Data Privacy Act Flashcards

1
Q

“The
right to be let alone

A

privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

“The obligations of those who receive
information in the context of an intimate
relationship to respect the privacy
interests of those to whom the data relate
and to safeguard that information

A

confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

“The procedural and technical measures required to
(a)prevent unauthorized access, modification, use, and
dissemination of data stored or processed in a computer
system
(b)prevent any deliberate denial of service and
(c)to protect the system in its entirety from physical harm

A

security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

“An Act protecting individual personal information and communications systems in then government and the private sector, creating for this purpose a National Privacy Commission, and for other purposes.

A

data privacy act of 2012 or republic act no. 10173

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

when was the data privacy act approved?

A

August 15 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

data privacy act of 2012 is consists of?

A

9 chapters 45 sections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Operations performed upon personal information including the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure, or destruction of data

A

data processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

information from which the
identity of an individual is
apparent or ascertained by the
entity holding the information

A

personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Person or organization
who controls the
collection, holding,
processing, or use of
personal information

A

personal information controller (PIC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Any natural or juridical
person qualified to whom
the PIC may outsource the
processing of personal
data pertaining to a data
subject.

A

personal information processor (PIP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what are the privacy principles of general data?

A

transparency
legitimate purposes
proportionality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Data subject s must
be aware of the
nature, purpose, and
extent o f the
processing of their
personal data.

A

transparency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The processing of
information shall be compatible with a
declared and specified purpose.

A

legitimate purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

processing of information
shall be adequate, relevant,
suitable, necessary, and not excessive.

A

proportionality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what are the five pillar of compliance?

A

1 Data Protection Officer
2 Privacy Impact Assessment
3 Privacy management Program
4 Security Measures
5 Breach Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Process undertaken and used to evaluate and manage privacy impacts for each program, process, or measure within the agency that involves personal data.

A

privacy impact assessment (PIA)

17
Q

Serves to align everyone in the organization in the same direction

A

privacy management program

18
Q

what are the implement security measures?

A

organizational
physical
technical

19
Q

what are the preparation of breach?

A

confidentiality
integrity
availability

20
Q

generating, sending, receiving, storing or otherwise processing
electronic data messages or electronic documents

A

information and communication system

21
Q

computer system or other similar device by or which data is recorded, transmitted, or stored

A

information and communication system

22
Q

any procedure related to the recording, transmission or storage of electronic data, electronic message, or electronic document

A

information and communication system

23
Q

an individual whose personal information is processed

A

data subject

24
Q

the processing of personal information shall be allowed, subject to compliance with the requirements of this Act and other laws allowing disclosure of information

A

General Data Privacy Principle

25
Q

Name, Birthplace and Date, Address, Place of work, Gender, Contact Information, Citizenship

A

personal information

26
Q

means that the data subject has the right to know when his or her personal data shall be, are being, or have been processed

A

right to be inform

27
Q

involves being able to compel any entity possessing any personal data to provide the data subject with a description of such data in its possession, as well as the purposes for which they are to be or are being processed

A

right to access

28
Q

consent of the data subject be secured in the collecting and processing of his or her data

A

right to object

29
Q

grants the data subject the choice of refusing to consent,
as well as the choice to withdraw consent, as regards to
collection and processing

A

right to object

30
Q

allows the data subject to suspend, withdraw or order the blocking, removal, and destruction of his or her personal information from the personal information controller’s filing system upon discovery and substantial proof that the personal information are incomplete, outdated, false, unlawfully obtained, used for unauthorized purposes, or are no longer necessary for the purposes for which they were collected

A

right to erasure or blocking

31
Q

allows the data subject to dispute any inaccuracy or error in the personal information processed, and to have the
personal information controller correct it immediately

A

right to rectify

32
Q

enables the data subject to obtain and electronically move, copy, or transfer personal data for further use

A

right to data portability

33
Q

with the National Privacy Commission affords a remedy to any data subject who “feels that [his or her] personal
information has been misused, maliciously disclosed, or improperly disposed,” or in case of any violation of his or
her data privacy rights

A

right to file a complaint

34
Q

entitles the aggrieved data subject to be indemnified for any damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use
of his or her personal information

A

right to damages

35
Q

Personal Information Controllers (and designated individuals are accountable for processing of personal information under their control or custody

A

principle of accountability

36
Q

Race or ethnicity, Marital Status, Religion, Health Information, Educational Attainment, Criminal Offense History

A

sensitive personal information (SPI)

37
Q

made primarily responsible for compliance with the security requirements set by the Data Privacy Act

A

Heads of Agencies (DICT and NPC)

38
Q

the authority to monitor compliance and
recommend to the agency the necessary action to comply with the minimum standards

A

National Privacy Commission NPC

39
Q

it is required before a government
employee may be able to access these sensitive personal information

A

security clearance