SlideShare a Scribd company logo
Security of Sensitive
Personal Information in Government
Basics of Philippine Data Privacy Law
for Non-Lawyers
Applicability to Government
The Data Privacy Law expressly and specifically provides for the applicability
of the provisions to Government Agencies.
Accordingly, heads of agencies are made primarily responsible for ensuring
that their offices are compliant with the security of sensitive personal
information that are in their control or custody.
Reference: Section 22, R.A. 10173
Responsibility: Heads of Agencies
All sensitive personal information maintained by the government, its agencies and instrumentalities shall
be secured, as far as practicable, with the use of the most appropriate standard recognized by the
information and communications technology industry, and as recommended by the Commission. The head
of each government agency or instrumentality shall be responsible for complying with the security
requirements mentioned herein while the Commission shall monitor the compliance and may recommend
the necessary action in order to satisfy the minimum standards.
The heads of agencies are made primarily responsible for compliance with
the security requirements set by the Data Privacy Law.
The NPC has the authority to monitory compliance and recommend to the
agency the necessary to action to comply with the minimum standards.
Reference: Section 23, R.A. 10173
Responsibility: Heads of Agencies
(a) On-site and Online Access – Except as may be allowed through guidelines to be issued by the
Commission, no employee of the government shall have access to sensitive personal information on
government property or through online facilities unless the employee has received a security clearance
from the head of the source agency.
Sensitive personal information with the Government is required to be
maintained as strictly confidential and only for those authorized to access
them.
Accordingly, security clearance is required before a Government employee
may be able to access these sensitive personal information.
Reference: Section 23, R.A. 10173
Responsibility: Heads of Agencies
(b) Off-site Access – Unless otherwise provided in guidelines to be issued by the Commission, sensitive
personal information maintained by an agency may not be transported or accessed from a location off
government property unless a request for such transportation or access is submitted and approved by the
head of the agency in accordance with the following guidelines:
(1) Deadline for Approval or Disapproval – In the case of any request submitted to the head of an
agency, such head of the agency shall approve or disapprove the request within two (2) business
days after the date of submission of the request. In case there is no action by the head of the agency,
then such request is considered disapproved;
Reference: Section 23, R.A. 10173
Responsibility: Heads of Agencies
(2) Limitation to One thousand (1,000) Records – If a request is approved, the head of the agency
shall limit the access to not more than one thousand (1,000) records at a time; and
(3) Encryption – Any technology used to store, transport or access sensitive personal information
for purposes of off-site access approved under this subsection shall be secured by the use of the most
secure encryption standard recognized by the Commission.
Transportation or access off-site of sensitive personal information with the
Government requires an approved request by the head of agency. Further,
a 1,000 records at a time limitation is imposed.
Most secure encryption standard is required of the technology to be used.
Reference: Section 23, R.A. 10173
Government Contractors
In entering into any contract that may involve accessing or requiring sensitive personal information from
one thousand (1,000) or more individuals, an agency shall require a contractor and its employees to
register their personal information processing system with the Commission in accordance with this Act
and to comply with the other provisions of this Act including the immediately preceding section, in the
same manner as agencies and government employees comply with such requirements.
Government contractors and their employees have to register their Personal
Information Processing System with the National Privacy Commission – if their
contracts involve accessing or requiring sensitive personal information from
1,000 or more individuals.
Reference: Section 24, R.A. 10173
Summary
1) Data Privacy Law applies to Government Offices.
2) Heads of Agencies are the ones primarily responsible for compliance.
3) Security clearance is required for Government Employees who are
accessing sensitive personal information.
4) A request approved by the Head of the Agency is required prior to
transportation or access off-site of sensitive personal information.
5) NPC registration is required for Government Contractors for contracts
involving access or requiring senstive personal information from at least
1,000 individuals.
Basics of Philippine Data Privacy Law
for Non-Lawyers
Atty. Jericho B. Del Puerto
SME Business Lawyer
For inquiries, comment, or permission to use slides, send us an email : info@jdpconsulting.ph.
Security of Sensitive
Personal Information in Government
Data Privacy- Security of Sensitive Personal Information

