RA 10173 (Data Privacy Act of 2012) Flashcards
An Act Protecting Individual Personal Information In Information And Communications Systems In The Government And The Private Sector, Creating For This Purpose A National Privacy Commission, And For Other Purposes
Republic Act 10173
Data Privacy Act of 2012
What is the Section 1 of RA 10173?
Title:
Data Privacy Act of 2012
What is the Section 2 of RA 10173?
Declaration of Policy
Identify what Section:
This section protect the fundamental human right of privacy, of communication while ensuring free flow of information.
Section 2: Declaration of Policy
Identify what Section:
This section provides vital role of information and communications technology in nation-building.
Section 2: Declaration of Policy
Identify what section:
This sections ensure that personal information in information and communications systems in the government and in the private sector are secured and protected.
Section 2: Declaration of Policy
What is the Section 3 of RA 10173?
Definition of Terms
What is the Section 4 of RA 10173?
Scope
Section 4: Scope
The RA 10173 does not apply to the following:
- Officer or employee of a government institution
- Individual performing service under contract for a government institution
- Discretionary benefit of a financial nature
- Personal information processed for jounalistic, artistic, literary researches
- Information necessary to carry out the functions of public authority
- Information necessary for banks and financial institutions
- Personal information from residents of foreign jurisdictions
Republic Act of 1405
Secretary of Bank Deposits Act
Republic Act of 6426
Foreign Currency Deposit Act
Republic Act of 9510
Credit Information System Act (CISA)
What is the Section 5 of RA 10173?
Protection Afforded to Jounalists and their Sources
Section 5: Protected Afforded to Jounalists and their Sources
Publishers, editors or duly accredited reporters of any newspaper, magazine, or periodical of general circulation protection from being compelled to reveal the source of any news report or information appearing in said publication which was related in any confidence to such publisher, editor, or reporter.
Republic Act No. 53
What is the Section 6 of RA 10173?
Extraterritorial Application
Identify what Section:
This section consists of personal information about a Philippine citizen or a resident.
Section 6: Extraterritorial Application
Section 6: Extraterritorial Application
The entity has a link with the Philippines, and the entity is processing personal information in the Philippines or even if the processing is outside the Philippines as long as it is about Philippine citizens or residents. Who are these entities?
- A contract is entered in the Philippines
- A juridical entity has central management and control in the country
- An entity that has a branch, agency, office or subsidiary in the Philippines and the parent or affiliate of the Philippine
Section 6: Extraterritorial Application
What are the entities that has other links in the Philippines as stated in Section 6?
- The entity carries on business in the Philippines
- The personal information was collected or held by an entity in the Philippines
What is the Section 7 of RA 10173?
Functions of the National Privacy Commission
Section 7: Functions of the National Privacy Commission
What are the functions of the National Privacy Commission?
- Ensure compliance of personal information controllers
- Receive complaints, institute investigations, facilitate or enable settlement of complaints, prepare reports on disposition of complaints and resolution of any investigation it initiates, and, in cases it deems appropriate, publicize any such report
- Issue cease and desist orders, impose a temporary or permanent ban
- Compel or petition any entity, government agency or instrumentality
- Monitor the compliance of other government agencies or instrumentalities
- Coordinate with other government agencies and the private sector
- Publish on a regular basis a guide to all laws relating to data protection
- Publish a compilation of agency system of records and notices, including index and other finding aids
- Recommend to the Department of Justice (DOJ) the prosecution and imposition of penalties specified in Section 25 to 29 of this Act
- Review, approve, reject or require modification of privacy codes voluntarily adhered to by personal information controllers
- Provide assistance on matters relating to privacy or data protection
- Comment on the implication on data privacy of proposed national or local statutes, regulations or procedures, issue advisory opinions and interpret the provisions
- Propose legislation, amendments, or modifications to Philippine laws
- Ensure proper and effective coordination with data privacy regulators in other countries and private accountability agents, participate in international and regional initiatives for data privacy protection
- Negotiate and contract with other data privacy authorities of other countries for cross-border application and implementation of respective privacy laws
- Assist Philippine companies doing business abroad to respond to foreign privacy or data protection laws and regulations
- Generally perform such acts as may be necessary to facilitate cross-border enforcement of data privacy protection
What is the Section 8 of RA 10173?
Confidentiality
Identify what Section:
The Commission shall ensure at all times the confidentiality of any personal information that comes to its knowledge and possession.
