Podcast
Questions and Answers
What is the definition of a filing system?
What is the definition of a filing system?
Which of the following best describes personal data?
Which of the following best describes personal data?
What occurs during a personal data breach?
What occurs during a personal data breach?
Which of the following is NOT a function of a personal information controller?
Which of the following is NOT a function of a personal information controller?
Signup and view all the answers
What is included in an information and communications system?
What is included in an information and communications system?
Signup and view all the answers
What characterizes personal information?
What characterizes personal information?
Signup and view all the answers
Which statement about personal information controllers is true?
Which statement about personal information controllers is true?
Signup and view all the answers
What is the primary role of an information and communications system?
What is the primary role of an information and communications system?
Signup and view all the answers
What does the term "personal information processor" refer to?
What does the term "personal information processor" refer to?
Signup and view all the answers
Which of the following activities is considered 'processing' of personal data?
Which of the following activities is considered 'processing' of personal data?
Signup and view all the answers
What does 'profiling' consist of?
What does 'profiling' consist of?
Signup and view all the answers
Which of the following describes 'privileged information'?
Which of the following describes 'privileged information'?
Signup and view all the answers
What is a 'security incident'?
What is a 'security incident'?
Signup and view all the answers
What constitutes sensitive personal information?
What constitutes sensitive personal information?
Signup and view all the answers
Who is classified as a 'public authority'?
Who is classified as a 'public authority'?
Signup and view all the answers
Which of the following is NOT an element of 'processing'?
Which of the following is NOT an element of 'processing'?
Signup and view all the answers
What principle requires that the processing of personal data should not exceed what is necessary for the specified purpose?
What principle requires that the processing of personal data should not exceed what is necessary for the specified purpose?
Signup and view all the answers
Which of the following is NOT a requirement for the processing of personal data under the legislation?
Which of the following is NOT a requirement for the processing of personal data under the legislation?
Signup and view all the answers
What must a data subject be informed about according to the principle of transparency?
What must a data subject be informed about according to the principle of transparency?
Signup and view all the answers
For what reasons can consent for the processing of personal data be withdrawn?
For what reasons can consent for the processing of personal data be withdrawn?
Signup and view all the answers
What is the primary purpose of requiring consent prior to data collection?
What is the primary purpose of requiring consent prior to data collection?
Signup and view all the answers
Which of the following best describes the principle of legitimate purpose?
Which of the following best describes the principle of legitimate purpose?
Signup and view all the answers
What does the principle of transparency primarily emphasize?
What does the principle of transparency primarily emphasize?
Signup and view all the answers
Under what condition is data processing considered permissible?
Under what condition is data processing considered permissible?
Signup and view all the answers
What type of issued information is primarily referenced?
What type of issued information is primarily referenced?
Signup and view all the answers
In which scenario does the Act apply to entities not established in the Philippines?
In which scenario does the Act apply to entities not established in the Philippines?
Signup and view all the answers
Which of the following is NOT a condition for the Act's applicability?
Which of the following is NOT a condition for the Act's applicability?
Signup and view all the answers
What is the significance of 'comity' in the context of the Act?
What is the significance of 'comity' in the context of the Act?
Signup and view all the answers
Which situation would likely NOT necessitate the collection of restricted information?
Which situation would likely NOT necessitate the collection of restricted information?
Signup and view all the answers
What type of entities does the Act explicitly apply to?
What type of entities does the Act explicitly apply to?
Signup and view all the answers
Which of the following statements is true regarding the special cases mentioned in the Act?
Which of the following statements is true regarding the special cases mentioned in the Act?
Signup and view all the answers
How is personal data processing defined in the context of the Act?
How is personal data processing defined in the context of the Act?
Signup and view all the answers
What is the primary obligation of employees, agents, or representatives who have access to personal data?
What is the primary obligation of employees, agents, or representatives who have access to personal data?
Signup and view all the answers
Which of the following is NOT part of the processing of personal data procedures?
Which of the following is NOT part of the processing of personal data procedures?
Signup and view all the answers
What must personal information controllers ensure through contractual agreements?
What must personal information controllers ensure through contractual agreements?
Signup and view all the answers
What is a key training component for employees who process personal data?
What is a key training component for employees who process personal data?
Signup and view all the answers
What type of timeline must be established for personal data retention?
What type of timeline must be established for personal data retention?
Signup and view all the answers
What responsibility do data subjects have under the processing of personal data?
What responsibility do data subjects have under the processing of personal data?
Signup and view all the answers
Which procedure is focused specifically on obtaining consent for data processing?
Which procedure is focused specifically on obtaining consent for data processing?
Signup and view all the answers
What is a necessary component of managing human resources in relation to personal data?
What is a necessary component of managing human resources in relation to personal data?
Signup and view all the answers
What is required of a personal information controller when subcontracting the processing of personal data?
What is required of a personal information controller when subcontracting the processing of personal data?
Signup and view all the answers
What must be included in the contract governing the processing of personal data?
What must be included in the contract governing the processing of personal data?
Signup and view all the answers
Which of the following is NOT a requirement for a personal information processor as per the outlined agreements?
Which of the following is NOT a requirement for a personal information processor as per the outlined agreements?
Signup and view all the answers
What must be ensured to prevent unauthorized use of personal data when subcontracting?