More Related Content

PPS
Introduction to Data Protection and Information Security
PPTX
Data privacy act
PDF
Privacy & Data Protection in the Digital World
PPT
Data Protection (Download for slideshow)
PPTX
GDPR
PDF
Privacy by design
PPTX
Physical Security In The Workplace
PPTX
Privacy & Data Protection
Introduction to Data Protection and Information Security
Data privacy act
Privacy & Data Protection in the Digital World
Data Protection (Download for slideshow)
GDPR
Privacy by design
Physical Security In The Workplace
Privacy & Data Protection

What's hot (20)

PDF
GDPR Basics - General Data Protection Regulation
PPT
Data protection in_india
PPSX
CRIMINOLOGY REVIEWER LEA POLICE ORGANIZATION
PPT
E Signature Presentation
PPTX
Gdpr presentation
ODP
GDPR: valutazione d'impatto (DPIA) - 11 maggio 2018
ODP
Corporate security
PDF
Best Practices for Implementing Data Loss Prevention (DLP)
PPTX
Training privacy by design
PDF
DPDP Act 2023.pdf
PPTX
skillcast-gdpr-training-presentation-q320.pptx
ODP
GDPR: principi - 21 maggio 2018
PPTX
Data Protection Officer Dashboard | GDPR
PDF
GDPR 2018 - Il nuovo Regolamento Privacy Europeo
PDF
Data Protection Predictions for 2023.pdf
PDF
Lezione n. 02 - Ordinamento della Polizia Municipale e Locale (1): Polizia am...
PPT
Personal Data Protection in Malaysia
PDF
GDPR Demystified
PPTX
GDPR e privacy - 6 dicembre 2018
PDF
The principles of the Data Protection Act in detail - uk
GDPR Basics - General Data Protection Regulation
Data protection in_india
CRIMINOLOGY REVIEWER LEA POLICE ORGANIZATION
E Signature Presentation
Gdpr presentation
GDPR: valutazione d'impatto (DPIA) - 11 maggio 2018
Corporate security
Best Practices for Implementing Data Loss Prevention (DLP)
Training privacy by design
DPDP Act 2023.pdf
skillcast-gdpr-training-presentation-q320.pptx
GDPR: principi - 21 maggio 2018
Data Protection Officer Dashboard | GDPR
GDPR 2018 - Il nuovo Regolamento Privacy Europeo
Data Protection Predictions for 2023.pdf
Lezione n. 02 - Ordinamento della Polizia Municipale e Locale (1): Polizia am...
Personal Data Protection in Malaysia
GDPR Demystified
GDPR e privacy - 6 dicembre 2018
The principles of the Data Protection Act in detail - uk
Ad

Similar to Data Privacy- Security of Sensitive Personal Information (20)

PPTX
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
PDF
Basic Data Privacy for Non Lawyers
PPTX
Data Privacy Act of 2012.pptx
PDF
Data Privacy - Security of Personal Information
PPT
The Data Privacy Act of 2012 by Tristan Calaguas
PPTX
RA 10173 or the Data Privacy Act of 2012.pptx
PPTX
Data Privacy Act in the Philippines
PDF
Philippine Data Privacy Act of 2012 (RA 10173)
PDF
Data privacy act of 2012 presentation
PDF
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
DOCX
Module 1- Living in the IT Era GE 12 FOR CHED
PPTX
Group 10 - PDPA II.pptx
PDF
Data Privacy - Rights of the Data Subject
PDF
2019 Bar Notes On Data Privacy Act Data Privacy Act Of 2012
PPTX
MAED 109 emergencies and disasters in education am
DOC
Personal Data and Information Classification under Data Privacy Act of the Ph...
PPTX
Group 5 Banking Laws Semi Finals.pptx
PDF
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
PPTX
Data Privacy Protection Competrency Guide by a Data Subject
PDF
Information Security: The Trinidad & Tobago Legal Context
DATA-PRIVACY-ACT OF 2012- draft only ppt.pptx
Basic Data Privacy for Non Lawyers
Data Privacy Act of 2012.pptx
Data Privacy - Security of Personal Information
The Data Privacy Act of 2012 by Tristan Calaguas
RA 10173 or the Data Privacy Act of 2012.pptx
Data Privacy Act in the Philippines
Philippine Data Privacy Act of 2012 (RA 10173)
Data privacy act of 2012 presentation
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Module 1- Living in the IT Era GE 12 FOR CHED
Group 10 - PDPA II.pptx
Data Privacy - Rights of the Data Subject
2019 Bar Notes On Data Privacy Act Data Privacy Act Of 2012
MAED 109 emergencies and disasters in education am
Personal Data and Information Classification under Data Privacy Act of the Ph...
Group 5 Banking Laws Semi Finals.pptx
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
Data Privacy Protection Competrency Guide by a Data Subject
Information Security: The Trinidad & Tobago Legal Context
Ad

