1 of 80

Justin David Pineda CISSP, CISM

May 2026 (rev 4)

Just be PRIVY | Pineda Cybersecurity | May 2026

Just be PRIVY

(Protecting Rights and Information through Vigilance for You)

Protecting Personal Data Starts With You

2 of 80

Just be PRIVY | Pineda Cybersecurity | May 2026

3 of 80

Just be PRIVY | Pineda Cybersecurity | May 2026

4 of 80

1. Introduction to RA 10173 (The Data Privacy Act of 2012)

Just be PRIVY | Pineda Cybersecurity | May 2026

5 of 80

Initial Questions

  • What is privacy for you?
  • Do you know your organization’s Data Protection Officer (DPO)?
  • Do you have a Privacy Manual in place?

6 of 80

Name That Meme

7 of 80

Name That Meme

“Akin na lisensya mo..”

“Golden Retriever Boy”

“Bakit mo nilalabas”

“Shoutout sa mga kabataan diyan..”

8 of 80

AI Prompts?

9 of 80

What is Data Privacy Act of 2012 (RA 10173)

AN ACT PROTECTING INDIVIDUAL PERSONAL INFORMATION IN INFORMATION AND COMMUNICATIONS SYSTEMS IN THE GOVERNMENT AND THE PRIVATE SECTOR, PRIVACY COMMISSION, AND FOR OTHER PURPOSES

10 of 80

Section 11, Article II of the�1987 Constitution

The State values the dignity of every human person and guarantees full respect for human rights.

Just be PRIVY | Pineda Cybersecurity | May 2026

11 of 80

Data Privacy Law

  • SEC. 2. Declaration of Policy. – It is the policy of the State to protect the fundamental human right of privacy, of communication while ensuring free flow of information to promote innovation and growth.

Just be PRIVY | Pineda Cybersecurity | May 2026

12 of 80

Scope of the Law

  • SEC. 4. Applies to the processing of all types of personal information, in the country and even abroad, subject to certain qualifications.

Just be PRIVY | Pineda Cybersecurity | May 2026

13 of 80

Scope & Coverage of the Law

Personal Information

  • Data identifying individuals
  • Protected by privacy laws, unlike IP, which focuses on business assets

Examples:

  • Name
  • Address
  • Age

Just be PRIVY | Pineda Cybersecurity | May 2026

14 of 80

What Does the Law Protect?

15 of 80

Personal Data, Personal Info, Sensitive Personal Info, or Privileged Info?

  1. An email address that includes a person’s full name (e.g., juan.dela.cruz@email.com).
  2. A medical record showing diagnosis and prescribed medication.
  3. A scanned copy of a person’s passport or driver’s license.
  4. An individual’s browsing history saved by a website.�

Just be PRIVY | Pineda Cybersecurity | May 2026

16 of 80

Personal Data, Personal Info, Sensitive Personal Info, or Privileged Info?

  1. A voicemail recording between a lawyer and client discussing a case.
  2. An individual’s IP address logged by a company’s website.
  3. A survey form collecting name, marital status and religion.
  4. A photo of a person attached to their employee ID.
  5. An internal memo showing an employee’s full name and their involvement in a disciplinary proceeding.�

Just be PRIVY | Pineda Cybersecurity | May 2026

17 of 80

PI & SPI in Local Context

Personal Information (PI) refers to any information from which the identity of an individual is apparent or can be reasonably and directly ascertained, or when put together with other information would directly and certainly identify an individual.

18 of 80

PI & SPI in Local Context

Sensitive Personal Information (SPI) refers to info about an individual’s:

  • Race
  • Ethnic origin
  • Marital status
  • Age
  • Color
  • Religious, philosophical or political affiliations
  • Health, education, genetic or secual life
  • Proceeding for any offense committed or alleged to have been committed by an individual Government-issued IDs
  • Those established by an executive order or an act of Congress to be kept classified

19 of 80

20 of 80

What does the law regulate?

  • The law regulates the “processing” of personal data.
  • “Processing” refers to any operation or any set of operations performed upon personal data.

