SlideShare une entreprise Scribd logo
1  sur  31
LECTURE COVERAGE
Clarify the following matters regarding Republic Act No. 10173, also
known as the Data Privacy Act of 2012 (DPA):
1.Whether the cooperatives registered under the
Cooperative Development Authority (CDA) are covered
by the DPA;
2.If indeed the cooperatives are covered by the law,
determine the following:
A. Obligations of cooperatives
B. Reportorial requirements to be submitted to the
NPC
C. Compliance period for such requirements
D. Penalties for non-compliance; and
3.Where cooperatives may course through or
communicate other concerns regarding data privacy.
In the DIGITAL ERA,
INFORMATION is POWER.
- Claude Elwood Shannon (National Inventors Hall of Fame)
BACKGROUND
In 2012, the Congress of the
Philippines passed Republic Act No.
10173, also known as the Data
Privacy Act (DPA) of 2012. Five
years later, the DPA’s Implementing
Rules and Regulations was put in
effect on September 9, 2016, thus
mandating all companies to comply.
It was estimated that 2.5 quintillion
— or 2.5 billion billion — bytes of
data were created everyday. This
includes unprecedented
knowledge about what real
individuals are doing, watching,
thinking, and feeling.
BACKGROUND
Companies must be held
accountable not only for what
they do with customer data —
but how they protect that
data from third parties.
The past few years of security
breaches, system errors, and
ethical scandals within some
of the country’s major banks
have reminded us that there
is much work to be done.
What is the DPA?
Data Privacy Act (DPA),
PROTECTS individuals from
unauthorized processing of
Personal Information/Sensitive
Personal Information.
It created the National Privacy
Commission (NPC) to monitor
the implementation of this law.
(Section 7 of DPA).
DATA PROTECTION
1.All personal information must be collected
for reasons that are specified, legitimate, and
reasonable.
2.All personal information must be handled
properly, kept accurate and relevant, used
only for the stated purposes, and retained
only for as long as reasonably needed.
3.All personal information must be discarded
in a way that does not make it visible and
accessible to unauthorized third parties.
4.Unauthorized processing, negligent
handling, or improper disposal of personal
information is punishable with up to six (6)
years in prison or up to five million pesos
(PHP 5,000,000) depending on the nature
and degree of the violation.
PERSONAL
INFORMATION 
Refers to any information
whether recorded in a
material form or not,
from which the identity of
an individual is apparent
or can be reasonably and
directly ascertained by the
entity holding the
information, or when put
together with other
information would directly
and certainly identify an
individual.
PERSONAL INFORMATION CONTROLLER
Refers to a person or organization
who controls the collection,
holding, processing or use of
personal information, including a
person or organization who
instructs another person or
organization to collect, hold,
process, use, transfer or disclose
personal information on his or her
behalf.
This term excludes:
(1)A person or organization who performs such functions
as instructed by another person or organization; and
(2)An individual who collects, holds, processes or use
personal information in connection with the individual’s
personal, family or household affairs.
PERSONAL INFORMATION PROCESSOR
Refers to any natural or
juridical person qualified
to act as such under this
Act to whom a personal
information controller may
outsource the processing
of personal data pertaining
to a data subject.
DATA SUBJECT 
Refers to an individual
whose personal
information is
processed.
COOPERATIVES REGISTERED
UNDER THE COOPERATIVE
DEVELOPMENT AUTHORITY
(CDA) ARE COVERED BY THE
DPA
The DPA applies to “any natural and
juridical person involved in the personal
information processing including those
personal information controllers and
processors who, although not found or
established in the Philippines, use
equipment that are located in the
Philippines, or those who maintain an office,
branch or agency in the Philippines.”
[Sections 3(par. g, h, and i) and 4 of the DPA]
Upon examination of the
nature of information handled
by cooperatives, it is clear that
cooperatives may be
considered as personal
information controllers (PICs)
who collect, hold, process
and use personal information
of its members
- (NPC Privacy Policy Office
Advisory Opinion No. 2017-021)
COOPERATIVES AS
PERSONAL INFORMATION
CONTROLLERS (PICs)
Cooperatives process personal
data of members, particularly
with regard to the application
and processing of their
individual loans, credit lines,
etc. Thus, cooperatives are
involved in the processing of
personal and sensitive personal
information and are thereby
obliged to adhere with the
provisions of the DPA.
- (NPC Privacy Policy Office
Advisory Opinion No. 2017-021)
COOPERATIVES AS
PERSONAL INFORMATION
CONTROLLERS (PICs)
COOPERATIVES AS
PERSONAL INFORMATION
PROCESSORS (PIPs)
Republic Act No. 6939 created
the CDA to formulate plans and
programs on cooperative
development, including the
development and conduct of
management and training
programs to assist members and
ensure the viability and growth
of cooperatives. Most
importantly, it is in-charge of the
registration of all cooperatives,
federations and unions.
- Section 3, par. 1, b, and 3 Republic Act
6939
COOPERATIVES AS
PERSONAL INFORMATION
PROCESSORS (PIPs)
Pursuant to this function,
cooperatives are mandated to
register as a cooperative and
provide documents to the
CDA, including financial and
membership details (CDA
Memorandum Circular 2015-01
on the Revised Guidelines
Governing the Registration of
Cooperatives).
Cooperatives, in this set
up, is outsourced by the
CDA as PIPs.
OBLIGATIONS OF COOPERATIVES IN
