Privacy Policy
PRIVACY POLICY NOTICE FOR APPLICANTS, STUDENTS, AND ALUMNI
STATEMENT OF PRIVACY POLICY
Manila Central University (MCU) is committed to protecting the privacy of its data subjects and ensuring the safety and security of their personal data under its control and custody. This policy provides information on how MCU will collect, use, process, share, secure and dispose of personal data, in accordance with Republic Act. No. 10173, also known as the Data Privacy Act of 2012 and its Implementing Rules and Regulations.
This Data Privacy Notice may be amended at any time without prior notice, and such amendments will be notified to you through MCU’s website.
PRIVACY NOTICE
a. Data Collected and Manner of Collection
We collect your personal data that include those you submit to us manually or electronically during your application for admission, upon your enrollment, during your stay with us, and after graduation as an MCU alumnus or alumna. This will include, but not limited to:
- Names, addresses, telephone numbers, email addresses, and other contact details;
- Personal information, such as date and place of birth, nationality, immigration status, religion, civil status, student ID, government-issued IDs, web and social media information, recommendations and assessment forms from previous schools, and other similar documents;
- Family background, including information on parents, guardians, siblings, related MCU alumni;
- Health records, psychological evaluation results, disciplinary records and the like;
- Photographic and biometric data, such as photos, audio visual information, CCTV videos, fingerprints, handwriting, and signature specimens;
- Academic or curricular undertakings, school works, including data from third party online learning and video recording tools, performance assessments and attendance records;
- Financial and billing information;
- Information to support student’s well-being and to provide medical, dental services, and guidance counseling;
- Co-curricular matters such as outreach activities, as well as extra-curricular activities such as membership in student organizations, leadership positions, and participation and attendance in seminars, competitions, and programs, resumes, job interview forms; and
- Any additional information provided to us by the student in the course of enrollment and after graduation.
These personal data are collected through the MCU ERP System (Applicant and Student Portal), Microsoft Teams, and through physical controlled forms submitted to the various offices of the University. In certain instances, personal data may also be obtained from third parties, such as parents or guardians, previous schools, government agencies, or other authorized sources, when necessary for legitimate academic, administrative, or regulatory purposes.
b. Basis, Purpose, and Use of Data
MCU may process your personal data based on your consent whenever required. However, there are instances when the processing of personal data may be carried out even without consent, particularly when such processing is necessary for the performance of the University’s legitimate functions, the fulfillment of contractual or legal obligations, or when it is otherwise authorized under Sections 12 and 13 of the Data Privacy Act of 2012.
Your personal data may be collected, used, stored, and otherwise processed for the following purposes:
- Evaluation of eligibility and processing for admission, scholarship, financial aid and enrollment in the University
- Promoting, measuring, evaluating and validating academic progression, program of study, curricula
- Documentation of students’ data
- Research and support services
- Posting of academic and non-academic achievements within the University premises and/or website Processing of application for issuance of school records (Transcripts, Diploma, Certificates)
- Processing of grades and generation of the statement of accounts
- Processing of application for graduation
- Alumni services
- Evaluation for board examinations
- Accreditation purposes
- Public relations, marketing and promoting the University and other academic and non-academic activities
- Providing library, research, community outreach, medical and dental services, alumni and other student support services
- Career services including references, work and other placements Safety and security of the MCU community
c. Methods Utilized for Automated Access
MCU utilizes DataMobility Corporation (DMC) as a third-party service to support the delivery of its digital platforms and services related to admission, enrollment, student services, and alumni engagement. These service providers may process limited personal and technical information through automated technologies to assist the University monitor system usage, maintain platform functionality, analyze website or portal engagement, and improve online services and user experience. These automated processing may involve the use of cookies and similar tracking technologies. The information collected through these systems is used solely for legitimate institutional and operational purposes and is subject to appropriate data protection and confidentiality safeguards.
The following web traffic or technical data that may be processed for these purposes include:
- IP address
- Pages and internal links accessed on the University website or portal
- Date and time of access or visit
- Geolocation
- Referring website or platform, if applicable
- Operating system
- Web browser type
d. Disclosure of Data
MCU will keep all personal information in strict confidence if not intended for public disclosure. There are instances, however, where we will share or disclose personal information pursuant to MCU’s legitimate purposes or when it is otherwise authorized under Sections 12 and 13 of the Data Privacy Act of 2012. The purposes for which MCU may share or disclose your personal information include among others:
- Posting of class lists and class schedules in school bulletin boards or other places within the campus;
- Sharing of information to persons, including parents, guardians or next of kin, as required by law or on a need-to-know basis as determined by the school to promote your best interests, or protect your health, safety, and security, or that of others;
- Providing academic institutions, companies, business partners and linkages, government agencies, private or public corporations, organizations or the like, upon their request, with scholastic ranking and academic information, certification of good moral character, and the like for purposes of admission, student exchange, internships, further studies, and job placements and verification;
- Sharing information to potential donors, funders, or benefactors for purposes of scholarship, grants, and other forms of assistance;
- Distributing the list of graduates and awardees during commencement exercises;
- Reporting and/or disclosing information to the government bodies, agencies or the courts (e.g., Commission on Higher Education, Department of Education and Department of Education);
- Sharing information for accreditation and university ranking purposes;
- Responding to inquiries verifying that you are a bona fide student or graduate of the school;
- Conducting research or surveys for purposes of institutional development; Sharing your directory information to the schools’ alumni association;
- Publishing academic, co-curricular, and extra-curricular achievements and success, including honors lists and names of awardees in school bulletin boards, website, social media sites, and publications;
- Sharing your academic accomplishments or honors and co-curricular or extracurricular achievements with schools you graduated from or was previously enrolled in, upon their request;
- Live-streaming of MCU events;
- Service providers who perform services to help us support your learning and manage operations of our school;
- Promoting the school, including its activities and events, through photos, audios, videos, brochures, website posting, newspaper advertisements, physical and electronic bulletin boards, and other media;
- Publishing communications such as news information in MCU’s publications, social media sites, and other news and media organization.
Where MCU considers it necessary or appropriate for data storage, processing, or providing any service or product on our behalf to you, we may transfer your personal data to third parties inside or outside the Philippines under conditions of confidentiality and similar levels of security safeguards.
e. Storage and Retention of Data
MCU securely stores personal information in its computer systems and servers, and, where applicable, with authorized cloud-based or third-party data storage providers. Physical records containing personal information are maintained in locked filing cabinets within secured storage rooms in each office. Your personal data are transmitted within the University securely in a variety of paper and electronic formats, including databases that are shared between the University’s different units or offices. Access to your personal data is limited to University personnel who have a legitimate interest in them to carry out their contractual duties. MCU implements appropriate technical, organizational, and administrative measures to safeguard all personal information against unauthorized access, disclosure, alteration, or destruction.
Personal information shall generally be stored in the database for five (5) years in accordance with University’s Document Management Policy. However, retention periods are determined in accordance with the University’s policies and procedures, as well as applicable laws and regulations. Certain categories of personal information may be retained for longer periods where required to fulfill legal obligations or institutional responsibilities. Personal data shall be securely disposed of upon the expiration of its retention period.
f. Disposal of Data
Where a retention period has expired, or as required by law or University policy, all affected records shall be securely disposed of. Physical records shall be destroyed through shredding, while electronic files shall be permanently deleted or anonymized. In all cases, disposal procedures shall ensure that personal information can no longer be retrieved, processed, or accessed by unauthorized persons.
g. Risks
Risk refers to the potential for an incident to result in harm or disadvantage to a data subject or MCU. In the course of processing personal data, there is a possibility of unauthorized collection, use, disclosure, access, or loss of information, which may affect the confidentiality, integrity, and availability of data or result in violations of data privacy principles and the rights of data subjects.