What must be ensured to prevent unauthorized use of personal data when subcontracting?
Signup and view all the answers
What type of document must the agreement for outsourcing be governed by?
What type of document must the agreement for outsourcing be governed by?
Signup and view all the answers
What is a key responsibility of the personal information processor regarding confidentiality?
What is a key responsibility of the personal information processor regarding confidentiality?
Signup and view all the answers
What is the purpose of ensuring safeguards during personal data processing?
What is the purpose of ensuring safeguards during personal data processing?
Signup and view all the answers
In what circumstance can personal data be transferred internationally without documented instructions?
In what circumstance can personal data be transferred internationally without documented instructions?
Signup and view all the answers
Study Notes
Implementing Rules and Regulations of Republic Act No. 10173
-
Pursuant to the Data Privacy Act of 2012, the National Privacy Commission implemented these rules and regulations.
-
The rules and regulations ensure compliance with international data protection standards.
Rule I. Preliminary Provisions
- Title: Implementing Rules and Regulations of Republic Act No. 10173, known as the “Data Privacy Act of 2012”, or the “Rules”.
- Policy: The Rules further enforce the Data Privacy Act and adopt international principles and standards for personal data protection, protecting the fundamental human right to privacy while promoting the free flow of information for growth.
-
Definitions:
- Act: Republic Act No. 10173, the Data Privacy Act of 2012
- Commission: National Privacy Commission
- Consent of the data subject: freely given, specific, informed indication of will, whereby the data subject agrees to the collection and processing of personal, sensitive personal, or privileged information
- data subject: individual whose personal, sensitive personal, or privileged information is processed
- Data Processing Systems: the structure and procedure for collecting and processing personal data
- Data sharing: disclosure or transfer of data to a third party by an information controller or personal information processor
- Direct marketing: communication by any means of advertising or marketing materials to particular individuals
- Filing system: an organized system for information relating to individuals that is not automated
- Information and communications system: system for generating, sending, receiving, storing, or otherwise processing electronic data or documents
- Personal data: all types of personal information
- Personal data breach: compromise of security leading to destruction, loss, alteration, unauthorized disclosure, or access of personal data
- Personal information: any information identifying an individual
Rule II. Scope of Application
- Scope: Applies to all natural and juridical persons processing data in the government or private sector. Includes acts in or outside the Philippines.
- Special cases: Certain information processing in the public interest is exempt, e.g., public access to information.
Rule III. National Privacy Commission
- Mandate: To administer and implement the Act and monitor compliance with international data protection standards.
- Functions: Rule making, reviewing existing rules, and promoting compliance by government agencies.
- Advisory: Provides advisory and guidance on data privacy matters.
Rule IV. Data Privacy Principles
- General Principles: Processing of personal data adheres to transparency, legitimate purpose, and proportionality
- Transparency: Data subjects are aware of data processing nature, purpose, and risks.
- Legitimate Purpose: Processing must be compatible with a stated purpose. The purpose must be legitimate, and not contrary to law, morals, or public policy.
- Proportionality: Data processing must be adequate, relevant, and necessary for its stated purpose, and not excessive.
Rule V. Lawful Processing of Personal Data
-
Criteria for Lawful Processing: Processing of personal information requires one of the following:
- Data Subject Consent;
- Contractual Obligations;
- Legal Obligations;
- Vital Interests;
- National Emergency;
- Constitutional/Statutory Mandate
Rule VI. Security Measures for the Protection of Personal Data
- Data Privacy and Security: Personal information controllers and processors must implement reasonable and appropriate organizational, physical, and technical security measures.
Rule VII. Security of Sensitive Personal Information in Government
- Responsibility of Heads of Agencies: Heads of government agencies are responsible for securing sensitive personal information with the appropriate standards.
Rule VIII. Rights of Data Subjects
- Right to be Informed: Data subjects must be informed about their personal data being processed.
- Right to Access: Data subjects have the right to obtain a copy of their personal data.
- Right to Rectify: Data subjects can correct inaccuracies in their personal data.
- Right to Erasure: Data subjects can request erasure of their personal data under certain conditions.
Rule IX. Data Breach Notification
- Data Breach Notification: Personal information controllers must notify the commission and data subjects of a data breach within 72 hours.
Rule X. Outsourcing and Subcontracting Agreements
-
Subcontract of Personal Data: A personal information controller can outsource data processing but must ensure adequate safeguards.
-
Agreements for Outsourcing: Contracts or legal documents govern data processing by third parties.
Rule XI. Registration and Compliance Requirements
- Registration of Personal Data Processing Systems: Systems processing data for at least one thousand individuals must be registered.
Rule XII. Rules on Accountability
- Accountability for Transfer of Personal Data: Personal information controllers are responsible for personal data, even if it is outsourced.
Rule XIII. Penalties
- Unauthorized Processing of Personal Information: Penalties for unauthorized processing range from imprisonment to a fine.
Rule XIV. Miscellaneous Provisions
Other Rules
- Appeal: Appeals from Commission decisions can be made to courts.
- Period for Compliance: Time periods for compliance with the rules are stipulated.
- Appropriations Clause: Funding for the Commission is ensured.
- Interpretation: Any ambiguities in the rules will be resolved liberally to protect the rights of individuals.
- Separability: Invalid provisions won't affect other valid provisions.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.