Data Privacy Policy

Home 9 Data Privacy Policy

Our Lady of Fatima University

 Data Privacy Policy

PRIVACY STATEMENT

Pursuant to the mandate of the Data Privacy Act of 2012 (R.A. 10173), Our Lady of Fatima University (OLFU) affirms its dedication to safeguarding the confidentiality of information belonging to its stakeholders, including students, faculty members, non-teaching personnel, and service providers, whose personal data it gathers in furtherance of its legitimate interests and obligations as an educational institution.

Accordingly, the University has adopted policies and implemented measures designed to ensure the security and confidentiality of personal information that it collects, maintains, and stores, and which it may, under appropriate circumstances, disclose or share. These policies and measures are consistent with, and adhere to, the provisions of R.A. 10173 and its Implementing Rules and Regulations.

 

The Data Protection Officer
Our Lady of Fatima University
Email Address: dpo_olfu@fatima.edu.ph
Telephone: 661-3023 (loc. 137)

DATA PRIVACY POLICY

PRIVACY NOTICE

  1. Our Commitment to Data Privacy

Our Lady of Fatima University (OLFU) is committed to protecting the privacy, confidentiality, integrity, and security of the personal information entrusted to the University by its students, faculty members, administrators, employees, alumni, applicants, contractors, partners, service providers, and other stakeholders.

As a Personal Information Controller (PIC), OLFU processes personal data in accordance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations, applicable issuances of the National Privacy Commission (NPC), and the University’s policies and procedures on data privacy and information security.

This Privacy Notice explains what personal data the University collects, how and why it is processed, how it is stored and protected, with whom it may be shared, how long it is retained, and how data subjects may exercise their rights.

  1. Personal Data We Collect

Depending on the nature of the transaction, service, activity, or relationship with the University, OLFU may collect and process personal and sensitive personal information, including, where applicable:

A. Personal Information

  • Full name and other identifying information;
  • Contact information, including address, telephone number, and email address;
  • Date and place of birth;
  • Identification numbers and identification documents;
  • Academic and educational information;
  • Employment and personnel information;
  • Financial and payment-related information;
  • Information contained in applications, forms, records, and correspondence;
  • Photographs, videos, and other information collected during University activities and events;
  • Information contained in visitor logs and access records; and
  • Other information necessary and relevant to the legitimate functions and activities of the University.

B. Sensitive Personal Information

Where necessary and permitted by law, OLFU may process sensitive personal information, including:

  • Academic records;
  • Health and medical information;
  • Financial information;
  • Employment and personnel records;
  • Disciplinary records;
  • Information relating to affiliations, activities, or circumstances requiring special protection; and
  • Other sensitive personal information necessary for the legitimate functions of the University or required by law.

The University collects only information that is necessary and directly related to its legitimate functions and activities.

  1. How We Collect Personal Data

OLFU may collect personal data through lawful and appropriate means, including:

  • Enrollment, admission, registration, and other University forms;
  • Employment applications and personnel records;
  • Academic, medical, financial, and disciplinary records;
  • University websites, online systems, learning management systems, portals, and other digital platforms;
  • Direct communications with students, employees, applicants, alumni, parents, partners, and other stakeholders;
  • CCTV recordings and visitor logs;
  • Research surveys and evaluation instruments;
  • University events and activities; and
  • Other lawful sources necessary for the University’s legitimate functions.

Personal data may be collected directly from the data subject and, when lawful and necessary, from authorized representatives, government agencies, partner institutions, service providers, or other legitimate sources.

  1. Basis for Processing Personal Data

OLFU processes personal data only when there is a lawful basis for processing under the Data Privacy Act and other applicable laws and regulations.

Depending on the circumstances, the University’s processing may be based on:

  • Consent of the data subject, when consent is required by law;
  • Performance of a contract or agreement, including academic, employment, service, or other institutional relationships;
  • Compliance with a legal or regulatory obligation imposed upon the University;
  • Protection of vital interests, when applicable;
  • Performance of a function or mandate involving public authority, when applicable; and
  • Legitimate interests of the University or a third party, provided that such interests do not override the fundamental rights and freedoms of the data subject.

