Data Privacy Act Philippines
Also known as: Republic Act No. 10173 · RA 10173 · DPA
Definition
The Data Privacy Act of 2012 (officially Republic Act No. 10173) is the primary Philippine statute governing the processing of personal information, protecting individual privacy while ensuring the free flow of information. Administered by the National Privacy Commission (NPC), the law strictly regulates how government agencies, private corporations, and educational institutions collect, store, process, and secure personal and sensitive information, including student records in school databases. (Wikipedia, LawPhil)
Identities
| Source Type | Identity |
|---|---|
| Wikipedia | Data Privacy Act of 2012 |
| Wikidata | N/A |
| DBpedia | N/A |
| ProductOntology | N/A |
| Wiktionary | privacy |
| Library of Congress Subject Headings (LCSH) | Data protection — Law and legislation — Philippines |
| MeSH | N/A |
| NCBI Taxonomy | N/A |
| AGROVOC | N/A |
| Google Scholar | Data Privacy Act Republic Act 10173 NPC data protection Philippines |
| ConceptNet | law |
| OpenCyc | N/A |
Also Known As
- Republic Act No. 10173
- RA 10173
- DPA
Examples and Analogies
- School Database Protection: A school registrar restricts access to the Learner Information System (LIS) containing students’ birth certificates, grades, and parent addresses to authorized personnel only, in compliance with the DPA.
- Corporate Consent: A developer requires clients to sign a data privacy consent form before collecting their personal contact details for real estate marketing.
Usage Scenarios
1. Processing Enrollment Records
A private school administrator drafts a Data Privacy Manual to ensure student registration forms clearly state how their private details will be processed.
2. Reporting Data Breaches
A company that experiences a database breach immediately notifies the National Privacy Commission and the affected data subjects within 72 hours.
Strategies
- Appoint a dedicated Data Protection Officer (DPO) in your educational or business organization to oversee DPA compliance.
- Implement encryption and access-control measures for all digital drives containing personal client or student records.
Security and Safety Measures
- Do not share student or client lists with third parties without explicit, written consent from the data subjects.
- Shred physical documents containing sensitive information before disposal.
Historical Context
The Data Privacy Act was signed into law by President Benigno Aquino III on August 15, 2012. It was designed to align Philippine data protection standards with global regulations, notably the EU data protection framework.
Challenges and Controversies
Administrative Burden
Small schools and businesses struggle with the cost of implementing NPC-compliant security policies and registering their databases.
Compliance Gaps
Public databases and municipal LGU sites frequently experience minor leaks, highlighting enforcement challenges for the NPC.