COMPLIANCE WITH THE PROVISIONS OF THE
DPA, ITS IRR AND OTHER NPC ISSUANCES
1.Adherence to the general data
privacy principles of transparency,
legitimate purpose, and
proportionality. PICs and personal
information processors (PIPs) are
also mandated to uphold the rights
of the data subjects.
OBLIGATIONS OF COOPERATIVES IN
COMPLIANCE WITH THE PROVISIONS OF THE
DPA, ITS IRR AND OTHER NPC ISSUANCES
2. To appoint a Data
Protection/Privacy
Officer (DPO). Pursuant to
Section 21(b) of the DPA
and Section 50(b) of the
IRR, PICs shall designate
an individual or
individuals who are
accountable for the
organization’s compliance
with this Act.
3. To implement reasonable
and appropriate
organizational, physical and
technical measures intended
for the protection of
personal information
against any accidental or
unlawful destruction,
alteration and disclosure,
as well as against any other
unlawful processing.
OBLIGATIONS OF COOPERATIVES IN
COMPLIANCE WITH THE PROVISIONS OF THE
DPA, ITS IRR AND OTHER NPC ISSUANCES
4. Review of all existing data sharing
arrangements and/or actual contracts, joint
issuances, or any similar documents, and
make the necessary revisions thereto,
execution of a data sharing agreement
where applicable, and the immediate
termination of the sharing of personal data
in instances where the arrangement is not
for the purpose of performing a public
function or providing a public service.
- NPC Circular No. 2016-02
OBLIGATIONS OF COOPERATIVES IN
COMPLIANCE WITH THE PROVISIONS OF THE
DPA, ITS IRR AND OTHER NPC ISSUANCES
REPORTORIAL REQUIREMENTS TO BE SUBMIT
COOPERATIVES TO THE NPC
1.Registration Of Personal Data Processing
Systems.
Section 47 of the IRR of
the DPA provides for the
registration of personal
data processing systems.
This provision states that
if a personal information
controller or personal
information processor
employs at least two
hundred fifty (250)
persons, registration is
automatically required.
When the personnel employed are fewer than two
hundred fifty (250), registration is not required, unless
the any of the following circumstances is present:
1.The processing it carries out is likely to pose a risk to
the rights and freedoms of the data subjects;
2.The processing is not occasional; or
3.The processing includes sensitive personal information
of at least one thousand (1,000) individuals.
In case any of the circumstances enumerated above are
present, the cooperative is then required to register its
data processing system.
1.Registration Of Personal Data Processing
Systems.
REPORTORIAL REQUIREMENTS TO BE SUBMIT
COOPERATIVES TO THE NPC
REPORTORIAL REQUIREMENTS TO BE SUBMIT
COOPERATIVES TO THE NPC
1.Registration Of Personal Data Processing
Systems.
The NPC will be implementing the registration process in
two phases:
1. Phase I requires the submission of a notarized
registration form containing details on the PIC,
head of the organization, and the DPO; and
2. Phase II is the registration of the data processing
systems to be done online.
* As the NPC is still in the process of optimizing its
website for the Phase II endeavor, for purposes of the
September 2017 deadline, only Phase I will be strictly
required. The public is advised to visit the website of the
NPC for any updates and announcements on the
implementation and deadline for Phase II.
REPORTORIAL REQUIREMENTS TO BE SUBMIT
COOPERATIVES TO THE NPC
2. Data Breach Notification
A PIC is required to
notify the NPC and the
affected data subjects
“within seventy-two
(72) hours upon
knowledge of, or when
there is reasonable belief
that a personal data
breach has occurred”.
- Section 38 (a), IRR of the DPA
REPORTORIAL REQUIREMENTS TO BE SUBMIT
COOPERATIVES TO THE NPC
2. Data Breach Notification
The report may be
submitted in a written or
electronic format containing
the required contents of the
notification stated in
Sections 20(f) and 39 of the
DPA and the IRR,
respectively.
- Section 41 (a), IRR of the
DPA
NPC Circular 16-03
comprehensively discusses the
framework for personal data
breach management and the
procedures for personal data
breach notification, as well as
the requirement for the
submission of the annual
report of all personal data
breaches and security
incidents.
REPORTORIAL REQUIREMENTS TO BE SUBMIT
COOPERATIVES TO THE NPC
3. Annual Report Of All Personal Data
Breaches And Security Incidents.
A personal information controller
“carrying out any wholly or partly
automated processing operations or
set of such operations intended to
serve a single purpose or several
related purposes shall notify the
Commission when the automated
processing becomes the sole basis for
making decisions about a data
subject, and when the decision would
significantly affect the data subject”.
As of the moment, the NPC does not
require any format for the
notification, as long as it contains the
contents enumerated in Section 48 of
the IRR.
4. Notification of Automated Decision-Making
REPORTORIAL REQUIREMENTS TO BE SUBMIT
COOPERATIVES TO THE NPC
The law and the IRR do not provide for
penalties for non-compliance with the
appointment of the DPO, registration of
data processing systems, notification of
automated decision-making, submission
of annual reports, among others.
However, in case of the occurrence of a
personal data breach, the filing of a
complaint by a data subject, or an audit
of the Commission, compliance with
such requirements shall be considered
by the NPC in evaluating the situation
and its determination of liability under
the penal provisions, if any.
- Section 25-33, DPA
PENALTIES FOR NON-COMPLIANCE
THANK YOU!
DATA PRIVACY ACT (DPA) OF 2012:
(Republic Act No. 10173)
Implications to Cooperatives as
Personal Information Controller
and/or Personal Information Processor
Atty. PHILLIP RAYMUND S. RIVERA
Legal Officer III
Cooperative Development Authority
Dagupan Extension Office