Where consent is the applicable legal basis, the data subject may withdraw consent subject to applicable laws and regulations and to legitimate consequences of such withdrawal.

  1. Purposes of Processing

OLFU collects and processes personal data for legitimate and specific purposes, including:

  • Student admission, enrollment, registration, and academic evaluation;
  • Employee recruitment, appointment, personnel administration, performance evaluation, and payroll management;
  • Provision of academic, administrative, health, guidance, student development, and other University services;
  • University research, accreditation, quality assurance, and institutional development;
  • Campus security, safety, and emergency management;
  • Compliance with legal, regulatory, accreditation, and reporting requirements;
  • Communication with students, employees, alumni, applicants, parents, partners, and other stakeholders;
  • Alumni and institutional relations;
  • Management of University events and activities;
  • Implementation and administration of learning management systems and other online platforms;
  • Management of health, safety, and security concerns;
  • Processing of applications, requests, inquiries, complaints, and other transactions; and
  • Other purposes that are compatible with the University’s legitimate functions and activities and are permitted by law.
  1. Primary and Secondary Uses of Personal Data

Primary Uses

Personal data are primarily used to perform the University’s academic, administrative, employment, regulatory, security, research, and institutional functions, including the delivery of services and fulfillment of obligations to students, employees, applicants, alumni, partners, and other stakeholders.

Secondary or Ancillary Uses

Where lawful and appropriate, personal data may also be used for:

  • University communications and institutional relations;
  • Alumni relations;
  • Accreditation and quality assurance activities;
  • Institutional research and development;
  • Public acknowledgment of students, alumni, faculty, and employees who participate in University activities or receive honors and awards;
  • Publication of photographs or videos for legitimate informational, marketing, or promotional purposes, subject to applicable privacy requirements; and
  • Other compatible purposes that are reasonably necessary for the University’s legitimate activities.

The University shall not process personal data for purposes incompatible with the original purpose of collection unless permitted by law or supported by an appropriate lawful basis.

  1. Disclosure and Sharing of Personal Data

OLFU may disclose or share personal data with third parties when such disclosure is lawful, necessary, and consistent with the purpose for which the information was collected or otherwise permitted by law.

These third parties may include:

Government and Regulatory Agencies

As required for legal, regulatory, accreditation, or reporting purposes, including, where applicable:

  • Commission on Higher Education (CHED);
  • Department of Education (DepEd);
  • Professional Regulation Commission (PRC);
  • Bureau of Internal Revenue (BIR);
  • Securities and Exchange Commission (SEC);
  • Social Security System (SSS);
  • Philippine Health Insurance Corporation (PhilHealth);
  • National Privacy Commission (NPC); and
  • Other government or regulatory agencies authorized by law.

Partner Institutions and Organizations

Personal data may be shared with partner institutions, organizations, OJT host companies, facilitating agencies, community partners, research partners, and other organizations when necessary for academic, research, training, community engagement, or other legitimate University activities.

Service Providers

Personal data may be disclosed to contracted third-party service providers that perform legitimate functions on behalf of the University, such as information technology systems, learning management systems, health services, insurance, and other institutional services.

Other Authorized Recipients

Information may also be disclosed when necessary for the management of health, safety, and security, including coordination with hospitals, clinics, law enforcement authorities, or other authorized parties, subject to applicable law.

Where required, data sharing or processing arrangements shall be governed by appropriate Data Sharing Agreements, Data Processing Agreements, contracts, or other lawful arrangements.

  1. Retention of Personal Data

OLFU retains personal data only for as long as necessary to fulfill the purposes for which they were collected, comply with legal and regulatory requirements, establish or defend legal claims, and meet legitimate institutional and operational requirements.

Retention shall be governed by the University’s approved Records Retention and Disposal Schedule, applicable laws, regulatory requirements, and legitimate institutional requirements.

