WebWeaver

Philippine Data Privacy Act of 2012

Protecting Your Privacy and Personal Information

What is the Data Privacy Act?

The Philippine Data Privacy Act of 2012 (Republic Act No. 10173) is designed to protect individuals' personal information by regulating how personal data is collected, stored, processed, and shared. It ensures that individuals’ privacy rights are respected and that personal data is securely handled.

Key Provisions

The Role of the National Privacy Commission (NPC)

The NPC is responsible for enforcing the provisions of the Data Privacy Act. It ensures compliance, conducts investigations, and imposes penalties for violations. It also provides guidance and education on best practices for data protection.

Implementing Rules and Regulations (IRR)

The IRR provides actionable guidelines to help organizations comply with the Data Privacy Act. It covers consent management, data sharing, security protocols, and accountability within organizations.

Case Example: A Data Breach in a Health Organization

Background: A health maintenance organization (HMO) in the Philippines experiences a data breach when an employee mistakenly sends an email with sensitive patient data to the wrong recipient. This results in the unauthorized exposure of the personal health information (PHI) of hundreds of members.

Steps in the Case: