Data Privacy Act Flashcards

1
Q

Data privacy refers to the right while

data protection refers to the means to implement the right data privacy.

A

Notes only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Commission shall refer to the National Privacy Commission (NPC) created by virtue of this Act.

A

Notes only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

refers to an individual whose personal information is processed.

A

Data subject - always natural person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

refers to any freely given, specific, informed indication of will, whereby the data subject agrees to the collection and processing of
personal information about and/or relating to him or her.
Consent shall be evidenced by written, electronic or recorded means. It may also be given on behalf of the data subject by an agent specifically authorized by the data subject to do so.

A

Consent of the data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

refers to communication by whatever means of any advertising or marketing materials which is directed to particular individuals.

A

Direct marketing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

refers to any act of information relating to natural or juridical persons to the extent that, although the information is not processed by equipment operating automatically in response to instructions given for that purpose, the set is structured, either by reference to individuals or by reference to criteria relating to individuals, in such a way that specific information relating to a particular person is readily accessible.

A

Filing system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

refers to a system for generating, sending, receiving, storing or
otherwise processing electronic data messages or electronic documents and includes the computer system or other similar device by or which data is recorded, transmitted or stored and any procedure related to the
recording, transmission, or storage of electronic data,
electronic message, or electronic document.

A

Information and Communications System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

refers to any information whether
recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information
would directly and certainly identify an individual.

A

Personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

refers to a person or organization who controls the collection, holding, processing or use of personal information, including a
person or organization who instructs another person or
organization to collect, hold, process, use, transfer or disclose personal information on his or her behalf.

A

Personal information controller (PIC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

refers to any natural or juridical person qualified to act as such under this Act to whom a personal information controller may outsource the processing of personal data pertaining to a data
subject.

A

Personal information processor (PIP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

refers to any operation or any set of operations performed upon personal information including but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or
destruction of data.

A

Processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

refers to any and all forms of data
which under the Rules of Court and other pertinent laws constitute privileged communication.

A

Privileged information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Sensitive personal information refers to personal information about the following:

A

✓ About an individual’s race, ethnic origin, marital status, age, color; and religious, philosophical or
political affiliations;

✓ About an individual’s health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such person, the disposal of such
proceedings, or the sentence of any court in such proceedings;

✓ Issued by government agencies peculiar to an individual which includes, but not limited to, social
security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns; and

✓ Specifically established by an executive order or an act of Congress to be kept classified.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Scope of Data Privacy Act

A

o The law applies to the processing of all types of personal information and to any natural and juridical person involved in personal information processing including those personal information controllers and processors who, although, not found or established in the Philippines, use equipment that are located in the Philippines, or those who maintain an office, branch or agency in the Philippines subject to the immediately succeeding paragraph: Provided, That the requirement of Section 5 are complied with Section 5 affords protection to journalists and their sources.

o Nothing in this Act shall be construed as to have amended or
repealed the provisions of Republic Act No. 53, which affords
the publishers, editors or duly accredited reports of any newspaper, magazine or periodical or periodical of general circulation protection from being compelled to reveal the source of any news report or information appearing in said publication which was related in any confidence to such publisher, editor or reporter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Exceptions to Coverage of Data Privacy Act

o The law does not apply to the following:

A
  • Information about any individual who is or was an officer or employee of a government institution that relates to the position or functions of the individual, including:
    ✓ The fact that the individual is or was an officer or employee of the government institution.
    ✓ The title, business address and office telephone number of the individual.
    ✓ The classification, salary range and responsibilities of the position held by the individual.
    ✓ The name of the individual on a document prepared by the individual in the course of employment with the government.
  • Information about an individual who is or was performing service under contract for a government institution that relates to the services performed, including the terms of the contract, and the name of the individual given in the
    course of the performance of those services.
  • Information relating to any discretionary benefit of a financial nature such as the granting of a license or permit given by the government to an individual, including the name of the individual and the exact nature
    of the benefit.
  • Personal information processed for journalistic, artistic, literary or research purposes.
  • Information necessary in order to carry out the functions of public authority which includes the processing of personal data for the performance by the independent,
    central monetary authority and law enforcement and regulatory agencies for their constitutionally and statutorily mandated functions.
  • Information necessary for banks and other financial institutions under the jurisdiction of the independent, central monetary authority or Bangko Sentral ng Pilipinas to comply with Republic Act. No. 9510, and Republic Act
    No. 9160, as amended, otherwise known as the Anti- Money Laundering Act and other applicable laws.
  • Personal information originally collected from residents of foreign jurisdictions in accordance with the laws of those foreign jurisdictions, including any applicable data privacy laws, which is being processed in the Philippines.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Explain Extraterritorial Application of Data Privacy Act

A

o The law applies to an act done or practice engaged in and outside of the Philippines by an entity if:

