DATA PROTECTION Data privacy gives individuals control over their personal data, except in certain cases recognized by law. With that, it is significant in many ways. It protects individuals against unwarranted surveillance, identity theft, profiling, and discrimination, among others. As a key aspect of the right to privacy, it also allows individuals to exercise their other fundamental rights, like freedom of association and freedom of speech.¹⁹ Like FOI, proponents argue that it is essential to making democracy possible. Germany supposedly enacted the first data protection law in 1970.²⁰ As of 2017, there were already 114 data protection laws and 40 pending bills around the world.²¹ Practically all of them operate under certain principles popularized by the Organization for Economic Cooperation and Development, namely: (1) collection limitation; (2) data quality; (3) purpose specification; (4) use limitation; (5) security safeguards; (6) openness; (7) individual participation; and (8) accountability.²² The Philippines’s Data Privacy Act (DPA) was enacted in 2012. Patterned after the 1995 European Union (EU) Data Protection Directive, it lay dormant for four years before being put into action in 2016, with the appointment of the inaugural members of the National Privacy Commission (NPC), which is the agency tasked to administer its implementation. Notably, the DPA also recognizes the equally vital role of free information flows to society.²³ In general, entities covered by the DPA must ensure that their data processing activities are carried out in a manner consistent with the so-called data privacy principles²⁴ and the various criteria for processing personal data.²⁵ They ought to uphold the rights of individuals vis-à-vis their personal data,²⁶ and should put in place necessary and appropriate security measures.²⁷ Notably, the law does recognize exemptions, subject to certain conditions, including data that: (1) qualify as matters of public concern;²⁸ (2) are processed for journalistic, artistic, or literary purposes; and (3) are necessary for a public authority to carry out its constitutionally or statutorily-mandated functions.²⁹ ¹⁹ Banisar, D. and Davies, S. Op. cit. ²⁰ Werry N., Kirschbaum, B., et.al. (2017, December) The Privacy, Data Protection and Cybersecurity Law Review. 4th ed. thelawreviews.co.uk/edition/the-privacy-dataprotection-and-cybersecurity-law-review-edition4/1151282/germany ²¹ Banisar, D. (2010). Op. cit. ²² oecdprivacy.org/#principles ²³ Rep. Act No. 10173, Chap. I, §2 ²⁴ Rep. Act No. 10173, Chap. III, §11 ²⁵ Rep. Act No. 10173, Chap. III, §12, 13 ²⁶ Rep. Act No. 10173, Chap. IV, §16 ²⁷ Rep. Act No. 10173, Chap. V, §20 ²⁸ Rep. Act No. 10173, Chap. I, §4(a) ²⁹ Rep. Act No. 10173, Chap. I, §4(e) 4

Sélectionner le paragraphe cible3