NotarizeITDATA PRIVACY POLICY
An electronic notarization platform operated by Unawa Inc.
I. Introduction
Purpose and Authority. This Data Privacy Policy governs the processing of personal data through NotarizeIT, an electronic notarization platform operated by Unawa Inc. (“Unawa”). It is adopted in compliance with Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations, the issuances of the National Privacy Commission (NPC), and the requirements of the Supreme Court of the Philippines governing electronic notarization, including A.M. No. 24-10-14-SC and the Electronic Notarization Data Sharing Guidelines. It reflects Unawa’s commitment to transparency, legitimate purpose, and proportionality in processing personal data through NotarizeIT.
Scope. This Policy applies to all personal data processed in connection with the NotarizeIT platform — including data of electronic notaries public (ENPs), their clients, document signatories, corporate and enterprise users, and platform personnel — across the full data lifecycle, from collection to secure disposal.
Controller. Unawa Inc. is the Data Controller for personal data processed through NotarizeIT. Unawa determines the purposes and means of processing and is accountable for ensuring that this Policy and the requirements of the Data Privacy Act are observed, including by any third party that processes personal data on its behalf.
II. Definition of Terms
In this Policy, unless the context otherwise requires, the following terms have the meanings set out below:
Data. Information stored electronically, on a computer, or in certain paper-based filing systems.
Personal Data. Any information relating to an identifiable person who can be directly or indirectly identified, in particular by reference to an identifier.
Processing. Any operation performed upon personal data, whether automated or manual, including collection, recording, organization, storage, updating, retrieval, consultation, use, consolidation, blocking, erasure, or destruction of data.
Data Controller. The entity that determines the purposes, conditions, and means of the processing of personal data. For NotarizeIT, this is Unawa Inc.
Data Processor. The entity that processes data on behalf of the Data Controller.
Data Subject. A natural person whose personal data is processed by a controller or processor.
Electronic Notary Public (ENP). A notary public commissioned and accredited by the Supreme Court to perform electronic notarial acts through an accredited Electronic Notarization Facility.
Electronic Notarization Facility (ENF). The Supreme Court–accredited facility through which electronic notarial acts are performed. NotarizeIT operates as a platform pending and subject to ENF accreditation.
ENS. The Electronic Notarization System or service of the Supreme Court through which the Court accesses, monitors, and supervises electronic notarial acts and related records.
Data Protection Officer (DPO). The individual formally designated to ensure compliance with the Data Privacy Act of 2012, its IRR, and NPC issuances. The DPO monitors data protection activities, advises management, and serves as the contact person for the NPC and data subjects regarding data privacy concerns.
Consent. Any freely given, specific, informed, and unambiguous indication of will by which the data subject agrees to the collection and processing of personal data. Consent must be evidenced by written, electronic, or recorded means and may be withdrawn at any time.
Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
III. Governance and Accountability
Roles & Responsibilities
I. Data Protection Officer (DPO):
The DPO is primarily responsible for ensuring organizational compliance with the Data Privacy Act of 2012, its IRR, and relevant NPC issuances in respect of NotarizeIT. The DPO shall:
- Monitor and evaluate the privacy and data protection practices applied to NotarizeIT.
- Provide guidance to management and personnel on their obligations under the law.
- Serve as the contact person for the NPC and data subjects in relation to privacy concerns.
- Ensure that privacy impact assessments, breach reports, and mandatory submissions are properly completed and filed.
- Lead awareness and training programs to strengthen the culture of privacy within the organization.
II. Legal and Administrative Department
The Legal Department supports the DPO and management by:
- Reviewing contracts, data sharing agreements (DSAs), and memoranda of understanding (MOUs), including arrangements with the Supreme Court and accredited partners, to ensure compliance with privacy requirements.
- Drafting or updating legal advisories on the data privacy implications of new laws, regulations, or projects affecting NotarizeIT.
- Assisting in incident management by providing legal advice on breach reporting, evidence preservation, and liability exposure.
- Coordinating with the DPO to align legal compliance with organizational privacy policies.
III. Other Relevant Units
- Technology Department: Responsible for implementing technical security measures, maintaining access controls, and ensuring the confidentiality, integrity, and availability of personal data on the NotarizeIT platform.
- Human Resources Department: Ensures that employee data is properly collected, stored, and processed, and that privacy principles are embedded in recruitment, retention, and exit processes.
- Operations: Ensures that privacy principles are integrated into day-to-day processes involving notary, client, signatory, or partner information.
- All Personnel: Required to observe organizational privacy policies, safeguard personal data, and immediately report any actual or suspected data breach.
