Data Privacy Act Primer
Data Privacy Act Primer
Data Privacy Act Primer
3. Priveleged Communication
- refers to those as provided by the Rules of Court and other pertinent laws.
(a) The act, practice or processing relates to personal information about a Philippine citizen or a
resident;
(b) The entity has a link with the Philippines, and the entity is processing personal information in
the Philippines or even if the processing is outside the Philippines as long as it is about
Philippine citizens or residents such as, but not limited to, the following: (1) A contract is
entered in the Philippines; (2) A juridical entity unincorporated in the Philippines but has
central management and control in the country; and (3) An entity that has a branch,
agency, office or subsidiary in the Philippines and the parent or affiliate of the Philippine
entity has access to personal information;
(c) The entity has other links in the Philippines such as, but not limited to: (1) The entity carries
on business in the Philippines; and (2) The personal information was collected or held by
an entity in the Philippines.
*Nothing in this act shall be construed as to have ammended or repealed the following:
(1) RA 53 - which affords protection to Journalists and their Sources - Sec. 5; (2) RA 1405 - The
Secrecy of Bank Deposits Act; (3) RA 6426 - The Foreign Currency Deposits Act; (4) RA 9510 -
Credit Information System Act Sec.4(e)
Penal Provisions
1. Unauthorized Processing of Personal Information, and Sensitive Personal Information
2. Provided Personal Information and Sensitive Personal Information Due to Negligence
3. Willful and Negligent Improper Disposal of Information and Sensitive Personal
Information
4. Processing of Personal Information and Sensitive Personal Information for Unauthorized
Purposes
5. Unauthorized Access or Intentional Breach
6. Concealment of Security Breaches involving Sensitive Personal Information
7. Malicious Disclosure of Personal Information
8. Unauthorized Disclosure of Personal Information
9. Combination or Series of Acrs of the foregoing
Maximum Penalty shall be imposed when at least personal information of 100 persons is
harmed, affected or involved.