare of
Children
Department of Agrarian
Reform
Department of Social
Welfare and Development
DILG Regional Office - NCR
Games and Amusements
Board
Government Service
Insurance System
Home Development Mutual
Fund
Home Guaranty Corporation
Sweepstakes Office
Philippine Commission on
Sports Scuba Diving
Philippine Commission on
Women
Philippine International
Trading Corp.
Philippine Racing
Commission
Social Security System
Technical Education and
Skills Development Authority
Bureau of Corrections
Bureau of Jail Management
and Penology
Dangerous Drugs Board
Department of Foreign
Affairs
Department of Public Works
Food and Nutrition Research
Institute
Mindanao Development
Authority
Department of Foreign
Affairs - Overseas Voting
Secretariat
Philippine Statistical
Research and Training
Institute
Bicol Regional Training &
Teaching Hospital
Mayon Hilarion A. Ramiro Sr.
Medical Center
DTI Regional Office IX
National Conciliation and
Mediation Board DOLE
National
Telecommunications
Commission
North Luzon Philippines
State College
Ilocos Sur Polytechnic State
College
Ilocos Science and
Technology University
Ramon Magsaysay
Technological University
University of the Philippines
- Manila
Eulogio Amang Rodriguex
Institute of Science
and Technology Tarlac
Agricultural University
Marikina Polytechnic College
Northern Negros State
Collage of Science and
Technology
Capiz State University
Nueva Ecija University of
West Visayas State
University
Catanduane State University
Surigao Del Sur State
University
Siquijor State College
Cebu Technological
University
Batangas State University
Romblon State University
Cavite State University
Isabela State University
J.H Cerilles State College
Technological University of
the Philippines
Technological University of
the Philippines Visayas
Naval State University
Northwestern Mindanao
State college of Science and
Technology Bicol University
Rizal Technological
University
Laguna State Polytechnic
University
Northern Iloilo Polytechnic
State College
Reyes Tacandong & Co.
Ayala Foundation
Microsourcing Philippines
Inc.
Philippine National Bank
Cebu Educational
Development Foundation for
Information Technology AP
Renewables Inc.
Pilmico Foods Corporation
PetNet, Inc.
Aboitiz Equity ventures, Inc.
PHILAM Equitable Life
Assurance Company, Inc.
The Phiilippine American
Life and General Insurance
Company
PAMI Income Payout Fund
Inc.
Philam Managed Income
Fund Incorporation
PAMI Global Equity Fund
Incorporation
PAMI Equity Index Fund
Incorporation
PAMI Asia Balanced Fund
Inc.
Tower Club Inc.
Maybank Philippines, Inc.
EMQ Limited
Manila Doctors Hospital
Ayala Aviation Corporation
Kyocera Document Solutions
Development Philippines,
Inc.
Aboitiz Power Corporation
ING Bank N.V., Manila
Branch
Hedcor, Inc.
Malayan Bank Savings and
Mortgage Bank, Inc.
Philippine Savings Bank
Balikatan Property Holding,
Inc.
Balikatan Housing Finance,
Inc.
Bahay Financial Services, Inc.
The Bank of Tokyo -
Mitsubishi UFJ, LTD.
Rizal Commercial Banking
Corporation
Manila Water Company, Inc.
Deutsche Knowledge
Alveo Land Corporation
Makati Development
Corporation
Ayala Property Management
Corporation
DirectPower Services Inc.
Metrobank Card Corporation
(A Finance Company)
Development Bank of the
Philippines
Prime Suupport Services,
Inc.
Alveo-Federal Land
Communities Inc.
Accendo Commercial Corp.
Bellavita Land Corp.
Avida Land Corporation
MDC Buildplus, Inc.
MDC Conqrete, Inc.
MDC Equipment Solutions,
Inc.
MDC - Subic Inc.
Cagayan De Oro Gateway
Corp.
Avencosouth Corp.
Leisure and Allied Industries
Philippines Inc - Timezon
01
Armed Forces and Police
Mutual Benefit Association,
Inc.
Starr International Insurance
Philippine Branch
Express Gifts Philippines Inc.
Philippine Associated
Smelting & Refining
Corporation
Manila Memorial Park
Cemetery Inc.
Eastern Telecommunications
Philippines, Inc.
Oceanagold Inc.
Good Shepherd Nursing
Home
Agricultural Credit Policy
Council
Chirica Resorts Corporation
Avida Sales Corp.
Amicassa Process Solutions,
Inc.
Buklod Bahayan Realty and
Development Corp.
Ali Makati Hotel Property Inc.
Greenhaven Property
Venture Inc
First Life Financial Co. Inc.
Infosys BPO Limited
Philippine Branch
SEAOIL Philippines, Inc.
Yuanta Savings Bank
Philippines, Inc.
ING Bank N.V., Manila
Branch
RCBC Leasing and Finance
Corporation
Meralco Employees
Mutal Aid and Benefits
Association, Inc.
Viva Artists Agency, Inc.
Unilever Philippines, Inc.
University of Asia and the
Pacific Foundation, Inc.
Manuel S. Enverga University
Foundation
Public Safety Savings and
Loan Association, Inc.
Rizal MicrobankAndresons
Global, Inc.
Raffles & Company, Inc.
Emperador Inc.
Emperador distillers, Inc.
Manila Tytana Colleges
National Development and Highways Science ad Technology Services PTE. LTD
GOCCs Philam Strategic Growth Aprisa Business Process Ali Makati Hotel &
Company Inter-Country Adoption Foreign Service Institute University of Science and Blackhounds Security and
University of Rizal System Fund Inc. RCBC Capital Corporation Solutions Residences, Inc
Government Arsenal Philippine Mining Board Technology of Southern Investigation Agency, Inc.
National Bureau of Cotabato City State Philam Global Fund Inc. North Luzon Railways Ayalaland Hotels and
Government Procurement Development Corporation Lung Center of the Philippines Guimaras State FLT Prime Insurance Bluehounds Security and
Investigation Polytechnic College Corporation Resorts Corporation
Policy Board Philippines State Universities and College Philam Dollar Bond Fund Inc. Corporation Investigation Agency, Inc.
Philippine Rice Research National Defense College of Colleges (SUCs) University of the Philippines Arellano University Philam Bond Fund Inc. Huawei Technologies Phils., Taft Punta Engao Property, Ecosouth Hotel Ventures Inc.
National Printing Office Institute Manila Waterworks and the Philippines House of Investments, Inc.
Visayas Inc. Inc. Northgate Hotel Ventures
Office of the Presidential Philippine Coconut Authority Sewerage System University of Southeastern Philam Fund Inc.
National Intelligence RCBC Securities Inc. Inc. Global Support and Service
