MT6313 RA10173 Flashcards

1
Q

AN ACT PROTECTING INDIVIDUAL PERSONAL INFORMATION IN INFORMATION AND COMMUNICATIONS SYSTEMS IN THE GOVERNMENT AND THE PRIVATE SECTOR, CREATING FOR THIS PURPOSE A NATIONAL PRIVACY COMMISSION, AND FOR OTHER PURPOSES

A

RA 10173

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the title of RA 10173?

A

“Data Privacy Act of 2012′′.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Section 2 of RA 10173?

A

Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the declaration of policy of RA 10173 state?

A

Protect the fundamental human right of privacy, of communication while ensuring free flow of information

Vital role of information and communications technology in nation- building

To ensure that personal information in information and communications systems in the government and in the private sector are secured and protected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is section 3 of RA 10173?

A

Definition of Terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the terms listed under section 3 of RA 10173?

A

a. Commission
b. Data subject
c. Personal data
d. Personal information
e. Personal information controller
f. Processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does the term “commission” refer to? (RA 10173)

A

National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the term “data subject” refer to? (RA 10173)

A

Individual whose personal information is processed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the term “personal information” refer to? (RA 10173)

A

Information on the identity of the individual in which it is apparent and can be ascertained by the entity holding the information, or when put together with other information would directly identify the individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the term “personal information controller” refer to? (RA 10173)

A

A person or organization who controls the collection, holding, processing or use of personal information, excluding people who have been instructed only to execute these functions and those who hold personal information in connection with the person’s family or household affairs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does the term “processing” refer to? (RA 10173)

A

Any operation performed upon personal information (collection, recording, organizing, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is section 4 of RA 10173?

A

SCOPE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does RA 10173 NOT apply to?

A

Information about any individual who is or was an officer or employee of a government institution

Information about an individual who is or was performing service under contract for a government institution

Information relating to any discretionary benefit of a financial nature

Personal information processed for journalistic, artistic, literary or research purposes

Information necessary in order to carry out the functions of public authority

Information necessary for banks and other financial institutions

Personal information originally collected from residents of foreign jurisdictions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is section 5 of RA 10173?

A

Protection Afforded to Journalists and Their Sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In section 5 of RA 10173, nothing in the act shall be construed as having amended what Republic act?

A

RA 53

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is included in the information about any individual who is or was an officer or employee of a government institution?

A

Fact that s/he was/is an officer of the government institution

Title, business address and office telephone number

Classification, salary range and responsibilities of the position

The name of the individual on a document prepared

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

In section 4(e) of RA 10173, nothing in the act should be construed as amending or repealing what republic acts?

A

RA 1405
RA 6426
RA 9510

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the Secrecy of Bank Deposits Act?

A

RA 1405

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the Foreign Currency Deposit Act?

A

RA 6426

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the Credit Information Systems Act?

A

RA 9510

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

The information necessary for banks and other financial institutions is under the jurisdiction of?

A

Bangko Sentral ng Pilipinas or central monetary authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What RA does the exclusion of the information necessary for banks and other financial institutions comply with in section 4 of RA 10173?

A

RA 9160 Anti-Laundering Act and RA 9510

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Section 6 of RA 10173 is entitled?

A

Extraterritorial Application.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Section 6 of RA 10173 states that the act applies to any action done in or out of the PH by an entity if the action, practice or processing relates to?

A

Personal information about a Philippine citizen or a resident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Section 6 of RA 10173 states that the act applies to any action done in or out of the PH by an entity if the entity has?

A

Other links in the PH, or has links in the PH, where the entity is processing personal information in the Philippines or even if the processing is outside the Philippines as long as it is about Philippine citizens or residents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is section 7 of RA 10173 entitled?