Retention Periods

The applicable retention period shall depend on the category and nature of the personal data or record:

Record/Data Category

Basis

Student academic and institutional records

Quality Records Matrix and Retention Schedule/ applicable CHED and other requirements

Employee/personnel records

Quality Records Matrix and Retention Schedule / applicable labor, tax, and regulatory requirements

Financial and accounting records

Quality Records Matrix and Retention Schedule / applicable laws and regulations

Medical/health records

Quality Records Matrix and Retention Schedule / applicable laws and regulations

CCTV recordings

OLFU CCTV Policy / legitimate security purposes

Research records

OLFU Research/Records Retention requirements

Other institutional records

Quality Records Matrix and Retention Schedule and applicable requirements

When the retention period expires, personal data shall be securely disposed of or destroyed in accordance with the University’s approved disposal procedures.

  1. Storage and Security of Personal Data

OLFU stores personal data in physical and electronic formats and implements reasonable and appropriate organizational, physical, and technical measures to protect personal data against unauthorized access, alteration, disclosure, loss, destruction, or other unlawful processing.

Security measures include, as applicable:

  • Access controls and authorization procedures;
  • Restricted access to authorized personnel;
  • Strong password and authentication controls;
  • Encryption and secured servers;
  • Physical security controls;
  • CCTV and campus security measures;
  • Regular data privacy and security training;
  • Backup and data recovery procedures;
  • Security and access monitoring;
  • Policies and procedures governing the handling of personal data; and
  • Other appropriate organizational, physical, and technical safeguards.

Access to personal data is limited to personnel and authorized parties who have a legitimate need to access such information.

  1. Secure Disposal and Destruction

When personal data are no longer necessary or when the applicable retention period has expired, OLFU shall ensure their secure disposal or destruction in a manner that prevents unauthorized recovery, access, use, disclosure, or reconstruction.

Depending on the format and nature of the records, secure disposal may include:

  • Physical records: shredding, secure destruction, or other methods that render the information unreadable or irretrievable;
  • Electronic records: secure deletion, wiping, destruction of storage media, or other appropriate methods that prevent unauthorized recovery; and
  • Devices or storage media: secure disposal or destruction consistent with applicable information security procedures.

Disposal shall be undertaken only by authorized personnel or authorized service providers and shall be properly documented where required by University policy.

  1. Automated Access and Digital Systems

OLFU uses online systems and digital platforms in the performance of its academic, administrative, research, communication, and institutional functions.

Where automated access, retrieval, profiling, or other automated processing mechanisms are utilized, the University shall implement appropriate access controls and security measures and shall process personal data in accordance with the Data Privacy Act and applicable regulations.

Where applicable, data subjects shall be informed of the existence and nature of automated processing when such processing produces legal or similarly significant effects on them.

  1. Risks in the Processing of Personal Data

The University recognizes that personal data may be exposed to risks throughout its life cycle, including during collection, transmission, access, use, storage, sharing, retention, and disposal.

Potential risks include:

  • Unauthorized access or disclosure;
  • Loss, theft, alteration, or destruction of personal data;
  • Accidental disclosure or misdelivery;
  • Unauthorized copying or use;
  • Cybersecurity incidents or malicious attacks;
  • Improper retention or disposal;
  • Unauthorized access to physical or electronic records; and
  • Other forms of unlawful or unauthorized processing.

OLFU continuously assesses and manages these risks through appropriate organizational, physical, and technical safeguards.

  1. Measures to Address Privacy and Security Risks

To address identified risks, OLFU implements appropriate safeguards, including:

  • Data privacy policies and procedures;
  • Access controls based on legitimate need;
  • Confidentiality obligations for authorized personnel;
  • Information security controls;
  • Encryption and secure systems, where appropriate;
  • Physical security controls;
  • Backup and recovery mechanisms;
  • Regular data privacy and security awareness and training;
  • Incident and data breach response procedures;
  • Monitoring and review of privacy and security controls; and
  • Appropriate agreements with third parties that process personal data on behalf of the University.

