DATA PROTECTION
Data privacy gives individuals control over
their personal data, except in certain cases
recognized by law. With that, it is significant
in many ways. It protects individuals against
unwarranted surveillance, identity theft,
profiling, and discrimination, among others.
As a key aspect of the right to privacy, it also
allows individuals to exercise their other
fundamental rights, like freedom of
association and freedom of speech.¹⁹ Like
FOI, proponents argue that it is essential to
making democracy possible.
Germany supposedly enacted the first data
protection law in 1970.²⁰ As of 2017, there
were already 114 data protection laws and
40 pending bills around the world.²¹
Practically all of them operate under certain
principles popularized by the Organization
for Economic Cooperation and Development,
namely: (1) collection limitation; (2) data
quality; (3) purpose specification; (4) use
limitation; (5) security safeguards; (6)
openness; (7) individual participation; and
(8) accountability.²²
The Philippines’s Data Privacy Act (DPA) was
enacted in 2012. Patterned after the 1995
European Union (EU) Data Protection
Directive, it lay dormant for four years before
being put into action in 2016, with the
appointment of the inaugural members of
the National Privacy Commission (NPC),
which is the agency tasked to administer its
implementation. Notably, the DPA also
recognizes the equally vital role of free
information flows to society.²³
In general, entities covered by the DPA must
ensure that their data processing activities
are carried out in a manner consistent with
the so-called data privacy principles²⁴ and
the various criteria for processing personal
data.²⁵ They ought to uphold the rights of
individuals vis-à-vis their personal data,²⁶ and
should put in place necessary and
appropriate security measures.²⁷ Notably, the
law does recognize exemptions, subject to
certain conditions, including data
that: (1) qualify as matters of public
concern;²⁸ (2) are processed for journalistic,
artistic, or literary purposes; and (3) are
necessary for a public authority to carry out
its constitutionally or statutorily-mandated
functions.²⁹
¹⁹ Banisar, D. and Davies, S. Op. cit.
²⁰ Werry N., Kirschbaum, B., et.al. (2017, December) The
Privacy, Data Protection and Cybersecurity Law Review. 4th
ed. thelawreviews.co.uk/edition/the-privacy-dataprotection-and-cybersecurity-law-review-edition4/1151282/germany
²¹ Banisar, D. (2010). Op. cit.
²² oecdprivacy.org/#principles
²³ Rep. Act No. 10173, Chap. I, §2
²⁴ Rep. Act No. 10173, Chap. III, §11
²⁵ Rep. Act No. 10173, Chap. III, §12, 13
²⁶ Rep. Act No. 10173, Chap. IV, §16
²⁷ Rep. Act No. 10173, Chap. V, §20
²⁸ Rep. Act No. 10173, Chap. I, §4(a)
²⁹ Rep. Act No. 10173, Chap. I, §4(e)
4