Podcast
Questions and Answers
What is the primary purpose of the Data Privacy Act (RA No 10173)?
What is the primary purpose of the Data Privacy Act (RA No 10173)?
The Data Privacy Act applies only to the private sector.
The Data Privacy Act applies only to the private sector.
False (B)
What does 'personal information' refer to?
What does 'personal information' refer to?
Any information that can identify an individual
The Data Privacy Act created a __________ to oversee its implementation.
The Data Privacy Act created a __________ to oversee its implementation.
Signup and view all the answers
Match the terms with their definitions:
Match the terms with their definitions:
Signup and view all the answers
Which of the following is included in the definition of an Information and Communications System?
Which of the following is included in the definition of an Information and Communications System?
Signup and view all the answers
The Data Privacy Act allows unrestricted access to personal information for innovation purposes.
The Data Privacy Act allows unrestricted access to personal information for innovation purposes.
Signup and view all the answers
What is the policy of the State regarding individual privacy?
What is the policy of the State regarding individual privacy?
Signup and view all the answers
What must a personal information controller do when subcontracting the processing of personal information?
What must a personal information controller do when subcontracting the processing of personal information?
Signup and view all the answers
A personal information processor with less than 250 employees must always register, regardless of the risk level involved.
A personal information processor with less than 250 employees must always register, regardless of the risk level involved.
Signup and view all the answers
What is the maximum number of individuals whose sensitive personal information would require a processor to register?
What is the maximum number of individuals whose sensitive personal information would require a processor to register?
Signup and view all the answers
The personal information controller must submit a __________ summary of the reports to the Commission annually.
The personal information controller must submit a __________ summary of the reports to the Commission annually.
Signup and view all the answers
Which of the following is NOT required to be included in the registration of personal data processing?
Which of the following is NOT required to be included in the registration of personal data processing?
Signup and view all the answers
The Commission must always request the reports from the personal information controller.
The Commission must always request the reports from the personal information controller.
Signup and view all the answers
What should the personal information controller ensure while processing personal information?
What should the personal information controller ensure while processing personal information?
Signup and view all the answers
What is the role of a personal information controller?
What is the role of a personal information controller?
Signup and view all the answers
The National Privacy Commission is responsible for ensuring the confidentiality of personal information.
The National Privacy Commission is responsible for ensuring the confidentiality of personal information.
Signup and view all the answers
What does NPC stand for?
What does NPC stand for?
Signup and view all the answers
A personal information processor is any natural or juridical person who is qualified to act under this Act to whom a personal information controller may outsource the __________ of personal data.
A personal information processor is any natural or juridical person who is qualified to act under this Act to whom a personal information controller may outsource the __________ of personal data.
Signup and view all the answers
Match the following terms with their correct definitions:
Match the following terms with their correct definitions:
Signup and view all the answers
Which of the following is NOT excluded from the definition of a personal information controller?
Which of the following is NOT excluded from the definition of a personal information controller?
Signup and view all the answers
The NPC can refer to entities created under different acts.
The NPC can refer to entities created under different acts.
Signup and view all the answers
What is the primary function of the National Privacy Commission?
What is the primary function of the National Privacy Commission?
Signup and view all the answers
What is the definition of consent of the data subject?
What is the definition of consent of the data subject?
Signup and view all the answers
Sensitive personal information cannot include race or political affiliation.
Sensitive personal information cannot include race or political affiliation.
Signup and view all the answers
What does 'processing' refer to in the context of personal information?
What does 'processing' refer to in the context of personal information?
Signup and view all the answers
Which of the following conditions allows for the processing of personal information?
Which of the following conditions allows for the processing of personal information?
Signup and view all the answers
Consent may also be given on behalf of the data subject by an agent specifically authorized by the data subject to do so, and can be evidenced by __________.
Consent may also be given on behalf of the data subject by an agent specifically authorized by the data subject to do so, and can be evidenced by __________.
Signup and view all the answers
Personal information can be processed indefinitely as long as it serves a legitimate purpose.
Personal information can be processed indefinitely as long as it serves a legitimate purpose.
Signup and view all the answers
What principle requires that personal information be processed fairly and lawfully?
What principle requires that personal information be processed fairly and lawfully?