Policy Review
Unawa shall review this Policy and related policies at least once every two (2) years, or earlier as necessary, to ensure alignment with:
- New issuances of the National Privacy Commission (NPC).
- New issuances of the Supreme Court on electronic notarization, including amendments to the Electronic Notarization Data Sharing Guidelines.
- Changes in relevant laws, industry standards, or best practices.
- Organizational or platform process changes that affect personal data handling.
The DPO, in coordination with the Legal Department and concerned business units, leads the review. Updates are formally approved by management and disseminated to all personnel.
IV. Key Privacy Principles and Lawful Bases for Processing
Privacy Principles
NotarizeIT upholds the following fundamental principles of data privacy as mandated by the Data Privacy Act of 2012:
A. Transparency
Data subjects shall be informed of how their personal data is collected, processed, stored, shared, and disposed of. Privacy notices and consent forms must clearly communicate these practices in plain and understandable language.
B. Legitimate Purpose
Personal data shall be processed only for purposes that are lawful, declared, and specific. Processing shall always be aligned with the operation of NotarizeIT and shall not be used for activities inconsistent with the stated purpose.
C. Proportionality
The collection of personal data shall be limited to what is necessary, adequate, and relevant in relation to the purposes for which it is processed. NotarizeIT shall avoid the collection or retention of excessive or irrelevant personal data.
D. Accountability
Unawa, as Data Controller, acknowledges responsibility for ensuring that all privacy principles and requirements of the Data Privacy Act are observed, including ensuring that third parties processing personal data on its behalf adhere to the same standards.
Lawful Bases for Processing
Processing of personal data through NotarizeIT shall only be carried out under one or more of the following lawful bases:
- A. Consent – Where the data subject has freely given, specific, informed, and unambiguous permission for the processing of personal data.
- B. Contract – Where processing is necessary for the performance of a contract with the data subject, or to take steps prior to entering into such a contract.
- C. Legal Obligation – Where processing is necessary for compliance with a legal obligation to which the organization is subject, including obligations under Supreme Court rules on electronic notarization.
- D. Vital Interests – Where processing is necessary to protect the life and health of the data subject or another individual.
- E. Public Interest – Where processing is necessary to carry out a task in the interest of the public or required in the exercise of official authority.
- F. Legitimate Interest – Where processing is necessary for the legitimate interests pursued by the organization or a third party, provided such interests do not override the fundamental rights and freedoms of the data subject.
V. Consent Management
NotarizeIT ensures that the processing of personal and sensitive personal information is based on valid and informed consent, in accordance with the Data Privacy Act of 2012 and NPC Circular No. 2023-04.
Obtaining Consent
Prior to using electronic notarization services or accessing the NotarizeIT platform, notaries, clients, and data subjects are required to review and explicitly accept the applicable Terms and Conditions and this Data Privacy Policy. Such acceptance constitutes the data subject’s informed, freely given, specific, and unambiguous consent to the collection, use, processing, and retention of personal data in accordance with applicable data protection laws and the purposes stated herein.
Consent is obtained through clear affirmative actions (e.g., checking a consent box, clicking an “I Agree” button, or equivalent electronic confirmation). Data subjects may withdraw their consent at any time, subject to legal, contractual, or regulatory obligations that may require continued processing or retention of certain data — including the retention and access obligations owed to the Supreme Court in respect of notarized records.
Managing Consent
- Specificity & Granularity – Consent is obtained for defined purposes and is not bundled with unrelated activities.
- Informed Choice – Data subjects are provided sufficient information to understand what they are agreeing to, including potential risks.
- Evidence of Consent – Records of consent, including system-generated logs, timestamps, user identifiers, and the specific terms agreed to at the time of consent, are securely stored in electronic form as proof of consent.
- Withdrawal of Consent – Data subjects may withdraw consent at any time by submitting a written or electronic request. NotarizeIT shall honor such withdrawal, subject to applicable legal and contractual obligations.
- Review & Renewal – Consent is reviewed periodically, especially when there are significant changes to services, processing activities, or privacy policies.
NPC Circular No. 2023-04 Alignment
- Consent must be freely given, specific, informed, and unambiguous, and is evidenced by a clear affirmative act, such as the deliberate selection of a consent tick box or equivalent electronic confirmation.
- NotarizeIT may use layered or just-in-time notices to simplify communication of complex data processing activities.
- Consent shall not be obtained through silence, pre-ticked boxes, or inactivity.
- When processing sensitive personal information, the highest standard of consent management will be applied.
VI. Privacy Notices and Data Subject Rights
Privacy Notices
NotarizeIT is committed to ensuring that data subjects are fully informed of how their personal data is collected, processed, stored, shared, and disposed of. To this end:
- Privacy Notices are presented at the point of data collection and are acknowledged by data subjects before providing consent.
