Archive
Complying, step one: The DPO
The amount of information we put out about ourselves today is tremendous – social media has our personal details while specialized platforms like banking and ridesharing apps use both our personal and sensitive information.
The freer flow of data that technology has enabled today has largely been to our benefit. At the same time, it also means our information is vulnerable to abuse by unscrupulous entities.
It means our National Privacy Commission (NPC), a still-small entity by any measure, has a lot of ground to cover. That’s why we need advocates – data protection officers (DPO).
The appointment of a DPO is a legal requirement for public and private organizations that process and control the information of individuals, as specified in Section 4 of NPC’s Circular 16-01. It’s also the first key principle of our 32-point framework on Data Privacy Accountability and Governance, the rest of which will be discussed in my next columns.
Designating a DPO is a way to centralize all data privacy measures, ensure compliance with the Data Privacy Act (DPA) and drive greater awareness of privacy and data protection in their organizations. For consumer-facing companies, it can also be a key differentiator and strategic advantage – people want to know their interests are being protected, after all.
In NPC’s Advisory 2017-01, we made it a point to state that a DPO should be allowed a significant level of independence and autonomy from top management in exercising his or her functions within the organization. Although he or she may take on other functions and roles, they should make sure it will not give rise to any conflict of interest.
A DPO is responsible for monitoring his or her organization’s compliance with the DPA of 2012, its IRR, issuances by the Commission and other applicable laws and policies.
For this purpose, he or she may collect and maintain a record of information; analyze and check the compliance of processing activities, such as security clearances and compliance of third-party service providers; inform, advise and issue recommendations; ascertain renewal of accreditations or certifications, and advise top management about the importance of executing a data sharing agreement with third parties.
Part of the DPO’s mantle is ensuring the conduct of a privacy impact assessment; advising management on data subjects’ complaints and requests; ensuring proper data breach and security management; informing and cultivating awareness on data privacy and protection within the organization, and advocating the development, review and/or revision of policies, guidelines, projects and/or programs of the organization. Additionally, the DPO serves as his or her organization’s focal person attending to the needs of data subjects, the NPC, and other authorities involved in data privacy and protection.
Correspondingly, top management must involve the DPO in all issues related to data privacy and protection in their organization from the get-go. The DPO must be consulted by management in the event of a personal data breach or security incident and must be granted sufficient time, resources and access to the matter at hand for the effective and efficient completion of tasks.
In December, the NPC launched the pilot class of the DPO Accountability, Compliance and Ethics program which is designed to establish a skills benchmark from local privacy professionals. Fifty DPO from government and the private sector attended an intensive series of workshops on ethical data processing – not just talks, but also advanced case studies, practical exercises and written exams. One participant even said, “The breach is just a drill, but the pressure is real.”
The pressure is, indeed, real – and that’s why we’ve put our energy into launching programs like this. The DPO ACE program will be publicly available to all interested DPO this year. We welcome everyone to participate in it.
For news and updates, like the NPC’s page on Facebook.
Email info@privacy.gov.ph for comments and questions.