While MCU is processing your data, potential risks include exposure of personal data to breaches, system failures, or physical damage, such as fire or flood, affecting both electronic and physical records. Risks may also arise from faults in automated systems, including the MCU ERP System (Applicant and Student Portal). While MCU implements appropriate physical, organizational, and technical security measures, absolute protection against cybersecurity threats, such as phishing, malware, or ransomware attacks, privacy violations involving sensitive personal information, and reputational harm resulting from data breaches or misuse cannot be guaranteed.
Policies and procedures within the University are in place to ensure effective security incident management, in compliance with applicable laws, University policies, and guidance issued by the National Privacy Commission.
h. Security Measures
MCU is committed to protecting the confidentiality, integrity, and availability of personal information through a combination of organizational, physical, and technical safeguards. These measures are designed in accordance with best practices in data privacy and information security, and they are regularly reviewed to address evolving risks.
- Organizational Security Measures
- MCU has designated a Data Protection Officer (DPO) responsible for overseeing the implementation of data protection measures, ensuring compliance with the Data Privacy Act (DPA), coordinating with University departments, and leading responses to data breaches.
- All personnel handling personal data are required to undergo periodic training on privacy and security practices, with attendance and participation monitored by the DPO.
- Privacy Impact Assessments (PIAs) are conducted for initiatives, systems, or projects that process personal data, whether managed internally or through authorized third parties.
- Policies and procedures are reviewed regularly to remain aligned with regulatory requirements and institutional standards.
- Physical Security Measures
- Paper records containing personal information are secured in locked cabinets within restricted storage areas in each office. Access to these areas is limited to authorized personnel, while visitors or others must receive explicit approval from the DPO and comply with confidentiality requirements.
- Entry and access are logged, and, where feasible, monitored through CCTV.
- Workstations are arranged to prevent unauthorized viewing of sensitive information.
- Records no longer needed are disposed of securely, following University retention policies, legal obligations, and regulatory requirements.
- Technical Security Measures
- Electronic records are stored on secure on-premises servers or authorized cloud-based systems in compliance with data privacy standards.
- The University employs monitoring systems to detect unauthorized access, breaches, or other suspicious activities.
- All software undergoes security review before deployment, and periodic vulnerability assessments and penetration testing are conducted to maintain system integrity.
- Access to electronic personal data is controlled through strong authentication measures, secure storage protocols, and confidential communications for the transmission of sensitive information.
i. Data Subject Rights
As provided by the Data Privacy Act of 2012, the data subject has the right to:
- Be informed about the collection and processing of his or her personal data, including its purpose, scope, recipients, storage period, and the identity of the personal information controller.
- Access and obtain a copy of such information
- Request correction of inaccurate or incomplete data
- Object to or request the blocking, removal, or destruction of unlawfully processed or unnecessary personal data, and
- Be indemnified for damages resulting from the unlawful or unauthorized use of personal information, in accordance with applicable data privacy laws.
For the details of your rights as a data subject, you can get in touch with our Data Protection Officer at the contact details below or at the National Privacy Commission at https://privacy.gov.ph/.
The Data Protection Officer
Email Address: dataprivacy@mcu.edu.ph
Write to: Data Protection Officer
MCU Campus, EDSA, Monumento, Caloocan City, Philippines 1400
PRIVACY POLICY NOTICE FOR JOB APPLICANTS, EMPLOYEES AND TRAINEES
STATEMENT OF PRIVACY POLICY
MANILA CENTRAL UNIVERSITY (MCU) is committed to protect and respect your personal data privacy. This Personal Data Privacy Notice, prepared in accordance with the Data Privacy Act of 2012 and its Implementing Rules and Regulations, sets out our personal information protection practices that are put in place to protect the personal information of individuals whom we deal with. Please note that we may amend this Data Privacy Notice at any time without prior notice and we will notify you of any such amendment via our website or by email.