Spokesperson Metals Industry Research Caraga State University Bukidnon State University Philippines Sterling Bank of Asia Inc.
Philippine Competition Coordinating Agency PAMI Horizon Fund Inc. for Entertainment Philippine
and Development Center Bohol Island State University Standard Chartered Bank Olongapo Electricity Cebu Property Ventures and Corporation
Optical Media Board Commission National Security Council Surigao State College of Philam Asset Management
R.G Manabat & Co. (KPMG in Distribution Company Development Corporation
Peoples Television Network, Philippine Crop Insurance National Archives of the Technology Bataan Peninsula State Inc. WeChat Pay Hong Kong
Philippines Office for Transport Security University the Philippines) Cebu Holdings, Inc.
Inc. Corporation Iloilo State College of Merck Sharp and Dohme GM Bank of Luzon Inc. Limited
National Commission for Office of the Presidential Fisheries Bulacan Agricultural State Bank of Makati Anvaya Cove Golf & Sports
Presidential Communications Philippine Economic Zone Private Institutions (I.A) LLC Cebu Pacific Portico Land Corp.
Culture and Arts Adviser on the Peace College Club Inc.
Operations Office Authority Camigui Polytechnic State Visayan Electric Co., Inc. AEON Credit West Technology and Payroll Service Providers Inc.
Process
National Dairy Authority College Mariano Marcos State Service(PHILIPPINES) Inc. Communications Services Ayala Land Inc.
Professional Regulation Philippine Fiber Industry Office of the Solicitor Davao Light and Power Co., Philippine Eds Techno-
University ISACA Manila Chapter St. Lukes Medical Center Inc. Sentera Hotel Ventures Inc.
Commission Development Authority National Electrification General Palompon Institute of Inc. service, Inc.
Administration Technology Jose Rizal Memorial State Ayala Corporation (Global City) Melco Resorts Leisure Southcrest Hotel Ventures
Advanced Science and Philippine Institute for Philippine Center on Subic Enerzone Corporation Station Square Commercial
Technology Institute Development Studies National Kidney & Transplant Benguet State University University - Dipolog Campus SteelAsia Manufacturing Ibero Asistencia Sociedad Corporation Inc.
Transnational Crime AboitizLand, Inc. Corp.
Institute Ifugao State University Corporation Anonima Sucursal En Hongkong & Shanghai North Triangle Hotel
Agricultural Training Institute Philippine Reclamation Philippine National Volunteer Benguet State University Verde Golf Development
Novare Technologies Inc. Aboiotiz Construction Pilipinas City Savings Bank Banking Corp. Ventures Inc.
Al-Amanah Islamic Authority National Maritime Service Coordination University of the Philippines Kalinga State University Corporation
International, Inc. Ayala Greenfield
Investment Bank of the Philippine Statistics Authority Polytechnic Agency Southern Leyte State MDI / Micro-D Internation, 3M Service Center APAC, BGNorth Properties, Inc.
Central Mindanao University Manila-Oslo Renewable Development Corporation Roxas Land Corporation
Philippines Philippine Textile Reserach University Inc. Inc. Cebu Insular Hotel Company,
Philippine Science High Philippine Veterans Affairs Eastern Visayas State Enterprise Inc. Airswift Transport, Inc.
Institute MAPFRE Insular Insurance Ayala Land Sales, Inc. Maxs Group, Inc. Inc.
Authority of Freeport Area School System Office University Central Luzon State
Corporation Pilmico Animal Nutrition Ayalaland Malls, Inc. Amec Operations Limited -
of Bataan Philippine Sports Philippine Atmospheric, Presidential Commision for University Anvaya Cove Beach and Bonifacio Hotel Ventures Inc.
Zamboanga State College Corporation Manila Shared Service
Bases Conversion Commission Geographical and the Urban Poor Jose Rizal Memorial State EEI Corporation Ayala Hotels, Inc. Nature Club, Inc.
of Marine Sciences and Aboitiz Construction, Inc. Solinea, inc.
Development Authority Astronomical Services University - Main Campus J Anthony Management Ayalaland Commercial
Philippine Statistical Public Attorneys Office Technology Aurora State Arinso International Cebu Leisure Company Inc.
Administration Consultants, Inc. Cotabato Light and Power Center, Inc.
Bureau of Agriculture Research & Training Center College of Technology Palawan State University Philippines Inc & Northgate
Philippine Council for Health Veterans Memorial Medical Company Southportal Properties, Inc.
and Fisheries Products Team Absolute Global, Inc. BGSouth Properties, Inc. Arinso Belgium NV
Philippine Trade Training Research and Development Center Mindanao State University Nueva Viscaya State
Standards Manila Water Foundation, philippines ROHQ Ayala Land Sales, Inc.
Center Laguna Lake Development General Santos University First Metro Securities Fresenius Medical Care
Philippine Council for Inc. First Oceanic Property Manila Electric Company
Bureau of Animal Industry Privatization and Authority Zamboanga City State Mindanao State University - Brokerage Corporation Philippines Inc.
Industry Energy and Metro Pacific Tollways Management, Inc. Pricewaterhouse Coopers
Cagayan Economic Zone Management Officer Emerging Technology National Mapping and Polytechnic College Iligan Institue of Technology First Metro Investment FMC Renal Care Corp.
Corporation Technology Application and Service Delivery Centre
Authority Quedan and Rural Credit Research and Development Resource Information Western Mindanao State Camarines Sur Polytechnic Corporation Asia Renal Care (Philippines)
College BPI Philam Life Insurance Promotion Institute Limited
Cebu Ports Authority Guarantee Corporation Philhealth Insurance Authority University First Metro Asset Inc.
Corp. Federal Land, Inc. Orix Metro Leasing and
Civil Aeronautics Board Science and Technology Corporation Bureau of Communications Camarines Norte State Sorsogon State College Management, Inc. DSI Dialysis Center, Inc.
Pampanga II Electric Perpetual Succor Hospital Finance Corporation
Civil Aviation Authority of Information Institute Philippine Charity Services College Cagayan State University Metropolitan Bank & Trust Mindanao Renal Care, Inc.
Cooperative Inc. and Maternity, Inc. PSI Technologies, Inc.
Company

