Skip to main content

Main Secondary Navigation

  • About Ateneo de Manila
  • Schools
  • Research
  • Global
  • Alumni
  • News
  • Events

Main navigation

  • Learn & Grow
  • Discover & Create
  • Make an Impact
  • Campus & Community
  • Apply
  • Home >
  • News >
  • Preserving Privacy in a Unified Contact Tracing System

Preserving Privacy in a Unified Contact Tracing System

02 Sep 2021 | Shari Datu Tambuyung

Photo from Unsplash
 

 

After more than a year and a half into this pandemic, be honest: have you ever grown tired of filling up contract tracing forms or apps by this time? Do you ever feel like you’re only doing it to comply (and not really because you believe it’s useful)? Have you ever asked yourself: where will my data go; are they being kept safe; is there really a need to get this much information from me?

If you have, you’re not alone. The adoption of contact tracing systems for the COVID-19 pandemic has become such a common practice by this time all across the globe. It’s been the same here in the Philippines, where private companies and government entities alike have all come up with their own mechanisms, all for the same common purpose of contact tracing.

For all its efforts, though, the country is still having a hard time tracking down and monitoring COVID-19 cases and their close contacts. Just this March, the government admitted that contact tracing has consistently been the weakest point in its pandemic response. One major reason for this are the numerous apps currently being used today and their inability to operate in an integrated manner.

Taking stock of the country’s contact tracing problem, a House Resolution calling for a unified contact tracing protocol in the country was filed by current House Speaker, Lord Allan Velasco, and subsequently approved by the House Committees on Health and Information and Communications Technology. The Resolution notes that the different contact tracing apps and the decentralized nature of storing the collected data have led to redundant products, cost duplication, and ultimately, a very ineffective contact tracing effort.

If the call is heeded, it may allow StaySafe.ph, the country’s official contact tracing system, to assume a prominent role in the government’s centralized approach to disease monitoring and management. In theory, at least, the app will let the authorities act more promptly based on the greater amount of incoming information it will get, after all the different apps currently in use have been integrated.

Despite its good intentions, however, the Resolution doesn’t seem to address the trust issues people have with Staysafe.ph, both in terms of security and reliability. And it certainly hasn’t helped that former Undersecretary of the Department of Information and Communication Technology, Eliseo Rio, and even contact tracing czar, Mayor Benjamin Magalong, have both come forward and expressed their doubts about the app.

Most concerns relate to the possibility that the collected information could potentially be used for surveillance and other unauthorized purposes, as a result of function creep. Some are worried that the government could retain the collected data and use it for other purposes even after its usefulness for contact tracing has expired.

Not even assurances from the Department of Interior and Local Government, the agency currently managing the app, about its compliance with all applicable laws, rules, and regulations have had the effect of calming people’s nerves. Neither has the express endorsement by the National Privacy Commission via its press statement.

This is unfortunate since social trust is extremely important if a unified contact tracing system is to be effective. This, since the collection and use of personal data in contact tracing cannot be avoided. And in order for people to be okay with that, they need to trust the system.

A good way to earn that trust is to take data protection seriously. The government needs to show people it can and will take care of their data. To go about doing that, here are some data privacy principles the government needs to adhere to when the unified contact tracing system is implemented:

Limit data processing to what is needed for contact tracing.  Collect and process only those data necessary for contact tracing. The Department of Health has already released the guidelines for this. They should be followed. In line with this, retain the data for a limited period of time only (i.e., thirty days as per NPC Advisory No. 2020-03), and dispose of it soon after.

Be transparent and obtain consent, if necessary. To demonstrate commitment to transparency, inform users about the collection of their information, including the nature of the data processing, its purpose, scope, and any available safeguards. Explain also when and how disposal of the data will be carried out. This is usually achieved by drawing up a Privacy Notice. There may be times when consent will have to be obtained—usually, when sensitive personal information is involved. Keep in mind the elements and acceptable formats of a valid consent.

Adopt or implement security measures.  There should be adequate security measures for the system, whether it be in the app, website, or overall process. They should be incorporated in such a way that they mitigate any possible disadvantages and risks that users may be exposed to.  Conducting a Privacy Impact Assessment as a prelude will help identify such risks and disadvantages.

Establish and enforce data governance policies and procedures.  Well-crafted policies make sure data is used and managed properly and consistently. They keep everybody on the same page, regularly following agreed-upon best practices.

Execute appropriate contracts or agreements. Since contact tracing is a collective effort, the collected data will usually end up in the hands of multiple entities. It is therefore important to make sure that all of them are complying with the Data Privacy Act (DPA) and are aware of their respective responsibilities. One way of doing this is by entering into contracts like data sharing agreements (with LGUs or other entities acting as personal information controllers), data processing outsourcing agreements (with service providers), and non-disclosure agreements.