Application of this Policy
This Policy applies to all persons engaged in a contract of service with MCU (whether on a part-time, temporary, contractual/casual or full-time basis/item positions) and trainees working at or affiliated with/attached to us (collectively referred to as “employees”) as well as persons who have applied for any such position with the Company (“job applicants”), and all references to “employment” shall apply equally to training (or on-job-trainees’ OJT) (as may be applicable)
PRIVACY NOTICE
a. Data Collected and Manner of Collection
We collect your personal data that include those you submit to us manually or electronically during your application for admission, upon your hiring and in the course of your employment with MCU. This will include, but not limited to:
- full name, address, email address, date of birth, civil status;
- family background;
- face/photo, fingerprints, or handwriting;
- contact numbers;
- government-issued ID numbers;
- medical, psychological, and dental history and condition;
- psychological evaluation results;
- educational history;
- employment history and work experience;
- background investigation results and character reference;
- interview assessment; and
- other similar information.
These personal data are collected through the MCU ERP System (Employee Portal), Microsoft Teams, and through physical controlled forms submitted to the various offices of the University. In certain instances, personal data may also be obtained from third parties, such as person to contact in the event of an emergency, professional referees, when necessary for legitimate administrative or regulatory purposes.
b. Basis, Purpose, and Use of Date
MCU may process your personal data based on your consent whenever required. However, there are instances when the processing of personal data may be carried out even without consent, particularly when such processing is necessary for the performance of the University’s legitimate functions, the fulfillment of contractual or legal obligations, or when it is otherwise authorized under Sections 12 and 13 of the Data Privacy Act of 2012.
Your personal data may be collected, used, stored, and otherwise processed for the following purposes:
- recruitment and hiring of employees;
- promotion, evaluation, and ranking of employees;
- attendance and timekeeping of employees;
- employee discipline;
- conduct of administrative investigation of employee cases;
- processing of compensation and benefits and payroll of employees;
- distribution of teaching loads and work assignments;
- updating and verification of employee service records;
- training and development;
- performance evaluation;
- HR development plans and reports
c. Methods Utilized for Automated Access
MCU utilizes DataMobility Corporation (DMC) as a third-party service to support the delivery of its digital platforms and services related to admission, enrollment, student services, and alumni engagement. These service providers may process limited personal and technical information through automated technologies to assist the University monitor system usage, maintain platform functionality, analyze website or portal engagement, and improve online services and user experience. These automated processing may involve the use of cookies and similar tracking technologies. The information collected through these systems is used solely for legitimate institutional and operational purposes and is subject to appropriate data protection and confidentiality safeguards.
The following web traffic or technical data that may be processed for these purposes include:
- IP address
- Pages and internal links accessed on the University website or portal
- Date and time of access or visit
- Geolocation
- Referring website or platform, if applicable
- Operating system
- Web browser type
d. Disclosure of Data
MCU will keep all personal information in strict confidence if not intended for public disclosure. There are instances, however, where we will share or disclose personal information pursuant to MCU’s legitimate purposes or when it is otherwise authorized under Sections 12 and 13 of the Data Privacy Act of 2012. Your personal data may be shared with:
- Government agencies (SSS, PhilHealth, Pag-IBIG, BIR, DOLE, CHED, LGU)
- Banks, HMOs, insurers, and benefit providers
- Third-party (IT services, payroll systems, background check firms)
- Partner institutions for job-related functions
e. Storage and Retention of Data
MCU securely stores personal information in its computer systems and servers, and, where applicable, with authorized cloud-based or third-party data storage providers. Physical records containing personal information are maintained in locked filing cabinets within secured storage rooms in each office. Your personal data are transmitted within the University securely in a variety of paper and electronic formats, including databases that are shared between the University’s different units or offices. Access to your personal data is limited to University personnel who have a legitimate interest in them to carry out their contractual duties. MCU implements appropriate technical, organizational, and administrative measures to safeguard all personal information against unauthorized access, disclosure, alteration, or destruction.