- Notices are written in clear, concise, and easily understandable language, avoiding legal or technical jargon.
Notices include:
- Purpose and scope of processing.
- Types of personal and sensitive personal data collected.
- Information on data sharing with third parties, including the Supreme Court, if any.
- Storage, retention, and disposal practices.
- A summary of the rights available to the data subject.
Data Subject Rights
In line with the Data Privacy Act of 2012, all data subjects are entitled to the following rights:
- A. Right to be Informed. Data subjects have the right to be notified and informed before their personal data is collected and processed.
- B. Right of Access. Data subjects have the right to request access to their personal data and obtain a copy in an electronic or structured format.
- C. Right to Rectification (Correction). Data subjects have the right to dispute any inaccuracy or error in their personal data and have the organization correct it within a reasonable period.
- D. Right to Erasure or Blocking. Data subjects have the right to suspend, withdraw, or order the blocking, removal, or destruction of their personal data if it is inaccurate, outdated, incomplete, unlawfully obtained, or no longer necessary, subject to the retention obligations owed to the Supreme Court for notarized records.
- E. Right to Data Portability. Data subjects have the right to obtain and electronically move, copy, or transfer their personal data for their own purposes, subject to regulation and feasibility.
- F. Right to File a Complaint. Data subjects have the right to file a complaint with the National Privacy Commission (NPC) for any violation of their data privacy rights.
- G. Right to Withdraw Consent. Data subjects have the right to withdraw their consent to the processing of personal data at any time. Withdrawal does not affect the lawfulness of prior processing done before consent was withdrawn.
VII. Data Lifecycle: Handling Personal Data
NotarizeIT follows the principles of responsible data management throughout the entire lifecycle of personal data, from collection to secure disposal.
A. Collection and Use
- Personal data is collected only for legitimate and specific purposes, in line with the electronic notarization services offered through NotarizeIT.
- The collection of data is limited to what is necessary and proportionate, avoiding excessive or irrelevant information.
B. Storage and Retention
- All personal data is stored securely, either in electronic systems with appropriate access controls and encryption, or in physical facilities with restricted access.
Data retention periods are determined in accordance with legal, regulatory, and operational requirements, as set out in the Data Retention Schedule annexed to the Data Retention Policy, and in accordance with Supreme Court rules on the retention of electronic notarial records:
- Notarized documents: Retained for the period required by Supreme Court rules on electronic notarization and, in any case, no less than six (6) years after the last engagement, then securely destroyed.
- Employee records: Retained for six (6) years after separation, unless required longer by law.
- Financial and contractual data: Retained in compliance with statutory periods.
Retention schedules are reviewed annually by the DPO to ensure ongoing compliance with the Data Privacy Act of 2012, NPC guidelines, and Supreme Court issuances.
C. Disposal and Destruction
At the end of the retention period, personal data is securely disposed of to prevent unauthorized recovery or use:
- Paper records: Shredded or incinerated.
- Electronic data: Permanently deleted using secure overwriting methods.
- Disposal activities are documented, including the date, method, and personnel responsible. Records of disposal are kept for six (6) months.
- Third-party processors are contractually required to follow NotarizeIT’s disposal procedures and to certify in writing that data has been securely destroyed.
D. Archiving and Exceptions
- During the retention period, some data may be archived under secure conditions but remains subject to the same safeguards as active data.
- Exceptions to standard retention (e.g., ongoing litigation, regulatory or Supreme Court requests) must be approved by the DPO and documented in accordance with the Data Retention Policy.
E. Privacy Impact Assessments (PIAs)
- A PIA is required for new or significantly modified processes, projects, or systems that involve personal or sensitive personal data.
- The DPO oversees PIAs to ensure risks are identified and mitigated at the earliest possible stage.
VIII. Security Measures
NotarizeIT adopts appropriate organizational, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of personal data.
A. Organizational and Human Resource Security
Privacy and security measures are embedded throughout the employee lifecycle — from recruitment to separation — to minimize risks to personal data. This includes background checks prior to granting access to systems processing personal data; mandatory data privacy orientation and signed confidentiality agreements at onboarding; role-based access with periodic review and refresher training during employment; and immediate revocation of access, asset recovery, and a reminder of continuing confidentiality obligations upon termination or offboarding.
B. Asset Management
- All IT and storage assets are logged, tagged, and inventoried.
- Laptops, mobile devices, and external drives are subject to encryption and access controls.
- Disposal or re-assignment of assets follows secure wipe and decommissioning protocols.