Contenu connexe

Tendances

Data Privacy - Penalties for Non-Compliance
Data Privacy - Penalties for Non-ComplianceData Privacy - Penalties for Non-Compliance
Data Privacy - Penalties for Non-ComplianceJDP Consulting
 
Cybercrime law in the philippines
Cybercrime law in the philippinesCybercrime law in the philippines
Cybercrime law in the philippinesian_oguis
 
Data Privacy- Security of Sensitive Personal Information
Data Privacy- Security of Sensitive Personal InformationData Privacy- Security of Sensitive Personal Information
Data Privacy- Security of Sensitive Personal InformationJDP Consulting
 
Data Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data SubjectData Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data SubjectJDP Consulting
 
Special laws on children 8353, 9262, 9231, 7877, 7610, 920
Special laws on children   8353, 9262, 9231, 7877, 7610, 920Special laws on children   8353, 9262, 9231, 7877, 7610, 920
Special laws on children 8353, 9262, 9231, 7877, 7610, 920Omar Jacalne
 
Republic Act 9208 or the Anti-Trafficking in Persons_As Amended.pptx
Republic Act 9208 or the Anti-Trafficking in Persons_As Amended.pptxRepublic Act 9208 or the Anti-Trafficking in Persons_As Amended.pptx
Republic Act 9208 or the Anti-Trafficking in Persons_As Amended.pptxMarsha Pasong
 
Samples of Decided Administrative Cases in the Philippines
Samples of Decided Administrative Cases in the PhilippinesSamples of Decided Administrative Cases in the Philippines
Samples of Decided Administrative Cases in the PhilippinesJohanna Manzo
 
Orientation ra 9208 ii
Orientation ra 9208 iiOrientation ra 9208 ii
Orientation ra 9208 iiOmar Jacalne
 
Republic Act 10175: Cybercrime Prevention Act of 2012
Republic Act 10175: Cybercrime Prevention Act of 2012Republic Act 10175: Cybercrime Prevention Act of 2012
Republic Act 10175: Cybercrime Prevention Act of 2012Michael Roa
 
Rules Implementing the Code of Conduct and Ethical Standards for public offic...
Rules Implementing the Code of Conduct and Ethical Standards for public offic...Rules Implementing the Code of Conduct and Ethical Standards for public offic...
Rules Implementing the Code of Conduct and Ethical Standards for public offic...Jo Balucanag - Bitonio
 
Bill of Rights
Bill of RightsBill of Rights
Bill of RightsAngelLu21
 
ARTICLE III - Sections11-16
ARTICLE III - Sections11-16ARTICLE III - Sections11-16
ARTICLE III - Sections11-16tzeri_apple
 
Polsc2 13 bill of rights (sec2-7)
Polsc2   13 bill of rights (sec2-7)Polsc2   13 bill of rights (sec2-7)
Polsc2 13 bill of rights (sec2-7)Yvan Gumbao
 
Bill of rights (lecture 2)
Bill of rights (lecture 2)Bill of rights (lecture 2)
Bill of rights (lecture 2)John Torres
 
Laws on Graft and Corruption
Laws on Graft and CorruptionLaws on Graft and Corruption
Laws on Graft and CorruptionMarlyn Allanigue
 
Concept of Bill of Rights (Philippines)
Concept of Bill of Rights (Philippines)Concept of Bill of Rights (Philippines)
Concept of Bill of Rights (Philippines)Rich Elle
 

Tendances (20)

Data Privacy - Penalties for Non-Compliance
Data Privacy - Penalties for Non-ComplianceData Privacy - Penalties for Non-Compliance
Data Privacy - Penalties for Non-Compliance
 
Cybercrime law in the philippines
Cybercrime law in the philippinesCybercrime law in the philippines
Cybercrime law in the philippines
 
