PHILDPA-1 | Scope, Lawful Basis, General Principles, Sensitive Personal Info | 0 |
PHILDPA-2 | Data Subject Rights, Notice, Direct Marketing, Cookies | 0 |
PHILDPA-3 | Children's Data, PIA, Privacy by Design, Sensitive Categories | 0 |
PHILDPA-4 | Security of Personal Data, Access Logs, Encryption | 0 |
PHILDPA-5 | Cross-Border Transfer and Processor Agreements | 0 |
PHILDPA-6 | DPO, NPC Registration, Records, Privacy Management Program, Training | 0 |
PHILDPA-7 | Personal Data Breach Notification and Breach Management | 0 |
PHILDPA-8 | NPC Cooperation, Compliance, Enforcement, Sectoral Considerations | 0 |
1-3 | Title, declaration of policy and definitions | 0 |
11 | General data privacy principles: transparency, legitimate purpose, proportionality | 0 |
12 | Criteria for lawful processing of personal information | 0 |
13 | Sensitive personal information and privileged information | 0 |
14 | Subcontract of personal information | 0 |
15 | Extension of privileged communication | 0 |
16 | Rights of the data subject (section 16) | 0 |
16(a)-(b) | Right to be informed and the information to be furnished before processing | 0 |
16(c) | Right to reasonable access | 0 |
16(d) | Right to dispute inaccuracy and have it corrected | 0 |
16(e) | Right to suspend, withdraw, block, remove or destroy personal information | 0 |
16(f) | Right to be indemnified for damages | 0 |
17 | Transmissibility of the data subject's rights | 0 |
18 | Right to data portability | 0 |
19 | Non-applicability of the rights chapter | 0 |
20 | Security of personal information (section 20) | 0 |
20(a)-(c) | Reasonable and appropriate organizational, physical and technical security measures | 0 |
20(d) | Security measures by third-party processors | 0 |
20(e) | Confidentiality of personnel processing personal information | 0 |
20(f) | Notification of the Commission and affected data subjects of a personal data breach | 0 |
21 | Principle of accountability (section 21) | 0 |
21(a) | Accountability for transferred personal information: comparable protection | 0 |
21(b) | Designated individual accountable for compliance (Data Protection Officer) | 0 |
22 | Responsibility of heads of government agencies for sensitive personal information | 0 |
23 | Access by agency personnel to sensitive personal information: on-site, online and off-site | 0 |
24 | Applicability to government contractors | 0 |
25-32 | Chapter VIII: penalties | 0 |
33-37 | Combination of acts, extent of liability, large scale, public officers, restitution | 0 |
38-45 | Chapter IX: interpretation, IRR, reports, appropriations, transitory period and repeal | 0 |
5 | Protection afforded to journalists and their sources | 0 |
6 | Extraterritorial application | 0 |
7-10 | The National Privacy Commission | 0 |
IRR | Implementing Rules and Regulations of RA 10173 (NPC, 24 August 2016) | 0 |
R.19 | IRR section 19: consent, collection, data quality, retention and secure disposal | 0 |
R.20 | IRR section 20: data sharing and data sharing agreements | 0 |
R.26 | IRR section 26: organizational security measures | 0 |
R.27 | IRR section 27: physical security measures | 0 |
R.28 | IRR section 28: technical security measures | 0 |
R.34 | IRR section 34(b): right to object | 0 |
R.41 | IRR section 41: breach report to the Commission, documentation of all incidents and the annual summary | 0 |
R.44 | IRR section 44: contents of agreements for outsourcing to a personal information processor | 0 |
R.47 | IRR section 47: registration of personal data processing systems | 0 |
R.48 | IRR section 48: notification of automated processing operations and decisions based solely on them | 0 |