Continuous monitoring and evaluation of the system.  As with any other system, constant monitoring for technical vulnerabilities, policy gaps, or any unauthorized access or use of data is necessary. Technology upgrades, new policies, and revised procedures may be necessary to address issues and other problems that come up along the way.

Observing these practices is not an easy task. But it is worth pursuing, since they all help gain the trust of the public, which, again, is crucial when asking them to embrace a system they are supposed to entrust their sensitive personal data with.

Is the list exhaustive? No, but it should be at least sufficient to show the level of commitment the government has towards the preservation of privacy and the security of personal data when it comes to its contract tracing system.

General Interest Administration Administration Cluster
Share:

Recent News

Bending toward justice: A forum on the ICC, the Duterte Case, and victim participation

31 Mar 2026

[Hot Off the Press] Arkipelago

31 Mar 2026

Matthew General clinches gold at Excalibur Fencing Tournament

31 Mar 2026

Silver success for Belarmino at Wilson Epee Invitational

31 Mar 2026

From AGS to ASHS: Ateneo fencers haul 6 medals at 1st Estudio de Espada League

31 Mar 2026

Ethan Santos grabs bronze at Hampton Fencing Club’s 3rd Winter Cup

31 Mar 2026

Blue Eagle blades Santos and General grab gold in Young Musketeers meet

31 Mar 2026

Matthew General secures gold at Coach Benny Fencing Competition

31 Mar 2026

Bending Toward Justice: ALS Forum Examines the ICC, the Duterte Case, and Victim Participation

31 Mar 2026

Protecting Creativity: AIPO and Rizal Library Host Copyright Awareness Session for the Ateneo Community

31 Mar 2026

You may also like these articles

Arkipelago

31 Mar 2026

[Hot Off the Press] Arkipelago

New book from the Ateneo Press Arkipelago provides a fascinating and fantastical twist on Philippine politics and history Our country is an archipelago of stories

Copyright Awareness Session

31 Mar 2026

Protecting Creativity: AIPO and Rizal Library Host Copyright Awareness Session for the Ateneo Community

On March 18, 2026, the Ateneo Intellectual Property Office (AIPO), in collaboration with the Rizal Library, successfully conducted a Copyright Awareness Session held on the

Close up of University seal and logo at Xavier Hall

31 Mar 2026

Holy Week 2026 Holidays (Memo # UHR2526-038)

Memo # UHR2526-038 31 March 2026 TO: All Employees FROM: [Sgd] Maria Victoria T Cortez, PhD Vice President for University Human Resources SUBJECT: Holy Week

ASOG’s Tobacco Control initiatives spotlighted in DOH National Technical Working Group for Tobacco Prevention and Control

31 Mar 2026

ASOG’s Tobacco Control initiatives spotlighted in DOH National Technical Working Group for Tobacco Prevention and Control

On March 10 to 12, 2026, the Ateneo School of Government (ASOG), through its research and public policy unit, the Ateneo Policy Center, participated in

Geloy Concepcion Exhibition 2026

30 Mar 2026

Things You Wanted to Say But Never Did: Geloy Concepcion’s six-year project makes Its exhibition debut at the Ateneo Art Gallery

Geloy Concepcion’s Things You Wanted To Say But Never Did comes to the Ateneo Art Gallery this 18 April 2026. After receiving almost 300,000 messages

Love If I'm Pretty

30 Mar 2026

[Hot Off the Press] Love If I'm Pretty

New YA Release from the Ateneo Press Love If I’m Pretty tackles the nuances of growing up through complex characters and straightforward prose What do

Katipunan Avenue, Loyola Heights, Quezon City 1108, Philippines

info@ateneo.edu

+63 2 8426 6001

Connect With Us
  • Contact Ateneo
  • A to Z Directory
  • Social Media
Information for
  • Current Students
  • Prospective Students
  • International Students
  • Faculty & Staff
  • Alumni
  • Researchers & Visiting Academics
  • Parents
  • Donors & Partners
  • Visitors & Media
  • Careers
Security & Emergency
  • COVID-19
  • Campus Safety
  • Network & Tech
  • Emergency Management
  • Disaster Preparedness
Digital Resources
  • AteneoBlueCloud
  • Archium
  • Rizal Library
  • Ateneo Mail (Staff)
  • Ateneo Student Email
  • Alumni Mail
  • Branding & Trademarks
  • Data Privacy
  • Acceptable Use Policy
  • Report Website Issues
  • Ateneo Network
  • Philippine Jesuits

Copyright © 2022 Ateneo de Manila University. All rights reserved. | info@ateneo.edu | +63 2 8426 6001

Search