Sunteți pe pagina 1din 23

PRODUCED BY

The National Privacy Commission

CONTRIBUTORS
Office of the Privacy Commissioner
Public Information and Assistance Division
Finance and Administrative Office
Data Security and Compliance Office
Legal and Enforcement Office
Privacy Policy Office
Kristine Danica S. Adis
Alec Jean G. Del Castillo
Anella Vianchi G. Arevalo

DESIGN AND LAYOUT


Charlene Mae Muyula
Donna A. Escarcha

PHOTO
Lauro M. Montellano, Jr.
Katrice A. Obrero
Pauleen Joy T. Saavedra

EDITOR
Olivia Khane S. Raza
Joseph U. Vizcarra
CONTENTS

06 PRIVACY
COMMISSIONER’S

24
NOTES
COMPLIANCE AND
MONITORING

08
THE NATIONAL
PRIVACY
COMMISSION

26
Vision, Mission and Functions
The Senior Leadership of the NPC
ENFORCEMENT

10
RULE
MAKING
Privacy Policy Office

28
Data Security and Technology
Standards Division COMPLAINTS AND
INVESTIGATION

16
ADVISORY
Advisory Opinions

30
Position Papers and Comments
INTERNAL
MANAGEMENT

18 PUBLIC
EDUCATION
PRIVACY
COMMISSIONER’S
NOTES
Around two years ago, the National Privacy Commission set out to pursue its
mission. Our goal, then and now, can be distilled into this philosophical vision:
To bring life to the Data Privacy Act—to make it permeate the daily practice
of Filipino individuals and organizations; to establish a regime of vigilance,
accountability, and ultimately, trust; to have data privacy and security become a
driving force of stability, progress, and nation-building.

For many, the NPC’s release of its Five Pillars of Data Privacy Accountability
and Compliance signaled the start of the journey towards compliance and
accountability.

In June 2017, most Filipinos did not know what “Personal Data Privacy” meant.
Only 13% were aware of the Data Privacy Act and only 11% at that time had
heard of the National Privacy Commission. As will be demonstrated in our 2017
Annual Report, these figures have surely increased.

It is safe to attribute the growing number of concerns to the parallel growth of


awareness of data subjects. By pursuing our Filipino data subjects, they are
now better protected, and more so, empowered.

It is worthwhile to look back on how we have embarked to empower Filipinos


to protect personal data through this Report. Our stakeholders have been part
of this journey. For me as Privacy Commissioner, I found it important to set the
direction of the NPC to achieve meaningful results, and more importantly, to set
the values we will hold dear to guide us in this arduous task.

In all humility I must say we have accomplished quite a sum in these areas these
past two years. I have been blessed with a hardworking and dedicated team of
professionals who were all equal to the challenge.

Beyond all of the figures and inventory of what we’ve done so far as
documented in this Report, is a simple synthesis: Two years ago, we set out to
do a job. We realized that we can only do it by tapping into the energies of our
many stakeholders. We planned, we toiled, and here we are now—lengthening
our strides and emerging as one of the most promising data sectors in the
world.

Two years ago, only a handful of local experts were talking about data privacy.
Today, it has become a buzzword in Philippine business circles. In as little as two
years, the Data Protection Officer has emerged as the hottest new profession
in town and many of our citizens, especially youngsters, are quickly catching up
on what data privacy is all about.

This is proof positive that our strong and close collaboration with our
stakeholders is effective. We continue to move in the right direction: Forward,
upward, faster and more efficiently towards a culture of trust and resiliency.

6 2017 MILESTONES PRIVACY COMMISSIONER’S NOTE 7


ABOUT US
The National Privacy Commission or NPC is the country’s privacy watchdog; it is an
independent body mandated to administer and implement the Data Privacy Act of 2012, and
to monitor and ensure compliance of the country with international standards set for data
protection.

The Commission is headed by a Privacy Commissioner who serves as the Chairperson. The
Privacy Commissioner is assisted by two Deputy Privacy Commissioners.

VISION MISSION The NPC is an attached agen- ADVISORY ENFORCEMENT


cy of the Department of Infor-
A world-class regulatory and We shall continuously deliver services to: mation and Communications serve as the advisory body on effectively implement the
enabling agency upholding the right Technology for policy and matters affecting protection DPA, its Implementing Rules
1
to data privacy, ensuring personal program coordination purpos- of personal data and Regulations and issuanc-
data protection while promoting the Be the authority on data privacy and es, but is completely indepen- es, and enforce its Orders,
free flow of information; committed protection, providing knowledge, know-how dent in the performance of PUBLIC EDUCATION Resolutions or Decisions,
to excellence, driven by a workforce and relevant technology; the following functions: including the imposition of ad-
that is highly competent, future- inform and educate the ministrative sanctions, fines,
2
oriented, and ethical, towards a RULE-MAKING public on data privacy, or penalties
competitive, knowledge-based, and Establish a regulatory environment that data protection, and fair
innovative nation. ensures accountability in the processing develop, promulgate, review information rights and COMPLAINTS AND
of personal data and promotes global or amend rules and regula- responsibilities INVESTIGATIONS
standards for data privacy and protection; tions for the effective imple-
and mentation of the Republic Act COMPLIANCE AND adjudicate on complaints and
3 No. 10173 or the Data Privacy MONITORING investigations on matters
Act (DPA) of 2012 affecting personal data
Build a culture of privacy through people monitor and ensure
empowerment that enables and upholds the compliance for the
right to privacy and supports free flow of effective implementation
information. of the DPA

8 2017 MILESTONES THE NATIONAL PRIVACY COMMISSION 9


RULEMAKING
ADVISORIES
NPC ADVISORY
The PPO is tasked with This emphasized the need
for PICs and PIPs to appoint
NO. 2017-01
the development and
recommendation of policies a DPO who will be in charge Designation of
to uphold the data privacy of ensuring the organization’s Data Protection
of individuals in ICT systems compliance with the DPA. Officers (DPO)

