Data Privacy: Frequently Asked Questions ON
Data Privacy: Frequently Asked Questions ON
ASKED QUESTIONS
ON DATA PRIVACY
NPC FAQs
NPC FAQs
IN THE
TABLE OF CONTENTS
CONTENTS
II. THE DATA PRIVACY ACT & ITS COVERAGE 12 VI. RAISING AWARENESS & CAPACITY-BUILDING 56
What is the Data Privacy Act of 2012? 14 What is the DPO ACE Training Program? 58
Who is the National Privacy Commission? 16 What is the DPO Journal? 60
Am I covered by the DPA? 18 Who is a Sector Policy Adviser? 62
2 3
I. WHAT’S IN
IT FOR ME?
4 5
HEALTH AND HOSPITALS SECTOR
Q A
01
6 7
HEALTH AND HOSPITALS SECTOR
Q A
02
A health institution that prioritizes data privacy is an
institution that cares for its clients.
Why is data privacy
important in the Health
and Hospitals Sector?
8 9
HEALTH AND HOSPITALS SECTOR
Q A
03
10 11
II. DATA
PRIVACY ACT &
ITS COVERAGE
12 13
HEALTH AND HOSPITALS SECTOR
Q A
DATA PRIVACY
ACT OF 2012 Republic Act No. 10173 is also known as the Data
Privacy Act of 2012 (DPA).
14 15
HEALTH AND HOSPITALS SECTOR
Q A
05
16 17
HEALTH AND HOSPITALS SECTOR
Q A
06
Am I covered by the
DPA?
18 19
III. DATA
PRIVACY & ITS
COMPLIANCE
20 21
HEALTH AND HOSPITALS SECTOR
Q A
Appointing a Data Protection Officer (DPO) is a legal
requirement for personal information controllers (PICs)
and personal information processors (PIPs), under the
Data Privacy Act of 2012.
A A
07
24 25
HEALTH AND HOSPITALS SECTOR
Q A
A privacy notice is a statement made to a data
subject that describes how the organization collects,
uses, retains and discloses personal information. It is
sometimes referred to as a privacy statement, a fair
processing statement, or privacy policy.
26 27
HEALTH AND HOSPITALS SECTOR
Q A
Privacy Impact Assessment (PIA) is a process
undertaken and used to evaluate and manage
impacts on privacy of a particular program, project,
process, measure, system or technology product of
a PIC or PIP. It takes into account the nature of the
personal data to be protected, the personal data
flow, the risks to privacy and security posed by the
processing, current data privacy best practices,
the cost of security implementation, and, where
applicable, the size of the organization, its resources,
and the complexity of its operations.
28 29
HEALTH AND HOSPITALS SECTOR
Q A
30 31
HEALTH AND HOSPITALS SECTOR
Q A
A PIC or PIP is instructed to implement reasonable
and appropriate measures to protect personal data
against natural dangers such as accidental loss or
destruction, and human dangers such as unlawful
access, fraudulent misuse, unlawful destruction,
alteration and contamination.
32 33
IV. DATA
PROCESSING
GUIDELINES
34 35
HEALTH AND HOSPITALS SECTOR
Q A
What is the consent of recorded means. It may also be given on behalf of the
data subject by an agent specifically authorized by
the data subject? the data subject to do so.
36 37
HEALTH AND HOSPITALS SECTOR
A A
12
38 39
HEALTH AND HOSPITALS SECTOR
Q A
What are the who are in the health team must have minimum and
necessary access to enable the performance of their
guidelines in collecting functions.
40 41
HEALTH AND HOSPITALS SECTOR
Q A
The DPA and its IRR provides that personal data shall
not be retained longer than necessary:
1. for the fulfillment of the declared, specified, and legitimate
purpose, or when the processing relevant to the purpose
has been terminated;
2. for the establishment, exercise or defense of legal claims; or
3. for legitimate business purposes, which must be consistent
with standards followed by the applicable industry or
approved by appropriate government agency.
42 43
HEALTH AND HOSPITALS SECTOR
Q A
15
44 45
V. COVID-19
RELATED
QUESTIONS
46 47
HEALTH AND HOSPITALS SECTOR
Q A
48 49
HEALTH AND HOSPITALS SECTOR
Q A
50 51
HEALTH AND HOSPITALS SECTOR
Q A
And while there are laws that allow for the sharing
of information about COVID-19 patients from one
institution to another, PICs must ensure that such
is kept to a minimum extent keeping in mind the
three general data privacy principles: transparency,
legitimate purpose, and proportionality.
17
It must be noted as well that in instances when a Data
Sharing Agreement (DSA) is not mandated by law,
Can I share information PICs and PIPs may still opt to execute it if they have to
about COVID-19 detail the terms and conditions of the data sharing or
to outline security measures.
patients?
52 53
HEALTH AND HOSPITALS SECTOR
Q A
54 55
VI. RAISING
AWARENESS &
CAPACITY-
BUILDING
56 57
HEALTH AND HOSPITALS SECTOR
Q A
Training Program?
an email to dpo.ace@privacy.gov.ph.
58 59
HEALTH AND HOSPITALS SECTOR
Q A
60 61
HEALTH AND HOSPITALS SECTOR
Q A
The NPC adapted a sectoral approach which allows
for a wider reach and faster implementation of all
its projects and programs. Each sector has been
assigned a Policy Adviser who acts as the liaison
between the Commission and its stakeholders. At
present, we have identified more or less 22 sectors
which include:
1. Government, including NGAs, GOCCs and LGUs
2. Banks
3. Telecommunications and Internet Service Providers
4. Education
5. Business Process Outsourcing
6. Social Media
7. Health and Hospitals
8. Retail and Direct Marketing
9. Life Insurance
10. Non-Life Insurance and PADPAO
11. Pharmaceutical
12. Utilities
13. Non-Bank Financial Institutions
14. Hotels
21 15. Manning
16. Transportation and Logistics
17. Real Estate
Adviser? To know more about the Policy Adviser for the Health
and Hospitals Sector, you can go to
https://www.privacy.gov.ph/policy-advisors/
62 63
Para sa dagdag na kaalaman, makipag-ugnayan sa
National Privacy Commission (NPC).
info@privacy.gov.ph
privacy.gov.ph
8234 2228