A

Functions of the National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

The National Privacy Commission should review, approve, reject or require modification of privacy codes voluntarily adhered to by personal information controllers, provided that? (3)

A
  • That the privacy codes shall adhere to the underlying data privacy principles
  • Privacy codes may include private dispute resolution mechanisms for complaints against any participating personal information controller
  • The Commission shall consult with relevant regulatory agencies in the formulation and administration of privacy codes applying the standards in this Act
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Can the commission propose legislation, amendments or modifications to Philippine laws?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What section of RA 10173 is Confidentiality?

A

8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What section is the Organizational Structure of the Commission?

A

9

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

The commission (RA 10173) shall be attached to?

A

Department of Information and Communications Technology (DICT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Who is the chairman of the National Privacy Commission?

A

Privacy Commissioner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

The chairman of the commission (RA 10173) shall be aided by?

A

Two Deputy Privacy Commissioners, 1 for Data Processing Systems and the other for Policies and Planning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Who appoints the chairman and the 2 deputy officers?

A

President of the Philippines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

How long is the term of the chairman and deputy officers?

A

3 yrs and then can extend to 3 more if appointed again

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Requirements for the privacy commissioner?

A

must be at least thirty-five y/o

good moral character, unquestionable integrity and known probity, and a recognized expert in the field of information technology and data privacy

shall enjoy the benefits, privileges and emoluments equivalent to the rank of Secretary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Who is the present Privacy Commissioner or Chairman of the Commission?

A

Raymund Enriquez Liboro

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What are the requirements for the Dept. Privacy Commissioners?

A

recognized experts in the field of information and communications technology and data privacy.

shall enjoy the benefits, privileges and emoluments equivalent to the rank of Undersecretary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Who are the current Dept. Privacy Commissioners?

A

Leandro Angelo Aguirre
John Henry Du Naga

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What is section 10 of RA10173 entitled?

A

The Secretariat.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Major members of the Secretariat must serve for how many years in what government agencies?

A

5 yrs in any of the following:

SSS
GSIS
LTO
BIR
PHILHEALTH
COMELEC
DFA
DOJ
PHILPOST

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What section is the General Data Privacy Principles?

A

11

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

What section states that:

“The processing of personal information shall be allowed, subject to compliance with the requirements of this Act and other laws allowing disclosure of information to the public and adherence to the principles of transparency, legitimate purpose and proportionality.”

A

11

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

In section 11 of RA 10173, personal information must be?

A
  1. Collected for specified and legitimate purposes
  2. Processed fairly and lawfully
  3. Accurate, relevant and kept up to date for processing personal information
  4. Adequate and not excessive in relation to the purposes for which they are collected and processed
  5. Retained only for as long as necessary
  6. Kept in a form which permits identification of data subjects for no longer than is necessary
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Section 12 is entitled?

A

Criteria for Lawful Processing of Personal Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Lawful processing of information is permissible under what conditions?

A
  1. Data subject has given consent
  2. Personal information is necessary and is related to the fulfillment of a contract
  3. For compliance with a legal obligation
  4. To protect vitally important interests
  5. To respond to national emergency, to comply with the requirements of public order and safety, or to fulfill functions of public authority
  6. Legitimate interests pursued by the personal information controller or by a third party or parties to whom the data is disclosed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

What section is entitled, “Sensitive Personal Information and Privileged Information”?

A

13

48
Q

What is Section 14 and 15 entitled in RA 10173?

A

Sec 14 - Subcontract of Personal Information
Sec 15 - Extension of Privileged Communication

49
Q

According to Section 15, subject to existing laws and regulations, any evidence gathered on privileged information is inadmissible or admissible?

A

Inadmissible

50
Q

What is the title of Section 16?

A

Rights of the Data Subject

51
Q

The data subject should be furnished on what information before encoding their personal information into a processing system?

A
  1. Description
  2. Purpose
  3. Scope and method
  4. Recipients
  5. Methods utilized for automated access
  6. Identity and contact details of controller
  7. Period of storage
  8. Existence of their rights
52
Q

The data subject also has reasonable access to?