THE PRIVACY in both public and private


sectors. These advisories Likewise, the advisory on
NPC ADVISORY
POLICY OFFICE elaborate further the
key concepts to assist
Access to Personal Data
Sheet (PDS) of Government NO. 2017-02
organizations and individuals’ Personnel was issued. The Access to Personal
The Privacy Policy It strives for the standards for the protection general understanding of Advisory harmonized the Data Sheets of
empowerment of the people of personal information in the DPA. Advisories issued principles of transparency Government
Office (PPO) is in the Personnel
by providing knowledge the government and private also provide guidance and accountability ensured by
forefront of defining and know-how on data sector, and to facilitate on significant public the right to information, and
policies, standards, privacy and data protection, cross-border enforcement interest issues with data the right to privacy, arising
and aims to contribute of data privacy protection. privacy implications. from the implementation NPC ADVISORY
rules and regulations NO. 2017-03
to education, innovation, of the Executive Order on
pertaining to data and social protection in Likewise, it is PPO’s task This 2017, the PPO the Freedom of Information Guidelines on
privacy and protection a globally competitive to review agreements and developed an advisory on on one hand, and the Privacy Impact
knowledge economy and policies which may have the Designation of Data DPA on the other. Assessments
of personal data.
data driven society. privacy implications, as well Protection Officers (DPO).
as provide advisory and
The PPO is responsible legal opinions on matters COORDINATION
for coordinating with related to data privacy
government regulatory concerns. Under the PPO
agencies and data privacy are two divisions: the Policy The NPC, through the PPO, that may have data privacy organized by Asia Pacific
regulators in other countries Development Division and became part of several task issues and implications Privacy Authorities (APPA),
to develop privacy policy the Policy Review Division. force and technical working and how they may update International Association of
groups, such as the Inter- current practices and Privacy Professionals (IAPP),
Agency Task Force formed by procedures to be in tune International Conference of
the Civil Service Commission with the Data Privacy Act. Data Protection and Privacy
(CSC) to review the Statement Commissioners (ICDPPC),
of Assets, Liabilities and Net Personnel from PPO Council of Europe (COE),
Worth (SALN) form to be also acted as resource and Asia-Pacific Economic
in sync with the provisions speakers on data privacy Cooperation (APEC).
of the DPA, as well as the on orientations, trainings,
Technical Working Group for and similar activities. This This provided an opportunity
the Philippine Identification consisted of the Data for PPO to be in-the-
System (PhilSys) spearheaded Protection Officers’ Summits, know on relevant updates
by the Philippine Statistics various privacy impact and international best
Office (PSA) for the crafting assessment workshops, practices, share insights
of the National ID System. DPO briefings, stakeholder- and experiences with other
initiated briefings, data privacy regulators
The PPO participated roadshows, and caravans. and privacy professionals,
in numerous meetings, and most importantly,
orientations, and Pursuant to its mandate to effectively utilize the
consultations with different to coordinate with data knowledge gained in these
stakeholders from the privacy authorities and other conferences for the Office’s
government and the private accountability agents, PPO core and strategic functions,
sector primarily to explain personnel likewise attended in support of NPC’s vision
and clarify the provisions international conferences and of being a world-class
of the DPA, its IRR, and the fora relating to data privacy regulatory and enforcement
issuances of the NPC. and personal data protection. agency, upholding the
Stakeholders’ main concern right to privacy and data
were regarding their This included participation in protection while ensuring
programs and activities conferences and meetings the free flow of information.

10 2017 MILESTONES RULE MAKING 11


DATA
SECURITY Philippine Standards (BPS) Governing the Accreditation
TC 60 (Technical Committee of Certification Authorities
AND on Information Technology) for Electronic Signatures”.
monthly meetings. TC 60
TECHNOLOGY is the mirror committee of A month after, the team
SC 27 in the Philippines. attended the meeting
STANDARDS In addition, DSTSD joined
of National Economic
and Development
DIVISION three (3) Technical Working
Group (TWG) Meetings
Authority (NEDA)
Interagency Committee
regarding National Security on Trade in Services.
The Data Security and Issues on Government-Issued
Documents at the National DSTSD also represented
Technology Standards
Security Council (NSC). the Commission on the
Division (DSTSD) serves following Data Security
as the backbone of COORDINATION partnership with the data NATIONAL Furthermore, DSTSD and Technology related
protection authorities in other ENGAGEMENT participated in the quarterly meetings/public hearings and
the National Privacy
In line with the NPC’s nations and jurisdictions. meetings of Task Force on submitted DPA related inputs;
Commission (NPC). function to monitor and Big Data at the Philippine Orientation and Workshop
To support the NPC in
Primarily, it coordinates ensure the compliance In line with this, DSTSD performing its function of Statistics Authority (PSA). on Data Privacy Act of 2012
of the organizations with participated in the SC 27 conducted in Navotas Health
with other government coordinating with other
local and international Plenary and Working Group government agencies Last May, DSTSD attended Care Center and GSIS Annual
agencies, the private standards set for data Meetings in Hamilton, Joint Cybersecurity Working InfoSec Awareness Month.
and the private sector
sector and international protection, representatives New Zealand last April on efforts to formulate Group Meetings. They have
from the DSTSD were and Berlin, Germany last also provided inputs to the Lastly, DSTSD is fortunate
bodies to develop the and implement plans and
sent to different meetings October-November. policies to strengthen the Ease of Doing Business to have been invited by
most appropriate privacy and engagements. They (EODB) Exploratory support UNTV for two (2) interviews
protection of personal
and data protection are tasked to present Moreover, last October information in the country, exercise together with discussing the current
the NPC’s position DSTSD took part on the other government agencies ransomware attacks. The
standards recognized DSTSD keenly took part in
on various topics and Seminar in Capacity-Building various meetings, events and namely, Department of first interview was held in
by the Information issues and coordinate for Compliance with Cross- Trade and Industry (DTI), their studio in relation with
seminars. DSTSD contributed
and Communications the agency’s projects. border Privacy Rules (CBPR) to the Development of National Competitiveness the morning TV program
System spearheaded by Asia- Council (NCC), Department “Good Morning Kuya”,
Technology e-Government Masterplan
CROSS BORDER Pacific Economic Cooperation 2017-2033, under the of Information and and the other one was
(ICT) industry for (APEC) held at Taipei, Taiwan. Communications Technology conducted in Meeting Room
ENGAGEMENT Focus Group Discussion
organizational, The purpose of this seminar of Enterprise Network (DICT) and different Social 1 at the GSIS Building.
is to advance work on Agencies. At the same
physical and technical Regional and global Administration and Identity
discussion and promotion of Management System. time, the division attended
security measures. meetings are avenues for
participation CBPR System. a public hearing on DTI’s
the NPC to be updated
Moreover, it analyzes on the current trends and DSTSD attended the Department Administrative
Order (DAO) no. 10-09 3
technological trends developments in data Department of Trade and
Industry (DTI) – Bureau of entitled “Prescribing Rules
and developments privacy and expand its
and conducts risk
assessment of
existing and emerging
technologies.