Data Privacy- Security of Sensitive Personal Information
Data Privacy- Security of Sensitive Personal InformationData Privacy- Security of Sensitive Personal Information
Data Privacy- Security of Sensitive Personal Information
 
Data Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data SubjectData Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data Subject
 
Special laws on children 8353, 9262, 9231, 7877, 7610, 920
Special laws on children   8353, 9262, 9231, 7877, 7610, 920Special laws on children   8353, 9262, 9231, 7877, 7610, 920
Special laws on children 8353, 9262, 9231, 7877, 7610, 920
 
Republic Act 9208 or the Anti-Trafficking in Persons_As Amended.pptx
Republic Act 9208 or the Anti-Trafficking in Persons_As Amended.pptxRepublic Act 9208 or the Anti-Trafficking in Persons_As Amended.pptx
Republic Act 9208 or the Anti-Trafficking in Persons_As Amended.pptx
 
Ra 7610
Ra 7610Ra 7610
Ra 7610
 
Types of offenses and corresponding penalties
Types of offenses and corresponding penalties Types of offenses and corresponding penalties
Types of offenses and corresponding penalties
 
ra 10364 new.pptx
ra 10364 new.pptxra 10364 new.pptx
ra 10364 new.pptx
 
Samples of Decided Administrative Cases in the Philippines
Samples of Decided Administrative Cases in the PhilippinesSamples of Decided Administrative Cases in the Philippines
Samples of Decided Administrative Cases in the Philippines
 
Orientation ra 9208 ii
Orientation ra 9208 iiOrientation ra 9208 ii
Orientation ra 9208 ii
 
Republic Act 10175: Cybercrime Prevention Act of 2012
Republic Act 10175: Cybercrime Prevention Act of 2012Republic Act 10175: Cybercrime Prevention Act of 2012
Republic Act 10175: Cybercrime Prevention Act of 2012
 
Rules Implementing the Code of Conduct and Ethical Standards for public offic...
Rules Implementing the Code of Conduct and Ethical Standards for public offic...Rules Implementing the Code of Conduct and Ethical Standards for public offic...
Rules Implementing the Code of Conduct and Ethical Standards for public offic...
 
Bill of Rights
Bill of RightsBill of Rights
Bill of Rights
 
ARTICLE III - Sections11-16
ARTICLE III - Sections11-16ARTICLE III - Sections11-16
ARTICLE III - Sections11-16
 
Cybercrime law
Cybercrime lawCybercrime law
Cybercrime law
 
Polsc2 13 bill of rights (sec2-7)
Polsc2   13 bill of rights (sec2-7)Polsc2   13 bill of rights (sec2-7)
Polsc2 13 bill of rights (sec2-7)
 
Bill of rights (lecture 2)
Bill of rights (lecture 2)Bill of rights (lecture 2)
Bill of rights (lecture 2)
 
Laws on Graft and Corruption
Laws on Graft and CorruptionLaws on Graft and Corruption
Laws on Graft and Corruption
 
Concept of Bill of Rights (Philippines)
Concept of Bill of Rights (Philippines)Concept of Bill of Rights (Philippines)
Concept of Bill of Rights (Philippines)
 

Similaire à Data Privacy Act of 2012 implication to cooperatives

All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfJakeAldrinDegala1
 
Regulatory Compliance in Colombia
Regulatory Compliance in ColombiaRegulatory Compliance in Colombia
Regulatory Compliance in ColombiaProColombia
 
Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...Vijay Dalmia
 
Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...Vijay Dalmia
 
Overview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawOverview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawFatmaAkram2
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfDaviesParker
 
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...REVULN
 
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...Dr. Oliver Massmann
 
Examples of international privacy legislation
Examples of international privacy legislationExamples of international privacy legislation
Examples of international privacy legislationUlf Mattsson
 
Indonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdfIndonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdfAHRP Law Firm
 
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdfDIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdfDaviesParker
 
E bplscbppbd moa-template-2021-v.2.5_draft
E bplscbppbd moa-template-2021-v.2.5_draftE bplscbppbd moa-template-2021-v.2.5_draft
E bplscbppbd moa-template-2021-v.2.5_draftPsycheCunanan
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityEmerson Bryan
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law Owako Rodah
 

Similaire à Data Privacy Act of 2012 implication to cooperatives (20)

All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
Regulatory Compliance in Colombia
Regulatory Compliance in ColombiaRegulatory Compliance in Colombia
Regulatory Compliance in Colombia
 
The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013The Protection of Personal Information Act 4 of 2013
The Protection of Personal Information Act 4 of 2013
 
The Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCMThe Popi Act 4 of 2013 - Implications for iSCM
The Popi Act 4 of 2013 - Implications for iSCM
 
Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...
 
Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...Reasonable security practices and procedures and sensitive personal data or i...
Reasonable security practices and procedures and sensitive personal data or i...
 
China-PIPL.pdf
China-PIPL.pdfChina-PIPL.pdf
China-PIPL.pdf
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Overview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawOverview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection Law
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdf
 
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
Dr. Rolando Rivera Lansigan - The Privacy Act of 2012, its compliance and imp...
 
