DEFINITIONS
Data Privacy Act refers to Republic Act No. 10173 or the Data Privacy Act of 2012 and its implementing rules and regulations;
Data Subject refers to an individual whose personal, sensitive personal, or privileged information is processed;
CMDFI refers to Capital Markets Development Foundation, Inc. ;
Personal Data collectively refers to personal information, sensitive personal information, and privileged information;
Personal Information refers to any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual;
Processing refers to any operation or set of operations performed upon personal data including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data. Processing may be performed through automated means, or manual processing, if the personal data are contained or are intended to be contained in a filing system;
Privileged information refers to any and all forms of personal data, which, under the Rules of Court and other pertinent laws constitute privileged communication;
Security incident is an event or occurrence that affects or tends to affect data protection, or may compromise the availability, integrity and confidentiality of personal data. It includes incidents that would result to a personal data breach, if not for safeguards that have been put in place;
Sensitive Personal Information refers to personal data:
ORGANIZATIONAL SECURITY MEASURES
Data Privacy Officer
A Data Privacy Officer (DPO, for brevity) shall be appointed by the CMDFI. The DPO shall be chosen from one of the members of the CDMFI’s Risk Assessment Group.
The DPO is responsible for ensuring the Office’s compliance with applicable laws and regulations protection of data privacy and security. The DPO’s functions and responsibilities shall particularly include, among others:
Data Privacy Principles
All processing of personal data within the CMDFI should be conducted in compliance with the following data privacy principles as espoused in the Data Privacy Act:
Data Processing Records
Adequate records of the CMDFI’s personal data processing activities shall be maintained at all times. The DPO, with the cooperation and assistance of the CMDFI’s Management Information Systems Department (MISD, for brevity) shall be responsible for ensuring that these records are kept up-to-date. These records shall include, at the minimum:
Management of Human Resources
The DPO, with the cooperation of the CMDFI’s Human Resources Department (HRD, for brevity), shall develop and implement measures to ensure that all the CMDFI’s staff who have access to personal data will strictly process such data in compliance with the requirements of the Data Privacy Act and other applicable laws and regulations. These measures may include drafting new or updated relevant policies of the CMDFI and conducting training programs to educate employees and agents on data privacy related concerns.
Employment Agreements
The DPO shall ensure that all employment agreements reflect appropriate clauses indicating the employee’s informed consent to:
Data Collection Procedures
The DPO, with the assistance of the CMDFI’s MISD, HRD, and Finance Department (FD, for brevity) and any other departments of the CMDFI responsible for the collection and processing of personal data, shall document the CMDFI’s personal data collection and processing procedures. The DPO shall ensure that such procedures are updated and that the consent of the data subjects (when required by the DPA or other applicable laws or regulations) is properly obtained. Such procedures shall also be regularly monitored, modified, and updated to ensure that the rights of the data subjects are respected, and that processing thereof is done fully in accordance with the DPA and other applicable laws and regulations.
Data Retention Schedule
Subject to applicable requirements of the DPA and other relevant laws and regulations, personal data shall not be retained by the CMDFI for a period longer than necessary and/or proportionate to the purposes for which such data was collected. The DPO shall be responsible for developing measures to determine the applicable data retention schedules, as well as to safeguard the destruction and disposal of such personal data in accordance with the DPA and other applicable laws and regulations.
PHYSICAL SECURITY MEASURES
The DPO shall develop and implement policies and procedures for the CMDFI to monitor and limit access to, and activities in, the offices of the CMDFI’s FD, HRD, and MISD, as well as any other departments and/or workstations in the CMDFI where personal data is processed, including guidelines that specify the proper use of, and access to, electronic media.
The design and layout of the office spaces and work stations of the abovementioned departments, including the physical arrangement of furniture and equipment, shall be periodically evaluated and readjusted in order to provide privacy to anyone processing personal data, taking into consideration the environment and accessibility to the public.
The duties, responsibilities, and schedules of individuals involved in the processing of personal data shall be clearly defined to ensure that only the individuals actually performing official duties shall be in the room or work station, at any given time. Further, the rooms and workstations used in the processing of personal data shall, as far as practicable, be secured against natural disasters, power disturbances, external access, and other similar threats.
TECHNICAL SECURITY MEASURES
The DPO, with the cooperation and assistance of MISD, shall continuously develop and evaluate the CMDFI’s security policy with respect to the processing of personal data. The security policy should include the following minimum requirements:
RIGHTS OF THE DATA SUBJECT
As provided under the DPA, data subjects have the following rights in connection with the processing of their personal data: right to be informed, right to object, right to access, right to rectification, right to erasure or blocking, and right to damages. Employees and agents of the CMDFI are required to strictly respect and obey the rights of the data subjects. The DPO shall be responsible for monitoring such compliance and developing the appropriate disciplinary measures and mechanism.