Just be PRIVY | Pineda Cybersecurity | May 2026

21 of 80

Processing

  • Any operation of any set of operations performed upon personal data including, but not limited to the following:

✓ Collection

✓ Recording

✓ Organization

✓ Storage

✓ Updating or modification

✓ Retrieval

✓ Use

✓ Consolidation

✓ Blocking

✓ Erasure

✓ Destruction

✓ Consultation

22 of 80

Is it Processing or Not Processing?

  1. A marketing assistant compiles a spreadsheet of client emails for a newsletter campaign.
  2. An HR officer verbally reminds an employee about the company’s data privacy policy.
  3. A receptionist stores customer ID photocopies in a locked cabinet.
  4. A system automatically deletes inactive user accounts after one year.
  5. An employee reads a printed list of names during roll call without writing anything down.�

Just be PRIVY | Pineda Cybersecurity | May 2026

23 of 80

Criteria for Lawful Processing �(Sections 12 & 13 of the DPA)

Personal Information

Sensitive Personal Information

Consent

Law and Regulation

Protect Life

Contract

Legal Obligation

Public Order and Safety

Government Mandate

Legitimate Interest

Consent

Law and Regulation

Protect Life

Lawful and Non-commercial Objectives of Public Organizations and their Associations

Medical Treatment

Court Proceeding, Legal Claims

24 of 80

Lawful or Unlawful Processing

  1. A gym collects and processes client health information from attendance registration for marketing supplements.
  2. An online store processes a customer’s name and address to ship a purchased item.
  3. A hospital shares a patient’s medical history with a research group without consent.
  4. A bank reports account holder information to the Anti-Money Laundering Council (AMLC).
  5. An emergency responder accesses unconscious accident victim’s ID and health data to alert family and medics.�

Just be PRIVY | Pineda Cybersecurity | May 2026

25 of 80

Comparing Data Privacy & Cybersecurity

Ensures that personal and sensitive data is collected, stored, and shared in a lawful and ethical manner.

Both focus on safeguarding information.

Protects systems, networks, and data from unauthorized access, cyberattacks, and breaches.

26 of 80

Key DPA Actors

27 of 80

Key DPA Actors

28 of 80

Key DPA Actors

29 of 80

Key DPA Actors

30 of 80

Data Subject, PIC or PIP?

  1. A hospital patient fills out a consent form and provides their medical history.
  2. A payroll outsourcing firm processes employee salary data on behalf of a corporation.
  3. A university registrar decides how student records will be stored and for how long.
  4. A job applicant submits their résumé and transcript to a recruitment agency.
  5. An IT company hired by a hospital manages the electronic health record system but follows only the hospital’s instructions.

Just be PRIVY | Pineda Cybersecurity | May 2026

31 of 80

Scope & Coverage of the Law

Shopee’s data center in China

  • The Data Privacy Act applies to all entities processing personal data of Filipinos, regardless of location.
  • Shopee must comply with Philippine data protection laws, even if storing data in China.
  • MAF vs. Shopee Philippines, Inc. highlighted Shopee's accountability for a privacy breach involving a minor's photo.
  • The National Privacy Commission (NPC) ruled that Shopee, as a Personal Information Controller (PIC), is responsible for its Personal Information Processors (PIPs), even if outsourced.

32 of 80

33 of 80

2. Data Privacy Principles & Rights of Data Subjects

Just be PRIVY | Pineda Cybersecurity | May 2026

34 of 80

Just be PRIVY | Pineda Cybersecurity | May 2026

35 of 80

General Privacy Principles

Transparency

Legitimate Purpose

Proportionality

You have the right to know what, why, and how your data will be collected and used.

Your data should only be used for a specific, legal, and fair reason.

They should only collect the data they actually need.

36 of 80

37 of 80

Law vs. Reality

What the law says…

  • Users should know what they’re agreeing into.
  • Collect only what is necessary.

38 of 80

39 of 80

Compliant or Non-Compliant? What data privacy principle can be applied?

