DATA PRIVACY NOTICE

We, the City Government of Cagayan de Oro values your privacy and rights. It is our duty to give you assurance and confidence to notify you on the submitted data most specifically your given personal information as well as your sensitive personal information on how it is being collected, processed, kept, and disposed in the Higala App. This is also to inform you on your rights in accordance of the laws and regulations stated and specified in the Republic Act No. 10173 which is also known as the "Data Privacy Act of 2012 (DPA)" and with the pursuant to the NPC Advisory No. 2020-03 on the "Guidelines for workplace and establishments processing personal data for covid-19 response" in managing your personal solely for the contact tracing purpose that is necessary for the containment of the Covid-19 and other highly infectious diseases within the jurisdiction of Cagayan de Oro. Moreover, the processing of data is based on the City Ordinance No. 14023-2021 Series of 2021 entitled "An Ordinance Instituting the Higala Online Application (Higala App) as the principal contact tracing".

 

Definition of Terms:

  • Higala App – Cagayan de Oro City’s Higala Online Application is the primary system to be used for the contact tracing activity that is necessary for the containment of the Covid-19 and other infectious diseases within the jurisdiction of Cagayan de Oro;
  • Data Privacy Act (DPA) – refers to the Republic Act No. 10173 or the Data Privacy Act of 2012 and its implementing rules and regulations;
  • Processing – refers to any operation or set of operations performed upon personal data including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data. Processing may be performed through automated means, or manual processing, if the personal data are contained or are intended to be contained in a filing system;
  • Personal data – collectively refers to personal information, sensitive personal information, and privileged information;
  • Personal Information – refers to any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual;
  • Sensitive Personal Information refers to personal data:
    • About an individual’s race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;
    • About an individual’s health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such individual, the disposal of such proceedings, or the sentence of any court in such proceedings;
  • Personal Information Controller (PIC) - refers to a person or organization who controls the collection, holding, processing or use of personal information.
  • City Ordinance No. 14023-2021 - An ordinance instituting the Higala Online Application (Higala App) as the principal contact tracing system for Covid-19 Response Plan and other highly infectious diseases in the City of Cagayan de Oro, mandating all residents and non-residents to use it in entering all establishments, offices and other entities, whether public or private, and providing penalties for violation thereof.

 

What We Collect?

We collect the following personal information from you starting when you sign up or register an account and when you declare your entry on an establishment or any service entity through the Higala App for the Contact Tracing activities for the containment of the Covid-19 and other highly infectious diseases within the jurisdiction of Cagayan de Oro:

Individual Account:

  • Preferred username: to be used to log-in individual accounts to retrieve Personal Higala QR Code, Access function to read Service entity QR Codes, view transaction history at most 30days prior to the retrieval date, and view and update personal information.
  • Full Name: Consist of First Name, Middle Name, Last Name, and Name extension of the registering individual
  • Sex: Gender of the Individual
  • Birthdate: For age determination purposes (sensitive personal information);
  • Nationality: Nationality of the individual (sensitive personal information);
  • Contact Number: Valid and is currently being used to directly contact the individual for contact tracing purpose only; This contact number is being validated through a verification code function after registration;
  • Email: Email is not necessarily needed, but serves as a secondary contact for the individual; lost username will be sent here as well as Higala App notifications;
  • Address: Consist of Province, City or Municipality, and if a resident in Cagayan de Oro, the Barangay of the individual and the House # and Street to be used for contact tracing purpose only

 

Customer Information and Health Checklist when entering to an identified establishment (if Customer have Higala App Account):

  • Body Temperature: Body temperature of the individual upon declaration of entry in the establishment
  • Travel History in the Past 14 days
  • Covid-19 Symptoms: such as Headache, dry cough, difficulty in breathing, fever, sneezing
  • Covid-19 case exposure history
  • Mode of transportation prior to the declaration of entry of the establishment
  • Declaration of entry in the establishment/service entity: A proof of declaration will pop-out (Higala App ticket) after successfully declared entry by the Higala App.

 

Establishments and Service Entities (PUV, Cemetery, Churches, Hospitals, etc): Data below is needed to allow control of the establishment and service entity registration and avoid scams and spammers unauthorized to use such account type.

  • Preferred username: to be used to login the registered establishment/service facility account and retrieve your Establishment
  • Service Entity’s Name: Name of the service entity or establishment;
  • Service Entity’s Address: address of the service or establishment;
  • Service Entity’s Owner/Head: Manager, head or owner of the establishment or service entity that be directly contacted if contact tracing activity arises and is needed to coordinate in connection with the Higala app on the establishment or service entity level;
  • Service Entity’s Contact Number: active contact number and advisable to use a mobile number to not only receive Higala app notifications and registration confirmation messages but also to help the City Government directly contact the service entity or establishment if contact tracing activity arises and is needed to coordinate in connection with the Higala app on the establishment or service entity level;
  • Service Entity’s Email: active official email is needed and advisable not to use personal email of anyone; registration notification will be sent here; serves as secondary contact to the service entity or establishment;
  • Service Entity’s Service Category: to help controller track type of establishment and service entity registering as establishment/service entity in the Higala App;
  • Establishment’s Business Permit Number: to help controller track type of establishment and service entity registering as establishment/service entity in the Higala App;

 

WHY WE COLLECT YOUR PERSONAL DATA?