Personal information shall generally be stored in the database for five (5) years in accordance with University’s Document Management Policy. However, retention periods are determined in accordance with the University’s policies and procedures, as well as applicable laws and regulations. Certain categories of personal information may be retained for longer periods where required to fulfill legal obligations or institutional responsibilities. Personal data shall be securely disposed of upon the expiration of its retention period.
f. Disposal of Data
Where a retention period has expired, or as required by law or University policy, all affected records shall be securely disposed of. Physical records shall be destroyed through shredding, while electronic files shall be permanently deleted or anonymized. In all cases, disposal procedures shall ensure that personal information can no longer be retrieved, processed, or accessed by unauthorized persons.
g. Risks
Risk refers to the potential for an incident to result in harm or disadvantage to a data subject or MCU. In the course of processing personal data, there is a possibility of unauthorized collection, use, disclosure, access, or loss of information, which may affect the confidentiality, integrity, and availability of data or result in violations of data privacy principles and the rights of data subjects.
While MCU is processing your data, potential risks include exposure of personal data to breaches, system failures, or physical damage, such as fire or flood, affecting both electronic and physical records. Risks may also arise from faults in automated systems, including the MCU ERP System (Employee Portal). While MCU implements appropriate physical, organizational, and technical security measures, absolute protection against cybersecurity threats, such as phishing, malware, or ransomware attacks, privacy violations involving sensitive personal information, and reputational harm resulting from data breaches or misuse cannot be guaranteed.
Policies and procedures within the University are in place to ensure effective security incident management, in compliance with applicable laws, University policies, and guidance issued by the National Privacy Commission.
h. Security Measures
MCU is committed to protecting the confidentiality, integrity, and availability of personal information through a combination of organizational, physical, and technical safeguards. These measures are designed in accordance with best practices in data privacy and information security, and they are regularly reviewed to address evolving risks.
- Organizational Security Measures
- MCU has designated a Data Protection Officer (DPO) responsible for overseeing the implementation of data protection measures, ensuring compliance with the Data Privacy Act (DPA), coordinating with University departments, and leading responses to data breaches.
- All personnel handling personal data are required to undergo periodic training on privacy and security practices, with attendance and participation monitored by the DPO.
- Privacy Impact Assessments (PIAs) are conducted for initiatives, systems, or projects that process personal data, whether managed internally or through authorized third parties.
- Policies and procedures are reviewed regularly to remain aligned with regulatory requirements and institutional standards.
- Physical Security Measures
- Paper records containing personal information are secured in locked cabinets within restricted storage areas in each office. Access to these areas is limited to authorized personnel, while visitors or others must receive explicit approval from the DPO and comply with confidentiality requirements.
- Entry and access are logged, and, where feasible, monitored through CCTV.
- Workstations are arranged to prevent unauthorized viewing of sensitive information.
- Records no longer needed are disposed of securely, following University retention policies, legal obligations, and regulatory requirements.
- Technical Security Measures
- Electronic records are stored on secure on-premises servers or authorized cloud-based systems in compliance with data privacy standards.
- The University employs monitoring systems to detect unauthorized access, breaches, or other suspicious activities.
- All software undergoes security review before deployment, and periodic vulnerability assessments and penetration testing are conducted to maintain system integrity.
- Access to electronic personal data is controlled through strong authentication measures, secure storage protocols, and confidential communications for the transmission of sensitive information.
i. Data Subject Rights
As provided by the Data Privacy Act of 2012, the data subject has the right to:
- Be informed about the collection and processing of his or her personal data, including its purpose, scope, recipients, storage period, and the identity of the personal information controller.
- Access and obtain a copy of such information
- Request correction of inaccurate or incomplete data
- Object to or request the blocking, removal, or destruction of unlawfully processed or unnecessary personal data, and
- Be indemnified for damages resulting from the unlawful or unauthorized use of personal information, in accordance with applicable data privacy laws.
For the details of your rights as a data subject, you can get in touch with our Data Protection Officer at the contact details below or at the National Privacy Commission at https://privacy.gov.ph/.
