Data Privacy Act - Test Bank Flashcards
In all cases, the publishers, editors, or duly accredited reporters of any newspaper, magazine or periodical of general circulation shall not be compelled to reveal the source of any news report or information appearing in said publication.
a. True. Because they are protected by the law.
b. False. Only Publishers are included in the privilege.
c. False. Only Publishers and Reporters are included in the privilege.
d. True. But only for those information that were related in any confidence to such publisher, editor, or reporter.
True. But only for those information that were related in any confidence to such publisher, editor, or reporter.
Personal information controllers may invoke the principle of privileged communication over privileged information that they lawfully control or process. Subject to existing laws and regulations, any evidence gathered from privileged information is
a. Admissible
b. Privilege
c. Confidential
d. Inadmissible
Inadmissible
Refers to the structure and procedure by which personal data is collected and further processed in an information and communications system or relevant filing system, including the purpose and intended output of the processing.
a. Data Sharing Systems
b. Data Collection Systems
c. Internal Control Systems
d. Data processing Systems
Data processing Systems
The Act and its Implementing Rules and Regulations apply to the processing of all types of personal information. Who may be held liable for violation of Data Privacy Law?
a. Only Natural Persons
b. Both Natural and Juridical Persons
c. Juridical Persons and Personal information Controller
d. Only Personal Information Processor
Both Natural and Juridical Persons
One of the following is not included in the Right to be informed by the data owner.
a. The right to object to the processing of his or her personal data.
b. The recipients or classes of recipients of the information gathered.
c. The period for which the information will be stored.
d. The identity and contact details of the personal data controller or its representative.
The right to object to the processing of his or her personal data.
Outsourcing or subcontracting generally does not require the consent of the data subject but requires the execution of an outsourcing or subcontracting agreement.
a. True. Provided the information to be processed is not sensitive personal information
b. True
c. False. consent of the majority of the data subjects is generally required in an outsourcing agreement.
d. False
True
Any information and communication relating to the processing of personal data should be easy to access and understand, using clear and plain language.
This is the principle of?
a. Legitimate Purpose
b. Understandability
c. Transparency
d. Accessibility
Transparency
As a general rule, when a data subject objects or withholds consent, the personal information controller shall no longer process the personal data, unless:
a. There is subpoena from the court.
b. The Personal Information Processor had personal interests over the matter.
c. Necessary for the cancellation of contract.
d. There is natural obligation to disclose.
There is subpoena from the court.
Refers to any information whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.
a. Sensitive Personal Information
b. Personal Identity
c. Personal Data
d. Personal Information
Personal Information
Which of the following is required to register its personal data processing systems?
a. A PIP employing 300 employees
b. A PIP processing sensitive personal information of at least 100 individuals
c. A PIC employing 200 employees
d. A PIC processing personal information of at least 1,000 individuals
A PIP employing 300 employees
Refers to a natural or juridical person, or any other body who controls the processing of personal data, or instructs another to process personal data on its behalf.
a. Personal Data Processor
b. Personal Data Controller
c. Personal Information Controller
d. Personal Information Processor
Personal Information Controller
Refers to the disclosure or transfer to a third party of personal data under the custody of a personal information controller or personal information processor.
a. Data Sharing
b. Data Disclosure
c. Data Transferring
d. Data Enlisting
Data Sharing
Which of the following is not a sensitive personal information?
a. TIN
b. Birthday
c. SSS Number
d. Tax Returns
Birthday
The Commission requires the ________ of personal data processing systems operating in the country that involves accessing or requiring sensitive personal information of at least one thousand (1,000) individuals.
a. Submission
b. Disclosure
c. Approval of Data Subiect
d. Registration
Registration
Violations of Data Privacy Law may be committed in and outside of the Philippines.
a. False. Because it may only be committed by Filipino citizens or residents of the Philippines.
b. True. Because it has extraterritorial application
c. False. Because it has no extraterritorial application.
d. True. As long as the personal data breach refers to a person found in the Philippines.
True. Because it has extraterritorial application
Refers to an event or occurrence that affects or tends to affect data protection, or may compromise the availability, integrity and confidentiality of personal data. It includes incidents that would result to a personal data breach, if not for safeguards that have been put in place.
a. Personal Data Breach
b. Security Incident
c. Security Breach
d. Personal Data Incident
Security Incident