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
 
Examples of international privacy legislation
Examples of international privacy legislationExamples of international privacy legislation
Examples of international privacy legislation
 
Indonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdfIndonesian Legislatives Passes Personal Data Protection Bill.pdf
Indonesian Legislatives Passes Personal Data Protection Bill.pdf
 
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdfDIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
DIGITAL-PERSONAL-DATA-PROTECTION-ACT-2023-WHITEPAPER.pdf
 
Data Privacy Act.pdf
Data Privacy Act.pdfData Privacy Act.pdf
Data Privacy Act.pdf
 
E bplscbppbd moa-template-2021-v.2.5_draft
E bplscbppbd moa-template-2021-v.2.5_draftE bplscbppbd moa-template-2021-v.2.5_draft
E bplscbppbd moa-template-2021-v.2.5_draft
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business community
 
The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law The Summary Guide to Compliance with the Kenya Data Protection Law
The Summary Guide to Compliance with the Kenya Data Protection Law
 
GDPR: how IT works
GDPR: how IT worksGDPR: how IT works
GDPR: how IT works
 

Plus de jo bitonio

Part III Policy Formulation for CDA R11
Part III  Policy Formulation for CDA R11Part III  Policy Formulation for CDA R11
Part III Policy Formulation for CDA R11jo bitonio
 
Part - II Policy Formulation for CDA R11
Part - II Policy Formulation for CDA R11Part - II Policy Formulation for CDA R11
Part - II Policy Formulation for CDA R11jo bitonio
 
Part 1 Policy Formulation for CDA R11ptx
Part 1 Policy Formulation for CDA R11ptxPart 1 Policy Formulation for CDA R11ptx
Part 1 Policy Formulation for CDA R11ptxjo bitonio
 
Policy Development 4 La Union Coops.pptx
Policy Development 4 La Union Coops.pptxPolicy Development 4 La Union Coops.pptx
Policy Development 4 La Union Coops.pptxjo bitonio
 
Basic Education and Literacy on Livelihood for the youth, women and Farmers
Basic Education and Literacy on Livelihood for the youth, women and Farmers Basic Education and Literacy on Livelihood for the youth, women and Farmers
Basic Education and Literacy on Livelihood for the youth, women and Farmers jo bitonio
 
6 Adult learning & teaching.pptx
6  Adult learning & teaching.pptx6  Adult learning & teaching.pptx
6 Adult learning & teaching.pptxjo bitonio
 
5 Coop as a tool for development.pptx
5 Coop as a tool for development.pptx5 Coop as a tool for development.pptx
5 Coop as a tool for development.pptxjo bitonio
 
4 Best Practices.pptx
4 Best Practices.pptx4 Best Practices.pptx
4 Best Practices.pptxjo bitonio
 
3 Philosophy, concepts, principles and values.pptx
3 Philosophy, concepts, principles and values.pptx3 Philosophy, concepts, principles and values.pptx
3 Philosophy, concepts, principles and values.pptxjo bitonio
 
2 Overview History, laws and trends.pptx
2 Overview History, laws and trends.pptx2 Overview History, laws and trends.pptx
2 Overview History, laws and trends.pptxjo bitonio
 
1 Expectation Setting & Objectives.pptx
1 Expectation Setting & Objectives.pptx1 Expectation Setting & Objectives.pptx
1 Expectation Setting & Objectives.pptxjo bitonio
 
VUCA Prepraring to face the competition.pptx
VUCA Prepraring to face the competition.pptxVUCA Prepraring to face the competition.pptx
VUCA Prepraring to face the competition.pptxjo bitonio
 
4-Rev-HRM-and-Development.pptx
4-Rev-HRM-and-Development.pptx4-Rev-HRM-and-Development.pptx
4-Rev-HRM-and-Development.pptxjo bitonio
 
3-HRM-and-Development.pptx
3-HRM-and-Development.pptx3-HRM-and-Development.pptx
3-HRM-and-Development.pptxjo bitonio
 
2-HRM-and-Development.pptx
2-HRM-and-Development.pptx2-HRM-and-Development.pptx
2-HRM-and-Development.pptxjo bitonio
 
1-HRM-and-Development.pptx
1-HRM-and-Development.pptx1-HRM-and-Development.pptx
1-HRM-and-Development.pptxjo bitonio
 
4-How-to-conduct-Meeting pptx
4-How-to-conduct-Meeting  pptx4-How-to-conduct-Meeting  pptx
4-How-to-conduct-Meeting pptxjo bitonio
 
2-Leadership-vs-Management Feb 23.pptx
2-Leadership-vs-Management Feb 23.pptx2-Leadership-vs-Management Feb 23.pptx
2-Leadership-vs-Management Feb 23.pptxjo bitonio
 
1 Governance & Management pptx
1  Governance & Management pptx1  Governance & Management pptx
1 Governance & Management pptxjo bitonio
 