12 2017 MILESTONES RULE MAKING 13


TECHNOLOGICAL TRENDS
AND DEVELOPMENT
Philippines. These will be environments and processors (PIPs) in one of the common violations newly approved circulars
With regard to the rapid used in the development using presentation complying with the Data of the right to privacy and advisories. It was
rise of technology, DSTSD of international privacy attack detection Privacy Act of 2012. which the NPC is mandated successfully released last
identifies and analyzes and data protection mechanisms. to protect. DSTSD has December and is being
technological trends and standards. DSTSD Specifically, it The Data Privacy released a set of guidelines used by organizations
developments in electronic submitted Philippine suggested to include Accountability and entitled “Redacting Personal in the Philippines.
platforms and digital media. positions on the Privacy in Day-to-Day Compliance Checklist, Data in Electronically filed
Numerous seminars and following topics: Information Life Cycle commonly known as the Documents”. Its main DPO SUMMIT
trainings were participated Operations, Managing 32-point checklist, is a objective is to ensure that INVOLVEMENT
by the representatives Identity proofing & Personal Data step-by-step guide the personal data are properly
of the division to further Identity Assurance Security Risks, and NPC recommends for redacted by completely With the NPC having a
improve their knowledge Framework Compliance with Data agencies to follow. removing the information total of twelve (12) DPO
in cybersecurity. Breach Management from the document, Summits conducted last
The main concept of Requirements. The Data Privacy whether in electronic year, DSTSD, together
DSTSD took part in the Joint identity proofing is to Aside from the Accountability and or physical format, as with the other divisions,
Cyber Security Working verify the identifying topics given Compliance Guidelines opposed to obscuring the helped plan, organize, and
Group Cyber Investigation attributes of an above, DSTSD also contain specific documents information or hiding it. facilitate each event.
Training, What the Hack individual. The best provided comments to be prepared and
Cyber Security Training, way to proceed it is to on the Privacy submitted in relation to the DEVELOPMENT
Information Security have all the information Framework, Privacy Compliance Checklist. NPC WEBSITE
OF STANDARDS CONTENT MAKING
Officers Group (ISOG) readily available in Smart Cities,
KISS Summit 2017, Web for verification or Identity Assurance RISK ASSESSMENT
One of the functions NPC successfully launched
Application IT Security comparison. DSTSD Framework, Privacy of DSTSD is to develop
& Cyber Defense Forum, proposed the addition Engineering and The NPC as a government privacy.gov.ph last year.
standards for physical and DSTSD contributed by
and Office 365 training. of guidelines to collect Privacy Management. agency itself, is not excluded technical security measures
only the necessary data from complying with the providing substantive
for data protection using content about emerging
Apart from participating in in order to prove an IMPLEMENTING DPA. After appointing its most appropriate standard
the different events, DSTSD individual’s identity. own Data Protection Officer technologies, present threats
PRIVACY AND recognized by the information and vulnerabilities, and
managed to create Data (DPO), DSTSD is tasked with and communications
Processing System Online Privacy Reference & DATA PROTECTION recommendation of standards
two things: first, enhance the technology industry,
Registry and a justification Phase II Consideration MEASURES first version of the Privacy followed worldwide. 6
including security standards REFERENCES
for CyberCon Asia 2017. on Smart Phones Impact Assessment (PIA) for the processing of sensitive
The National Privacy Template; and second is Information Security
Commission has devised information in government. Resources (n.d) Retrieved
DSTSD also partnered with DSTSD suggested to conduct Risk Assessment
DICT Undersecretaries, consider the Rights various means to address inside the Commission. February 23, 2018,
possible threats in an The following templates from https://www.sans.
Business Profiles, Laggui of a Data Subject were studied, refined and
Associates and Israeli at each stage of agency. DSTSD is entrusted The team conducted the PIA org/information-security/
to identify and assess these submitted last year; Privacy https://www.iso.org/
Ambassador Secretary the Data Life Cycle. of the Biometrics System Notice, Self-Assessment
Rodolfo A. Salalima on Likewise, it specified measures and revise the of the Commission using its committee/45306.html
early versions of the Data Template, and General NPC Privacy Toolkit
Cyber Security and Data and described the newest version. This led to Data Protection Regulation
Privacy Capacity Building. essential components Privacy Accountability and an improved content of the Sec. 32, DPA
Compliance Framework, (GDPR) and Data Portability. Redaction Draft Manual
of the framework. template which agencies
ISO COMMENTS Guidelines, and Checklist. can use in conducting
Furthermore, DSTSD NPC PRIVACY TOOLKIT
their risk assessments.
As stated earlier, NPC, a contributed to WG The Data Privacy
member of the ISO Sub 5 Study Period Accountability and The NPC Privacy Toolkit
Compliance Framework ISSUANCE OF serves as the guide of
Committee 27 Working on a Framework
Group 5 has submitted of enhanced is a visual representation GUIDELINES every DPO. DSTSD helped
contributions/comments authentication meant to help personal to improve the current
on behalf of the in tele biometric information controllers (PICs) Unauthorized disclosure is version by incorporating the