  • An online store collects customer birthdays for surprise discounts and discloses this in its privacy notice.
  • A school collects detailed health records from all students but does not explain how they will be used.
  • A mobile app asks for access to the user's microphone even though it only functions as a calculator.
  • A government agency requires your address and ID number for issuing a driver's license.
  • A company uses employee emergency contact info for sending marketing offers.��

40 of 80

Rights of the Data Subject

Be Informed

To Object

To Access

You have the right to know the data being, or have been processed.

You can withhold consent to the processing of your personal data.

You have the right to access your data upon your demand.

41 of 80

Rights of the Data Subject

To Rectification

To Erasure

To Damages

You have the right to dispute the inaccuracy or error in your data.

You have the right to suspend, withdraw, or order the blocking, removal, or destruction of your data especially when it is being misused or no longer needed.

You have the right to sue for compensation when the company or organization misused your data

42 of 80

  • Can you just file a complaint to NPC if there is a violation of your data privacy rights and do not attend hearings and mediation?

43 of 80

44 of 80

Case: CA v. Westparc Condominium, NPC 18-004 & 18-005 (NPC 2018)

Summary

  • Westparc Condominium required residents to submit sensitive personal data via Unit Information Sheets ("201 Files").
  • Complainants raised concerns about denied access to their own files, lack of data protection, and unauthorized handling by JAC security personnel.
  • Privacy issues included poor safeguards and installation of audio-recording CCTVs.
  • NPC ordered compliance, but Westparc repeatedly failed to submit documents or attend required conferences without valid explanation.

45 of 80

How would you respond to a data subject request?

An employee exercises her Right to Erasure under the Data Privacy Act and requests that the organization delete all her personal data from its record. Can the organization legally refuse this request? If yes, under what conditions?

46 of 80

Case: JCR vs. Globe Telecom, Inc.

47 of 80

Case: JCR vs. Globe Telecom, Inc.

Summary

  • The National Privacy Commission (NPC) disagreed, stating:

    • Globe failed to promptly deactivate the SIM, exposing the user to risk.
    • SIM identifiers like IMSI and ICCID are considered personal data under the law.
    • Globe had a duty to act swiftly to protect such data.
    • Delayed responses to deactivation requests undermine data protection obligations, especially when SIMs are used for two-factor authentication and account access.

48 of 80

Case: EG v. JI, RO, and RR

Summary:

  • EG had a verbal altercation with another unit owner, described as a British-Filipino nurse
  • the CEC administration, represented by the respondents JI, RO, and RR, conducted an internal investigation and retrieved CCTV footage of EG.
  • The CCTV footage was then shown or made available to the other tenant involved in the incident, without the knowledge or consent of EG
  • He further emphasized that he was not given the opportunity to give or withhold consent, nor was he informed about how his personal data would be processed.
  • Respondents said that the disclosure was made to clarify the situation and resolve a possible security issue in the condominium.

49 of 80

Case: EG v. JI, RO, and RR

Issue:

  • Whether Respondents committed a violation of the DPA

  • Whether the disclosure of the CCTV footage of EG to a third party (the other tenant) without his consent constitutes a violation of the Data Privacy Act of 2012.

50 of 80

Case: EG v. JI, RO, and RR

Ruling:

  • While the sharing of CCTV footage was scrutinized, there was a lack of substantial evidence to prove that the respondents, JI, RO, and RR, unlawfully disclosed personal information

  • NPC concluded that the complaint did not merit further action and dismissed the case for lack of merit

51 of 80

3. Compliance Requirements and the Role of the DPO

Just be PRIVY | Pineda Cybersecurity | May 2026

52 of 80

53 of 80

The Role of the Data Protection Officer (DPO)

Monitor compliance with data privacy regulations.

Train employees on data protection policies.

Serve as a point of contact for regulators and data subjects.

Conduct Privacy Impact Assessments (PIA) and risk evaluations.

54 of 80

Qualifications of a DPO

  • Legal Knowledge (Data Protection Laws, Industry Regulations)
  • Technical Understanding (Security & IT Policies)
  • Communication & Leadership Skills

Who should be a DPO?

