HIS FINALS: MODULE 5 (3) Flashcards

1
Q

The data subject must be aware of the nature, purpose, and extent of the processing of his or her data, including the risks and safeguards involved, the identity of a personal information controller, his or her rights as a data subject, and how these can be exercised.

A

Transparency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Any information and communication relating to the processing of personal data should be easy to access and understand, using clear and understandable language.

A

transparency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The processing of information shall be compatible with a declared and specified purpose, which must not be contrary to law, morals, or public policy.

A

Legitimate Purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The processing of information shall be adequate, relevant, suitable, necessary, and not excessive concerning a declared and specified purpose

A

Proportionality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Personal data shall be processed only if the purpose of the processing could not reasonably be fulfilled by other mean

A

Proportionality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

data privacy act states that the collection of perconal data:

A

must be declared, specified and legitimate purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When obtaining consent, the ——– is informed about the extent and purpose of processing, and it specifically mentions the “automated processing of his or her data for profiling, or processing for direct marketing, and data sharing.”

A

data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Consent is not required for processing where:

A

o The data subject is a party to a contractual agreement
o For purposes of fulfilling that contract
o Compliance with a legal obligation upon the data controller
o Protection of the vital interests of the data subject
o Response to a national emergency is also available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

when: Processing is necessary to pursue the legitimate interests of the data controller, except where overridden by the fundamental rights and freedoms of the data subject

A

exception to consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The law requires that when sharing data, the sharing be covered by an agreement that provides adequate safeguards for the rights of data subjects, and that these agreements are subject to review by the ———

A

national privacy commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The law defines sensitive personal information as being:

A

• About an individual’s race, ethnic origin, marital status, age, color, and religious, philosophical, or political affiliations.
• About an individual’s health, education, the genetic or sexual life of a person, or to any proceeding or any offense committed or alleged to have committed.
• Issued by government agencies “peculiar” (unique) to an individual, such as social security number.
• Marked as classified by executive order or act of Congress.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

All processing of sensitive and personal information is prohibited except in certain circumstances. The exceptions are:

A

• Consent of the data subject.
• Pursuant to a law that does not require consent.
• Necessity to protect the life and health of a person.
• Necessity for medical treatment.
• Necessity to protect the lawful rights of data subjects in court proceedings, legal proceedings, or regulation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

a major anti-terrorism law that enables surveillance

A

Human Security Act of 2007

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The law further provides that not all “personal data breaches” require notification., which provides several bases for not notifying —————-

A

data subjects or the data protection authority.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Section 38 of the Implementing Rules and Regulations (IRRs) provides the requirements of breach notification:

A

• The breached information must be sensitive personal information or information that could be used for identity fraud, and
• There is a reasonable belief that unauthorized acquisition has occurred, and
• The risk to the data subject is real, and
• The potential harm is serious.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The law places a concurrent obligation to notify the National Privacy Commission as well as affected data subjects within ——— of knowledge of or reasonable belief by the data controller of a personal data breach that requires notification.

A

72 hours

17
Q

Any combination or series of acts may cause the entity to be subject to imprisonment ranging from —- as well as a fine of approximately ——-

A

three to six years
PHP 1,000,000 to PHP 5,000,000.