14 2017 MILESTONES RULE MAKING 15


ADVISORY
ADVISORY OPINIONS

This 2017, the PPO produced Production Unit. consent of employees for use publicly accessible platform recommendations on specific for the health sector which
sixty-nine (69) advisory Additionally, the PPO of their personal information this does not mean he or she issues, applying a personal was spearheaded by the
opinions on the interpretation created Advisory Opinions for marketing purposes and has given blanket consent for data protection perspective Department of Health. PPO
of the provisions of the DPA, that addressed pressing government requirements, its use for whatever purposes. on these proposals. was involved in the public
IRR, and other issuances of issues directly affecting employer’s access to PPO personnel, as consultation regarding
the NPC. These were issued the public at large. employees’ healthcare POSITION PAPERS representatives of the the said code as well as
in response to inquiries service usage, and validity Commission, acted as prepared in-depth comments
AND COMMENTS
from different stakeholders In 2017, the Office crafted an of consent in an employment resource persons in Senate and recommendations.
from both the government advisory opinion concerning contract, to name a few. and House hearings
The Privacy Policy Office
and the private sector. online merchants’ right to Of note also is the issue on on these bills. Their
likewise prepared policy
retain credit card details of whether a mobile number attendance ensured that
papers and comments on
Some of these advisory their customers. In doing is considered personal data privacy provisions
behalf of the Commission
opinions gave light to the so, the following should be information or not. are incorporated in the
on proposed legislations
data privacy implications taken into consideration: To determine this, proposals, when necessary.
both from the House
of certain government a distinction was

69
of Representatives
initiatives. These included 1. Retention of made whether Moreover, this gave an
and the Senate.
the Securities Exchange personal data it is a postpaid opportunity for the PPO to
Commission’s Reverse Search should be only to number or a share and impart data privacy
The PPO submitted
Module, the Department of the extent required prepaid one. The awareness and understanding
its comments and
Foreign Affairs’ proposed for the fulfillment former is personal
proposed revisions to the country’s legislators ADVISORY
software application for of the purposes information since
on bills such as the in the hopes that they may OPINIONS
monitoring Filipino nationals for which the data telecommunication consider data privacy and
Philippine HIV and Aids
working and residing abroad, was obtained, companies assign personal data protection as
Policy Act, proposed
Philippine National Police’s unless data a specific number an important consideration
amendments on the
request of personal data from subjects consent to each individual in formulating legislation.
Bank Secrecy Law, SEC’S REVERSE
the Department of Social to allow longer subscriber while
and proposals for SIM SEARCH MODULE
Welfare and Development retention periods; the latter only Review of Documents
Card Registration,
(DSWD), and data sharing becomes personal from Stakeholders.
No-Call and Text
concerns of the Anti- 2. Data subjects information
Registry, Social Media
Money Laundering Council should be once activated Part of the PPO’s DFA’S PROPOSED
(AMLC), among others. adequately and associated Registration, responsibilities is the review MONITORING
informed of the or linked to an and National ID of policies, guidelines, SOFFTWARE
Several government nature and extent individual System, among standards, and codes APPLICATION
agencies also sought formal of the processing subscriber. others. The PPO relative to data privacy
guidance on the application of their personal was likewise from stakeholders from
of the Data Privacy Act to data; and Another involved in the different sectors. In 2017,
is regarding information crafting of the these included review of PNP’S REQUEST OF
its operations, such as the
3. Security measures available in the public Implementing data sharing agreements, PERSONAL DATA
Philippine Health Insurance
for the protection domain. In several advisory Rules and consent forms, and personal FROM THE DSWD
Corporation (Philhealth),
Bangko Sentral ng Pilipinas of personal opinions, it was stated Regulations (IRR) of data protection policies
(BSP), Philippine Deposit data should be that the DPA still applies Republic Act No. 10929 or from organizations in the
Insurance Corporation implemented. since there is no express the Free Internet Access public and private sector.
(PDIC), Department of mention that personal data in Public Places Act. Pursuant to its mandate to DATA SHARING
Finance (DOF), Commission The issue of how the Data which is available publicly review standards and codes CONCERNS
on Elections (COMELEC), Privacy Act affects employer- is outside of its scope. These submissions put relating to organizational OF AMLC
Social Security System employee relationship emphasis on the inclusion of security measures for
(SSS), Tourism Information was also tackled in several Moreover, even if the data data privacy and protection protection of personal data,
Enterprise Zone Authority Advisory Opinions. Some of subject has provided his provisions in the proposed the PPO took part in the
(TIEZA), and APO these opinions are regarding or her personal data in a bills, as well as provided review of the privacy code

16 2017 MILESTONES RULE MAKING


ADVISORY 17
PUBLIC EDUCATION
For a fairly new agency like the NPC, public education and awareness
are central in establishing the relevance of data privacy to stakeholders,
both data subjects and personal information controllers & processors. As
part of the communication strategy, the NPC tapped digital and traditional
communication channels in 2017 to reach and engage stakeholders.

OW MORE
SOCIAL MEDIA N WEBSITE

K
Social media proved to be a From writers to artists, tasks In light of making the data After its launch in April 2017,
cost-efficient communication were meticulously laid out privacy law and data privacy the NPC website continually
channel for the NPC. In 2017, and executed to meet this protection much easier for met its objective of being
the Commission continued goal. Content buckets such mass consumption, efforts a knowledge hub for Data
to be present in three as related news, engagement were directed towards Protection Officers (DPOs)
social media platforms: posts, privacy push, and in putting together outputs that and Personal Information
Facebook (@privacy.gov. review made sure that the are simple, concise and fun. Controllers and Processors
ph), Twitter (@PrivacyPH), materials produced were In one year, NPC’s Facebook (PICs/PIPs), when it comes
and YouTube (National always new and engaging. page grew in Likes by to DPA compliance. It served
Privacy Commission). The 1,000.9 %, while the Twitter as repository of information

M PL Y
Commission easily reached page grew in Followers by on various NPC issuances—
the public through these 529.4%. Since the inception Memorandum Circulars,
accounts with daily content of the online information Advisories, Advisory Opinions

CO
that revolve around the and awareness campaign, and Legal Opinions, data
concepts of privacy in the the Commission has gained subject rights, knowledge
Philippines—from updates an audience of over 46,404 materials, presentations and
on the Commission and users in Facebook, 856 in latest updates about the
its activities, to everyday
tips that can protect one’s
personal data privacy.
1,000.9 %
FACEBOOK
Twitter, and 169 in Youtube
by December 2017. A total
of 458 Facebook posts
Commission. The design
enabled PICs, PIPs and data
subjects to easily explore the
were made in 2017, with an website depending on their
The team had a goal in mind: average reach of 5,142 users objective (‘I want to know
AIN
PL
529.4 %
to heighten engagement with per post. Notably, there were more’, ‘I want to comply’,
the Filipino public online, social media materials that M ‘I want to complain’).

