data privacy act of 2012 - ceap · general principles governing collection, processing, and...

50

Upload: others

Post on 14-May-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 2: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

DATA PRIVACY ACT OF 2012

IN HIGHER EDUCATION INSTITUTIONS

by Estrada & Aquino Law

Page 3: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

He who holds the information, holds the power

3

Page 4: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 5: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

The State through the Data Privacy Act provides the safeguards

to privacy of information of individuals in school environment

DATA PROTECTION

STUDENTS EDUCATORS SCHOOL

PERSONNEL

!

5

Page 6: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

Is there a “Right to Privacy” in the 1987 Constitution?

expressly provide for Right to Privacy?

Page 7: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

NO!

The right to privacy is implicit in the Bill of Rights under

the 1987 Constitution. While “right to privacy” is not stated

as one of the fundamental rights, it can be inferred from

several provisions of the Constitution.

7

Page 8: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

There are 3 strands to the right to privacy

according to Justice Puno, these are:

1) Locational/Situational;

2) Informational; and

3) Decisional.

Relevant to DPA is the right to

informational privacy, or the right of

individuals to control information about

themselves.8

Page 9: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

RIGHTS OF DATA SUBJECT

RIGHT TO BE

INFORMED

RIGHT TO

ERASURE

RIGHT TO

DAMAGES

RIGHT TO

ACCESS

RIGHT TO FILE

COMPLAINT

RIGHT TO

OBJECT

9

RIGHT TO

RECTIFY

RIGHT TO

DATA

PORTABILITY

Page 10: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

ACADEMIC FREEDOM

While privacy rights are enjoyedby students and teachers like all citizens,

it should be harmonized and limited by the HEIs’ exercise of its

constitutionally guaranteed academic freedom.

10

Page 11: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

HEIs relationships are essentially governed by contracts. 11

Page 12: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

HOW DOES DATA PRIVACY AFFECT SCHOOLS?

12

ABC University has a bad practice of

storing its student records. One day,

papers were blowing around in the

wind beside a garbage container. A

student, seeing the papers, grabbed

some out of curiosity.

The Student read information about

Joseph, a 5th grade student, relating

to his special needs assessment, his

IQ score, psychological assessment

score, behavioral information, and

family history.

Page 13: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

13

THIS STUDENT AND HIS FRIENDS AFTER MAKING FUN

OF JOSEPH’S MENTAL DEFICIENCY PASSED IT TO

ANOTHER STUDENT (AND SO ON AND SO FORTH).

WITHIN A WEEK, JOSEPH BECAME SUBJECT OF

TAUNTS IN SCHOOL; HE WAS CALLED “DUMB” AND

“RETARD”. BECAUSE OF ABC UNIVERSITY’S POOR

DATA SECURITY PRACTICES, IT LED TO THE DIRECT

HARM OF ONE OF ITS STUDENTS.

Page 14: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

14

As a matter of fact, this story happened in reallife in the US. Joseph’s story tells us the needto secure student data and the legalimplications of failing to do so. ApplyingJoseph’s case in our jurisdiction, it is likely forJoseph to have a cause of action under DPA,i.e., accessing of sensitive personalinformation through negligence.

Page 15: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

HEIS AS PERSONAL INFORMATION CONTROLLER

A personal information controller is aperson or entity that controlsprocessing or instructs another personto carry out processing.

Page 16: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

16

STUDENTS AND THEIR PARENTS ENTRUST SCHOOLS WITH THEIR

PERSONAL INFORMATION WITH THE EXPECTATION THAT THIS

INFORMATION WILL BE USED BY THE SCHOOLS

to serve the needs of the students effectively & efficiently and

to perform their function as educational institutions

Page 17: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

3 KINDS OF INFORMATION

Personal Information Sensitive Personal Information Privileged Information

17

Page 18: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

refers to any information whether recorded in a material form or not, from which theidentity of an individual is apparent or can be reasonably and directly ascertained by theentity holding the information, or when put together with other information woulddirectly and certainly identify an individual.