6 Performance Indicators in Ope Mgmt.pptx
6 Performance Indicators in Ope Mgmt.pptx6 Performance Indicators in Ope Mgmt.pptx
6 Performance Indicators in Ope Mgmt.pptxjo bitonio
 

Plus de jo bitonio (20)

Part III Policy Formulation for CDA R11
Part III  Policy Formulation for CDA R11Part III  Policy Formulation for CDA R11
Part III Policy Formulation for CDA R11
 
Part - II Policy Formulation for CDA R11
Part - II Policy Formulation for CDA R11Part - II Policy Formulation for CDA R11
Part - II Policy Formulation for CDA R11
 
Part 1 Policy Formulation for CDA R11ptx
Part 1 Policy Formulation for CDA R11ptxPart 1 Policy Formulation for CDA R11ptx
Part 1 Policy Formulation for CDA R11ptx
 
Policy Development 4 La Union Coops.pptx
Policy Development 4 La Union Coops.pptxPolicy Development 4 La Union Coops.pptx
Policy Development 4 La Union Coops.pptx
 
Basic Education and Literacy on Livelihood for the youth, women and Farmers
Basic Education and Literacy on Livelihood for the youth, women and Farmers Basic Education and Literacy on Livelihood for the youth, women and Farmers
Basic Education and Literacy on Livelihood for the youth, women and Farmers
 
6 Adult learning & teaching.pptx
6  Adult learning & teaching.pptx6  Adult learning & teaching.pptx
6 Adult learning & teaching.pptx
 
5 Coop as a tool for development.pptx
5 Coop as a tool for development.pptx5 Coop as a tool for development.pptx
5 Coop as a tool for development.pptx
 
4 Best Practices.pptx
4 Best Practices.pptx4 Best Practices.pptx
4 Best Practices.pptx
 
3 Philosophy, concepts, principles and values.pptx
3 Philosophy, concepts, principles and values.pptx3 Philosophy, concepts, principles and values.pptx
3 Philosophy, concepts, principles and values.pptx
 
2 Overview History, laws and trends.pptx
2 Overview History, laws and trends.pptx2 Overview History, laws and trends.pptx
2 Overview History, laws and trends.pptx
 
1 Expectation Setting & Objectives.pptx
1 Expectation Setting & Objectives.pptx1 Expectation Setting & Objectives.pptx
1 Expectation Setting & Objectives.pptx
 
VUCA Prepraring to face the competition.pptx
VUCA Prepraring to face the competition.pptxVUCA Prepraring to face the competition.pptx
VUCA Prepraring to face the competition.pptx
 
4-Rev-HRM-and-Development.pptx
4-Rev-HRM-and-Development.pptx4-Rev-HRM-and-Development.pptx
4-Rev-HRM-and-Development.pptx
 
3-HRM-and-Development.pptx
3-HRM-and-Development.pptx3-HRM-and-Development.pptx
3-HRM-and-Development.pptx
 
2-HRM-and-Development.pptx
2-HRM-and-Development.pptx2-HRM-and-Development.pptx
2-HRM-and-Development.pptx
 
1-HRM-and-Development.pptx
1-HRM-and-Development.pptx1-HRM-and-Development.pptx
1-HRM-and-Development.pptx
 
4-How-to-conduct-Meeting pptx
4-How-to-conduct-Meeting  pptx4-How-to-conduct-Meeting  pptx
4-How-to-conduct-Meeting pptx
 
2-Leadership-vs-Management Feb 23.pptx
2-Leadership-vs-Management Feb 23.pptx2-Leadership-vs-Management Feb 23.pptx
2-Leadership-vs-Management Feb 23.pptx
 
1 Governance & Management pptx
1  Governance & Management pptx1  Governance & Management pptx
1 Governance & Management pptx
 
6 Performance Indicators in Ope Mgmt.pptx
6 Performance Indicators in Ope Mgmt.pptx6 Performance Indicators in Ope Mgmt.pptx
6 Performance Indicators in Ope Mgmt.pptx
 

Dernier

Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangaloreamitlee9823
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756dollysharma2066
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...amitlee9823
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...rajveerescorts2022
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfAmzadHosen3
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptxnandhinijagan9867
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 

Dernier (20)

Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
Call Girls Kengeri Satellite Town Just Call 👗 7737669865 👗 Top Class Call Gir...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdf
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 