CO
thus elevating awareness TWITTER reached as many as 347,038
and discourse on data users in just one post. During the height of the
privacy and security. Taking registration period of DPOs
on such an endeavor is no and their respective PIC/PIP
easy feat; however, the Data Processing Systems,
team took advantage of the website primarily catered
the high online presence to compliance concerns.
of Filipinos, and rode along
with trending topics and
issues to incorporate good
data privacy protection
practices in NPC materials.

18 2017 MILESTONES PUBLIC EDUCATION 19


EVENTS KNOWLEDGE
To quickly raise awareness On the other hand, the MATERIALS
and facilitate compliance Roadshow responded to the
among PICs and PIPs demand for data privacy To more effectively reach
through their DPOs, the NPC compliance orientation its target audience, the NPC
held 11 DPO Assemblies, outside Metro Manila, with produced the following
14 DPO Briefing sessions, local operations. So far, the knowledge materials and
and 14 PrivaMoves sessions roadshow has reached ten publications in 2017:
(Data Privacy Compliance cities (Cebu, Cagayan de
1. Print Media
Workshop/Roadshow). A Oro, Butuan, Zamboanga,
Advertisement
total of 4,013 stakeholders Iloilo, Dumaguete,
of Memorandum
nationwide were reached Dagupan, Legazpi,
Circulars No. 17-01
through these events. Batangas and Sorsogon)
in 14 separate sessions. 2. Manila Bulletin’s
Each event type catered to a Privacy
different set of participants. Except for the DPO Commissioner’s
Both DPO Assemblies and Briefings, said activities weekly columns
Briefings were aimed at were conducted through
engaging the DPOs of central the substantial support of 3. DPO Forum (online
offices of organizations, NPC partners: which are newsletter)
located in Metro Manila. But industry partners for the DPO 4. Data Subject Intro
DPO Assemblies differed in Assemblies and local ICT Poster (Gaano
approach as each session councils for the Roadshow. kahalaga ang
was devoted to a specific As such, NPC incurred data mo?)
sector or industry, while lesser cost in implementing
each DPO briefing had a its awareness initiatives. 5. Compliance Poster
mix of participants from (5 Pillars of Data
different sectors. In 2017, the Apart from these NPC- Privacy Accountability
DPO Assemblies covered organized events, the & Compliance)
the government, banking, Commission also responded
telecommunications, higher to 507 speaking invites by 6. Wag magpabiktima
education, BPO, media, various organizations all video
health, retail, life insurance, throughout the year. NPC 7. Ano nga ba ang
pharmaceutical sectors. resource speakers talked data privacy video
about data privacy topics
ranging from the DPA 8. Handle personal info
overview, jumpstarting DP with care video
compliance, to the conduct of
Privacy Impact Assessment. 9. Social Media Materials

566 11 10
invites DPO Data Privacy
attended by Assemblies Roadshows
the Commission

20 2017 MILESTONES PUBLIC EDUCATION 21


PUBLIC
ASSISTANCE
As part of the NPC’s commitment to enhance the delivery of frontline
services to the public, a process review of frontline services was done

FAST NUMBERS
to reduce processing time. The turnaround time of 3-45 working days
in 2016 was cut to 1-3 working days for general inquiries and 3-15
working days for inquiries relating to compliance and policy in 2017.

Aside from the continuous assessment of frontline service delivery

2626
and on-going revision of the Citizen’s Charter, the Public Assistance Total number of
unit also started preparing the development of a public assistance inquiries received via
manual- an internal guideline for NPC frontline staff. e-mail, Facebook,
and AskPriva in 2017

218
In the same year, the establishment of AskPriva, an online assistance
and inquiry system, contributed in providing citizen-centric services. It Average inquiries
served as an additional channel with which the public can lodge their received per month
inquiry, suggestion or any other feedback. With this addition coupled with
the wider advocacy initiative, the average number of inquiries received

100%
per month rose from 5 in 2016 to 218 in 2017. The rate of inquiries acted Walk-in inquiries
upon by the NPC improved from 48.86% in 2016 to 73% in 2017. acted upon by
the NPC

100%
Phone-in inquiries
acted upon by
the NPC

73%
Inquiries received via
e-mail, Facebook,
and AskPriva acted
upon by the NPC

22 2017 MILESTONES PUBLIC EDUCATION 23


COMPLIANCE
Corollary to this mandate, the following are the highlights of the CMD accomplishment for 2017:

& MONITORING 3
Members from the different

7
The CMD conducted seven (7)
sectors were invited during
compliance check visit to the
the Focus Group Discussion
following PICs: 1.) Bank of the
to get their respective view
Philippine Island 2.) West Visayas
and opinion with respect to
State University Medical Center
the draft Data Protection
COMPLIANCE 3.) Google Philippines, Inc. 4.) Focus group Officer Designation,
Department of Education 5.)
The National Privacy and recommend the employees entering CHECK Healthway Medical, Inc. 6.) Suy- discussions Data Processing System
Circular and Compliance
Commission (NPC) is the necessary action into contracts with
VISITS Sing Corporation 7.) Philippine DPO,DPS, ccv Check Visit Guidelines.
country’s independent body in order to meet the government that International Life Insurance.
mandated to administer and minimum standards involves accessing
implement the Data Privacy for protection of or requiring sensitive