Experience Required for a DPO

  • Prior Work in Data Privacy or Compliance
  • Experience with Risk Assessments & Privacy Audits
  • Collaboration with Legal, IT, and Business Units

55 of 80

Should the DPO Be a Standalone Role?

56 of 80

Know Your Risks: Conduct a Privacy Impact Assessments (PIA)

    • Process used to identify, assess, and mitigate risks
    • Helps ensure compliance with data privacy laws and best practices.
    • Evaluates how personal data is collected, stored, shared, and disposed of.

57 of 80

How to conduct a Privacy Impact Assessment (PIA)?

58 of 80

Where do you draw the line to data collection?

59 of 80

Data Lifecycle – From Womb to Tomb

60 of 80

Data Sharing, Outsourcing & Third Parties

Third-party vendors are the top cause of security breaches.

61 of 80

Data Sharing, Outsourcing & Third Parties

Data Breach at DISA Global Solutions

  • In 2024, DISA Global Solutions, a prominent third-party employment screening services provider, experienced a data breach that exposed personal information of over 3.3 million individuals.

62 of 80

Summary

  • Data Privacy Act (RA 10173) protects personal information processed by organizations.
  • Different types of protected data include PI, PII, SPI, and PPI.
  • The law applies to entities processing personal data of Filipinos, regardless of location.
  • Key actors include the NPC, Data Subject, PIC, and PIP.
  • Organizations must ensure lawful and responsible handling of personal data.

63 of 80

Knowledge Check # 1

  1. What is the primary purpose of RA 10173?
  2. Protect intellectual property
  3. Regulate internet access
  4. Control social media use
  5. Protect personal information

64 of 80

Knowledge Check # 2

2. Which type of information requires higher protection under DPA?

  1. Sensitive Personal Information (SPI)
  2. Public Information
  3. Trade Secrets
  4. Marketing Data

65 of 80

Knowledge Check # 3

3. Which agency is responsible for implementing the Data Privacy Act?

  1. DICT
  2. DTI
  3. NPC
  4. NBI

66 of 80

Knowledge Check # 4

4. What does PIC stand for?

  1. Personal Information Collector
  2. Personal Information Controller
  3. Privacy Information Center
  4. Personal Information Custodian

67 of 80

Knowledge Check # 5

5. Does the Data Privacy Act apply only within the Philippines?

  1. Yes
  2. No, it applies to entities processing Filipinos’ personal data regardless of location
  3. Only to government agencies
  4. Only to private companies

68 of 80

Just be PRIVY | Pineda Cybersecurity | May 2026

69 of 80

Exercise – Mapping Personal Data Lifecycle and Priority

Please group yourselves and assign a recorder.

The recorder will document the answers of the group in the worksheet and send it at the end of the session.

Just be PRIVY | Pineda Cybersecurity | May 2026

70 of 80

Annex A: Sanctions, Liabilities & Current Trends

Just be PRIVY | Pineda Cybersecurity | May 2026

71 of 80

Penalties under RA 10173

Unauthorized Processing & Access (Negligence & Intentional)

  • Personal Information: 1-3 years imprisonment, PHP 500,000 - 2,000,000 fine
  • Sensitive Personal Information: 3-6 years imprisonment, �PHP 500,000 - 4,000,000 fine

Improper Disposal (Negligence or Intentional)

  • Personal Information: 6 months-2 years imprisonment, �PHP 100,000 - 500,000 fine
  • Sensitive Personal Information: 1-3 years imprisonment, �PHP 100,000 - 1,000,000 fine

72 of 80

Penalties under RA 10173

Processing for Unauthorized Purposes

  • Personal Information: 1.5-5 years imprisonment, PHP 500,000 - 1,000,000 fine
  • Sensitive Personal Information: 2-7 years imprisonment, PHP 500,000 - 2,000,000 fine

Unauthorized Access, Disclosure, and Concealment

  • Unauthorized access, breach, concealment, or disclosure: 1-5 years imprisonment, PHP 500,000 - 2,000,000 fine

