Podcast
Questions and Answers
What is the primary purpose of the Data Privacy Act (RA No 10173)?
What is the primary purpose of the Data Privacy Act (RA No 10173)?
- To promote social media usage
- To protect individual personal information (correct)
- To regulate the internet
- To enhance government transparency
The Data Privacy Act applies only to the private sector.
The Data Privacy Act applies only to the private sector.
False (B)
What does 'personal information' refer to?
What does 'personal information' refer to?
Any information that can identify an individual
The Data Privacy Act created a __________ to oversee its implementation.
The Data Privacy Act created a __________ to oversee its implementation.
Match the terms with their definitions:
Match the terms with their definitions:
Which of the following is included in the definition of an Information and Communications System?
Which of the following is included in the definition of an Information and Communications System?
The Data Privacy Act allows unrestricted access to personal information for innovation purposes.
The Data Privacy Act allows unrestricted access to personal information for innovation purposes.
What is the policy of the State regarding individual privacy?
What is the policy of the State regarding individual privacy?
What must a personal information controller do when subcontracting the processing of personal information?
What must a personal information controller do when subcontracting the processing of personal information?
A personal information processor with less than 250 employees must always register, regardless of the risk level involved.
A personal information processor with less than 250 employees must always register, regardless of the risk level involved.
What is the maximum number of individuals whose sensitive personal information would require a processor to register?
What is the maximum number of individuals whose sensitive personal information would require a processor to register?
The personal information controller must submit a __________ summary of the reports to the Commission annually.
The personal information controller must submit a __________ summary of the reports to the Commission annually.
Which of the following is NOT required to be included in the registration of personal data processing?
Which of the following is NOT required to be included in the registration of personal data processing?
The Commission must always request the reports from the personal information controller.
The Commission must always request the reports from the personal information controller.
What should the personal information controller ensure while processing personal information?
What should the personal information controller ensure while processing personal information?
What is the role of a personal information controller?
What is the role of a personal information controller?
The National Privacy Commission is responsible for ensuring the confidentiality of personal information.
The National Privacy Commission is responsible for ensuring the confidentiality of personal information.
What does NPC stand for?
What does NPC stand for?
A personal information processor is any natural or juridical person who is qualified to act under this Act to whom a personal information controller may outsource the __________ of personal data.
A personal information processor is any natural or juridical person who is qualified to act under this Act to whom a personal information controller may outsource the __________ of personal data.
Match the following terms with their correct definitions:
Match the following terms with their correct definitions:
Which of the following is NOT excluded from the definition of a personal information controller?
Which of the following is NOT excluded from the definition of a personal information controller?
The NPC can refer to entities created under different acts.
The NPC can refer to entities created under different acts.
What is the primary function of the National Privacy Commission?
What is the primary function of the National Privacy Commission?
What is the definition of consent of the data subject?
What is the definition of consent of the data subject?
Sensitive personal information cannot include race or political affiliation.
Sensitive personal information cannot include race or political affiliation.
What does 'processing' refer to in the context of personal information?
What does 'processing' refer to in the context of personal information?
Which of the following conditions allows for the processing of personal information?
Which of the following conditions allows for the processing of personal information?
Consent may also be given on behalf of the data subject by an agent specifically authorized by the data subject to do so, and can be evidenced by __________.
Consent may also be given on behalf of the data subject by an agent specifically authorized by the data subject to do so, and can be evidenced by __________.
Personal information can be processed indefinitely as long as it serves a legitimate purpose.
Personal information can be processed indefinitely as long as it serves a legitimate purpose.
What principle requires that personal information be processed fairly and lawfully?
What principle requires that personal information be processed fairly and lawfully?
Match the following types of information with their descriptions:
Match the following types of information with their descriptions:
Which of the following is NOT considered sensitive personal information?
Which of the following is NOT considered sensitive personal information?
Personal information must be ______ for specified and legitimate purposes.
Personal information must be ______ for specified and legitimate purposes.
The Act applies only to legal persons involved in personal information processing.
The Act applies only to legal persons involved in personal information processing.