C. Communications Security
- Official communication channels (email, chat, video calls) are secured with encryption.
- Transmission of sensitive data outside the organization requires secure channels (e.g., encrypted email or secure portals).
- Public Wi-Fi use is restricted unless connected via secure VPN.
- All communications over the internet must use SSL/TLS (https) encryption.
D. Cryptography and Data Protection
- Encryption at rest and in transit is applied to sensitive and personal data.
- Strong password and authentication policies are enforced (multi-factor authentication where feasible).
- Cryptographic protocols are reviewed regularly to ensure compliance with current standards.
E. Physical Security
- Offices and storage facilities are access-controlled.
- Visitor access is logged and monitored.
- Secure areas are designated for handling physical documents containing personal or sensitive information.
IX. Incident Management and Breach Response
NotarizeIT has established an Incident Management Process to ensure that all actual or suspected information security and data privacy incidents are reported, assessed, contained, and resolved in a timely and secure manner.
A. Confidentiality of Incident Information
- All information related to actual or suspected incidents is treated as confidential.
- Details are shared only with staff who have designated responsibilities for managing the incident, on a need-to-know basis.
- Personal data of individuals involved is disclosed only to those directly responsible for managing the incident and its consequences.
B. Reporting an Incident
All suspected incidents must be reported immediately by sending an Incident Report to [email protected]. The Incident Report Form includes: date and place of incident; person reporting and their department; description of the incident; personal data involved (type, sensitivity, number of records or individuals affected); containment and recovery steps taken; and parties notified, internal and external.
C. Assessment and Classification
Incidents are reviewed and classified by the Lead Officer, in coordination with the DPO and relevant units:
- High Criticality – Major incident requiring significant resources beyond normal operations. Escalate to the Chief Technology Officer and senior management.
- Medium Criticality – Serious adverse incident requiring notification to senior managers and possible external reporting.
- Low Criticality – Incident manageable within normal operating procedures. Report to the relevant office and submit a copy to the DPO.
D. Containment and Recovery
- The Lead Officer, with support from IT and other responsible units, takes steps to contain the breach and recover any lost or compromised data.
- Actions taken are documented, including the timeline of containment and recovery.
- Where external service providers are involved, they must cooperate in line with contractual obligations and NotarizeIT’s data protection standards.
E. Notifications and Escalations
- The DPO determines whether notification to affected data subjects, the NPC, the affected client’s point of contact, the Supreme Court, or other regulators is required, in line with NPC Circulars on Breach Notification and applicable Supreme Court rules.
- For incidents involving criminal activity, the Police may be informed.
- Where communication with affected individuals, regulators, or the media is necessary, the DPO coordinates with Marketing and Communications to ensure consistent and appropriate messaging.
F. Asset Management
- Every incident is assigned a reference number and fully documented, including cause, impact, and resolution steps.
- A post-incident review is conducted to identify lessons learned and strengthen preventive controls.
- Records of incidents and responses are maintained by the DPO for accountability and compliance monitoring.
X. Data Sharing and Third-Party Agreements
Unawa recognizes that sharing personal data with third parties is sometimes necessary for the delivery of NotarizeIT services, compliance with legal obligations, or fulfillment of contractual or regulatory requirements. To protect the rights of data subjects, Unawa applies strict standards in managing such data sharing arrangements.
A. General Principles
- Personal data shall only be shared with third parties when there is a lawful basis for processing and when the sharing is necessary and proportionate to the intended purpose.
- All data sharing must be conducted in accordance with the Data Privacy Act of 2012, its IRR, the issuances of the NPC, and applicable Supreme Court rules on electronic notarization.
- Data sharing must always be guided by the principles of transparency, legitimate purpose, proportionality, and accountability.
B. Supreme Court and ENS Access
The Electronic Notarization System (ENS) or any other officer authorized by the Supreme Court (SC) shall have access to the information subject to the Electronic Notarization Data Sharing Guidelines. As a platform operating within the Supreme Court’s electronic notarization framework, NotarizeIT enables such access to allow the Supreme Court to supervise, monitor, and verify electronic notarial acts and related records.
- Access by the ENS/SC is limited to the information, scope, and purposes defined in the Electronic Notarization Data Sharing Guidelines, and is exercised in accordance with those Guidelines.
- Such access constitutes data sharing under a legal and regulatory basis, and forms part of the privacy notice provided to data subjects at the point of collection.
- NotarizeIT maintains technical and organizational controls, including access logging and audit trails, to ensure that ENS/SC access is properly authenticated, recorded, and confined to permitted information.
- This arrangement is documented through the applicable data sharing instrument with the Supreme Court and reviewed whenever the Electronic Notarization Data Sharing Guidelines are amended.