73 of 80

Penalties under RA 10173

Aggravating Circumstances

  • Combination of offenses: 3-6 years imprisonment, PHP 1,000,000 - 5,000,000 fine
  • Large-scale (100+ affected individuals): Maximum penalties apply
  • Public officials: Additional disqualification from office
  • Corporate liability: Responsible officers held accountable, potential business suspension

74 of 80

NPC Sanctions & Fines

The National Privacy Commission (NPC) can impose:

  • Temporary or permanent ban on processing�personal data
  • Fines ranging from PHP 100,000 to PHP 5,000,000
  • Suspension or revocation of business operations

75 of 80

Terminologies (A-C)

  • Accountability�The principle that a personal information controller is responsible for all personal data under its control or custody, including data processed by third parties.
  • Anonymization�The process of removing personally identifiable information from data sets, so that individuals cannot be identified directly or indirectly.
  • Automated Processing�Processing of personal data through the use of computers or software, including profiling and automatic decision-making without human intervention.
  • Breach Notification�The obligation of a personal information controller to notify the NPC and affected data subjects within 72 hours upon knowledge of a personal data breach.
  • Consent�Any freely given, specific, informed indication of will, expressed in writing, electronically, or recorded by any means, by which the data subject agrees to the collection and processing of personal data.

76 of 80

Terminologies (D)

  • Data Processing System (DPS)�The structure and procedure by which personal data is collected and processed, including manual or automated methods.
  • Data Protection Officer (DPO)�An individual designated by a personal information controller or processor to ensure compliance with applicable privacy laws and policies.
  • Data Sharing�Disclosure or transfer of personal data between two or more entities, done under an appropriate Data Sharing Agreement.
  • Data Subject�An individual whose personal, sensitive personal, or privileged information is processed.
  • Direct Marketing�Communication by whatever means of any advertising or marketing material directed at particular individuals.

77 of 80

Terminologies (E-P)

  • Encryption�The process of converting data into a code to prevent unauthorized access.
  • Filing System�Any set of personal data structured and accessible according to specific criteria, whether centralized, decentralized, or dispersed.
  • Information Security Incident�An event or occurrence that affects or tends to compromise the confidentiality, integrity, or availability of personal data.
  • Lawful Processing�Processing of personal data that complies with the requirements of RA 10173 and related regulations.
  • Personal Data�Collective term for Personal Information, Sensitive Personal Information, and Privileged Information.

78 of 80

Terminologies (P)

  • Personal Data BreachA breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
  • Personal Information�Any information from which the identity of an individual is apparent or can be reasonably and directly ascertained.
  • Personal Information Controller (PIC)�A natural or juridical person who controls the processing of personal data and determines the purposes and means of processing.
  • Personal Information Processor (PIP)�Any natural or juridical person qualified to process personal data on behalf of the PIC.
  • Privacy Impact Assessment (PIA)�A process to assess and mitigate risks to the privacy rights of individuals from data processing activities.

79 of 80

Terminologies (P-R)

  • Privileged Information�Any and all forms of data which under the Rules of Court and other pertinent laws constitute privileged communication.
  • Processing�Any operation performed on personal data, whether automated or manual, including collection, recording, storage, alteration, retrieval, use, and erasure.
  • Profiling�Automated processing of personal data to evaluate certain personal aspects, such as preferences, interests, behavior, or location.
  • Public Authority�An entity established by law that exercises powers or performs functions for the public good.
  • Retention Period�The duration for which personal data is kept before being anonymized or securely destroyed.

80 of 80

Terminologies (S-U)

  • Security Measures�Technical, organizational, and physical safeguards to ensure the protection of personal data.
  • Sensitive Personal Information (SPI)�Personal information about an individual's race, ethnic origin, marital status, age, health, education, genetic or sexual life, legal proceedings, government-issued identifiers, and more.
  • Third Party�Any natural or juridical person other than the data subject, PIC, PIP, or representative thereof.
  • Transborder Data Flow�Transfer of personal data across national borders, which must comply with the DPA’s requirements on cross-border processing.
  • Unauthorized Processing�Processing of personal data without lawful basis or beyond what was authorized.