Signup and view all the answers
Match the following types of information with their descriptions:
Match the following types of information with their descriptions:
Signup and view all the answers
Which of the following is NOT considered sensitive personal information?
Which of the following is NOT considered sensitive personal information?
Signup and view all the answers
Personal information must be ______ for specified and legitimate purposes.
Personal information must be ______ for specified and legitimate purposes.
Signup and view all the answers
The Act applies only to legal persons involved in personal information processing.
The Act applies only to legal persons involved in personal information processing.
Signup and view all the answers
Match the condition of lawful processing to its description:
Match the condition of lawful processing to its description:
Signup and view all the answers
Which of the following is NOT a valid reason for processing personal information?
Which of the following is NOT a valid reason for processing personal information?
Signup and view all the answers
Name one type of information categorized under privileged information.
Name one type of information categorized under privileged information.
Signup and view all the answers
Data controllers must ensure the accuracy and relevance of the personal information they process.
Data controllers must ensure the accuracy and relevance of the personal information they process.
Signup and view all the answers
The processing of personal information for performing public functions includes the activities of __________.
The processing of personal information for performing public functions includes the activities of __________.
Signup and view all the answers
Which of the following statements regarding sensitive personal information is TRUE?
Which of the following statements regarding sensitive personal information is TRUE?
Signup and view all the answers
What must be done with inaccurate personal data?
What must be done with inaccurate personal data?
Signup and view all the answers
Data must be kept in a form that permits ______ for no longer than necessary.
Data must be kept in a form that permits ______ for no longer than necessary.
Signup and view all the answers
What principle ensures that personal information is adequate and not excessive?
What principle ensures that personal information is adequate and not excessive?
Signup and view all the answers
Under what circumstance is the processing of sensitive personal information allowed?
Under what circumstance is the processing of sensitive personal information allowed?
Signup and view all the answers
Consent of the data subject is required for all instances of sensitive personal information processing.
Consent of the data subject is required for all instances of sensitive personal information processing.
Signup and view all the answers
What should be included in the information furnished to the data subject prior to processing?
What should be included in the information furnished to the data subject prior to processing?
Signup and view all the answers
The processing of sensitive personal information is prohibited except in cases where _______ is obtained.
The processing of sensitive personal information is prohibited except in cases where _______ is obtained.
Signup and view all the answers
Match the following scenarios with the appropriate condition for processing sensitive personal information:
Match the following scenarios with the appropriate condition for processing sensitive personal information:
Signup and view all the answers
Which of the following is NOT a right of the data subject?
Which of the following is NOT a right of the data subject?
Signup and view all the answers
Sensitive personal information may be processed without the data subject's consent if related to public health.
Sensitive personal information may be processed without the data subject's consent if related to public health.
Signup and view all the answers
What is the obligation of the personal information controller before processing personal information?
What is the obligation of the personal information controller before processing personal information?
Signup and view all the answers
Personal information processing should inform the data subject about the ______ of their information.
Personal information processing should inform the data subject about the ______ of their information.
Signup and view all the answers
Which one of the following indicates a condition under which sensitive personal information can be processed?
Which one of the following indicates a condition under which sensitive personal information can be processed?
Signup and view all the answers
Study Notes
Data Privacy Act (RA No. 10173)
- Protects individual personal information in information and communications systems in the government and private sector.
- Creates a National Privacy Commission (NPC) for this purpose.
- Ensures confidentiality of personal information held by the NPC.
Declaration of Policy
- Protects the fundamental human right to privacy and communication.
- Promotes innovation and growth by ensuring free flow of information.
- Recognizes the crucial role of information and communications technology in nation-building.
Functions of the National Privacy Commission (NPC)
- Administers and implements the provisions of the Act.
- Monitors compliance with international data protection standards.
- Ensures the confidentiality of all personal information.
Terminologies
- Consent: Freely given, specific, informed indication of willingness to allow collection and processing of personal information.
- Data subject: An individual whose personal information is processed.
- Information and Communications System (ICS): System for generating, sending, receiving, storing, or processing electronic data, including procedures.
- Personal information: Any information (recorded or not) identifying an individual, or enabling identification when combined with other information.
- Personal information controller: Person/organization controlling collection, holding, processing, or use of personal information.