47
Act of 2012 (R.A. 10173), personal information personal information Through coordination
with other divisions, CMD

11
and to monitor and ensure pursuant to the DPA A total of 47 Partial Check
Compliance Letter were sent personnel participated in
compliance of the country 6. Adopt a system for the following DPO Summit
to the identified PICs by the
with international standards 3. Provide assistance registration of data Commission. Said letter were per sectors: 1.) Government
Agencies 2.) Bank 3.)
set for data protection. on matters relating processing systems partial sent primarily to require the latter
Telecommunications 4.)
to data protection in the country
check
to send documents or policies
as embedded in the 32-point
dpo summits’ Education 5.) BPO 6.) Internet
As an integral division at the request of
of the Commission, the a national or local 7. Assist in the compliance compliance to check their level participation Society and Social Media
7.) Private Hospital 8.) Retail
of compliance with the DPA.
Compliance and Monitoring agency, a private compilation of letters (sent) Industry 9.) Insurance Non-
Life 10.) Pharmaceutical
Division shall have the entity or any person agency system of 11.) Local Government.
following core functions: records and notices,
4. Assist Philippine including index and

1
1. Ensure compliance of companies doing other finding aids,

8
Out of 47 PICs who received the
personal information business abroad for publication; and Partial Check Compliance Letter, Data Processing System was
controllers with the to respond to data eight (8) of which complied developed that primarily
and these are the following: 1.) handle records of the
provisions of the DPA protection laws 8. Manage requests Data Protection Officer for
Holcim Philippines, Inc. 2.) JR &
and regulations for off-site access online dps
2. Monitor the in government data partial R Distributors 3.) Magnolia, Inc.
4.) Maynilad Water Services, Inc. dpo registrtation
registration purposes.

compliance of other 5. Manage the processing systems. check 5.) Mitsubishi Motors Philippines
government agencies registration of the compliance Corporation 6.) Siemens
Corporation 7.) Supervalue, Inc.
or instrumentalities personal information (received) 8.) Victorias Milling Co., Inc. Others:
on their security and processing system of
technical measures contractors and its ●● Setting Up Local Area
Network (for encoders)

100
+As part of the public education ●● 300 Plus - Inquiries (phone
calls, emails and walk-ins)
program of the Commission,
CMD personnel were invited ●● 300 Plus Follow ups for
and served as guest speaker DPO Registration (NGAs)
speakerships- for the awareness, summits
awareness and DPO briefing apart ●● Development CMD Encoding
from the compliance and
summits & monitoring functions.
System (Software)
dpo briefings ●● Participation in the Development
of Process Flow for Phase I and
Phase II Registration System

4,656
A total of 4,656 PICs ●● Membership in the BAC
submitted their respective TWG and ICT Task Force
DPO Registration form. This is
a manifestation that PICs are ●● Two Key positions in the Employee
Phase i dpo taking the initial phase towards Associations (Atty. Vida Zora Bocar
registration compliance with the DPA. and Mr. Cleo Martinez as President
and Vice-President, respectively of
the NPC Employees Organization.)

24 2017 MILESTONES COMPLIANCE & MONITORING 25


ENFORCEMENT LEGAL DIVISION
As a national government entitled “How to Get Corrupt Practices Act
agency catering to various Away with Lawsuits: A and Related Laws.
The Legal and Enforcement To reinforce the rights It also attended World Bank stakeholders, the National Law Lecture Series” was Apart from this program,
Office (LEO), comprised of the data subjects, the roundtable discussions Privacy Commission created and became the LD staff members also had
of three (3) divisions Enforcement Division also on National ID System, (NPC), its officers and flagship program of the the privilege to represent
namely: Complaints and served as resource persons Technical Working employees are all heavily Legal Division for 2017. the Commission in various
Investigations Division, Legal and legislative liaisons Group on Toll Collection tasked to deliver service events like Senate hearings,
Division and Enforcement during Congressional/ Interoperability, Freedom at the level of quality Through this project, six (6) NPC LGU Roadshow, Data
Division, is at the core Senate hearings on the of Information Exceptions, expected and deserved by legal skills training for NPC Protection Officers (DPO)
of the National Privacy following proposed bills: and the NPC-BSP TWG. the public. On the way to employees were conducted Briefings, and Data Privacy
Commission (NPC). This Likewise, the Division accomplish their duties, it covering significant topics Orientation Seminars.
Office handles complaints prepared drafts of is, however, ubiquitous to such as: (1) Procedural
pertaining to alleged Memorandum of encounter obstacles that and Practical Guide in Also, the Legal Division
violations of Republic Act Agreement with may challenge them and Conducting Public Bidding, continuously provided
No. 10173, otherwise known different institutions even the institution itself. (2) Procurement Training for legal assistance to the
as the Data Privacy Act including the End-Users, (3) Procurement Commission through
of 2012 (DPA), including International Rice One of the challenges that Planning and Compliance, the provision of legal
management of breach Research Institute. may be easily anticipated Procedural and Practical references, conduct of legal
notification. Of importance These proposed is the filing of lawsuits Guide in Conducting researches, review and
is its function related to agreements cater to against the officials and Alternative Methods of drafting of contracts, and
enforcement of privacy the implementation employees of NPC. Hence, Procurement and Other issuance of legal opinion
rights, which is handled by of rules for data the Legal Division (LD), as Special Topics, (4) Principles that paved the way for
the Enforcement Division. protection and the the general counsel of the of Auditing and Accounting, the commencement and
In 2017, Enforcement strengthening of NPC, took steps to identify and Preparation of subsequent completion
cooperation among possible areas of risk and Financial Reports, (5) Code of several projects and
Division continued to various stakeholders. to implement programs of Conduct and Ethical activities of the NPC.
perform its mandate. It that will help manage the Standards for Public
assisted the Office of the To assist the OPC in same. Being a foreseeable Officials and Employees,
Privacy Commissioner the internal matters situation, it is the conviction and (6) Anti-graft and
(OPC) in the formulation of the Commission, of the LD that the foremost
of policies and procedure the Division prepared the intervention in this case is
to ensure enforcement proposed NPC Internal Rules to equip all the concerned
of Resolutions and 1.BPI Data Breach; and the draft guidelines on employees with the
coordination with other Complete Staff Work. basic legal knowledge
government agencies. It 2.SIM Card Registration; of ordinary processes
coordinated with other With respect to and issues which are the
law enforcement agencies 3.No Call/No Text Registry; Administrative matters, usual subjects of charges
such as the Joint Cyber the Division assisted in the against government
Security Working Group, 4.Amendment of Republic procurement of supplies entities and their officials
Department of Information Act No. 10175; and services necessary and employees.
and Communications for general support of the
Technology-Cybercrime 5.UMID+; Commission, and assisted Thus, a law lecture series
Investigation and the Bids and Awards
Coordinating Center (DICT- 6.Fake News; Committee-Technical
CICC), the Bangko Sentral Working Group on Post-
ng PIlipinas, the Anti-Money 7.National Identification (ID) Qualification Evaluations. Procedural and Practical Guide Principles of Auditing and