20 privacy.gov.ph privacy.gov.ph 21
01
Interested DPOs may RSVP with the
Commission on Higher Education via
e-mail at chedncr@ched.gov.ph or
call (02) 441-0985 / (02) 441-1224.

22 privacy.gov.ph privacy.gov.ph 23
DPO Briefings

Want to learn more about compliance with the


Data Privacy Act but not sure where to start?

Beginning this month, well be holding bi-monthly


DPO Breifings at the Audio Visual Room of the
WANT YOUR SECTOR to be Department of Information and Communications
front and center in the next DPO Technology Headquarters in Quezon City.
Assembly? Send us an e-mail at
info@privacy.gov.ph.
There will be morning and afternoon sessions
on 16 and 30 August 2017. Organizations may
reserve up to three slots for their representatives
by calling our office at (02) 565-9623 today or
sending an e-mail to paola.nartea@privacy.gov.ph.

24 privacy.gov.ph privacy.gov.ph 25
3rd Floor, Core G, GSIS Headquarters Bldg.,
Financial Center, Pasay City, Metro Manila 1308

For invitations: (02)565-9623


For complaints: (02)517-7806
For compliance: (02)517-7810
For public assistance: 09451534299 / 09399638715

privacy.gov.ph

privacyPH

info@privacy.gov.ph
complaints@privacy.gov.ph

privacy.gov.ph #AskPriva #PrivacyPH

Das könnte Ihnen auch gefallen