BACKGROUND
The Republic Act No. 10173 also known as the Data Privacy Act of 2012 which requires the government and the private sector to follow and comply to fulfill their objective to protect personal data in information and communications systems.
With this, it ensures that entities of the Local Government Unit of San Enrique to implement measures and procedures that guarantee the safety and security of personal data under their control or custody and thereby upholding an individual’s data privacy rights; this also applies the principles of Transparency, Legitimate Purpose, and Proportionality in processing of the personal data submitted and stored in the information and communication system.
This Manual serves as a guide or handbook for ensuring the compliance and the Municipal Government with the Data Privacy Act and its Implementing Rules and Regulations (IRR). This also encapsulates the privacy and data protection protocols that is being observed and is being carried out within this entity for specific circumstances (e.g., from collection to destruction), directed toward the fulfillment and realization of the rights of data subjects.
INTRODUCTION
We, the Local Government Unit of San Enrique respects and values your data privacy rights. It is our duty to give you assurance and confidence to notify you on the submitted with data most specifically your given personal information on how it is being collected, processed, and kept. This is also to inform you on your rights in accordance of the laws and regulations stated and specified in the Republic Act No. 10173 which is also known as the “Data Privacy Act of 2012 (DPA)”.
DEFINITION OF TERMS
SCOPE AND LIMITATIONS
All personnel of the Local Government Unit of San Enrique especially the office processing the data, regardless of the type of employment or contractual arrangement, must comply with the terms set out in this Data Privacy Manual. This Data Privacy Manual is publicly posted for the information and transparency of the data being processed through the information systems with the data processors identified in the next section of this manual.
[Can also include here the purpose of the IS on highlighting the scope of the data being processed within the IS]
PROCESSING OF PERSONAL DATA: WHAT WE PROCESS, HOW WE PROCESS, WHO WILL PROCESS, WHY WE PROCESS
The processing office with the processor collects the information required in the Pre-Marriage Counseling Online Application. The information provided and submitted by the clients, including their [full name, address, email address, contact number, birthday and other personal data together with their attached documents and the kind of request or process selected]. The information system stores the personal data in the database system assigned for this information system respectively and is being protected through the security protocol set out by the server where the database system is located to give assurance that the data will be protected and secured.
Personal data collected shall be used accordingly base on the data subject’s request as well as for the processing office and the Municipal Government records which is as follows:
The processor as well as the information system will ensure that personal data under its custody are protected against any other unlawful processing (misused, modified, interfered, lost or disclosed to unauthorized processors without the Data Sharing Agreement).
The implementation and the management of the information system shall have security practices and processes such as but not limited to the following:
The personal data shall be kept and maintained up to a certain period or as long as necessary for the purpose for which they were collected or as required by laws and regulations.
[Add retention period here.]
Due to the sensitive and confidential nature of the personal data under the custody of the Municipal Government, only the client/data subject and the authorized processor shall be allowed to access such personal data, for any purpose, except for those contrary to law, public policy, public order or morals. The authorized processor of this information system are as follows:
All processors shall maintain the confidentiality and secrecy of all personal data that come to their knowledge and possession, even after resignation, termination of contract, or other contractual relations. Personal data under the custody of the Municipal Government shall be disclosed only pursuant to a lawful purpose, and to authorized recipients of such data.
SECURITY MEASURED: HOW WE PROTECT YOUR DATA
The Data Privacy of the Municipal Government is being managed by the registered Data Protection Officer, Mrs. Elena Martirizar. The Data Protection Officer who is being assisted by the Compliance Officer for Privacy of each Municipal Government Offices/Department, shall oversee the compliance of the organization with the DPA, its IRR, and other related policies, including the conduct of a Privacy Impact Assessment, implementation of security measures, security incident and data breach protocol, and the inquiry and complaints procedure. All employees will be asked to sign a Non-Disclosure Agreement. All employees with access to personal data shall operate and hold personal data under strict confidentiality if the same is not intended for public disclosure.
Personal data in the custody of the organization may be in digital/electronic format and paper-based/physical format. All personal data being processed by the organization shall be stored in a data room, where paper-based documents are kept in locked filing cabinets while the digital/electronic files are stored in secured server managed by the [who manages the server of this IS]. And only the authorized personnel have the access of the server with the level of access permission.
BREACH AND SECURITY INCIDENTS: RISK INVOLVE IN PROCESSING
The [server manager/CMISO] shall always maintain a backup file for all personal data under its custody. In the event of a security incident or data breach, it shall always compare the backup with the affected file to determine the presence of any inconsistencies or alterations resulting from the incident or breach.
In case of breach incident, the [server manager/CMISO] will report to the Data Protection Officer together with the responsible Compliance Officer for Privacy of the certain Municipal Government Office for the notification protocol. The [server manager/CMISO] detailed documentation of the incident or breach encountered as will be forwarded to the management and to the NPC depending on the Municipal Government DPO’s advise.
HOW MAY CONTACT US FOR INQUIRIES AND COMPLAINTS
You as our Data Subjects have the following rights (RIGHTS OF DATA SUBJECTS):
Personal information will be made available to the clients and authorized processors anytime in case there are requests for correction, modification or deletion. It is the right of the individual owning the personal data to inquire or obtain a copy of the personal information provided to us.
The right to rectify, thus you have the right to correct your submitted through [the system or through the data information processor].
For further inquiries or complaints, you may report or coordinate with our Municipal Government’s Data Privacy Officer:
Elena Martirizar
Public Information Officer
Ground Floor, Municipal Hall, San Enrique, Iloilo
Email: dpo@sanenriqueiloilo.com
Contact Number:
EFFECTIVITY OF THIS DATA PRIVACY MANUAL:
The provisions of this Manual are effective this June day of 29, 2021, until revoked or amended by this entity, the Local Government Unit of San Enrique.
DPM Version 1.0 as of June 29, 2025