RFBT - DATA PRIVACY ACT OF 2012 Flashcards
What is the scope of the Data Privacy Act?
It applies to the PROCESSING OF ALL TYPES OF PERSONAL INFORMATION BE IT NATURAL OR JURIDICAL PERSONS. It also applies to THOSE INVOLVED IN PERSONAL INFORMATION PROCESSING including those information controllers and processors, who, although not located in the Philippines or those who maintain an office/branch/agency in the Philippines
RA 10173 is known as?
Data Privacy Act of 2012
What Commission is being referred to in the Data Privacy Act?
It refers to the National Privacy Commission, which was created by the Act.
What is meant by Direct marketing?
It refers to communication by whatever means of any advertising or marketing material which is directed to particular individuals.
What is not covered by the Data Privacy Act?
- ) Information about a government officer/employee that relates to his details such as his address/telephone number/title/salary range/service performed/benefits received/ and information necessary to carry out the functions of public authority.
- ) Personal information processed for journalistic/artistic/literary/research purposes
- ) Information necessary for banks and other institutions to comply with AMLA and other applicable laws
- ) Personal information originally collected from residents of foreign jurisdictions in accordance with laws.
Explain the Extraterritorial application of the Data Privacy Act.
GR: Penal law applies only within PH territory
Exceptions:
-it relates to personal info about a PH citizen
- entity has a link with the PH and the entity is processing personal info of a PH citizen/resident such as when
a.) A contract is entered in the PH
b.) Juridical entity has branch in PH
c.) The entity does business in PH
d.) Personal information was collected/held by an
entity in the PH
What is the Organizational Structure of the National Privacy Commission?
National Privacy Commission shall be attached to the Department of Information and Technology.
It shall be HEADED BY A PRIVACY COMMISSIONER (same rank as a Secretary) who shall act as CHAIRMAN OF THE COMMISSION and he must be:
- at least 35 years old
- Good moral character
- unquestionable integrity and known probity
- recognized expert in IT and data privacy
It shall also have 2 DEPUTY PRIVACY COMMISSIONERS
1 is for DATA PROCESSING SYSTEMS
1 is for POLICIES AND PLANNING
both of whom should be RECOGNIZED EXPERTS IN IT AND DATA PRIVACY.
What is the term of office of the Commissioner and Deputy Commissioners?
The commissioner and deputy commissioner shall be APPOINTED BY THE PRESIDENT OF THE PHILIPPINES for a TERM OF 3 YEARS and may be REAPPOINTED AGAIN for 3 YEARS.
What is the composition of the NPC’s Secretariat?
The NPC is authorized to establish a Secretariat, where a MAJORITY OF THE MEMBERS MUST HAVE SERVED FOR AT LEAST 5 YEARS in ANY AGENCY OF THE GOVERNMENT HEAVILY INVOLVED IN PROCESSING OF PERSONAL INFORMATION.
Distinguish Sensitive Personal Information from Privileged Information.
Sensitive Personal Information - refers to race/ethnic origin/marital status/age/religion/political affiliations/health/education/government issued records such as SSS and TIN
Privileged Information - refers to any and all forms of data which under Rules of Court and other pertinent laws constitute privileged information.
What are the personas involved in DPA?
- ) Data Subject
- ) Personal Information Controller
- ) Personal Information Processor
What are our rights under the DPA?
Under the DPA, we have the
- Right to informed consent - be informed whether personal info are processed
- Right to Access - upon demand, access his info
- Right to Object - right to object to the processing of his personal data
- Right to Erasure or Blocking - right to block/remove/destroy his data
- Right to Damages - right to be indemnified
- Right to File a Complaint
- Right to Rectify/correction - right to dispute the inaccuracy/error on his data
- Right to Data portability - right to obtain copy of his data
What are the criteria for lawful processing of personal information?
- ) Processing of personal information is not prohibited by law and necessary for compliance with a legal obligation.
- ) Personal information must be processed fairly and lawfully, collected for specified and legitimate purposes, accurate, relevant, retained only for as long as necessary for the fulfillment of the purposes, and be guaranteed by adequate safeguards.
- ) Consent has been given by the data subject.
- Processing is necessary to protect vitally important interests
- Processing is necessary for the purpose of legitimate interests and to respont to national emergency to comply with requirements of public order and safety and to fulfill the functions of public authority
When is processing of sensitive personal information and privileged information allowed?
- ) When the data subject has given CONSENT
- ) Regulatory enactments GUARANTEE THE PROTECTION OF SENSITIVE PERSONAL and PRIVILEGED INFORMATION
- ) Processing is necessary to protect the life and health of data subject or another person and the data subject is not legally/physically able to express his consent
- ) Processing is necessary to achieve lawful and noncommercial objectives
- ) Processing is necessary for purposes of medical treatment and the same is carried out by a medical practitioner
Is the subcontracting of processing of personal information allowed?
Yes, provided that the PERSONAL INFORMATION CONTROLLER SHALL BE RESPONSIBLE FOR ENSURING THAT PROPER SAFEGUARDS ARE IN PLACE TO ENSURE THE CONFIDENTIALITY OF PERSONAL INFORMATION PROCESSED.
What is a personal information controller?
It refers to a person who controls the collection,holding,processing or use of personal information.
Are the rights of the data subject transmissible to his assigns/heirs?
Yes, they may invoke such rights any time AFTER the data subject’s death or incapacity.
What are the responsibilities of a personal information controller?
- ) Implement technical measures intended for the protection of personal information
- ) Implement measures to protect personal information against natural dangers
- ) Determine the appropriate level of security by taking into account the nature of the personal information to be protected and the risks and complexity involved.
- ) Ensure that 3rd parties processing information on his behalf implement the security measures required by DPA.
- ) Ensure that his employees involved in processing understand the confidential relations
- ) To promptly notify the NPC and affected data subjects when SENSITIVE INFORMATION MAY HAVE BEEN USED OR ACQUIRED BY AN UNAUTHORIZED PERSON.