PERSONAL INFORMATION

CONTACT

NUMBER

ADDRESSNAME

AGE

BIRTHDAY

18

Page 19: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

Sensitive personal information

(1) Race, ethnic origin, marital status,age, color, and religious,philosophical or politicalaffiliations;

(2) health, education, genetic orsexual life of a person, or courtproceedings;

(3) Issued by government agenciespeculiar to an individual (socialsecurity numbers, previous orcurrent health records, licenses orits denials, suspension orrevocation, and tax returns) and

(4) established by an executive orderor an act of Congress

Page 20: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

BA COMM - 1ST YEAR

Juan Dela Cruz

Page 21: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

SPOUSAL

PRIVILEGE

LAWYER-

CLIENT

PRIVILEGE

DOCTOR-

PATIENT

PRIVILEGE

PENITENT -

CLERGY

PRIVILEGE

PUBLIC

OFFICE

PRIVILEGE

21

Privileged information refers to any and all forms of

data which under the Rules of Court and other

pertinent laws constitute privileged communication.

Page 22: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

This has limited application to HEIs.

An example of this is information collected by medicine students under clerkship program rotating

in the hospitals as part of completion of the program.

Page 23: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

in our schools and the offices in charge:HERE ARE SOME OF THE USUAL INFORMATION PROCESSED IN

OUR SCHOOLS AND THE OFFICES IN CHARGE:

© 2015 YOUR COMPANY OR PROJECT

ADMISSIONS

OFFICE

GUIDANCE OFFICE AND

STUDENT AFFAIRS

OFFICE-

CLOUD COMPUTING

SERVICES/ ONLINE

CLASS

HR

DEPARTMENT:

CAREER

PLACEMENT AND

ALUMNI OFFICE

REGISTRAR

23

Page 24: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

REQUIREMENTS

OF THE DPA IN

PROCESSING

INFORMATION

24

Page 25: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

TRANSPARENCY

The data subject must be aware of thenature, purpose, and extent of theprocessing of his or her personal data,including the risks and safeguards involved.

LAWFUL

The processing of information

shall be compatible with a

declared and specified purpose

which must not be contrary to

law, morals, or public policy.

PROPORTIONALITY

The processing of informationshall be adequate, relevant,suitable, necessary, and notexcessive in relation to adeclared and specifiedpurpose. 25

General Principles of Data Processing

Page 26: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

GENERAL PRINCIPLES GOVERNING COLLECTION,

PROCESSING, AND RETENTION OF PERSONAL INFORMATION

1 3

2

CONSENTIn order for a data subject to give an informed consent as to the collection and processing of his personal data, he must be informed about the extent and purpose of processing.

DATA QUALITYdata must always be accurate or must be rectified in case of inaccuracy.

SAFETY MEASURES

Any authorized further processing shall have adequate safeguards.

Fair and Lawful

Personal data shall be processed fairly and lawfully.

RETENTIONPersonal Data shall not be

retained longer than necessary.

4

5

26

Page 27: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

DATA RETENTION

Page 28: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

HOW LONG IS THE RETENTION?

Retention of personal data shall only for as long asnecessary:

28

Page 29: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

The importance ofincorporating policiesrelated to Data Privacyto our studenthandbooks and facultyand administrativemanuals cannot beoveremphasized..

Page 30: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

HEIS’ RELATIONSHIP WITH ITS STUDENTS AND

PERSONNEL IS ESSENTIALLY CONTRACTUAL.

30

Page 31: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

31

The contract documents comprise all forms, rulesand regulations, including manuals and handbooks.Handbooks contain everything from the school’sphilosophy, stated purpose, to enumeration ofprohibited actions.

Page 32: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

32

Once a school handbook or manual is adopted by the education community, courts do not usually look into the details and circumstances how students and teachers agree on the specific provisions. This is one of the peculiarities of education.

Page 33: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 34: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

WALANG BASAGAN NG

FIELD TRIP

Page 35: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 36: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 37: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 38: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 39: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

MANDATORY DRUG TESTINGvs.RANDOM DRUG TESTING

ESTRADA & AQUINO LAW | www.estradaaquino.com

Page 40: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

Catholic and Religious schools, the largest component of non-government education in the Philippines.

Page 41: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

Legal problems have undergone many changes.

Page 42: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

We live in a litigious society.

Page 43: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

Complaints against schools are brought into the legal system.

Page 44: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

And even the media.

Page 45: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 46: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

Era where deregulation is a popular mantra.

Page 47: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

Salary Increase for Teachers

Page 48: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 49: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an
Page 50: DATA PRIVACY ACT OF 2012 - CEAP · GENERAL PRINCIPLES GOVERNING COLLECTION, PROCESSING, AND RETENTION OF PERSONAL INFORMATION 1 3 2 CONSENT In order for a data subject to give an

Any questions?You can reach me at:

email: [email protected]

Mobile: 09998817412

Land line: (02) 534 81 66

www.estradaaquino.com

Facebook: Joseph Noel Estrada

IG: attyerap