Data privacy act Flashcards
An Act Protecting Individual Personal Information in
Information and Communications Systems in the Government and the Private Sector
Data Privacy Act of 2012
When was the Data Privacy Act of 2012 enacted
Aug 15 2012
Supports the right of persons to life, liberty and
property
Right to privacy
Under the Bill of rights include these four:
- Due process
- Self incrimination
- Freedom of speech
- Freedom of religion
Individuals ability to control the flow of information
concerning or describing him
Right to information privacy
Right to Privacy must be overbalanced by _____
legitimate public concerns
_____ of information on the part of the patient is a prerequisite to quality care and better health outcomes.
Full disclosure
Implicit in the “Declaration of Policy” of the DPA is
the recognition that: (2 of them)
- Law protects privacy
2. Free flow of information
____ should not an obstacle for people to
obtain benefits from utilization of personal data
Data protection
Use of personal data comes with a responsibility. The
_____ subjects should, at all times, be a
paramount consideration.
rights of data
Any information from which the identity of an
individual is apparent
personal data
Data containing Race, ethic origin, marital staturs, certificates issued by government agencies, education etc.
Sensitive personal information
Processing of data can be done via: ( 2 of them)
- automatically
2. Manually
Who Process Personal Data
Personal information controller (PIC)
the one who controls the processing of personal data, the one who decides
The individual, corporation or other sectors
They are the ones that will be held liable in circumstances when Data Privacy Act is violated
Personal information controller (PIC)
PIC is usually the head of the agency/ company.
Not the employees, not the data protection
officer, NOT the _____
Chief information officer
Individual, corporation, or other body who
processes the personal data for a Personal
Information Controller (outsource. Ex: EMR
Provider)
Personal Information Processor
Transparent data must be aware of : (2)
- Nature
2. Purpose
4 Extent of the processing of his/her personal data
- Risk and safety
- Identify PIC
- Rights as data subject
- How these rights are exercised
The processing of information shall be with a declared
and specified purpose which must not be contrary to law, morals, or public policy
LEGITIMATE PURPOSE
Proportionality must be these 4
→ Adequate
→ Relevant
→ Suitable
→ Necessary
Any freely given, specified, informed indication of
will, whereby the data subject agree to the collection and processing of personal information
about and/or relating to him or her
Consent
requires that processing of personal data shall be compatible with a declared and specified purpose.
Adhering to the priciple of legitimate purpose
should be reflected on the
consent form
Data Privacy Principles
Under the privacy information law, data consent should be in
written consent
Cases in which consent is not required are as follows:
- Private facts of person
- Financial nature
- Research or journals
Info necessary for banks and Financial Institution to
comply with provisions of the ____
Anti-monetary laundering act
Section where PERSONAL INFORMATION, NOT SENSITIVE
OR PRIVILEGED
sect. 12
Under this section the processing is necessary to protect vitally important interests of the data subject, including his or her life and health.
sect. 12
Section where SENSITIVE PERSONAL INFORMATION AND PRIVILEGED INFORMATION
Sect. 13
Section stating that the processing is provided for by existing laws and regulations, where personal data protection is guaranteed, and consent is required
Sect. 13
Data sharing is allowed provided that: 3
- Safeguards
- Follow prinicple of transparency
- In agreement to the rules issued by the commission
Indicate what are the data to be shared, who can access,
how they will destroy, etc
DATA SHARING AGREEMENT
Data sharing agreement is subject to be reviewed via ____ or upon complaint of the data subject
motu proporio
Inform the patient about everything
Right to information
Object to the procurement of their data and object
to any violation of their rights
Right to object
Patients can have access to their data but they are
not allowed to have a copy of their record
Right to access
Any inaccurate information
Right to correct
When somebody is prejudiced because of data
breach, they can file a complaint. The court may
award damages.
Right to damages
If you have an old record from another hospital, you
can tell your physician about it and they can request
and use your old records from that hospital
Right to data portability
what to do when: adhering to dat Privacy rpinciples, from collection of personal data
Review and develop protection procedures
what to do when: Uphold the Rights of Data Subject, Including Privacy
Notices
PIC should implement
changes in policy and
systems
what to do when: Obtain MEANINGFUL CONSENT for processing of personal data
Review existing contracts,
consent forms, and notices
what to do when: Enter into DATA SHARING AGREEMENTS
Know if data sharing is being done beofre agreeing
shall aim to maintain the
confidentiality, integrity, and availability of personal data
Security measures
This is not simply a means to demonstrate compliance
with one of the legal requirements
DESIGNATING A DATA PROTECTION OFFICER
should be empowered to
perform functions so as to assure that an organization
takes data privacy and security seriously
Data protection officer
must have top management support to allow for
meaningful changes in the organization
Data protection officer
process to evaluate
and manage privacy impacts in an organization’s
programs, process, activities, systems, and operation
Privacy impact assessment (PIA)
This should proceed from an understanding of the
processing systems within an organization.
Privacy management program (PMP)
This should take into account PIA and legal obligations and requirements. It includes privacy notices and privacy policies
Privacy management program (PMP)
Non-disclosure agreements, training and capacity
building are involved
MANAGEMENT OF HUMAN RESOURCES
These measures include design of office space and
workstations, including the physical arrangement of
furniture and equipment, shall provide privacy to
anyone processing personal data
Physical sercurity measures
These measures are subject to guidelines are the commission may
issue from time to time.
Techinal security measures
Report to the National Privacy Commission within __ hours from knowledge of breach based on info available
72
Follow up report on the data breach is submitted within
5 days from knowledge