Daily Tribune

Archive

DPO COMPLex and the NPC’s responsive regulation

Raymund E. Liboro · Nov 14, 2019, 12:18 AM

Compliance itself is a journey and takes some time to perfect. We understand that. And that is why the NPC, despite being a regulator, endeavors hard to act supportively.

Following a marked improvement in the registration of data protection officers in the public sector, the National Privacy Commission (NPC) capitalized on the momentum by conducting the DPO COMPLex experiential compliance workshop at the Luxent Hotel in Quezon City.

Consistent with our philosophy of responsive regulation and inclusive stakeholder engagement, the DPO COMPLex is borne of insights gathered from government DPO themselves during our focus group discussions with them. One of its unique features is our experiential approach, which is more pro-active, hands-on and applied. Its most distinct aspect, however, is the fact that it is spearheaded by our Compliance and Monitoring Division, which means it’s not just another seminar but a compliance support activity — a rare chance to see your organization’s compliance through the lens of NPC officers who validate it.

Looking at our year-on-year DPO registration data, we’ve seen a very reassuring improvement. State universities and colleges (SCU) saw the biggest jump in the number of registered entities, jumping to 87 percent. National government agencies (NGA) are next at 73 percent, followed closely by government owned and controlled corporations (GOCC) at 72 percent, while local government units (LGU) are at 39 percent.

In contrast, NPC’s data in November 2018 show that registered DPO from SUC were only at 6 percent, NGA at 5 percent, GOCC at 17 percent, while that of LGU was at 12 percent.

What happened in between the jump in numbers, I believe, can be attributed, among other things, to the commission’s enhanced compliance program launched beginning last January, which culminated in the First Digital Data Governance for the Public Sector Conference held alongside other events during the Privacy Awareness Week last May.

Now, what all this means is that, undoubtedly, and encouragingly, privacy compliance awareness in the government is growing. On the flipside, however, it also means that the NPC’s work has just begun, and that a steep, arduous climb is up ahead. Realizing this, we forge ahead with the DPO COMPLex to guide those who are eager to comply and hopefully make model organizations out of them.

In its first iteration, the DPO COMPLex was designed to help government DPO in facing current challenges when instituting compliance-related measures and activities.

By the end of this experiential workshop, participants are expected to be better equipped on how to prepare and maintain records of processing activities of their agencies and create multilayered privacy notices using these, as well as perform a privacy impact assessment in accordance with NPC Advisory 17-03.

They are also expected to hone their skills at identifying the appropriate criteria or legal basis for their agency’s personal data processing activities; employing security measures required under NPC Circular 16-01 on security of personal data in government agencies; as well as preparing and implementing data sharing agreements in accordance with NPC Circular 16-02, when applicable.

Lastly, participants are also expected to gain a better understanding of how to establish personal data breach management procedures for their respective agencies in accordance with NPC Circular 16-03.

Compliance itself, however, is a journey and takes some time to perfect. We understand that. And that is why the NPC, despite being a regulator, endeavors hard to act supportively. We shall be punitive when we must, but we shall never tire of coming out with programs like the DPO COMPLex, the DPO ACE certification, and the DPO Briefing. After all, we are all data subjects and each organization’s compliance is for everyone’s good.

If you have questions or concerns, you may contact the National Privacy Commission via 234-22-28 (local 114) or email info@privacy.gov.ph.