6
Laundering Council (AMLC), System; in Conducting Public Bidding, Accounting, and Preparation
the United States Federal of Financial Reports
As part of its effort to
Bureau of Investigation, the 8.Privacy of strengthen the enforcement Procurement Training
Philippine National Police- Communications Act of for End-Users Code of Conduct and
mandate of the Commission,
Ethical Standards for Public
Anti-Cybercrime Group 2018; and the Division envisions 2018 LEGAL Officials and Employees
and the National Bureau of as a year where strong Procurement Planning and
Investigation. It also worked 9.Mobile Number Portability measures to protect data
SKILLS Compliance, Procedural and
Practical Guide in Conducting
with the DICT-CICC for the Act. rights will be implemented. TRAINING Alternative Methods of Procure-
Anti-graft and Corrupt
Practices Act and Related Laws.
take down of adult-section
ment and Other Special Topics
of the Manila Backpage.

26 2017 MILESTONES ENFORCEMENT 27


COMPLAINTS As of December 2017, the nature of cases received are as follows:

& INVESTIGATION CLASSIFICATION


No. of
Complaints
%

Unauthorized Processing 80 36.20%


Improper Disposal 3 1.36%
Unauthorized Access/Intentional Breach 14 6.33%
Unauthorized Disclosure 2 0.90%
Rights of a Data Subject 9 4.07%
Security of Personal Information 74 33.48%
General Inquiry 17 7.69%
Cybercrime 14 6.33%
Theft 3 1.36%
Consumer Protection 3 1.36%
Credit Card 1 0.45%
Drone 1 0.45%
Total 221 100.00%

The bulk of the complaints compromise. Few cases were


for 2017 pertained to alleged elevated to the Commission
unauthorized processing En Banc for appropriate
of personal information action/resolution.
and security of personal
information. It is followed by Lastly, the CID employed
general inquiries concerning measures to increase
the rights of data subjects. awareness on data privacy
and protection through the
The Complaints and Investigation Division (CID) continued to carry out its Out of 221 complaints conduct of seminars, trainings
function as the champion in hearing complaints and in instituting investigations
concerning alleged violations of the DPA, including handling reports on security
breach.
received, 153 complaints were
dismissed either for failure
of the respective parties
to prosecute or for being
beyond the NPC’s jurisdiction.
and workshops for various
controllers or processors as
part of reinforcing the NPC’s
mission to sustain a culture of
221
COMPLAINTS
privacy among Filipinos.
Part of its function is the preparation of fact-finding reports based on the For those cases dismissed RECEIVED
complaint and evidence gathered during its investigation with the end view of based on lack of jurisdiction,
referrals to appropriate
recommending appropriate actions to the Commission En Banc. regulatory agencies
were made. Some of the
parties, however, agreed to

28 2017 MILESTONES COMPLAINTS AND INVESTIGATION 29


INTERNAL
The FPMD has also prepared the Commission’s proposed FY 2018 Budget, in time for
the budget hearings with the Department of Budget and Management, the Senate
Committee on Finance, and the House of Representatives Committee on Appropriations.

MANAGEMENT The actual obligations per NPC Programs/Activities/Projects (PAPs) for


FY 2017 and utilization budget rate are summarized below:

SUMMARY OF ACTUAL OBLIGATIONS PER PAP


FINANCE AND
PAP Actual Obligation
ADMNISTRATIVE
Number of Circulars and other issuances on
OFFICE rules and regulations (ex. IRR, Data Security 67,006.00
Standards/Privacy Guidelines, Procedures)

The Financial, Planning of annual and long-range division also worked Number of publications (ex. Compilation of agency system
and Management Division Programs/Activities/Projects closely with the Human 352,598.40
or records and notices, laws, case reports)
(FPMD) provides planning (PAPs). This, to ensure Resource Development
support and financial that the commitments and Division in conducting
direction to help steer the performance are aligned with a series of workshops Number of Public Information/Education Projects
5,596,719.16
Commission towards its the Commission’s goals. The related to the crafting of implemented
fiscal targets for the year. division also spearheaded individual, division and office
the NPC Strategic Planning performance commitments Number of private sector and government agencies
To establish efficient and Workshop; Midyear review, to pave the way 1,191,996.25
representatives meeting/coordination
optimum use of resources, Performance Assessment; the agency’s establishment
the FPMD has consistently and 2018 Planning Workshop and implementation of
Number of Registration system established (ex. Government
played its critical role in the in June 2017 and November its Strategic Performance 2,072,248.97
contracts)
formulation and monitoring 2017, respectively. The Management System (SPMS).