The Data Protection Officer
Email Address: dataprivacy@mcu.edu.ph
Write to: Data Protection Officer
MCU Campus, EDSA, Monumento, Caloocan City, Philippines 1400
j. Withdrawing Consent
The consent that you provide for the collection, use, and disclosure of your personal data will remain valid until such time it is being withdrawn by you in writing. If you are a job applicant, you may withdraw consent and request us to stop using and/or disclosing your personal data for any of all the purposes listed above by submitting your request in writing or via email to our Data Protection Officer at the contact details provided above.
PRIVACY POLICY NOTICE FOR THIRD PARTIES
STATEMENT OF PRIVACY POLICY
Manila Central University (MCU) is committed to protecting the privacy of its data subjects and ensuring the safety and security of personal data under its control and custody. We aim to comply with the Data Privacy Act of 2012 (DPA) and cooperate fully with the National Privacy Commission (NPC) by giving importance to the privacy and security of personal data entrusted by our stakeholders (e.g. suppliers, visitors, and other third parties) for legitimate purposes.
This notice applies to the personal data of natural persons working for our suppliers or acting as agents or representatives of our suppliers (“you”, “your”). Suppliers are understood as any third party that provides goods or services to Manila Central University (e.g., visitor, service providers, agencies/company, consultant, contractor, advisor, or vendor). Board members under a non-employee status are also considered as suppliers. This notice explains what types of personal data are gathered from our suppliers, how the personal data are used, and with whom the personal data are shared. It also sets out our suppliers’ rights with personal data. For their exact definitions, you may refer to the text of the DPA. The Consent Form may be amended at any time without prior notice, and such amendments will be notified to you through MCU’s website or by email.
PRIVACY NOTICE
a. Data Collected and Manner of Collection, Basis, Purpose, and Use of Data
The primary reason we process your data is to approve, manage, administer, or effect an agreement between Manila Central University and the supplier you represent or work for. In this respect, we use your data to organize our sourcing activities, issue purchase orders, process payments, perform accounting, manage our contract or review the services or products you supply us with.
Also, we process personal data to meet our legal obligations (e.g., record-keeping obligations, screening duties of board members), to manage our risks and operations (e.g., prevent and detect security threats, exercise or defend legal claims), and whenever it is otherwise authorized under Sections 12 and 13 of the Data Privacy Act of 2012. We collect and process the following personal information from a visitor, service providers, agencies/company, consultant, contractor, advisor, or vendor:
| Purpose of Processing | Types of Personal Data |
Security of Confidential Information located in the University’s premises Recording, generating, and maintaining records, whether manually or electronically to establish the information and monitor the purpose of visit Prevention of loss, fraud, theft, injuries, terrorism, and other events of such kind in the University’s premises |
|
| Sourcing |
|
| Contract Management |
|
| Assessment of Suppliers |
|
| Access and Security Management |
|
| Payment of Invoices |
|
The personal data we collect from you comes from the following sources:
1. Personal data you give us
We collect personal data from you when you: send us personal data on forms and e-forms such as your name, address, telephone number, tax identification number, date of birth, copy of passport or ID card; provide us personal data necessary to enter into a contract such as your name, address, professional phone number and e-mail address, function and/or position held within our supplier’s organization; or provide us personal data during the performance of your services.
2. Information we receive from other sources
We collect your data through background information from third-party providers; our employees or business relationships such as feedback on you we receive from other contractors or our employees; publicly available sources to confirm signatory powers; or details on your intervention in board meetings (i.e., through board minutes).
The said data are not shared with any outside parties without your consent unless the law and our rules allow us to. We hold these personal information data and use them to monitor and report your progress, and assess the status of your employment with the University.
b. Security Measures
MCU is committed to protecting the confidentiality, integrity, and availability of personal information through a combination of organizational, physical, and technical safeguards. These measures are designed in accordance with best practices in data privacy and information security, and they are regularly reviewed to address evolving risks.
- Organizational Security Measures
- MCU has designated a Data Protection Officer (DPO) responsible for overseeing the implementation of data protection measures, ensuring compliance with the Data Privacy Act (DPA), coordinating with University departments, and leading responses to data breaches.
- All personnel handling personal data are required to undergo periodic training on privacy and security practices, with attendance and participation monitored by the DPO.