Match the condition of lawful processing to its description:
Match the condition of lawful processing to its description:
Which of the following is NOT a valid reason for processing personal information?
Which of the following is NOT a valid reason for processing personal information?
Name one type of information categorized under privileged information.
Name one type of information categorized under privileged information.
Data controllers must ensure the accuracy and relevance of the personal information they process.
Data controllers must ensure the accuracy and relevance of the personal information they process.
The processing of personal information for performing public functions includes the activities of __________.
The processing of personal information for performing public functions includes the activities of __________.
Which of the following statements regarding sensitive personal information is TRUE?
Which of the following statements regarding sensitive personal information is TRUE?
What must be done with inaccurate personal data?
What must be done with inaccurate personal data?
Data must be kept in a form that permits ______ for no longer than necessary.
Data must be kept in a form that permits ______ for no longer than necessary.
What principle ensures that personal information is adequate and not excessive?
What principle ensures that personal information is adequate and not excessive?
Under what circumstance is the processing of sensitive personal information allowed?
Under what circumstance is the processing of sensitive personal information allowed?
Consent of the data subject is required for all instances of sensitive personal information processing.
Consent of the data subject is required for all instances of sensitive personal information processing.
What should be included in the information furnished to the data subject prior to processing?
What should be included in the information furnished to the data subject prior to processing?
The processing of sensitive personal information is prohibited except in cases where _______ is obtained.
The processing of sensitive personal information is prohibited except in cases where _______ is obtained.
Match the following scenarios with the appropriate condition for processing sensitive personal information:
Match the following scenarios with the appropriate condition for processing sensitive personal information:
Which of the following is NOT a right of the data subject?
Which of the following is NOT a right of the data subject?
Sensitive personal information may be processed without the data subject's consent if related to public health.
Sensitive personal information may be processed without the data subject's consent if related to public health.
What is the obligation of the personal information controller before processing personal information?
What is the obligation of the personal information controller before processing personal information?
Personal information processing should inform the data subject about the ______ of their information.
Personal information processing should inform the data subject about the ______ of their information.
Which one of the following indicates a condition under which sensitive personal information can be processed?
Which one of the following indicates a condition under which sensitive personal information can be processed?
Flashcards
Right to Privacy
Right to Privacy
The right to control access to and use of personal information.
Data Privacy Act (RA 10173)
Data Privacy Act (RA 10173)
A legal framework protecting the personal information of individuals in information and communications systems (ICS).
Information and Communications System (ICS)
Information and Communications System (ICS)
A system used to generate, send, receive, store, or process electronic data messages, including computers and networks.
State Policy for Privacy Protection
State Policy for Privacy Protection
Signup and view all the flashcards
Personal Information
Personal Information
Signup and view all the flashcards
National Privacy Commission (NPC)
National Privacy Commission (NPC)
Signup and view all the flashcards
Balance of Privacy and Innovation
Balance of Privacy and Innovation
Signup and view all the flashcards
Personal Information Processing System
Personal Information Processing System
Signup and view all the flashcards
What is the National Privacy Commission (NPC)?
What is the National Privacy Commission (NPC)?
Signup and view all the flashcards
What are the main functions of the NPC?
What are the main functions of the NPC?
Signup and view all the flashcards
What is the NPC's responsibility regarding personal information?
What is the NPC's responsibility regarding personal information?
Signup and view all the flashcards
What does 'Commission' refer to in the context of the Data Privacy Act?
What does 'Commission' refer to in the context of the Data Privacy Act?
Signup and view all the flashcards
What is a Personal Information Controller?
What is a Personal Information Controller?
Signup and view all the flashcards
What is a Personal Information Processor?
What is a Personal Information Processor?
Signup and view all the flashcards
Who is NOT considered a Personal Information Controller?
Who is NOT considered a Personal Information Controller?
Signup and view all the flashcards
Why are these terms important in the context of the Data Privacy Act?
Why are these terms important in the context of the Data Privacy Act?
Signup and view all the flashcards
Consent of the data subject
Consent of the data subject
Signup and view all the flashcards
Processing (of personal data)
Processing (of personal data)
Signup and view all the flashcards
Data Subject
Data Subject
Signup and view all the flashcards
Sensitive Personal Information (Type 1)
Sensitive Personal Information (Type 1)
Signup and view all the flashcards
Sensitive Personal Information (Type 2)
Sensitive Personal Information (Type 2)
Signup and view all the flashcards
Sensitive Personal Information (Type 3)
Sensitive Personal Information (Type 3)
Signup and view all the flashcards
Sensitive Personal Information (Type 4)
Sensitive Personal Information (Type 4)
Signup and view all the flashcards
Scope of Application (of the Act)
Scope of Application (of the Act)
Signup and view all the flashcards
Privileged Information
Privileged Information
Signup and view all the flashcards
Sensitive Personal Information (Government Employee)
Sensitive Personal Information (Government Employee)
Signup and view all the flashcards
Lawful Processing of Personal Information (Section 11)
Lawful Processing of Personal Information (Section 11)
Signup and view all the flashcards
Consent
Consent
Signup and view all the flashcards
Fulfillment of Contract
Fulfillment of Contract
Signup and view all the flashcards
Compliance With Legal Obligation
Compliance With Legal Obligation
Signup and view all the flashcards
Protection of Vital Interests
Protection of Vital Interests
Signup and view all the flashcards
National Emergency or Public Interest
National Emergency or Public Interest
Signup and view all the flashcards
Legitimate Interests
Legitimate Interests
Signup and view all the flashcards
Purpose Limitation
Purpose Limitation
Signup and view all the flashcards
Fairness and Lawfulness
Fairness and Lawfulness
Signup and view all the flashcards
Accuracy and Relevance
Accuracy and Relevance
Signup and view all the flashcards
Subcontracting Personal Information Processing
Subcontracting Personal Information Processing
Signup and view all the flashcards
Exemption from Registration
Exemption from Registration
Signup and view all the flashcards
Accountability for Information Transfer
Accountability for Information Transfer
Signup and view all the flashcards
Registration Contents
Registration Contents
Signup and view all the flashcards
Purpose of Information Processing
Purpose of Information Processing
Signup and view all the flashcards
Personal Information Controller
Personal Information Controller
Signup and view all the flashcards
Personal Information Processor
Personal Information Processor
Signup and view all the flashcards
Annual Summary Report
Annual Summary Report
Signup and view all the flashcards
Right to be Informed
Right to be Informed
Signup and view all the flashcards
Right to Prior Information
Right to Prior Information
Signup and view all the flashcards
Right to Correction
Right to Correction
Signup and view all the flashcards
Processing of Sensitive and Privileged Information
Processing of Sensitive and Privileged Information
Signup and view all the flashcards
Personal Information Processing Principles
Personal Information Processing Principles
Signup and view all the flashcards
Safeguards for Long-Term Storage
Safeguards for Long-Term Storage
Signup and view all the flashcards
Consent for Sensitive Information
Consent for Sensitive Information
Signup and view all the flashcards
Processing for Life and Health Protection
Processing for Life and Health Protection
Signup and view all the flashcards
Data Processing for Public Organizations
Data Processing for Public Organizations
Signup and view all the flashcards
Processing Under Legal Requirements
Processing Under Legal Requirements
Signup and view all the flashcards
Study Notes
Data Privacy Act (RA No. 10173)
- Protects individual personal information in information and communications systems in the government and private sector.
- Creates a National Privacy Commission (NPC) for this purpose.
- Ensures confidentiality of personal information held by the NPC.
Declaration of Policy
- Protects the fundamental human right to privacy and communication.
- Promotes innovation and growth by ensuring free flow of information.
- Recognizes the crucial role of information and communications technology in nation-building.
Functions of the National Privacy Commission (NPC)
- Administers and implements the provisions of the Act.
- Monitors compliance with international data protection standards.
- Ensures the confidentiality of all personal information.
Terminologies
- Consent: Freely given, specific, informed indication of willingness to allow collection and processing of personal information.
- Data subject: An individual whose personal information is processed.
- Information and Communications System (ICS): System for generating, sending, receiving, storing, or processing electronic data, including procedures.
