In the Philippines, the law governing data protection policy in the workplace is the Data Privacy Act of 2012 (DPR) and its implementing rules and regulations (IRR). Employers are required to comply with the principles set out in the DPA and IRR, especially regarding the collection, use, storage, and disposal of personal information about employees and job applicants. It emphasises the importance of adherence to general data privacy principles and outlines specific obligations for personal information controllers and processors, including those operating within workplace environments.
The law requires that any personal information collected by employers must be relevant and necessary for their declared purpose and must be processed lawfully in a way that respects the rights of data subjects. Employers are also tasked with implementing reasonable and appropriate organisational, physical, and technical measures to protect personal data from unauthorised access, use, disclosure, or destruction.
It also establishes the necessity for organisations to create, implement, and maintain a data protection policy that outlines their data management practices. This policy should cover consent forms for the collection and use of personal data, a list of policies and procedures related to privacy and data protection, and specific procedures for dealing with information requests from parties other than the data subjects, such as the media, law enforcement, and other representatives.
To ensure compliance, organisations must appoint a Data Protection Officer (DPO) responsible for overseeing data protection measures and policies within the organisation. This responsibility extends to ensuring that personal data is processed transparently, lawfully, and securely, minimising the risks of unauthorised access and data breaches.
Philippine data protection authority
The primary data protection authority in the Philippines is the National Privacy Commission (NPC). The NPC is responsible for ensuring the protection of personal data and upholding individuals’ privacy rights. It does so by overseeing the enforcement of the Data Privacy Act of 2012, which aims to protect personal information maintained by government and private sector entities, including in the workplace.
The NPC plays several roles in protecting data in the workplace, including:
- Regulation and compliance: It regulates and monitors the compliance of personal information controllers and processors to ensure that personal data is being processed lawfully, fairly, and securely. This includes issuing advisories and circulars to guide entities on best practices for data protection.
- Culture building: The NPC promotes developing a culture of privacy through awareness and empowerment. It organises campaigns and activities to educate both the public and private sectors about their rights and obligations under the Data Privacy Act.
- Accountability and enforcement: The NPC has the authority to conduct investigations, audits, and inquiries in the event of a data breach or complaint. The NPC has the authority to recommend the prosecution of offenders and guarantee the indemnity of victims of privacy violations.
- Policy development: The NPC also plays a critical role in developing policies, guidelines, and frameworks for data protection, including in the workplace. This helps organisations align their operations with best practices in data privacy and security.