Data Privacy Act of 2012 implication to cooperatives

  • 1.
  • 2. LECTURE COVERAGE Clarify the following matters regarding Republic Act No. 10173, also known as the Data Privacy Act of 2012 (DPA): 1.Whether the cooperatives registered under the Cooperative Development Authority (CDA) are covered by the DPA; 2.If indeed the cooperatives are covered by the law, determine the following: A. Obligations of cooperatives B. Reportorial requirements to be submitted to the NPC C. Compliance period for such requirements D. Penalties for non-compliance; and 3.Where cooperatives may course through or communicate other concerns regarding data privacy.
  • 3. In the DIGITAL ERA, INFORMATION is POWER. - Claude Elwood Shannon (National Inventors Hall of Fame)
  • 4. BACKGROUND In 2012, the Congress of the Philippines passed Republic Act No. 10173, also known as the Data Privacy Act (DPA) of 2012. Five years later, the DPA’s Implementing Rules and Regulations was put in effect on September 9, 2016, thus mandating all companies to comply. It was estimated that 2.5 quintillion — or 2.5 billion billion — bytes of data were created everyday. This includes unprecedented knowledge about what real individuals are doing, watching, thinking, and feeling.
  • 5. BACKGROUND Companies must be held accountable not only for what they do with customer data — but how they protect that data from third parties. The past few years of security breaches, system errors, and ethical scandals within some of the country’s major banks have reminded us that there is much work to be done.
  • 6. What is the DPA? Data Privacy Act (DPA), PROTECTS individuals from unauthorized processing of Personal Information/Sensitive Personal Information. It created the National Privacy Commission (NPC) to monitor the implementation of this law. (Section 7 of DPA).
  • 7. DATA PROTECTION 1.All personal information must be collected for reasons that are specified, legitimate, and reasonable. 2.All personal information must be handled properly, kept accurate and relevant, used only for the stated purposes, and retained only for as long as reasonably needed. 3.All personal information must be discarded in a way that does not make it visible and accessible to unauthorized third parties. 4.Unauthorized processing, negligent handling, or improper disposal of personal information is punishable with up to six (6) years in prison or up to five million pesos (PHP 5,000,000) depending on the nature and degree of the violation.
  • 8. PERSONAL INFORMATION  Refers to any information whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.
  • 9.
  • 10. PERSONAL INFORMATION CONTROLLER Refers to a person or organization who controls the collection, holding, processing or use of personal information, including a person or organization who instructs another person or organization to collect, hold, process, use, transfer or disclose personal information on his or her behalf. This term excludes: (1)A person or organization who performs such functions as instructed by another person or organization; and (2)An individual who collects, holds, processes or use personal information in connection with the individual’s personal, family or household affairs.
  • 11. PERSONAL INFORMATION PROCESSOR Refers to any natural or juridical person qualified to act as such under this Act to whom a personal information controller may outsource the processing of personal data pertaining to a data subject.
  • 12. DATA SUBJECT  Refers to an individual whose personal information is processed.
  • 13. COOPERATIVES REGISTERED UNDER THE COOPERATIVE DEVELOPMENT AUTHORITY (CDA) ARE COVERED BY THE DPA The DPA applies to “any natural and juridical person involved in the personal information processing including those personal information controllers and processors who, although not found or established in the Philippines, use equipment that are located in the Philippines, or those who maintain an office, branch or agency in the Philippines.” [Sections 3(par. g, h, and i) and 4 of the DPA]
  • 14. Upon examination of the nature of information handled by cooperatives, it is clear that cooperatives may be considered as personal information controllers (PICs) who collect, hold, process and use personal information of its members - (NPC Privacy Policy Office Advisory Opinion No. 2017-021) COOPERATIVES AS PERSONAL INFORMATION CONTROLLERS (PICs)
  • 15. Cooperatives process personal data of members, particularly with regard to the application and processing of their individual loans, credit lines, etc. Thus, cooperatives are involved in the processing of personal and sensitive personal information and are thereby obliged to adhere with the provisions of the DPA. - (NPC Privacy Policy Office Advisory Opinion No. 2017-021) COOPERATIVES AS PERSONAL INFORMATION CONTROLLERS (PICs)
  • 16. COOPERATIVES AS PERSONAL INFORMATION PROCESSORS (PIPs) Republic Act No. 6939 created the CDA to formulate plans and programs on cooperative development, including the development and conduct of management and training programs to assist members and ensure the viability and growth of cooperatives. Most importantly, it is in-charge of the registration of all cooperatives, federations and unions. - Section 3, par. 1, b, and 3 Republic Act 6939
  • 17. COOPERATIVES AS PERSONAL INFORMATION PROCESSORS (PIPs) Pursuant to this function, cooperatives are mandated to register as a cooperative and provide documents to the CDA, including financial and membership details (CDA Memorandum Circular 2015-01 on the Revised Guidelines Governing the Registration of Cooperatives). Cooperatives, in this set up, is outsourced by the CDA as PIPs.