A
  1. Contents of own personal information
  2. Sources from where it was obtained
  3. Names and addresses or recipients
  4. Manner by which it was processed
  5. Reasons for disclosure
  6. Information on automated processes
  7. Date of access and modification
  8. Designation, name, identity of controller
53
Q

What is section 17 entitled?

A

Transmissibility of the Rights of the Data Subject

54
Q

Who can the rights of the data subject be transmitted to?

A

Lawful heirs

55
Q

What is section 18 entitled?

A

Right to Data Portability

56
Q

How is data portable?

A

Electronic means in structured and commonly used format

57
Q

What is section 19 entitled?

A

Non-applicability

58
Q

What section is the Security of Personal Information?

A

20

59
Q

In section 20, it states that the personal information controller must implement _____ and ______ ______,______ and _______ measures intended for the protection of personal information

A

reasonable and appropriate
organizational, physical and technical

60
Q

In section 20, it states that the personal information controller shall implement reasonable and appropriate measures to protect personal information against?

A

natural dangers

61
Q

In section 20, the determination of the appropriate level of security under this section must take into account the _____ of the personal information to be protected, the ______ represented by the processing, the ____ of the organization and _____ of its operations, current data privacy best practices and the cost of security implementation.

A

nature
risks
size
complexity

62
Q

The _____________ of a personal information controller who are involved in the processing of personal information shall operate and hold personal information ________ if the personal information are not intended for public disclosure. This obligation shall continue even after leaving the public service, transfer to another position or upon termination of employment or contractual relations.

A

employees, agents or representatives
under strict confidentiality

63
Q

The personal information controller shall promptly notify the Commission and affected data subjects when?

A

information or other information are reasonably believed to have been acquired by an unauthorized person

64
Q

Section 21 is entitled?

A

Principle of Accountability.

65
Q

Each personal information controller is responsible for?

A

personal information under its control or custody, including information that have been transferred to a third party for processing, whether domestically or internationally, subject to cross-border arrangement and cooperation.

66
Q

What section is Responsibility of Heads of Agencies?

A

22

67
Q

All sensitive personal information maintained by the government, its agencies and instrumentalities shall be?

A

secured

68
Q

Who shall be responsible for complying with the security requirements?

A

The head of each government agency or instrumentality

69
Q

What is Section 23 entitled?

A

Requirements Relating to Access by Agency Personnel to Sensitive Personal Information.

70
Q

No employee of the government shall have access to sensitive personal information on government property or through what type of facilities?

A

Online

71
Q

What kind of access is violated by sensitive personal information is being transported or accessed from a location off government property?

A

Off-site access

72
Q

In the deadline of approval or disapproval,

In the case of any request submitted to the head of an agency, such head of the agency shall approve or disapprove the request within ______ after the date of submission of the request.

A

two (2) business days

73
Q

When do you know if the request sent to the agency is disapproved?

A

If there is no action by the head of the agency

74
Q

If a request is approved, the head of the agency shall limit the access to not more than _______ at a time.

A

one thousand (1,000) records

75
Q

What is referred to as technology used to store, transport or access sensitive personal information for purposes of off-site access?

A

Encryption

76
Q

What is the title of Section 24?

A

Applicability to Government Contractors

77
Q

In entering into any contract that may involve accessing or requiring sensitive personal information from _______ individuals, an agency shall require a contractor and its employees to __________

A

one thousand (1,000) or more
register their personal information processing system

78
Q

What is Section 25 entitled?

A

Unauthorized Processing of Personal Information and Sensitive Personal Information

79
Q

What is Section 26 entitled?

A

Accessing Personal Information and Sensitive Personal Information Due to Negligence.

80
Q

What is Section 27 entitled?

A

Improper Disposal of Personal Information and Sensitive Personal Information.

81
Q

What is Section 28 entitled?

A

Processing of Personal Information and Sensitive Personal Information for Unauthorized Purposes.

82
Q

What is Section 29 entitled?

A

Unauthorized Access or Intentional Breach.

83
Q

What is Section 30 entitled?

A

Concealment of Security Breaches Involving Sensitive Personal Information.