C. Contracts and Data Sharing Agreements (DSAs)
All third-party engagements involving personal data must be covered by a written agreement, such as a contract or Data Sharing Agreement (DSA). These agreements must include, at minimum, the following safeguards:
- The purpose and scope of the data sharing.
- The types of personal data to be shared and the lawful basis for processing.
- The roles and responsibilities of Unawa (as Data Controller) and the third party (as either Data Controller or Data Processor).
- Confidentiality obligations and limitations on further use or disclosure of the data.
- Security measures the third party must implement to protect personal data.
- Procedures for reporting and managing data breaches.
- Provisions for data retention, return, or secure disposal after the end of the contract or processing activity.
- Audit and monitoring rights of Unawa to verify compliance.
D. Third-Party Compliance
- All third parties processing data on behalf of Unawa must adhere to the same standards of data protection as the organization.
- Vendors, contractors, and service providers are required to sign confidentiality undertakings and provide written confirmation of compliance with NotarizeIT’s privacy and security requirements.
- Failure to comply may result in termination of the agreement and, if applicable, reporting to regulatory authorities.
E. Transparency with Data Subjects
- Where applicable, data subjects shall be informed that their data may be shared with third parties, including the Supreme Court through the ENS, including the identity of such parties and the purpose of sharing.
- Any new or additional sharing of personal data not covered in the original consent or notice will require updated privacy notices and, where appropriate, renewed consent.
XI. Training and Awareness
The effectiveness of the NotarizeIT data privacy program depends on the knowledge, commitment, and accountability of personnel and third-party partners. Regular training and awareness activities are conducted to sustain a culture of privacy.
A. Employee Training
- All new employees undergo privacy and data protection orientation as part of onboarding.
- Existing employees receive refresher training at least annually, or sooner when there are significant updates in laws, NPC or Supreme Court issuances, or company policies.
- Specialized training is provided for employees with specific responsibilities (e.g., HR, IT, Operations) to address unique privacy risks in their functions.
- Training covers the principles of the Data Privacy Act; roles and responsibilities in protecting personal and sensitive personal information; data handling procedures; incident and breach reporting protocols; and emerging risks such as phishing, social engineering, and improper disclosures.
B. Awareness Activities
- Regular awareness campaigns are conducted through internal posts and team meetings.
- Privacy advisories are issued by the DPO when there are relevant legal, regulatory, or operational updates.
- Posters, infographics, and quick reference guides are made available to staff.
C. Third-Party Awareness
- Third-party service providers processing data on behalf of NotarizeIT are required to receive privacy orientation and to sign confidentiality agreements.
- Vendors and contractors may be subject to additional training or briefings depending on the level of data they access.
D. Training Documentation
- Training attendance and awareness activities are documented by the DPO.
- Records of training are retained as evidence of compliance with the Data Privacy Act and NPC requirements.
- Failure to participate in mandatory training may result in administrative action, in line with company policy.
XII. Monitoring and Compliance
Unawa is committed to ensuring continuous compliance with the Data Privacy Act of 2012, its IRR, the issuances of the NPC, and applicable Supreme Court rules on electronic notarization. The organization maintains a system of regular monitoring, audits, and reviews.
A. Compliance Monitoring
The DPO, in coordination with relevant departments, monitors the implementation of this Policy and related policies. Monitoring activities include reviewing adherence to privacy policies and procedures; assessing compliance with retention schedules and disposal procedures; checking the sufficiency of security measures; and ensuring third-party processors comply with contractual data protection obligations.
B. Internal Audits
- Periodic internal audits are conducted to evaluate the effectiveness of the privacy program.
- Findings are documented and corrective actions are assigned to relevant units.
- Follow-up audits may be conducted to verify the implementation of corrective actions.
C. Breach and Incident Review
- All data privacy and security incidents reported to the DPO are logged in an Incident Register.
- The DPO analyzes incident trends to identify recurring vulnerabilities and recommend preventive measures.
- Lessons learned are integrated into training, awareness, and policy updates.
D. Reporting and Accountability
- The DPO provides regular reports to management on compliance status, significant risks, and recommendations.
- When required, compliance reports and breach notifications are submitted to the NPC and, where applicable, the Supreme Court in accordance with regulatory requirements.
- Functional heads and managers are accountable for ensuring their teams comply with privacy and security policies.
E. Continuous Improvement
- This Policy and supporting policies are reviewed at least once every two (2) years, or sooner when significant organizational or regulatory changes occur.
- Updates are communicated promptly to all employees and, where applicable, to third-party processors.
- Feedback from employees, clients, and regulators is considered in strengthening the privacy program.