Section 8: Confidentiality
What is the Section 9 of RA 10173?
Organizational Structure of the Commission
Section 9: Organizational Structure of the Commission
What is the agency that is responsible for the organizational structure of the national privacy commission?
Department of Information and Communications Technology (DICT)
Section 9: Organizational Structure of the Commission
Who is the chairman of the Department of Information and Communications Technology (DICT)?
Privacy Comissioner
Section 9: Organizational Structure of the Commission
Who assists the Privacy Commissioner (head)?
Two Deputy Privacy Commissioners
- Data Processing Systems
- Policies and Planning
Section 9: Organizational Structure of the Commission
The privacy commissioner or the head is appointed by:
President of the Philippines
Section 9: Organizational Structure of the Commission
The privacy comissioner must be at least _ years of age.
35 years
Section 9: Organizational Structure of the Commission
The privacy comissioner must meet the following requirements:
- Good moral character
- Unquestionable integrity and known probity
- Recognized expert in the field of information technology and data privacy
Section 9: Organizational Structure of the Commission
The Privacy Commissioner shall enjoy the benefits, privileges, and emoluments equivalent to the rank of?
Secretary
Section 9: Organizational Structure of the Commission
Who is the Privacy Commissioner or the Chairman of the National Privacy Comission?
Raymund Enriquez Liboro
Section 9: Organizational Structure of the Commission
What are the functions of deputy privacy commissioners?
Recognized experts in the field of information and communications technology and data privacy.
Section 9: Organizational Structure of the Commission
The deputy privacy commissioners shall enjoy the benefits, privileges, and emoluments equivalent to the rank of?
Undersecretary
Section 9: Organizational Structure of the Commission
Who are the two deputy privacy commissioners in the National Privacy Commissioners?
- Leandro Angelo Y. Aguirre
- John Henry Du Naga
What is the Section 10 of RA 10173?
Secretariat
Section 10: Secretariat
Majority of the members of the Secretariat must have served for at least _ years.
5 years
Section 10: Secretariat
Majority of the members of the Secretariat must have served for at least five (5) years in any agency of the government that is involved in the processing of personal information, including:
o Social Security System (SSS)
o Government Service Insurance System (GSIS)
o Land Transportation Office (LTO)
o Bureau of Internal Revenue (BIR)
o Philippine Health Insurance Corporation (PhilHealth)
o Commission on Elections (COMELEC)
o Department of Foreign Affairs (DFA)
o Department of Justice (DOJ)
o Philippine Postal Corporation (PhilPost)
What is the Section 11 of RA 10173?
General Data Privacy Principles
Section 11: General Data Privacy Principles
What are the principles stated in Section 11?
● Collected for specified and legitimate purposes
● Processed fairly and lawfully
● Accurate, relevant and, where necessary for purposes for which it is to be used the processing of personal information, kept up to date
● Adequate and not excessive in relation to the purposes for which they are collected and processed.
● Retained only for as long as necessary for the fulfillment of the purposes for which the data was obtained or for the establishment, exercise, or defense of legal claims, or for legitimate business purposes, or as provided by law; and
● Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected and processed
What is the Section 12 of RA 10173?
Criteria for Lawful Processing of Personal Information
Section 12: Criteria for Lawful Processing of Personal Information
What are the following criterias in Section 12?
● The data subject has given his or her consent.
● Personal information is necessary and is related to the fulfillment of a contract
● For compliance with a legal obligation
● Necessary to protect vitally important interests
● To respond to national emergency, to comply with the requirements of public order and safety, or to fulfill functions of public authority
● For the purposes of the legitimate interests pursued by the personal information controller or by a third party or parties to whom the data is disclosed
What is the Section 13 of RA 10173?
Sensitive Personal Information and Privileged Information.
True or False:
As stated in Section 13, the data subject has given his or her consent, specific to the purpose prior to the processing, or in the case of privileged information, all parties to the exchange have given their consent prior to processing.
True
Section 10: Sensitive Personal Information and Privileged Information
What are the following sensitive personal information and privileged information guaranteed to protect stated in Section 13?
- Protect the life and health
- Achieve the lawful and noncommercial objectives
- Medical treatment
- Protections of lawful rights
What is the Section 14 of RA 10173?
Subcontract of Personal Information
Identify what Section:
A personal information controller may subcontract the processing of personal information.
Section 14: Subcontract of Personal Information
What is the Section 15 of RA 10173?
Extension of Privileged Communication