- Privacy Impact Assessments (PIAs) are conducted for initiatives, systems, or projects that process personal data, whether managed internally or through authorized third parties.
- Policies and procedures are reviewed regularly to remain aligned with regulatory requirements and institutional standards.
- Physical Security Measures
- Paper records containing personal information are secured in locked cabinets within restricted storage areas in each office. Access to these areas is limited to authorized personnel, while visitors or others must receive explicit approval from the DPO and comply with confidentiality requirements.
- Entry and access are logged, and, where feasible, monitored through CCTV.
- Workstations are arranged to prevent unauthorized viewing of sensitive information.
- Records no longer needed are disposed of securely, following University retention policies, legal obligations, and regulatory requirements.
- Technical Security Measures
- Electronic records are stored on secure on-premises servers or authorized cloud-based systems in compliance with data privacy standards.
- The University employs monitoring systems to detect unauthorized access, breaches, or other suspicious activities.
- All software undergoes security review before deployment, and periodic vulnerability assessments and penetration testing are conducted to maintain system integrity.
- Access to electronic personal data is controlled through strong authentication measures, secure storage protocols, and confidential communications for the transmission of sensitive information.
c. Storage and Retention of Data
MCU securely stores personal information in its computer systems and servers, and, where applicable, with authorized cloud-based or third-party data storage providers. Physical records containing personal information are maintained in locked filing cabinets within secured storage rooms in each office. Your personal data are transmitted within the University securely in a variety of paper and electronic formats, including databases that are shared between the University’s different units or offices. Access to your personal data is limited to University personnel who have a legitimate interest in them to carry out their contractual duties. MCU implements appropriate technical, organizational, and administrative measures to safeguard all personal information against unauthorized access, disclosure, alteration, or destruction.
MCU will only keep your data for as long as it is reasonably necessary for the purposes outlined above or to comply with legal requirements under applicable law(s). CCTV footages are stored for 90 days before being automatically deleted. MCU keeps personal data as long as we have a relationship with the supplier you represent or work for. After a contractual relationship ends, personal data are kept for 5 years.
d. Disposal of Data
Where a retention period has expired, or as required by law or University policy, all affected records shall be securely disposed of. Physical records shall be destroyed through shredding, while electronic files shall be permanently deleted or anonymized. In all cases, disposal procedures shall ensure that personal information can no longer be retrieved, processed, or accessed by unauthorized persons.
e. Disclosure of Data
Where MCU considers it necessary or appropriate for data storage or processing or providing any service or product on our behalf to you or when it is otherwise authorized under Sections 12 and 13 of the Data Privacy Act of 2012, we may transfer your personal information to third parties within or outside the Philippines, under conditions of confidentiality and similar levels of security safeguards. We do NOT transfer or share your data with other persons or organizations unless required or permitted by law.
f. What if you choose not to give us your data?
If you do not want to give us your data and the personal data are necessary to enter a contract or pursue business relations with our supplier, then we will not be able to enter into that contract or pursue our contractual relationship. If your contract or agreement with MCU as a third party provider has expired, you have the right to obtain and withdraw your data in hard copy and delete permanently all your information from our database files.
g. Data Subject Rights
As provided by the Data Privacy Act of 2012, the data subject has the right to:
- Be informed about the collection and processing of his or her personal data, including its purpose, scope, recipients, storage period, and the identity of the personal information controller.
- Access and obtain a copy of such information
- Request correction of inaccurate or incomplete data
- Object to or request the blocking, removal, or destruction of unlawfully processed or unnecessary personal data, and
- Be indemnified for damages resulting from the unlawful or unauthorized use of personal information, in accordance with applicable data privacy laws.
For the details of your rights as a data subject, you can get in touch with our Data Protection Officer at the contact details below or at the National Privacy Commission at https://privacy.gov.ph/.
The Data Protection Officer
Email Address: dataprivacy@mcu.edu.ph
Write to: Data Protection Officer
MCU Campus, EDSA, Monumento, Caloocan City, Philippines 1400