The collected data is solely used and processed for the recording and tracking for the emergency response of the City and for the contact tracing activity and other health related programs of the City Government that is necessary for the containment of the Covid-19 and other highly infectious diseases within the jurisdiction of Cagayan de Oro.
In accordance with your communication preferences, we will occasionally contact you to provide update status of your registrations, announce new features we build for you, if any, inform you of mandatory COVID-19 protocols, and share tips and information through the Higala App Facebook page and in other official webpages of the City Government of Cagayan de Oro.

 

HOW WE PROCESS YOUR PERSONAL DATA?

After registration, the data provided is kept in the Higala App and the data can only be processed through the Higala App.

Individual Accounts:
  1. Accessing, Processing, and Use:
    1. Scanning and Uploading of Higala QR Code:

      To record a transaction or visit of a certain establishment or service entity, the establishment or service entity will scan the individual Higala QR Codes that contain the individual’s Higala Unique Codes with Name of the person. The name of the individual will reflect in the Higala App scanner which the scanner can view the name of the individual or the owner of the Higala QR Code. The bearer or the owner of the Higala QR Code will also present the valid ID as mandated in the City Ordinance no. 14023-2021. This is to validate the bearer of the Higala QR Code is the owner of the Higala QR Code. 

      The scanned Higala QR Code will be saved in the establishment or service entity’s android device until it has been uploaded to the Higala App database server by the scanner. The scanned Higala QR Codes that are temporarily saved in the Higala App do not include the name of the individuals.

    2. Foot Traffic Report Generation:

      There are three account types for service entities: Establishment, Facility and Office. The uploaded Higala Unique Codes from the Higala QR Codes of the individuals will be processed by the system to produce reports. The following reports that can be viewed by the services entities are as follows:

      1. Foot Traffic By Time: The Establishment, Office, and Facility  account holders can view this report.This is a statistical report that displays how many males or females have been recorded at a certain time.
      2. Foot Traffic By Age: The Establishment, Office, and Facility  account holders can view this report. This is a statistical report that displays how many males or females have been recorded at a certain age.
      3. Foot Traffic Details: The Establishment  account holders can view this report. This is a detailed report without exposing the data subject's identity. It only displays the data subjects date and time the data subject got it, their address, age, and gender.

    3. Contact Tracing:

      The contact tracers specifically the CHO-HEMS under the City Health Office have their separate account to access certain personal information for the purpose of contact tracing only. Each contact tracer has their own account to access the data and all their search history is being recorded or tracked by the Data Processing System: Higala App as being developed.

      The contact tracers who has the contact tracing account can view the following data of the data subjects:

      1. Transactions done by the data subject to a certain service entity at a certain date and time.
      2. Data Subject’s Complete name, address, and contact number
      3. Information System Maintenance and Troubleshooting:s

        There will some instance especially when a needed updates or maintenance or troubleshooting is being made to fix glitches and bugs of the Higala App, the database of this system will be opened for investigation but encrypted personal information stored in the database cannot be accessed by the developer hence a dummy and replicated database structure will be used.

      4. Technical Support and Assistance

        Your data including your personal information and transactions recorded 30 days prior to the processing of data will be processed everytime a contact tracing activity is done by CHO-HEMS of the City. Moreover, your data will be processed for the covid-19 response plan by the respective data processor of the City Government of Cagayan de Oro.

        For lost or forgotten accounts, you can re-register in the Higala App.

        If the need for technical support arises, a consent will be asked from you to further assist you which will be done by the Higala App Technical Working Group, the City Tourism Office and the City Management Information System Office.

      5. Storage and Retention

        Recorded transactions can only be retrieved 30 days before the date of the retrieval. Transactions beyond 30 days are being deleted in an automated manner by the system. The personal information such as the accounts registered in the Higala App will remain. If Higala App can not anymore be used as per the City Ordinance of the Higala App’s scope, access of the Higala App will be blocked and database will be archived until Higala App is needed to roll back up again or if so any infectious diseases that need for contact tracing unless otherwise provided by laws, rules, and regulations..

        Moreover, the Higala App profile data will also be used for other health related programs of the City Government if so needed.


     

    Establishment Accounts or Service Entity Accounts:
    1. Recording :
    2. Your registration is being recorded by the system and only the assigned Data Controller as mentioned in the City Ordinance will access your data for validation and monitoring. Your transactions between your client and your establishment will also be recorded as it is being uploaded to our secured database.