- Personal information: Any information (recorded or not) identifying an individual, or enabling identification when combined with other information.
- Personal information controller: Person/organization controlling collection, holding, processing, or use of personal information.
- Personal information processor: Entity processing personal information on behalf of a controller.
- Processing: Any operation on personal information, including collection, recording, organization, storage, updating, etc.
- Privileged information: Information protected as privileged communication by laws/rules.
Sensitive Personal Information
- Includes information on race, ethnicity, marital status, age, color, religious/philosophical/political affiliation.
- Health, education, genetic/sexual life, any legal proceedings.
- Government-issued identification, records, permits, denials, suspensions, revocations, and tax returns.
- Any information classified by executive order or act of Congress.
The scope of application refers to the extent and boundaries within which laws, regulations, or policies are applicable. This includes the populations, entities, and situations affected by specific legal frameworks. It is important to delineate the parameters to ensure that individuals and organizations understand their rights, obligations, and protections under the relevant laws. It can also define geographic limitations and the temporal aspects, such as when certain rules take effect or expire. Understanding the scope is crucial for compliance and enforcement.
- Applies to all types of personal information processing by natural and juridical persons.
- Includes those in the Philippines and those processing data using Philippine equipment or having an office/branch here.
- Excludes information about government officers/employees related to their position, contracts with the government, and certain financial transactions.
- Excludes information collected from foreign jurisdictions under their laws.
Lawful Processing of Personal Information
- Processing allowed only if not prohibited by law.
- Consent from the data subject.
- Necessary for fulfilling a contract or taking steps prior to a contract.
- Necessary for complying with a legal obligation.
- Necessary for protecting vital interests (like life or health).
- Necessary for responding to a national emergency or public safety issue.
- Necessary for providing or performing a mandate based on public authority.
- Necessary for legitimate interests of a controller or third-party, unless overridden by data subject rights.
Sensitive Personal Information and Privileged Information Processing
- Processing prohibited unless specified conditions are met.
- Consent from the data subject, specific to the purpose.
- Processing permitted by existing law/regulation, with safeguards for sensitive/privileged information.
- Necessary for protecting life/health of data subject/another person, where they can't give consent.
- Necessary for non-commercial objectives of public organizations/associations, for members only, and with compliance with safeguards.
- Processing for purposes of medical treatment by a licensed medical professional.
- Required to protect lawful rights/interests of a party in court proceedings.
Rights of the Data Subject
- Be informed if personal information is processed.
- Receive information about the processing (description, purposes, recipients, storage period, etc.).
- Access, correct, or request removal of personal information (if inaccurate, incomplete, outdated, etc.).
- Lodge a complaint with the Commission.
- Suspend, withdraw, or order the removal of personal information if found to be incomplete, inaccurate, etc.
Personal Data Breach Notification
- Notification within 72 hours of knowledge of a breach.
- Requires notification if sensitive information has been compromised, significantly impacting a person's identity and/or causing harm, or in cases deemed likely for these issues.
- Includes a description of the nature, personal data involved, and measures taken.
- Delayed notification for certain reasons, such as further investigation or restoring system integrity.
Automated Processing Operations Notification
- Notification required for wholly or partially automated processing that significantly affects data subject rights.
- Includes details on processing purpose, data categories, data subjects, consent forms, recipients, data storage period, processing logic, decisions based on processed data, and officer contact.
- Decisions based on automated processing alone are prohibited without consent.
Review by the Commission
- Reviews actions from personal information controllers/processors.
- Reviews compliance with the Act and other data protection regulations.
- Reviews data sharing agreements and other relevant contracts.
- Reviews issues about whether processes sufficiently protect data subjects' rights.
- Reviews the implementation of the Act, rules, and other related issuances.
Accountability for Transfer of Personal Information
- Controller is responsible for transferring personal information.
- Must take measures to protect information transferred to third parties.
- Should designate an individual/individuals to ensure compliance with the Act.
Registration of Personal Data Processing Systems
- Registration requirements for systems using personal information.
- Applies to systems of organizations with more than 250 employees, or those with high-risk processing.
- Includes details on purpose of use, data categories, and recipients.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.