Data Privacy Act Flashcards

1
Q

Personal Information Controller

A

Person or organization who controls the collection, holding, processing or use of personal information including a person or organization who instructs another person or organization to collect hold process use transfer or disclose personal information on his or her behalf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Information not applicable in Data Privact Aact

A
  1. Information about any individual who is or was an officer or employee of a government institution.
  2. Information about an individual who is or was performing service under contract for a government institution
  3. Information relation to any discretionary benefit of a financial nature
  4. Personal information processed for journalistic, artistic, literary or research purpose
  5. Information necessary in order to carry out the functions of public authority
  6. Information necessary for banks and other financial institution
  7. Personal information originally collected from residents of foreign jurisdictions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

National Privacy Commission

A

Agency tasked by law to implement the provisions of the Data Privacy Act with administrative, quasi-judicial and quasi legislative powers and to monitor and ensure compliance of the country with international standards set for data protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Organizational Structure of National Privacy Commission

A

Headed by a Privacy Commissioner who shall act as Chairman. Assisted by two deputy privacy commissioners. one for data processing systems & one for policies and planning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Term and Vacancy

A

Appointed by the President of the Philippines for the term of 3 years and may be reappointed for another term of 3 years

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Qualifications of Commissioners

A
  1. 35 Years of Age
  2. Good Moral Character, unquestionable integrity and known probity; and
  3. Recognized expert in the field of information technology and data privacy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data Privacy Principle

A
  1. Principle of Proportionality
  2. Principle of Legitimate Purpose
  3. Principle of Transparency
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Principle of Proportionality

A

Processing of personal data shall be adequate, relevant, suitable, necessary and not excessive in relation to a declared and specified purpose.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Types of Personal Data

A
  1. Personal Information
  2. Sensitive Information
  3. Privileged Information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Personal Information

A

Information from which the identity of an individual:
1. Is apparent
2. Can be reasonably and directly ascertained by the entity holding the information
3. When put together with other information would be directly and certainly identify and individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Privileged Information

A

Refers to any and all forms of data under the Rules of Court and other pertinent laws constitute privileged communication. Examples incude:
1. Attorney Client
2. Doctor Patient
3. Marital Privilege
4. Priest Confessor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Sensitive Personal Information

A

Personal Information about:
1. Race, ethnic origin, marital status, age, color, and any affiliation with politics religious or philosophical
2. Individual’s health, education, genetic, sexual life of a person
3. Issued by government agencies peculiar to an individual
4. Specifically established by an executive order or an act of Congress

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Rights of a Data Subject

A
  1. Right to Informed Consent
  2. Right to Object
  3. Right to Withhold Consent
  4. Right to Access
  5. Right to Correction
  6. Right to Erasure
  7. Right to Damages
  8. Right to Data Portability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When should Notification be done when there is Data Breach

A

Within 72 hours upon knowledge of or the reasonable belief of PIC or PIP that breach has been occurred

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Access by Agency Personnel to Sensitive Personal Information

A
  1. On-site and Online Access- employees must have security clearance
  2. Off-site Access- may not be transported or accessed from a location off government property unless a request for such transporation is submitted and approved by the head of agency
How well did you know this?
1
Not at all
2
3
4
5
Perfectly