As an educational institution that processes personal information for academic purposes, the Academy is duty bound to comply with all relevant privacy and data protection laws, particularly the provisions of Republic Act No. 10173 or the Data Privacy Act of 2012 (hereafter referred to as “DPA” for brevity) and its implementing rules. If you are a parent/legal guardian of an applicant, student, or alumni, who is a minor, know that this data privacy notice refers to the personal data of your child or ward.
As such, Forbes Academy, Inc. is issuing this Data Privacy Notice, which explains in general terms the legal bases for the processing of personal information that it collects from applicants, former and current students—collectively known as data subjects. It sets out the categories of personal data collected by the Academy and provides for the purpose and extent of processing, securing and disposing of such personal data. More importantly, it enumerates the rights and remedies that data subjects may exercise and avail of, respectively, in relation to the protection of their data privacy.
Personal Data or Information We Collect, Acquire, or Process
We collect, acquire, or process your personal data in various ways. They may consist of written documents, photographic and video images, digital material, and other kind of records. In particular, these data, documents, and images are provided to us during your application for admission, enrolment, and during the course of your stay with us. The following are examples:
- Personal details such as name, date and place of birth, gender, civil status, nationality, immigration status, religion and affiliations, disability;
- Contact information, such as addresses, email, mobile and telephone numbers, and social media accounts;
- Family background, including information on parents, guardians;
- Photographic and biometric data such as photos, CCTV videos, fingerprints, handwriting and signature specimens;
- Data issued by government agencies which include, but not limited to, social security numbers, passport identification numbers, health records, licenses, tax returns, criminal records and court proceedings;
- Employment information such as government-issued numbers, position, functions, employment history;
- Applicant information such as academic background, disciplinary records, interviews, entrance exam results, guidance assessments;
- Academic records such as transcript of records, certificate of graduation, diploma, academic history, grades, extra-curricular activities, school work;
- Disciplinary record, employment record, and medical records;
- Financial and billing information; and
- Other information obtained through interviews, during admission examinations and the course of your stay with us.
Methods of Data Collection
Forbes Academy collects personal data physically through printed forms, attachments and other documents; and electronically through online forms or via email.
Processing of Personal Data
Under the DPA, “processing” refers to any operation or any set of operations performed upon personal information including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.
Personal information shall only be processed if not prohibited by law and only when you have given your consent; pursuant to a contract with a data subject; for compliance with a legal obligation, for protection of vitally important interests, including life and health; respond to a national emergency; fulfill any legitimate interests pursued by Forbes Academy, except where such interests are overridden by your fundamental rights.
Sensitive personal information, such as age, date of birth, educational records, health records, shall only be processed with your consent, when such is allowed by law, when there is need to protect the life and health of the data subject or another person and you are unable to legally and physically express consent; for medical treatment; or for the protection of the rights and interests of natural or legal persons in court proceedings; for the establishment, exercise or defense of legal claims; or where required by government or public authority.
Purposes of Data Collection
To the extent allowed by law, Forbes Academy will use your personal data only to pursue legitimate interests as an educational institution, including for academic, administrative, research, and statistical purposes. The DPA imposes stricter rules for processing of sensitive personal information and privileged information, and we are committed to comply with those rules.
Personal data are collected in order for Forbes Academy to exercise its rights, fulfill its contractual obligations to you, to protect your interests, including your life and health, or for the pursuit of the legitimate interests of the Academy, and further its mission as a duly accredited higher education institution. Forbes Academy may require your consent for any specific use of your personal data.
Pursuant to Section 1, Rule V of the Implementing Rules and Regulations of the DPA, information obtained from you shall be processed for any of the following legitimate educational interests of the Academy:
- Processing of application for admission, employment and scholarships
- Verification of authenticity of records and documents
- Enrollment, registration, filing of leave of absence, application for graduation, application for board examinations, internships
- Academic purposes, such as monitoring student progress in order to customize current learning techniques based on students’ needs
- Provision of medical services and guidance counselling
- Provision of library services and research facilities
- Communicating official school announcements
- Conduct of trainings, seminars, benchmarking, outreach programs, academic and extra-curricular activities, graduation and commencement exercises
- Participation in inter-school competitions and athletic leagues
- Documentation for directories and alumni records
- Posting and/or publication of academic and non-academic achievements on announcement boards and on the Academy’s website, official social media accounts and official publications
- Accreditation purposes
- Enabling distance and flexible learning, including the use of personal information for online tools such as videoconferencing and education apps for synchronous and asynchronous learning
- Disclosure of personal data to proper authorities, such as the Commission on Higher Education which supervises and governs tertiary education, and the Department of Health, especially during health emergencies
- Maintaining safety and security
- Marketing and publicity of the Academy
- Research purposes, such as evaluation for the improvement of programs, services and facilities and professional development of faculty and staff
Storage of Personal Data
Personal Data are stored physically in file management systems organized and maintained by the Academy. Meanwhile, electronic records are stored in the servers, electronic devices, and cloud systems maintained and controlled by the Academy.
Disclosure of Personal Data
Forbes Academy shall disclose personal data under its control and custody without need for consent only to authorized recipients of such data, such as school officials who have legitimate educational interest in the data.
These include the Forbes Academy Board of Trustees and Officers, persons employed by the Academy in administrative, supervisory, academic, research and support staff positions, as well as those employed in contractual and consultancy positions such as an attorney, auditor, healthcare provider and security officer. Personal data shall also be shared with students serving in official organizations such as the student council.
The Academy shall also share your data externally to government and regulatory agencies such as the Department of Education, accrediting institutions and organizations and other learning service providers.
Otherwise, the Academy shall obtain your consent prior to sharing your personal information with third parties, and consent shall be specific to such purpose.
Retention of Data
Unless otherwise provided by law or policies issued by the Academy, the Academy shall retain the academic records of its students and graduates perpetually for documentation, historical and research purposes. Data shall be retained for as long as necessary for the fulfillment of the Academy’s legitimate interests.
When personal data is no longer needed, the Academy shall ensure that data are securely destroyed, shredded and permanently deleted.
Access to and Correction or Updating of Personal Data
You have the right to access any of your personal and sensitive personal information processed by the Academy by requesting documents from relevant offices or through the Academy’s information systems. For security purposes, the Academy shall require you to present proof of identification or other documents to verify your identity. Should you be unable to access them personally, the Academy shall require you to provide a letter of authorization, your school ID and the government-issued ID of your representative. The letter of authorization shall only be specific to such request.
The law defines “personal data breach” as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
In case of breach, the Academy shall take necessary steps to mitigate its harmful effects and shall notify you and the National Privacy Commission (NPC) within 72 hours upon knowledge of the breach. The Academy shall also notify you and the NPC when there is reasonable belief that a data breach has occurred.
Forbes Academy recognizes your rights with respect to your personal data, as provided by the DPA. If you wish to exercise any of your rights under the DPA, or if you have questions and concerns about the processing of your personal information, this Notice, or any matter involving data privacy and the Forbes Academy, you may contact the Data Protection Officer through any of the following channels:
Email to: email@example.com
Call: (052) 742-0317
The Data Protection Officer
Forbes Academy, Inc.
Lakandula Drive, Peñaranda St.,
Legazpi City, Albay 4500, Philippines
Amendments and Modifications
Forbes Academy reserves the right to modify or amend this Data Privacy Notice at any time and without prior notice. You will be notified by such amendments via the Academy’s website or through email.