National Privacy Commission (Philippines)

The National Privacy Commission, or NPC, is an independent body created under Republic Act No. 10173 or the Data Privacy Act of 2012,[2] mandated to administer and implement the provisions of the Act, and to monitor and ensure compliance of the country with international standards set for data protection.[3] It is attached to the Philippines' Department of Information and Communications Technology (DICT) for purposes of policy coordination, but remains independent in the performance of its functions.[4] The Commission safeguards the fundamental human right of every individual to privacy, particularly Information privacy while ensuring free flow of information for innovation, growth, and national development.[5]

National Privacy Commission
Komisyon para sa Proteksiyon ng Personal na Impormasyon
Agency overview
FormedMarch 7, 2016 (2016-03-07)
HeadquartersGSIS Building, Pasay City
Annual budget₱229.60 million (2020)[1]
Agency executives
  • Raymund E. Liboro, Commissioner and Chairman
  • John Henry D. Naga, Deputy Privacy Commissioner
  • Leandro Angelo Y. Aguirre, Deputy Privacy Commissioner
Websitewww.privacy.gov.ph

In order to fulfill its mandate, the Commission is vested with a broad range of powers, from receiving complaints and instituting investigations on matters affecting personal data protection to compelling entities to abide by its orders in matters affecting data privacy. It also represents the Philippine Government internationally on data protection related issues. The Commission formulates and implements policies relating to the protection of personal data, including the relevant circulars and advisory guidelines, to assist organisations in understanding and complying with the Data Privacy Act. The Commission also reviews organizational actions in relation to data protection rules and issue decisions or directions for compliance where necessary. It is mandated to work with relevant sector regulators in exercising its functions.

Beyond regulating data protection issues, the NPC also undertakes public and sector-specific educational and outreach activities[6] to help organizations adopt good data protection practices and to help individuals to better understand how they may protect their own personal data from misuse.

History

The Data Privacy Act of 2012 is the first law in the Philippines which acknowledges the rights of Individuals over their Personal Data and Enforcing the responsibilities of entities who process them.

The initial definition was offered first in Republic Act 8792, Section 32 better known as the eCommerce Act of the Philippines and was formally introduced by the Department of Trade and Industry (DTI) on its Department Administrative Order #08 - Defining Guidelines for the Protection of Personal Data in Information Private Sector. Along with the Anti-Cybercrime Bill (now RA 10175), The first draft of the law started in 2001 under the Legal and Regulatory Committee of the former Information Technology and eCommerce Council (ITECC) which is the forerunner of the Commission on Information and Communication Technology (CICT). It was headed by former Secretary Virgilio "Ver" Peña and the Committee was chaired by Atty. Claro Parlade. It was an initiative of the Information Security and Privacy Sub-Committee chaired by Albert Dela Cruz who was the President of PHCERT together with then Anti-Computer Crime and Fraud Division Chief, Atty. Elfren Meneses of the NBI. The administrative and operational functions was provided by the Presidential Management Staff (PMS) acting as the CICT secretariat.

With rising concerns by the Information Technology and Business Process Association of the Philippines (IBPAP) of an absence of a Data Privacy Law, Philippine Congress passed Senate Bill No. 2965 and House Bill No. 4115 on June 6, 2012. President Benigno S. Aquino III signed Republic Act No. 10173 or the Data Privacy Act of 2012 on August 15, 2012. The law was influenced by the Data Protection Directive and the APEC Privacy Framework.[7]

President Aquino appointed on March 7, 2016 Raymund Liboro as inaugural head of the commission with Damian Domingo O. Mapa and Ivy D. Patdu as inaugural deputy privacy commissioners.[8] With fixed terms of office, they continued with their roles during the administration of President Rodrigo Duterte.

After consultation with various private organizations, civil societies and a series of public hearings in Manila, Cebu and Davao, the Implementing Rules and Regulations[2] of the Data Privacy Act was signed on August 24, 2016. It took effect on September 9, 2016.[9]

In May 2016, the Commission formally investigated the Commission on Elections for the Commission on Elections data breach one of the largest security breach in government held personal data.[10] On February 21, 2017, NPC announced that the Commission on Elections was being investigated for another security breach due to alleged theft of a computer containing personal data of voters.[11]

The NPC also began coordinating with different sectors on privacy and data protection.[12] In 2016, the National Privacy Commission was accepted as a member in the International Conference of Data Protection and Privacy Commissioners and the Asia Pacific Privacy Authorities.

Commissioners

Current Commissioners

CommissionerTitleAppointed
Raymund E. LiboroChairmanMarch 7, 2016
John Henry D. NagaDeputy CommissionerDecember 5, 2019[13]
Leandro Angelo Y. AguirreDeputy CommissionerFebruary 9, 2018[14]

Past Commissioners

CommissionerTitleTerm
Damian Domingo O. MapaDeputy CommissionerMarch 7, 2016 - February 9, 2018
Ivy D. PatduDeputy CommissionerMarch 7, 2016 - December 5, 2019
gollark: What data?
gollark: My stuff (mostly) runs dnscrypt-proxy, which works as a local DNS server which forwards requests to DNS over HTTPS/TLS servers.
gollark: I just run an adblocker on basically everything.
gollark: Me too. Their lack of respect for privacy and tentacles throughout the web are very irritating.
gollark: I have a copy of ungoogled-chromium for when applications require a Chrome-y browser (!!!) for some reason.

See also

References

  1. Aika Rey (8 January 2020). "Where will the money go?". Rappler. Retrieved 29 May 2020.
  2. Republic Act No. 10173: An Act Protecting Individual Personal Information in Information and Communications Systems in the Government and the Private Sector, Creating for this purpose a National Privacy Commission, and for Other Purposes (2012)
  3. Data Privacy Act, Section 7
  4. Data Privacy Act, Section 9
  5. Data Privacy Act, Section 2
  6. Ronda, Rainier Allan (1 Jan 2017). "Privacy body raises private sector awareness on data security". Philippine Star.
  7. "Philippine Data Privacy Law is Signed into Law". HL Chronicle of Data Protection. 23 Aug 2012.
  8. "DOST exec named first commissioner of National Privacy Commission". NewsBytes.ph. 7 Mar 2016.
  9. "IRR for Data Privacy Act released 4 years after passage of law". NewsBytes.ph. 27 Aug 2016.
  10. Ronda, Rainier Allan (6 Jan 2017). "Comeleak: Bautista faces criminal raps". Philippine Star.
  11. Nonato, Vince F. (21 Feb 2017). "Another Comeleak? Theft probed". Philippine Daily Inquirer.
  12. de Villa, Kathleen (30 Jan 2017). "Agency reminds bank on data privacy law". Philippine Daily Inquirer.
  13. Newsbytes.PH. "DICT usec named new NPC deputy commissioner". NewsBytes.ph. Retrieved 5 December 2019.
  14. Calimag, Melvin. "UP, Harvard law grad named new NPC deputy commissioner". NewsBytes.ph. Retrieved 12 May 2018.

Resources

This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.