Right to be Informed
The data subject has the right to be informed whether personal data pertaining to him or her shall be, are being, or have been processed.
The data subject shall be notified and furnished with information indicated hereunder before the entry of his or her personal data into the records of the CMDFI, or at the next practical opportunity:
Right to Object
The data subject shall have the right to object to the processing of his or her personal data, including processing for direct marketing, automated processing or profiling. The data subject shall also be notified and given an opportunity to withhold consent to the processing in case of changes or any amendment to the information supplied or declared to the data subject in the preceding paragraph.
When a data subject objects or withholds consent, the CMDFI shall no longer process the personal data, unless:
Right to Access
The data subject has the right to reasonable access to, upon demand, the following:
Right to Rectification
The data subject has the right to dispute the inaccuracy or error in the personal data, and the CMDFI shall correct it immediately and accordingly, unless the request is vexatious or otherwise unreasonable. If the personal data has been corrected, the CMDFI shall ensure the accessibility of both the new and the retracted personal data and the simultaneous receipt of the new and the retracted personal data by the intended recipients thereof: Provided, That recipients or third parties who have previously received such processed personal data shall be informed of its inaccuracy and its rectification, upon reasonable request of the data subject.
Right to Erasure or Blocking
The data subject shall have the right to suspend, withdraw, or order the blocking, removal, or destruction of his or her personal data from the CMDFI’s filing system.
Transmissibility of Rights of Data Subjects
The lawful heirs and assigns of the data subject may invoke the rights of the data subject to which he or she is an heir or an assignee, at any time after the death of the data subject, or when the data subject is incapacitated or incapable of exercising his/her rights.
Data Portability
Where his or her personal data is processed by the CMDFI through electronic means and in a structured and commonly used format, the data subject shall have the right to obtain a copy of such data in an electronic or structured format that is commonly used and allows for further use by the data subject. The exercise of this right shall primarily take into account the right of data subject to have control over his or her personal data being processed based on consent or contract, for commercial purpose, or through automated means. The DPO shall regularly monitor and implement the National Privacy Commission’s issuances specifying the electronic format referred to above, as well as the technical standards, modalities, procedures and other rules for their transfer.
DATA BREACHES & SECURITY INCIDENTS
Data Breach Notification
All employees and agents of the CMDFI involved in the processing of personal data are tasked with regularly monitoring for signs of a possible data breach or security incident. In the event that such signs are discovered, the employee or agent shall immediately report the facts and circumstances to the DPO within twenty-four (24) hours from his or her discovery for verification as to whether or not a breach requiring notification under the Data Privacy Act has occurred as well as for the determination of the relevant circumstances surrounding the reported breach and/or security incident. The DPO shall notify the National Privacy Commission and the affected data subjects pursuant to requirements and procedures prescribed by the DPA.
The notification to the DPA and the affected data subjects shall at least describe the nature of the breach, the personal data possibly involved, and the measures taken by the CMDFI to address the breach. The notification shall also include measures taken to reduce the harm or negative consequences of the breach and the name and contact details of the DPO. The form and procedure for notification shall conform to the regulations and circulars issued by the National Privacy Commission, as may be updated from time to time.
Breach Reports
All security incidents and personal data breaches shall be documented through written reports, including those not covered by the notification requirements. In the case of personal data breaches, a report shall include the facts surrounding an incident, the effects of such incident, and the remedial actions taken by the personal information controller. In other security incidents not involving personal data, a report containing aggregated data shall constitute sufficient documentation. These reports shall be made available when requested by the National Privacy Commission. A general summary of the reports shall be submitted by the DPO to the National Privacy Commission annually.
OUTSOURCING AND SUBCONTRACTING AGREEMENTS
Any personal data processing conducted by an external agent or entity (third-party service provider) on behalf of the CMDFI should be evidenced by a valid written contract with the CMDFI. Such contract should expressly set out the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, the obligations and rights of the CMDFI, and the geographic location of the processing under the contract.
The fact that the CMDFI entered into such contract or arrangement does not give the said external agent or entity the authority to subcontract to another entity the whole or part of the subject matter of said contract or arrangement, unless expressly stipulated in writing in the same contract or evidenced by a separate written consent/agreement of the CMDFI. The subcontracting agreement must also comply with the standards/criteria prescribed by the immediately preceding paragraph.
In addition, the contract and the subcontracting contract shall include express stipulations requiring the external agent or entity (including the subcontractor) to:
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.