Sie sind auf Seite 1von 2

Scope of Data Privacy Act of a license or permit given by the government

to an individual, including the name of the


SEC. 4. Scope. – This Act applies to the processing
individual and the exact nature of the benefit;
of all types of personal information and to any
natural and juridical person involved in personal (d) Personal information processed for
information processing including those personal journalistic, artistic, literary or research
information controllers and processors who, purposes;
although not found or established in the
(e) Information necessary in order to carry out
Philippines, use equipment that are located in
the functions of public authority which includes
the Philippines, or those who maintain an office,
the processing of personal data for the
branch or agency in the Philippines subject to the
performance by the independent, central
immediately succeeding paragraph: Provided,
monetary authority and law enforcement and
That the requirements of Section 5 are complied
regulatory agencies of their constitutionally and
with.
statutorily mandated functions. Nothing in this
Exceptions: Act shall be construed as to have amended or
repealed Republic Act No. 1405, otherwise
This Act does not apply to the following:
known as the Secrecy of Bank Deposits Act;
(a) Information about any individual who is or Republic Act No. 6426, otherwise known as the
was an officer or employee of a government Foreign Currency Deposit Act; and Republic Act
institution that relates to the position or No. 9510, otherwise known as the Credit
functions of the individual, including: Information System Act (CISA);

(1) The fact that the individual is or was (f) Information necessary for banks and other
an officer or employee of the government financial institutions under the jurisdiction of the
institution; independent, central monetary authority or
Bangko Sentral ng Pilipinas to comply with
(2) The title, business address and office Republic Act No. 9510, and Republic Act No.
telephone number of the individual; 9160, as amended, otherwise known as the Anti-
(3) The classification, salary range and Money Laundering Act and other applicable
responsibilities of the position held by the laws; and
individual; and (g) Personal information originally collected from
(4) The name of the individual on a residents of foreign jurisdictions in accordance
document prepared by the individual in with the laws of those foreign jurisdictions,
the course of employment with the including any applicable data privacy laws, which
government; is being processed in the Philippines.

(b) Information about an individual who is or was


performing service under contract for a
government institution that relates to the
services performed, including the terms of the
contract, and the name of the individual given in
the course of the performance of those services;

(c) Information relating to any discretionary


benefit of a financial nature such as the granting
Data Privacy Principles permit identification of the individual involved,
may be stored for longer periods.
A. Principle of Transparency
D. Data Quality Principle
Requires that the purpose for processing a
person’s data should be determined and Requires that personal data should be accurate
disclosed before its collection or as soon as and kept up to date. It also requires that
practicable. Also, consent of the data subject on inaccurate or incomplete data be rectified,
the collection and processing of his data should supplemented, destroyed, or restricted.
first be obtained, subject to exemptions
provided by laws and regulations. In obtaining
his consent, the data subject must be informed Elements of Consent Under the DPA and its IRR
of the nature, purpose, and extent of the
processing of such personal data, including the Sec. 19. General principles in collection,
risks and safeguards involved, the identity of the processing and retention. The processing of
personal information controller, his rights as a personal data shall adhere to the following
data subject as well as how these can be general principles in the collection, processing,
exercised. Moreover, information provided to a and retention of personal data:
data subject must always be in clear and plain a. Collection must be for a declared, specified,
language to ensure that they are easy to and legitimate purpose.
understand and access.
1. Consent is required prior to the collection and
B. Principle of Legitimate Purpose processing of personal data, subject to
Requires that the collection and processing of exemptions provided by the Act and other
information must also be compatible with a applicable laws and regulations. When consent is
declared and specified purpose, which must not required, it must be time-bound in relation to
be contrary to law, morals, or public policy. In the declared, specified and legitimate purpose.
other words, personal data should be processed Consent given may be withdrawn. (IRR)
fairly and lawfully.

C. Principle of Proportionality

Requires that the processing of personal


information must be relevant to, and must not
exceed, the declared purpose. The personal
information may be retained only for as long as
necessary for the fulfillment of the purposes for
which the data was obtained or for the
establishment, exercise, or defense of legal
claims, or as provided by law. It may also not be
retained in perpetuity in contemplation of a
possible future use yet to be determined.
However, personal information collected for
historical, statistical, scientific purposes, or in
other cases laid down by law, as well as, personal
information kept in a form which does not

Das könnte Ihnen auch gefallen