In the event of an actual or suspected personal data breach, OLFU shall implement its Data Breach Response Protocol and comply with applicable notification and reporting requirements.

  1. Personal Information Controller

Our Lady of Fatima University (OLFU) is the Personal Information Controller (PIC) responsible for determining the purposes and means of processing personal data within the University’s legitimate functions and activities.

Our Lady of Fatima University
120 MacArthur Highway
Barangay Marulas, Valenzuela City,
1440 Metro Manila

  1. Data Protection Officer

The University has designated a Data Protection Officer (DPO) who oversees and monitors the University’s compliance with applicable data privacy laws, regulations, and policies.

Data Protection Officer
Our Lady of Fatima University
Email: dpo_olfu@fatima.edu.ph
Telephone: 661-3023 local 137

Data subjects may contact the DPO regarding privacy concerns, requests, complaints, or questions relating to the processing of their personal data.

  1. Rights of Data Subjects

In accordance with the Data Privacy Act of 2012 and applicable regulations, data subjects have rights relating to their personal data, including:

Right to Be Informed
The right to be informed about the collection and processing of personal data, including the purposes, methods, and other relevant information concerning the processing.

Right to Access
The right to obtain reasonable access to personal data concerning the data subject and information about how such data are being processed.

Right to Object
The right to object to the processing of personal data under circumstances recognized by law.

Right to Rectification or Correction
The right to dispute and request correction of inaccurate or erroneous personal data.

Right to Erasure or Blocking
The right to request the suspension, withdrawal, blocking, removal, or destruction of personal data under circumstances provided by law.

Right to Data Portability
The right to obtain personal data in an accessible and usable format and to transmit such data to another personal information controller, where applicable under law.

Right to Damages
The right to seek compensation for damages sustained due to unlawful processing of personal data or violation of rights under the Data Privacy Act.

Other Rights Recognized by Law
Data subjects shall likewise enjoy other rights recognized under the Data Privacy Act, its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission.

  1. How to Exercise Your Data Privacy Rights

A data subject who wishes to exercise a privacy right or submit a privacy-related request or complaint may submit a written request to the Data Protection Officer through:

Email: dpo_olfu@fatima.edu.ph
Telephone: 661-3023 local 137

Requests should, where applicable, contain sufficient information to:

  • Identify the data subject;
  • Describe the personal data or processing involved;
  • Clearly identify the right being exercised or the concern being raised;
  • Provide relevant supporting information or documents; and
  • Provide contact information through which the University may communicate with the requesting data subject.

The University may require reasonable verification of the identity and authority of the requesting individual before releasing, correcting, deleting, or otherwise acting upon personal data.

Requests shall be evaluated and acted upon in accordance with applicable laws, regulations, University policies, and the rights and legitimate interests of the data subject and the University.

  1. Complaints and Privacy Concerns

Any data subject or stakeholder who has concerns regarding the University’s processing of personal data, or who believes that personal data have been processed in violation of applicable privacy laws or University policies, may submit a written complaint to the Data Protection Officer.

Suspected or actual personal data breaches should be reported immediately to the Data Protection Officer for proper assessment, documentation, containment, and appropriate action.

The University shall implement its applicable Data Breach Response Protocol and comply with reporting and notification requirements prescribed by law and the National Privacy Commission.

  1. Changes to this Privacy Notice

OLFU may update or amend this Privacy Notice from time to time to reflect changes in applicable laws, regulations, University policies, systems, processes, or data processing activities.

The latest version of this Privacy Notice shall be made available through the University’s official website and other appropriate channels.

  1. Contact Us

For questions, requests, complaints, or concerns regarding the University’s processing of personal data, please contact:

DATA PROTECTION OFFICER
Our Lady of Fatima University
Email: dpo_olfu@fatima.edu.ph
Telephone: 661-3023 local 137

Our Lady of Fatima University
Data Privacy Office