  • The act, practice or processing relates to personal information about a Philippine citizen or a resident.
  • The entity has a link with the Philippines:
    ▪ A contract is entered in the Philippines.
    ▪ A juridical entity unincorporated in the Philippines but has central management and control in the
    country.
    ▪ An entity that has a branch, agency, office or subsidiary in the Philippines and the parent or
    affiliate of the Philippine entity has access to personal information.
  • The entity has other links in the Philippines such as, but not limited to:
    ▪ The entity carries on business in the Philippines; and
    ▪ The personal information was collected or held by an entity in the Philippines.
17
Q

Explain Confidentiality in National Privacy Commission

A

The National Privacy Commission shall ensure at all times the confidentiality of any personal information that comes to its
knowledge and possession.

18
Q

o Organization Structure of National Privacy Commission
(NPC)

A

1 Chairman of the Commission.

The Privacy Commissioner shall be assisted by two (2) Deputy Privacy Commissioners, one to be responsible for Data processing Systems and one to be responsible for Policies and Planning.

Term of Office – The Privacy Commissioner and the two
(2) Deputy Privacy Commissioners shall have a term of three (3) years, and may be reappointed for another term of three (3) years.

19
Q

o Sensitive Personal Information and Privileged Information –
As a general rule, the processing of sensitive personal information and privileged information shall be prohibited. Unless:

A
  • The data subject has given his or her consent,
  • The processing is necessary to protect the life and health
  • The processing is necessary to achieve the lawful and noncommercial objectives
  • The processing is necessary for purposes of medical treatment,
  • protection of lawful rights and
    interests of
20
Q

o Criteria for Lawful Processing of Personal Information – The
processing of personal information shall be permitted only if not otherwise prohibited by law, and when at least one of the
following conditions exists:

A

✓ The data subject has given his or her consent;
✓ fulfillment of a contract
✓ vitally important interests of the data subject, including life and health;
✓ Legal Obligation
✓legitimate interest
✓ National Emergency

21
Q

Rights of Data Subject (Natural Person/Individual)

A
  • Right to be informed
  • Right to be furnished
  • Right to have reasonable access
  • Right to dispute the inaccuracy or error
  • Right to suspend, withdraw or order the blocking, removal or destruction
  • Right to indemnified for any damages
    ✓ Transmissibility of Rights of Data Subject – The lawful heirs and assigns of the data subject may invoke the rights of the data subject for, which he or she is an
    heir or assignee at any time after the death of the data subject or when the data subject is incapacitated or incapable of exercising the rights as enumerated above.
  • Right to Data portability– The data subject shall have the
    right, where personal information is processed by electronic means and in a structured and commonly used format.
    ✓ Non-Applicability of the Rights of Data Subject – The data privacy subject rights are not applicable if the processed information are used only for the needs of scientific and statistical research
22
Q

Sensitive Info or not?

  1. Information specifically established by an executive order or an act of Congress to be kept classified
  2. Information about the platform of a candidate for national elective position that is discussed in a public debate televised in national television network
A

Yes
No

23
Q

o General Data Privacy Principles –
The following are the general data
privacy principles:

A

✓ Personal information must be collected for specified and legitimate purposes determined and declared before, or as soon as reasonably practicable after collection, and later processed in a way compatible with such declared, specified and legitimate purposes only.

✓ Personal information must be processed fairly and lawfully.

✓ Personal information must be accurate, relevant and, where necessary for purposes for which it is to be used the processing of personal information, kept up to date; inaccurate or incomplete data must be rectified, supplemented, destroyed or their further processing restricted.

✓ Personal information must be adequate and not excessive in relation to the purposes of which they are collected and processed.

✓ Personal information must be retained only for as long as necessary for the fulfillment of the purposes for which the data were obtained or for the establishment,
exercise or defense of legal claims, or for legitimate business purposes, or as provided by law.

✓ Personal information must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were
collected and processed

24
Q

o General Data Privacy Principles –
The processing of personal info shall be allowed, subject to adherence to the ff principles:

  1. Principle of Proportionality
  2. Principle of Legitimate Purpose
  3. Principle of Transparency
A
  1. Principle of Proportionality - Processing of Personal Data shall be adequate, relevant, suitable, necessary and not excessive
  2. Principle of Legitimate Purpose - shall be compatible with declared and specified purpose
  3. Principle of Transparency - The data subject must be aware of the nature, purpose, and extent of the processing of his or her Personal Data
25
Q

Pag sensitive yung pinag uusapan, mas mataas yung penalty

A
26
Q

SPI Samples:
-Gender
-School Graduated from and date graduated
-Bank account number
-Income Tax Return
-Court cases filed against individual

PI Samples:
-Email addresses
-Laptop IP address
-Home address
-Location tracked using an app (grab)

Privileged:
Disclosure made to auditor or investigator

A