More from JDP Consulting (20)

PDF
Data Privacy - Penalties for Non-Compliance
PPTX
Philippine Franchising Law
PDF
Unfair Labor Practice
PDF
DOLE D.O. 147-15
PDF
What is Control in Contracting and Subcontracting?
PDF
DOLE D.O. 174-17 vs. DOLE D.O. 18-A-11
PDF
Pag-IBIG Benefits
PDF
SSS Benefits
PDF
PhilHealth Benefits
PDF
ECC Benefits
PDF
Retirement Pay
PDF
Separation Pay
PDF
13th Month Pay
PDF
Special Leave for Women
PDF
VAWC Leave
PDF
Solo Parental Leave
PDF
Paternity Leave
PDF
Service Incentive Leave
PDF
Service Charges
PDF
Night Shift Differential Pay
Data Privacy - Penalties for Non-Compliance
Philippine Franchising Law
Unfair Labor Practice
DOLE D.O. 147-15
What is Control in Contracting and Subcontracting?
DOLE D.O. 174-17 vs. DOLE D.O. 18-A-11
Pag-IBIG Benefits
SSS Benefits
PhilHealth Benefits
ECC Benefits
Retirement Pay
Separation Pay
13th Month Pay
Special Leave for Women
VAWC Leave
Solo Parental Leave
Paternity Leave
Service Incentive Leave
Service Charges
Night Shift Differential Pay

Recently uploaded (20)

PPTX
R.A. NO. 76 10 OR THE CHILD ABUSE LAW.pptx
PPTX
Sexual Harassment Prevention training class
PPTX
BUSINESS LAW AND IT IN CONTRACT SIGNING AND MANAGEMENT
PDF
A SEP and FRAND Overview 13 Aug 2024.pdf
PPT
wipo: IP _smes_kul_06_www_6899913 (1).ppt
PPTX
Court PROCESS Notes_Law Clinic Notes.pptx
PDF
Kayla Coates Wins no-insurance case Against the Illinois Workers’ Benefit Fund
PPT
Gender sensitivity and fair language implementation
PDF
OpenAi v. Open AI Summary Judgment Order
PPTX
What Happens to Your Business If You Become Incapacitated
PPTX
BL 2 - Courts and Alternative Dispute Resolution.pptx
PPTX
Constitutional Law 2 Final Report.ppt bill of rights in under the constitution
PDF
250811-FINAL-Bihar_Voter_Deletion_Analysis_Presentation.pdf
PPT
Over view on IPR and its components :ppt
PDF
The AI & LegalTech Surge Reshaping the Indian Legal Landscape
PDF
SUMMARY CASES-42-47.pdf tax -1 257++/ hsknsnd
PDF
Plausibility - A Review of the English and EPO cases
PPTX
Peter Maatouk Is Redefining What It Means To Be A Local Lawyer Who Truly List...
PPTX
FFFFFFFFFFFFFFFFFFFFFFTA_012425_PPT.pptx
PPTX
prenuptial agreement ppt my by a phd scholar
R.A. NO. 76 10 OR THE CHILD ABUSE LAW.pptx
Sexual Harassment Prevention training class
BUSINESS LAW AND IT IN CONTRACT SIGNING AND MANAGEMENT
A SEP and FRAND Overview 13 Aug 2024.pdf
wipo: IP _smes_kul_06_www_6899913 (1).ppt
Court PROCESS Notes_Law Clinic Notes.pptx
Kayla Coates Wins no-insurance case Against the Illinois Workers’ Benefit Fund
Gender sensitivity and fair language implementation
OpenAi v. Open AI Summary Judgment Order
What Happens to Your Business If You Become Incapacitated
BL 2 - Courts and Alternative Dispute Resolution.pptx
Constitutional Law 2 Final Report.ppt bill of rights in under the constitution
250811-FINAL-Bihar_Voter_Deletion_Analysis_Presentation.pdf
Over view on IPR and its components :ppt
The AI & LegalTech Surge Reshaping the Indian Legal Landscape
SUMMARY CASES-42-47.pdf tax -1 257++/ hsknsnd
Plausibility - A Review of the English and EPO cases
Peter Maatouk Is Redefining What It Means To Be A Local Lawyer Who Truly List...
FFFFFFFFFFFFFFFFFFFFFFTA_012425_PPT.pptx
prenuptial agreement ppt my by a phd scholar

