Data Privacy Policy
Our Lady of Fatima University
Data Privacy Policy
PRIVACY STATEMENT
Pursuant to the mandate of the Data Privacy Act of 2012 (R.A. 10173), Our Lady of Fatima University (OLFU) affirms its dedication to safeguarding the confidentiality of information belonging to its stakeholders, including students, faculty members, non-teaching personnel, and service providers, whose personal data it gathers in furtherance of its legitimate interests and obligations as an educational institution.
Accordingly, the University has adopted policies and implemented measures designed to ensure the security and confidentiality of personal information that it collects, maintains, and stores, and which it may, under appropriate circumstances, disclose or share. These policies and measures are consistent with, and adhere to, the provisions of R.A. 10173 and its Implementing Rules and Regulations.
The Data Protection Officer
Our Lady of Fatima University
Email Address: dpo_olfu@fatima.edu.ph
Telephone: 661-3023 (loc. 137)
DATA PRIVACY POLICY
Statement of Commitment
Our Lady of Fatima University upholds its dedication to safeguarding the privacy of its stakeholders, encompassing students, faculty members, administrators, employees, alumni, applicants, contractors, and partners whose personal data it gathers in furtherance of its legitimate interests and obligations as an academic institution, in accordance with the Data Privacy Act of 2012 and its Implementing Rules and Regulations (DPA IRR).
Scope
This Policy applies to all students, faculty members, administrators, employees, alumni, applicants, contractors, partners, and other individuals whose personal data are collected, processed, and stored by the University. It covers all personal information systems maintained by OLFU, whether electronic or manual, and extends across the life cycle of information, from collection, creation, storage, use, distribution, and disposal. Failure to comply with this Policy may constitute misconduct and may result in appropriate disciplinary action.
Principles
A. Collection and Use of Personal Information
The University only collects personal information that is necessary and directly related to one or more of its legitimate functions and activities as an academic institution, such as:
-
- Enrollment, admission, and registration forms;
- Employment applications and personnel records;
- Academic, medical, financial, and disciplinary records;
- Online systems and digital platforms;
- CCTV recordings and visitor logs; and
- Research surveys and evaluation instruments.
Personal data collected shall be processed only for legitimate purposes, including but not limited to:
-
- Student admission, registration, and academic evaluation;
- Employee recruitment, performance evaluation, and payroll management;
- University research, accreditation, and quality assurance;
- Campus security and safety management;
- Compliance with legal, regulatory, and accreditation requirements; and
- Communication, alumni relations, and institutional development.
B. Sharing of Personal Information
The University will share information with other parties in the pursuit of its legitimate interests and responsibilities as an educational institution, in accordance with regulations prescribed by law. Personal data may be shared with:
-
- Government agencies (e.g., CHED, DepEd, PRC, NPC) for regulatory compliance;
- Partner institutions for academic collaborations or internships; and
- Third-party service providers for legitimate University functions (e.g., IT systems, health insurance).
Examples of such situations are:
-
- Fulfillment of reporting requirements by mandated government bodies such as CHED, DepEd, PRC, BIR, SEC, SSS, PhilHealth, and the NPC;
- Communicating with other parties in fulfilment of curricular requirements relevant to a student’s course of study, such as OJT host companies or facilitating agencies, or partner organizations for community outreach work or academic collaboration;
- Implementation of a learning management system or other online platforms using proprietary software, through a contracted external service provider;
- Management of health, safety, and security of students, faculty, and employees, such as coordination with hospitals, clinics, or the police;
- Public acknowledgment and publication of photographs or videos of university students, alumni, faculty, and employees, taken in the course of their participation in a University event or as recipient of honors and awards, for informational, marketing, and promotional purposes; and
- Confirmation of the status as student, alumnus, or employee of the University in response to inquiries from other parties.
Data sharing is governed by a Data Sharing Agreement or Data Processing Agreement, ensuring compliance with data privacy principles.
C. Retention of Personal Information
All personal data shall be stored securely in both physical and electronic forms.
-
- Access is limited to authorized University personnel only.
- Retention shall follow the University’s records management policy and applicable laws.
- Disposal or destruction of records shall be done in a secure manner to prevent unauthorized access.
D. Access to, Correction, Blocking, or Deletion of Personal Information
The University upholds the rights of data subjects. Upon request, the University will allow access to a data subject’s own personal information and/or have it corrected, blocked, or deleted, unless there is a legitimate reason for refusal. Under the DPA, data subjects have the following rights:
-
- Right to be informed – to know how personal data is collected and used;
- Right to access – to request access to their personal data;
- Right to object – to withhold consent to data processing under certain conditions;
- Right to erasure or blocking – to request deletion or blocking of inaccurate or outdated data;
- Right to damages – to be indemnified for damages due to unlawful processing; and
- Right to data portability – to obtain and reuse personal data for other services.
E. Handling of Complaints and Data Security Breaches
All University stakeholders who become aware of a suspected or actual breach in data security must immediately bring it to the attention of the Data Protection Officer, in writing or by email, for proper recording and reporting to the National Privacy Commission, in accordance with the Data Privacy Act of 2012 and its Implementing Rules and Regulations.
In the event of a data breach, the University shall follow its Data Breach Response Protocol:
-
- Immediate containment and assessment;
- Notification of affected individuals and the NPC within 72 hours, as required; and
- Investigation and remediation measures.
The University likewise adopts appropriate organizational, physical, and technical security measures, including strong passwords, encryption, and secured servers; access control and regular data protection training; CCTV monitoring and physical security controls; and backup systems and data recovery procedures.
Note: All requests or complaints regarding data privacy must be submitted in writing to the Data Protection Officer, through the contact details indicated above.
Our Lady of Fatima University
Data Privacy Office | Email: dpo_olfu@fatima.edu.ph | Telephone: 661-3023 (loc. 137)