  • 18. OBLIGATIONS OF COOPERATIVES IN COMPLIANCE WITH THE PROVISIONS OF THE DPA, ITS IRR AND OTHER NPC ISSUANCES 1.Adherence to the general data privacy principles of transparency, legitimate purpose, and proportionality. PICs and personal information processors (PIPs) are also mandated to uphold the rights of the data subjects.
  • 19. OBLIGATIONS OF COOPERATIVES IN COMPLIANCE WITH THE PROVISIONS OF THE DPA, ITS IRR AND OTHER NPC ISSUANCES 2. To appoint a Data Protection/Privacy Officer (DPO). Pursuant to Section 21(b) of the DPA and Section 50(b) of the IRR, PICs shall designate an individual or individuals who are accountable for the organization’s compliance with this Act.
  • 20. 3. To implement reasonable and appropriate organizational, physical and technical measures intended for the protection of personal information against any accidental or unlawful destruction, alteration and disclosure, as well as against any other unlawful processing. OBLIGATIONS OF COOPERATIVES IN COMPLIANCE WITH THE PROVISIONS OF THE DPA, ITS IRR AND OTHER NPC ISSUANCES
  • 21. 4. Review of all existing data sharing arrangements and/or actual contracts, joint issuances, or any similar documents, and make the necessary revisions thereto, execution of a data sharing agreement where applicable, and the immediate termination of the sharing of personal data in instances where the arrangement is not for the purpose of performing a public function or providing a public service. - NPC Circular No. 2016-02 OBLIGATIONS OF COOPERATIVES IN COMPLIANCE WITH THE PROVISIONS OF THE DPA, ITS IRR AND OTHER NPC ISSUANCES
  • 22. REPORTORIAL REQUIREMENTS TO BE SUBMIT COOPERATIVES TO THE NPC 1.Registration Of Personal Data Processing Systems. Section 47 of the IRR of the DPA provides for the registration of personal data processing systems. This provision states that if a personal information controller or personal information processor employs at least two hundred fifty (250) persons, registration is automatically required.
  • 23. When the personnel employed are fewer than two hundred fifty (250), registration is not required, unless the any of the following circumstances is present: 1.The processing it carries out is likely to pose a risk to the rights and freedoms of the data subjects; 2.The processing is not occasional; or 3.The processing includes sensitive personal information of at least one thousand (1,000) individuals. In case any of the circumstances enumerated above are present, the cooperative is then required to register its data processing system. 1.Registration Of Personal Data Processing Systems. REPORTORIAL REQUIREMENTS TO BE SUBMIT COOPERATIVES TO THE NPC
  • 24. REPORTORIAL REQUIREMENTS TO BE SUBMIT COOPERATIVES TO THE NPC 1.Registration Of Personal Data Processing Systems. The NPC will be implementing the registration process in two phases: 1. Phase I requires the submission of a notarized registration form containing details on the PIC, head of the organization, and the DPO; and 2. Phase II is the registration of the data processing systems to be done online. * As the NPC is still in the process of optimizing its website for the Phase II endeavor, for purposes of the September 2017 deadline, only Phase I will be strictly required. The public is advised to visit the website of the NPC for any updates and announcements on the implementation and deadline for Phase II.
  • 25. REPORTORIAL REQUIREMENTS TO BE SUBMIT COOPERATIVES TO THE NPC 2. Data Breach Notification A PIC is required to notify the NPC and the affected data subjects “within seventy-two (72) hours upon knowledge of, or when there is reasonable belief that a personal data breach has occurred”. - Section 38 (a), IRR of the DPA
  • 26. REPORTORIAL REQUIREMENTS TO BE SUBMIT COOPERATIVES TO THE NPC 2. Data Breach Notification The report may be submitted in a written or electronic format containing the required contents of the notification stated in Sections 20(f) and 39 of the DPA and the IRR, respectively. - Section 41 (a), IRR of the DPA
  • 27. NPC Circular 16-03 comprehensively discusses the framework for personal data breach management and the procedures for personal data breach notification, as well as the requirement for the submission of the annual report of all personal data breaches and security incidents. REPORTORIAL REQUIREMENTS TO BE SUBMIT COOPERATIVES TO THE NPC 3. Annual Report Of All Personal Data Breaches And Security Incidents.
  • 28. A personal information controller “carrying out any wholly or partly automated processing operations or set of such operations intended to serve a single purpose or several related purposes shall notify the Commission when the automated processing becomes the sole basis for making decisions about a data subject, and when the decision would significantly affect the data subject”. As of the moment, the NPC does not require any format for the notification, as long as it contains the contents enumerated in Section 48 of the IRR. 4. Notification of Automated Decision-Making REPORTORIAL REQUIREMENTS TO BE SUBMIT COOPERATIVES TO THE NPC
  • 29. The law and the IRR do not provide for penalties for non-compliance with the appointment of the DPO, registration of data processing systems, notification of automated decision-making, submission of annual reports, among others. However, in case of the occurrence of a personal data breach, the filing of a complaint by a data subject, or an audit of the Commission, compliance with such requirements shall be considered by the NPC in evaluating the situation and its determination of liability under the penal provisions, if any. - Section 25-33, DPA PENALTIES FOR NON-COMPLIANCE
  • 30.
  • 31. THANK YOU! DATA PRIVACY ACT (DPA) OF 2012: (Republic Act No. 10173) Implications to Cooperatives as Personal Information Controller and/or Personal Information Processor Atty. PHILLIP RAYMUND S. RIVERA Legal Officer III Cooperative Development Authority Dagupan Extension Office