    3. Processing :
    4. Your data including your personal information and transactions recorded 30 days prior to the processing of data will be processed everytime a contact tracing activity is done by CHO-HEMS of the City. Moreover your data will be processed for the covid-19 response plan by the respective data processor of the City Government of Cagayan de Oro.

      If the need for technical support arises, a consent will be asked from you to further assist you which will be done by the Higala App Technical Working Group, the City Tourism Office and the City Management Information System Office.



    HOW WE PROTECT YOUR DATA?

    The City Government of Cagayan de Oro through the Higala App Data Controllers and workforce enforces data privacy and information security policies. It implements the security measure for protection your personal as specified in the Implementing Rules and Regulations of Republic Act No. 10173 (Data Privacy Act of 2012) – organization security, physical security and technical security to protect your personal data against loss, misuse or misprocessed by any data controller, modification, unauthorized or accidental access or disclosure, alteration or destruction. We put safeguards such as the following:

      • We keep and protect data using a secured server behind a firewall, deploying encryption on computing devices and physical security controls
      • We restrict access to your personal data only to qualified and authorized personnel who hold your personal data with strict confidentiality and
      • We train our data controllers to properly handle and process your data

     

    BREACH AND SECURITY INCIDENTS: RISK INVOLVED IN PROCESSING

    The server manager/CMISO shall always maintain a backup file for all personal data under its custody. In the event of a security incident or data breach, it shall always compare the backup with the affected file to determine the presence of any inconsistencies or alterations resulting from the incident or breach.

    In case of a breach incident, the server manager/CMISO will report to the Data Protection Officer together with the responsible Compliance Officer for Privacy of the certain City Government Office for the notification protocol. The server manager/CMISO detailed documentation of the incident or breach encountered will be forwarded to the management and to the NPC depending on the City Government DPO’s advice.

     

    YOUR ROLE IN ENSURING THE COMPLETENESS, ACCURACY AND PROTECTION OF YOUR PERSONAL DATA

    You should ensure that personal data submitted to us is complete, accurate, true and correct. Failure on your part to do so may put you to an equivalent administrative penalty as you have agreed and understand and declared in the consent of your true and correct personal data.  We encourage you to be vigilant in protecting your personal data by practicing the following security protocols:

    • Never let anyone process your personal data other than the authorized person.
    • When connecting online to the Higala App, make sure you are connected using a known secure internet connection.
    • Protect your individual Higala QR Code as well as your account by putting effective secure password of your Higala Account.
    • Do not forget to logout your individual account especially when using multiple user computers.
    • Input only your personal contact number and email address as much as possible.

    We advise you to exercise caution in protecting yourself against phishing, skimming and other electronic fraud.

     

    HOW YOU MAY CONTACT US

    You as our Data Subjects have the following rights (RIGHTS OF DATA SUBJECTS):

    Personal information will be made available to the clients and authorized processors anytime in case there are requests for correction, modification or deletion.  It is the right of the individual owning the personal data to inquire or obtain a copy of the personal information provided to us.

     

    1.     The right to be informed, thus this Data Privacy Manual on how your personal information collected be processed through this Information System.
    2.     The right to access, thus you have the access of your personal details and account.
    3.     The right to object, thus you can the right not to submit the data so as not the data to be processed.
    4.     The right to erasure or blocking. Unless otherwise provided by laws, rules, and regulations.
    5.     The right to damages, thus you can request for assessment of your data that might be mishandled to our Data Privacy Officer.
    6.     The right to file a complaint, thus you can file a complaint to our Data Privacy Officer to any misused, maliciously disclosed, or improperly disposition of your data.
    7.     The right to rectify, thus you have the right to correct your submitted through the Higala App.

    For further inquiries or complaints, you may report or coordinate with our City Government’s Data Privacy Officer:

    Atty. Reymond Q. Villablanca
    Asst. City Legal Officer
    City Legal Office
    Ground Floor, Executive Building, City Hall, Cagayan de Oro City
    Email: dpo.cdo@gmail.com
    Contact Number: (088) 857-2260 / +63-960-902-1208

     

     

    CONSENT

    Submitting your data to the Higala App signifies that you have read and understood the above Data Privacy Notice and expressly consent to the processing of your personal and/or sensitive personal information in the manner and for the purpose provided in this Notice. You understand and accept that this will include access to personal data and records submitted, which may be regarded as personal and/or sensitive personal data for the sole purpose provided in this Notice in compliance with the Data Privacy Act of 2012 and for the compliance of the City Ordinance No. 14023-2021 Series of 2021.

     

     

    For complete reference on the Data Privacy Act, please visit the National Privacy Commission website at https://www.privacy.gov.ph/.

     

     

     

    (DPN version 2.0) Updated as of July 13, 2021.


Developed by the CITY MANAGEMENT INFORMATION SYSTEM OFFICE
© Copyright 2021. All Rights Reserved.
Version 1.0

Like us on facebook and be updated with us: