Podcast
Questions and Answers
What is considered sensitive personal information related to an individual's background?
What is considered sensitive personal information related to an individual's background?
Which of the following is NOT classified as sensitive personal information?
Which of the following is NOT classified as sensitive personal information?
Under what condition do the Act and Rules apply to personal data processing outside of the Philippines?
Under what condition do the Act and Rules apply to personal data processing outside of the Philippines?
What must a government agency require from a private service provider when accessing sensitive personal information of over a thousand individuals?
What must a government agency require from a private service provider when accessing sensitive personal information of over a thousand individuals?
Signup and view all the answers
What is necessary for a data sharing agreement between agencies?
What is necessary for a data sharing agreement between agencies?
Signup and view all the answers
What happens before any request for off-site or online access is approved?
What happens before any request for off-site or online access is approved?
Signup and view all the answers
Which of the following is NOT included in sensitive personal information outlined in the content?
Which of the following is NOT included in sensitive personal information outlined in the content?
Signup and view all the answers
What is the purpose of the executive order regarding sensitive personal information?
What is the purpose of the executive order regarding sensitive personal information?
Signup and view all the answers
What is the maximum imprisonment penalty for unauthorized processing of personal information?
What is the maximum imprisonment penalty for unauthorized processing of personal information?
Signup and view all the answers
Which penalty applies to unauthorized processing of sensitive personal information?
Which penalty applies to unauthorized processing of sensitive personal information?
Signup and view all the answers
What penalty is imposed for negligence in accessing personal information without authorization?
What penalty is imposed for negligence in accessing personal information without authorization?
Signup and view all the answers
What is the minimum fine imposed for improper disposal of sensitive personal information?
What is the minimum fine imposed for improper disposal of sensitive personal information?
Signup and view all the answers
If a person processes personal information without the consent of the data subject, which punishment could they face?
If a person processes personal information without the consent of the data subject, which punishment could they face?
Signup and view all the answers
What rights does a data subject have regarding their personal data processing?
What rights does a data subject have regarding their personal data processing?
Signup and view all the answers
What must the personal information controller provide to the data subject?
What must the personal information controller provide to the data subject?
Signup and view all the answers
Which of the following describes the right to object for a data subject?
Which of the following describes the right to object for a data subject?
Signup and view all the answers
Which of these aspects is NOT a part of the right to be informed?
Which of these aspects is NOT a part of the right to be informed?
Signup and view all the answers
What is a requirement for notifying a data subject before processing their data?
What is a requirement for notifying a data subject before processing their data?
Signup and view all the answers
Which of the following reflects a right related to automated decision-making?
Which of the following reflects a right related to automated decision-making?
Signup and view all the answers
What must a data subject be informed about, concerning the processing of their data?
What must a data subject be informed about, concerning the processing of their data?
Signup and view all the answers
What is included in the information that must be provided to data subjects before processing their data?
What is included in the information that must be provided to data subjects before processing their data?
Signup and view all the answers
What is the minimum imprisonment penalty for someone who unlawfully breaks into a system storing personal information?
What is the minimum imprisonment penalty for someone who unlawfully breaks into a system storing personal information?
Signup and view all the answers
What is the maximum fine that can be imposed for concealing a security breach involving sensitive personal information?
What is the maximum fine that can be imposed for concealing a security breach involving sensitive personal information?
Signup and view all the answers
For malicious disclosure of personal information, what is the range of imprisonment that can be imposed?
For malicious disclosure of personal information, what is the range of imprisonment that can be imposed?
Signup and view all the answers
What is the minimum imprisonment sentence for a personal information controller who discloses sensitive personal information without consent?
What is the minimum imprisonment sentence for a personal information controller who discloses sensitive personal information without consent?
Signup and view all the answers
What is required for a personal information controller to legally disclose personal information to a third party?
What is required for a personal information controller to legally disclose personal information to a third party?
Signup and view all the answers
What penalty is imposed on a corporation if an offense is committed due to gross negligence?
What penalty is imposed on a corporation if an offense is committed due to gross negligence?
Signup and view all the answers
What is the penalty for a person who conceals a security breach of which they have knowledge?
What is the penalty for a person who conceals a security breach of which they have knowledge?
Signup and view all the answers
What is the fine range for a person who unlawfully discloses personal information without consent?
What is the fine range for a person who unlawfully discloses personal information without consent?
Signup and view all the answers
What is the penalty for an alien found guilty of a related offense?
What is the penalty for an alien found guilty of a related offense?
Signup and view all the answers
Which of the following actions triggers a penalty of imprisonment and a fine as described?
Which of the following actions triggers a penalty of imprisonment and a fine as described?