Percentage of complaints and investigations resolved 35,364.00

Number of Registration system established (ex. Government


2,072,248.97
contracts)

Number of International agreements/membership


entered for cooperation or coordination (ex. Cross-border 2,930,792.41
enforcement agreement)

Total 14,318,974.16

Particulars Allotment Expenditures Utilization rate

Personnel Services 57,069 51,075 89%

MOOE 99,293 78,407 79%

Capital Outlay 51,446 47,341 92%

Total 207,808 176,823 85%

30 2017 MILESTONES INTERNAL MANAGEMENT 31


ADMINISTRATIVE
SERVICES DIVISION The division has also lent its technical expertise via its membership in various NPC-created
committees such as, the Bids and Awards Committee, the Internal Affairs Committee, Task
Force Office Rental, the Performance Management Team, and the Fees Committee.
The Administrative Services Division (ASD) acts as one of the housekeeping units of the
Commission aimed at instituting cost-effective methods in the areas of records management,
general services, cashiering, procurement and property/supplies management.

387
units IT and Office
With a view in establishing effective and efficient systems, processes and procedures, the ASD Equipment
initiated the use of the DOST-Electronics Records Management System, which allowed for
the easy tracking of documents, thus facilitating timely decision-making. Through the division,

245
the NPC has also automated the procurement of airline tickets, both for domestic and foreign pieces of Furniture
travels.
and Fixtures
The ASD issued several guidelines to promote the efficient systems of procurement,
maintenance or repair and use of motor vehicles and management of NPC-owned properties
and equipment, thus putting in place internal management systems or controls. Among these
are the
(a) Policy on Request for Issuance of Supplies, Properties and Equipment; and the(b) Policy on
11 Motor Vehicles

the Maintenance, Repair, and Availment/Dispatch of Motor Vehicles and Allocation of Fuel.

The division also helped ensure the timely payment of NPC obligations amounting to a total of Overall, the division has greatly contributed to ensuring higher obligation rate at fiscal year-end
P78,684,868.99 to various creditors. Instrumental to achieving this was the ASD’s management by expediting the processing of purchase requests for the procurement of goods and services,
of funds collected and deposited to the bank within 24 hours from receipt. increasing the rate of absorptive capacity of the NPC to utilize its funds under the General
Appropriations Act.
Likewise, the ASD takes the lead in the planning, management and procurement of NPC’s
property, plant, and equipment registering a total of 387 units IT and Office Equipment, 245
pieces of Furniture and Fixtures, and 11 Motor Vehicles.

32 2017 MILESTONES INTERNAL MANAGEMENT 33


HUMAN
BY EDUCATIONAL ATTAINMENT BY SEX
RESOURCE
Particulars Total
MANAGEMENT HS Graduate 2
College
Human resource management is one of the
most crucial part in any organization. For that,
the NPC presents its 2017 personnel and its
personnel development initiatives.
Undergraduate
(Unit with 72 units earned)
College Graduate
1

38
25 58
Plantilla
34
28 COS 24
Masteral Degree 20

NUMBER OF PERSONNEL
Doctorate Degree
Total
1
62
53
Plantilla Non-Plantilla
Total
Division (has assumed PERSONNEL TRAINING
Authorized Filled Unfilled COS Consultant position)

OPC 18 11 7 6 0 17 79%
Plantilla personnel
In-house
Summary of Trainings
5

OED 5 0 5 0 0 0 Sponsored 7
completed the
PIAD 7 4 3 13 0 17 above-mentioned NPC - Funded 17
DASCO 3 0 3 0 0 0 trainings. Total 29
CMD 14 9 5 7 0 16
DSTD 6 5 1 2 0 7
LEO 3 0 3 0 0 0
LD 6 3 3 0 0 3
ED 6 4 2 0 0 4
CID 7 6 1 3 0 9
FAO 3 0 3 2 0 2
FPMD 8 7 1 3 0 10
ASD 6 4 2 11 0 15
HRDD 5 3 2 1 0 4
PPO 3 0 3 0 0 0
PDD 12 5 7 1 0 6
PRD 11 1 10 0 0 1

TOTAL 123 62 61 49 0 111

34 2017 MILESTONES INTERNAL MANAGEMENT 35


ELISA MAY A. CUEVAS ATTY. GILBERT V. SANTOS ATTY. IVY GRACE T. VILLASOTO BELMA G. MARTINEZ
Head Executive Assistant OIC, Legal and Enforcement Office OIC, Privacy Policy Office OIC, Finance and Administrative Office
may.cuevas@privacy.gov.ph gilbert.santos@privacy.gov.ph grace.villasoto@privacy.gov.ph bel.martinez@privacy.gov.ph
CORPORATE
DIRECTORY

ATTY. JANICE G. NADAL ATTY. FRANCISCO R. ACERO ATTY. RASIELLE DL. RELLOSA DR. ROLANDO R. LANSIGAN
OIC, Legal Division Chief, Complaints and Investigation Division OIC, Policy Development Division Chief, Compliance and Monitoring Division
janice.nadal@privacy.gov.ph francis.acero@privacy.gov.ph rashy.rellosa@privacy.gov.ph rolando.lansigan@privacy.gov.ph

JONATHAN S. RAGSAG MARIA DELIA S. PRESQUITO MALOU C. LEELIAN KIMBERLY ANN M. MEDINA OLIVIA KHANE S. RAZA
OIC, Data Security and Technology Chief, Administrative Services Division OIC, Financial Planning and Management Division OIC, Human Resource Development Division OIC, Public Information and Assistance Division
Standards Division madel.presquito@privacy.gov.ph malou.leelian@privacy.gov.ph kim.medina@privacy.gov.ph khane.raza@privacy.gov.ph
jonathan.ragsag@privacy.gov.ph
PRIVACY POLICY OFFICE

COMPLIANCE AND MONITORING DIVISION

DATA SECURITY AND TECHNOLOGY STANDARDS DIVISION

ENFORCEMENT DIVISION LEGAL DIVISION


PUBLIC INFORMATION AND ASSISTANCE DIVISION
FINANCE, PLANNING AND MANAGEMENT DIVISION

COMPLAINTS AND INVESTIGATION DIVISION

ADMINISTRATIVE SERVICES DIVISION

HUMAN RESOURCE DEVELOPMENT DIVISION

S-ar putea să vă placă și