Data Privacy Module 2
Data Privacy Module 2
PRINCIPLES
Data Privacy Fundamentals
Module 2
Legitimate Security
Purpose Safeguards Accountability
Purpose Purpose
Use Limitation
Specification Limitation
Source: https://ico.org.uk/media/about-the-ico/consultations/2013551/draft-gdpr-consent-guidance-for-consultation-201703.pdf
a) Consent
b) Contract
c) Compliance with a legal obligation
d) Protect vitally important interests of the data subject, including life and
health
e) Fulfill functions of public authority (national emergency, public order and
safety)
f) Legitimate interests
Sec. 12, DPA
a) Consent
b) Existing laws and regulations
c) Protect the life and health of a data subject or another person
(Emergency cases)
d) Medical treatment (Medical Practitioner)
e) Court proceedings, legal mandate of government authorities
“Lastly, as to the request of the media and other private organizations, the disclosure of statistical
or aggregated information without involving any personal or sensitive personal information
should suffice. The release of a copy of the master list of students and individuals who were
vaccinated with Dengvaxia®, which contains sensitive personal information to the Requesting, to
any requesting public, could constitute an unwarranted invasion of personal privacy”.
Collection
Storage Limitation Deidentification*
Limitation
Not
Relevant
excessive
Necessary Suitable
“It is proper for the CAAC and the Board to judiciously evaluate and determine whether the
publication of the decisions on the website is indispensable in achieving its purpose. The Board can
consider redaction of sensitive personal information, such as the identity of patients and their
health information, which may not be necessary for purposes of posting in the website”.
Continuing
•
•
Third-Party Management
Communication SUBJECTS
Assessment and • Continuity and Review
Development
X
▪ processing is based on consent (including processing
for direct marketing, automated processing, or profiling)
▪ processing is based on legitimate interests of the PIC
▪ Right to dispute the inaccuracy or error in the personal data and have the
PIC correct it immediately, unless the request is vexatious or otherwise
unreasonable.
▪ PIC shall ensure the accessibility of both the new and the retracted
information and the simultaneous receipt of the new and the retracted
information by the intended recipients.
▪ If you have disclosed the personal data in question to third parties, you must
inform them of the rectification upon reasonable request of the data subject.
✔
and freedoms as data subject.
ACCOUNTABILITY
Harms
privacy.gov.ph