Signup and view all the answers
What is the impact of committing an offense involving personal data of at least 100 persons?
What is the impact of committing an offense involving personal data of at least 100 persons?
Signup and view all the answers
What happens to a public official found guilty of offenses under Sections 54 and 55?
What happens to a public official found guilty of offenses under Sections 54 and 55?
Signup and view all the answers
Which entity is responsible for imposing penalties on violations related to data confidentiality?
Which entity is responsible for imposing penalties on violations related to data confidentiality?
Signup and view all the answers
What is the maximum fine for a combination of acts defined in Sections 52 to 59?
What is the maximum fine for a combination of acts defined in Sections 52 to 59?
Signup and view all the answers
What accessory penalty does a public officer face when committing an offense in the course of his duties?
What accessory penalty does a public officer face when committing an offense in the course of his duties?
Signup and view all the answers
Which of the following statements about the penalties for offenses against personal data protection is correct?
Which of the following statements about the penalties for offenses against personal data protection is correct?
Signup and view all the answers
Study Notes
Sensitive Personal Information
- Includes racial/ethnic origin, marital status, age, color, religious/philosophical/political affiliations.
- Covers health, education, genetic or sexual life; legal proceedings or sentences.
- Government-issued data like social security numbers, health records, licenses (including denials/revocations), tax returns.
- Information classified via executive order or Congressional act.
Scope of Application
- Act and rules apply to all natural and juridical persons (government or private) processing personal data.
- Applies to acts/practices inside or outside Philippines if:
- The processor is located in the Philippines.
- The data relates to a Filipino citizen or resident.
Security Requirements Implementation
- Security requirements must be implemented before any off-site or online access is approved.
- Data sharing agreements between agencies are subject to Commission review (initiative or complaint).
Applicability to Government Contractors
- Government agencies contracting private providers (accessing sensitive info from ≥1000 individuals) must require provider registration with the Commission.
- Providers must comply with all Act and Rule provisions, like government agencies and their employees.
Rights of Data Subjects
-
Right to be informed: Data subjects have the right to know if their data is being processed (including automated decisions/profiling). Notification includes:
- Description of data.
- Processing purposes (marketing, profiling, etc.).
- Processing basis (if not consent).
- Processing scope and method.
- Recipients of the data.
- Automated access methods (if applicable).
- Data controller's identity and contact.
- Data storage period.
- Data subject rights (access, correction, objection, complaint filing).
- Right to object.
Penalties for Unauthorized Processing
- Unauthorized processing of personal information: 1–3 years imprisonment, ₱500,000–₱2,000,000 fine.
- Unauthorized processing of sensitive personal information: 3–6 years imprisonment, ₱500,000–₱4,000,000 fine.
- Negligent access to personal information: 1–3 years imprisonment, ₱500,000–₱2,000,000 fine.
- Negligent access to sensitive personal information: 3–6 years imprisonment, ₱500,000–₱4,000,000 fine.
- Improper disposal of personal/sensitive information (knowingly unlawful or violating data confidentiality/system security): 1–3 years imprisonment, ₱500,000–₱2,000,000 fine.
- Concealment of security breaches (sensitive personal information): 1.5–5 years imprisonment, ₱500,000–₱1,000,000 fine.
- Malicious disclosure of unwarranted/false information: 1.5–5 years imprisonment, ₱500,000–₱1,000,000 fine.
- Unauthorized disclosure of personal information (not covered by malicious disclosure): 1–3 years imprisonment, ₱500,000–₱1,000,000 fine.
- Unauthorized disclosure of sensitive personal information (not covered by malicious disclosure): 3–5 years imprisonment, ₱500,000–₱2,000,000 fine.
- Combination/series of offenses: 3–6 years imprisonment, ₱1,000,000–₱5,000,000 fine.
Extent of Liability
- For corporations/juridical persons, penalties apply to responsible participating officers or those who allowed the crime through gross negligence.
- Courts may suspend or revoke rights under the Act.
- Alien offenders will be deported after serving their sentences.
- Public officials/employees guilty of offenses in Sections 54 and 55 face perpetual/temporary disqualification.
Large-Scale Offenses
- Maximum penalties apply if ≥100 persons are harmed/affected.
Offense Committed by Public Officer
- Public officers (as defined in the Administrative Code of 1987) committing offenses while on duty face an additional disqualification from public office, double the criminal penalty's term.
Restitution
- Note: The provided text cuts off here, preventing the inclusion of information regarding restitution.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
This quiz covers the regulations surrounding sensitive personal information and data privacy in the Philippines. It includes the application scope, security requirements, and the obligations of both government and private entities. Test your knowledge on how these laws affect data processing and handling.