L5.1: RA 10173 - Data Privacy Act of 2012 Flashcards

1
Q

This law aims to protect the fundamental human right of _______, of communication while ensuring free flow of ________ to promote innovation and growth

A
  1. Privacy
  2. Information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

RA 10173 aims to “protect the fundamental human right of privacy, of communication while ensuring free flow of information to promote innovation and growth” is based off of what law (include the specific chapter and section)

A

RA 10173, Chapter 1, Section 2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

RA 10173 also established this entity which enforces and oversees data protection

A

National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

T or F: The National Privacy Commission is endowed with judiciary power

A

False (rule-making power)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

When did the final IRRs of RA 10173 come into force?

A

Sept. 9, 2016

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

RA 10173 is a law that addresses what kind of crimes and concerns (clue: it’s not privacy-related crimes and concerns, think more broadly)

A

Contemporary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IRRs that added specificity to the act:

(1) It protects the ________ of individuals while ensuring the free flow of information to promote innovation and growth

A

Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IRRs that added specificity to the act:

(2) It ________ the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure, or destruction of ________ data

A
  1. Regulates
  2. Personal
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IRRs that added specificity to the act:

(3) It ensures that the country complies with ______ standards set for data protection through the National Privacy Commission (NPC)

A

International

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

People whose personal information is collected, stored, and processed are called as what?

A

Data Subjects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Organizations that deal with your personal details, whereabouts, and preferences are ________ to observe and respect your data privacy rights

A

Duty-bound

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

If you feel that your personal information has been misused, maliciously disclosed, or improperly disposed, the data subject has a right to file a ________

A

Complaint

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The law has ________ application, applying not only to businesses with offices in the PH, but when equipment based in the PH is used for processing

A

Extraterritorial

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

T or F: The act applies to the processing of personal information of PH citizens regardless of where they reside

A

True (they have extraterritorial applications)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

T or F: The law applies to the processing of personal information in the PH which was lawfully collected from residents of foreign jurisdictions

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The exception of not processing the information of residents of foreign jurisdictions is helpful for PH companies that offer what kind of services?

A

Cloud Services

17
Q

The PH law takes the approach that the processing of personal data shall be allowed subject to adherence to the principles of what 3 concepts?

A
  1. Transparency
  2. Legitimate purpose
  3. Proportionality
18
Q

The collection of personal data must be a ________, _________, and _________ purpose

A
  1. Declared
  2. Specified
  3. Legitimate
19
Q

________ is required prior to the collection of personal data

A

Consent

20
Q

When obtaining consent, the data subject should be informed about _____ and _______ of processing

A

Extent and Purpose

21
Q

The ________ processing of their personal data for profiling or for direct marketing and data sharing requires consent

A

Automated

22
Q

T or F: Consent is not as strictly implemented anymore when data is shared between affiliates and mother companies

A

False (still required)

23
Q

Consent is not required for processing where the data subject is a party to a _________ for the purposes of fulfilling it

A

Contractual Agreement

24
Q

Exceptions to ______ with a legal obligation upon the data controller, protection of the data subject’s vital interests, and response to national emergencies are also available

A

Compliance

25
Q

Exceptions to ________ is allowed where processing is necessary to pursue the legitimate interests of the data controller

A

Consent

26
Q

Exceptions to consent are not applicable when overridden by the fundamental ______ and ______ of the data subject

A

Rights and Freedoms

27
Q

The law requires that when sharing data, it must be covered by an agreement that provides adequate ______ for the rights of the data subjects

A

Safeguards

28
Q

Agreements by the data controllers and data subjects are subject to _______ by the National Privacy Commission

A

Review

29
Q

What type of information is being described?

Race, ethnic origin, marital status, age, color, religion, health, education, genetic/sexual life, SSS numbers, and those marked as “classified” by EOs or an act of Congress

A

Sensitive Personal and Privileged Information

30
Q

State whether the processing of sensitive information is prohibited or allowed:

When there is consent of the data controller

A

Prohibited (must be consent of data subject)

31
Q

State whether the processing of sensitive information is prohibited or allowed:

Pursuant to a law that does not require consent to proceed

A

Allowed

32
Q

State whether the processing of sensitive information is prohibited or allowed:

There is a necessity to protect the life and health of a person

A

Allowed

33
Q

State whether the processing of sensitive information is prohibited or allowed:

For medical treatment

A

Allowed

34
Q

State whether the processing of sensitive information is prohibited or allowed:

There is a necessity to override the lawful rights of data subjects in court/legal proceedings, or regulation

A

Prohibited (the necessity to PROTECT the lawful rights)