- Personal information processor: Entity processing personal information on behalf of a controller.
- Processing: Any operation on personal information, including collection, recording, organization, storage, updating, etc.
- Privileged information: Information protected as privileged communication by laws/rules.
Sensitive Personal Information
- Includes information on race, ethnicity, marital status, age, color, religious/philosophical/political affiliation.
- Health, education, genetic/sexual life, any legal proceedings.
- Government-issued identification, records, permits, denials, suspensions, revocations, and tax returns.
- Any information classified by executive order or act of Congress.
The scope of application refers to the extent and boundaries within which laws, regulations, or policies are applicable. This includes the populations, entities, and situations affected by specific legal frameworks. It is important to delineate the parameters to ensure that individuals and organizations understand their rights, obligations, and protections under the relevant laws. It can also define geographic limitations and the temporal aspects, such as when certain rules take effect or expire. Understanding the scope is crucial for compliance and enforcement.
- Applies to all types of personal information processing by natural and juridical persons.
- Includes those in the Philippines and those processing data using Philippine equipment or having an office/branch here.
- Excludes information about government officers/employees related to their position, contracts with the government, and certain financial transactions.
- Excludes information collected from foreign jurisdictions under their laws.
Lawful Processing of Personal Information
- Processing allowed only if not prohibited by law.
- Consent from the data subject.
- Necessary for fulfilling a contract or taking steps prior to a contract.
- Necessary for complying with a legal obligation.
- Necessary for protecting vital interests (like life or health).
- Necessary for responding to a national emergency or public safety issue.
- Necessary for providing or performing a mandate based on public authority.
- Necessary for legitimate interests of a controller or third-party, unless overridden by data subject rights.
Sensitive Personal Information and Privileged Information Processing
- Processing prohibited unless specified conditions are met.
- Consent from the data subject, specific to the purpose.
- Processing permitted by existing law/regulation, with safeguards for sensitive/privileged information.
- Necessary for protecting life/health of data subject/another person, where they can't give consent.
- Necessary for non-commercial objectives of public organizations/associations, for members only, and with compliance with safeguards.
- Processing for purposes of medical treatment by a licensed medical professional.
- Required to protect lawful rights/interests of a party in court proceedings.
Rights of the Data Subject
- Be informed if personal information is processed.
- Receive information about the processing (description, purposes, recipients, storage period, etc.).
- Access, correct, or request removal of personal information (if inaccurate, incomplete, outdated, etc.).
- Lodge a complaint with the Commission.
- Suspend, withdraw, or order the removal of personal information if found to be incomplete, inaccurate, etc.
Personal Data Breach Notification
- Notification within 72 hours of knowledge of a breach.
- Requires notification if sensitive information has been compromised, significantly impacting a person's identity and/or causing harm, or in cases deemed likely for these issues.
- Includes a description of the nature, personal data involved, and measures taken.
- Delayed notification for certain reasons, such as further investigation or restoring system integrity.
Automated Processing Operations Notification
- Notification required for wholly or partially automated processing that significantly affects data subject rights.
- Includes details on processing purpose, data categories, data subjects, consent forms, recipients, data storage period, processing logic, decisions based on processed data, and officer contact.
- Decisions based on automated processing alone are prohibited without consent.
Review by the Commission
- Reviews actions from personal information controllers/processors.
- Reviews compliance with the Act and other data protection regulations.
- Reviews data sharing agreements and other relevant contracts.
- Reviews issues about whether processes sufficiently protect data subjects' rights.
- Reviews the implementation of the Act, rules, and other related issuances.
Accountability for Transfer of Personal Information
- Controller is responsible for transferring personal information.
- Must take measures to protect information transferred to third parties.
- Should designate an individual/individuals to ensure compliance with the Act.
Registration of Personal Data Processing Systems
- Registration requirements for systems using personal information.
- Applies to systems of organizations with more than 250 employees, or those with high-risk processing.
- Includes details on purpose of use, data categories, and recipients.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Explore the key features of the Data Privacy Act (RA No. 10173), which safeguards individual personal information within both government and private sectors. Learn about the establishment of the National Privacy Commission and its essential functions in maintaining data confidentiality and compliance with international standards.