84
Q

What is Section 31 entitled?

A

Malicious Disclosure

85
Q

What is Section 32 entitled?

A

Unauthorized Disclosure

86
Q

What is Section 33 entitled?

A

Combination or Series of Acts.

87
Q

What is the penalty for Sec 25?

A

1 year to 3 years AND
500,000 to Php2,000,000
OR
3-6yrs AND
500,000 - 4,000,000

88
Q

What is the penalty for Sec 26?

A

1 year to 3 years AND
Php500,000 to Php2,000,000
OR
3-6yrs AND
500,000 - 4,000,000

89
Q

What is the penalty for Sec 27?

A

6mos to 2yrs AND
100,000 to 500,000
OR
1yr-3yrs AND
100,000 to 1,000,000

90
Q

What is the penalty for Sec 28?

A

1yr and 6mos - 5yrs AND
500,000 to 1,000,000
OR
2yrs-7yrs
500,000 to 2,000,000

91
Q

What is the penalty for Sec 29?

A

1yr - 3yrs AND
500,000 to 2,000,000

92
Q

What is the penalty for Sec 30?

A

1yr and 6mos to 5yrs AND
500,000 to 1,000,000

93
Q

What is the penalty for Sec 31?

A

1yr and 6mos - 5yrs
500,000 - 1,000,000

94
Q

What is the penalty for Sec 32?

A

1yr - 3yrs
500,000 - 1,000,000
OR
3yrs-5yrs
500,000-2,000,000

95
Q

What is the penalty for Sec 33?

A

3yrs - 6yrs
1,000,000 - 5,000,000

96
Q

What is section 34?

A

The extent of liability

97
Q

What is contained in the extent of liability?

A

If the offender is a corporation, partnership or any juridical person
If the offender is a juridical person
If the offender is an alien
If the offender is a public official or employee (Sections 27 and 28)

98
Q

What section is entitled Large-scale?

A

35

99
Q

How is the act considered large-scale?

A

at least one hundred (100) persons is harmed, affected or involved

100
Q

What is section 36?

A

Offense Committed by Public Officer.

101
Q

What is section 37?

A

Restitution

102
Q

What section is entitled Interpretation?

A

38

103
Q

What section is Implementing Rules and Regulations (IRR)?

A

39

104
Q

When should the rules and regulations be implemented?

A

90 days from the effectivity of this Act

105
Q

What is section 40?

A

Reports and Information.

106
Q

Who shall receive reports of this act?

A

President and Congress

107
Q

What is the appropriation clause?

A

Sec 41

108
Q

The Commission shall be provided with an initial appropriation of?

A

20M drawn from the national government

109
Q

The Commission shall likewise receive ____ per year for ____ years upon implementation of this Act drawn from the national government.

A

Ten million pesos (Php10,000,000.00)
five (5)

110
Q

What is Section 42 of this act?

A

Transitory Provision

111
Q

Existing industries, businesses and offices affected by the implementation of this Act shall be given ______ transitory period from the effectivity of the IRR or such other period as may be determined by the Commission, to comply with the requirements of this Act.

A

one (1) year

112
Q

In case that the DICT has not yet been created by the time the law takes full force and effect, the National Privacy Commission shall be attached to the?

A

the Office of the President.

113
Q

What are the sections for the separability clause, repealing clause and effectivity clause?

A

Sep - 43
Rep - 44
Eff - 45

114
Q

The provision of _________, otherwise known as the _________, is hereby amended.

A

Section 7 of Republic Act No. 9372
“Human Security Act of 2007”

115
Q

Signatories of 10173?

A

President of the Senate : JUAN PONCE ENRILE
Speaker of the House of Representatives: FELICIANO BELMONTE JR.
Secretary of Senate: EMMA LIRIO-REYES
Secretary General (House of Representatives): MARILYN B. BARUA-YAP

(Sgd.) BENIGNO S. AQUINO III
President of the Philippines

116
Q
A