Data Privacy- Security of Sensitive Personal Information

  • 1. Security of Sensitive Personal Information in Government Basics of Philippine Data Privacy Law for Non-Lawyers
  • 2. Applicability to Government The Data Privacy Law expressly and specifically provides for the applicability of the provisions to Government Agencies. Accordingly, heads of agencies are made primarily responsible for ensuring that their offices are compliant with the security of sensitive personal information that are in their control or custody. Reference: Section 22, R.A. 10173
  • 3. Responsibility: Heads of Agencies All sensitive personal information maintained by the government, its agencies and instrumentalities shall be secured, as far as practicable, with the use of the most appropriate standard recognized by the information and communications technology industry, and as recommended by the Commission. The head of each government agency or instrumentality shall be responsible for complying with the security requirements mentioned herein while the Commission shall monitor the compliance and may recommend the necessary action in order to satisfy the minimum standards. The heads of agencies are made primarily responsible for compliance with the security requirements set by the Data Privacy Law. The NPC has the authority to monitory compliance and recommend to the agency the necessary to action to comply with the minimum standards. Reference: Section 23, R.A. 10173
  • 4. Responsibility: Heads of Agencies (a) On-site and Online Access – Except as may be allowed through guidelines to be issued by the Commission, no employee of the government shall have access to sensitive personal information on government property or through online facilities unless the employee has received a security clearance from the head of the source agency. Sensitive personal information with the Government is required to be maintained as strictly confidential and only for those authorized to access them. Accordingly, security clearance is required before a Government employee may be able to access these sensitive personal information. Reference: Section 23, R.A. 10173
  • 5. Responsibility: Heads of Agencies (b) Off-site Access – Unless otherwise provided in guidelines to be issued by the Commission, sensitive personal information maintained by an agency may not be transported or accessed from a location off government property unless a request for such transportation or access is submitted and approved by the head of the agency in accordance with the following guidelines: (1) Deadline for Approval or Disapproval – In the case of any request submitted to the head of an agency, such head of the agency shall approve or disapprove the request within two (2) business days after the date of submission of the request. In case there is no action by the head of the agency, then such request is considered disapproved; Reference: Section 23, R.A. 10173
  • 6. Responsibility: Heads of Agencies (2) Limitation to One thousand (1,000) Records – If a request is approved, the head of the agency shall limit the access to not more than one thousand (1,000) records at a time; and (3) Encryption – Any technology used to store, transport or access sensitive personal information for purposes of off-site access approved under this subsection shall be secured by the use of the most secure encryption standard recognized by the Commission. Transportation or access off-site of sensitive personal information with the Government requires an approved request by the head of agency. Further, a 1,000 records at a time limitation is imposed. Most secure encryption standard is required of the technology to be used. Reference: Section 23, R.A. 10173
  • 7. Government Contractors In entering into any contract that may involve accessing or requiring sensitive personal information from one thousand (1,000) or more individuals, an agency shall require a contractor and its employees to register their personal information processing system with the Commission in accordance with this Act and to comply with the other provisions of this Act including the immediately preceding section, in the same manner as agencies and government employees comply with such requirements. Government contractors and their employees have to register their Personal Information Processing System with the National Privacy Commission – if their contracts involve accessing or requiring sensitive personal information from 1,000 or more individuals. Reference: Section 24, R.A. 10173
  • 8. Summary 1) Data Privacy Law applies to Government Offices. 2) Heads of Agencies are the ones primarily responsible for compliance. 3) Security clearance is required for Government Employees who are accessing sensitive personal information. 4) A request approved by the Head of the Agency is required prior to transportation or access off-site of sensitive personal information. 5) NPC registration is required for Government Contractors for contracts involving access or requiring senstive personal information from at least 1,000 individuals.
  • 9. Basics of Philippine Data Privacy Law for Non-Lawyers Atty. Jericho B. Del Puerto SME Business Lawyer For inquiries, comment, or permission to use slides, send us an email : info@jdpconsulting.ph. Security of Sensitive Personal Information in Government