January 24th, 12:20am January 24th, 11:08am Raymund E. Liboro
Privacy discourse in the country has come quite a long way over the past few years. From having no true centralized effort to cultivate a culture of data privacy and security, we’ve now built robust linkages between government, data handling organizations and the general public; these linkages are constantly being strengthened to create an even more dynamic synergy of awareness, compliance and enforcement. From a culture that, some might say, treats openness as both a value and an imperative, sometimes to the detriment of our own security, there is now at least a bit of mindfulness on which information to share or not to share — an awareness of what information could lead to your own ruin if it fell on the wrong hands.
While we continue to refine our public communications approach as regards data privacy and security awareness, we also recognize the essential role that data handlers play in building the culture that we want. Our thrust has always been thus: To advocate and empower first and foremost and to enforce, fairly and without favor, when efforts towards partnership do not prove as fruitful as expected.
In line with this, we’ve sustained our efforts to reach out to industries and sectors for which data handling is most integral. In the beginning, we’ve treated simplicity and directness as an imperative: We came up with the five pillars for data compliance; now, as we see data privacy and security gain more ground, stakeholders themselves are seeking more refinement and detail in the compliance framework.
If we can recall, the five pillars are: first, to appoint a data protection officer; second, to conduct a privacy impact assessment; third, to create a privacy management program; fourth, to implement data privacy and security measures, and fifth, to be ready in case of a data breach.
Housing is probably the biggest issue affecting people the world over.
Malacañang on Monday called for a more thorough investigation into the questioned flood control projects in Taguig…
The defense on Monday backed the move by senator-judges to exclude a prosecution witness who testified on the firearms…
From the foundation that these five imperatives have built, we’re now going down to the brass tacks.
We’ve identified a total of 10 areas of compliance, under which fall a total of 32 items that data handling organizations need to fulfill so as to be considered fully compliant with the Data Privacy Act of 2012. We’re calling this checklist the National Privacy Commission’s Data Privacy Accountability and Compliance Framework.
Over the coming months, I’ll use this space to discuss each of the 32 items in more detail — a sort of running brief for everyone, especially for our data handling organizations. We’ll also talk about ongoing campaigns and events that the NPC is spearheading, as well as offer explainers for issues that might come up. Suffice it to say that you’ll be hearing more from me and more about privacy, as we see privacy more and more in our daily lives.
Privacy Commissioner Raymund Liboro is a seasoned ICT convergence and communications and public administration professional.
He served as the former assistant secretary of the Department of Science and Technology for Climate Change Adaptation and Disaster Risk Reduction while concurrently the OIC director of the Science and Technology Information Institute.
Prior to joining government in 2010, he was involved in building multimedia platforms and IT startups.