Republic Act 10173 Flashcards

1
Q

Republic Act 10173

A

Data Privacy Act of
2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Section 1

A

Short Title

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CHAPTER I

A

GENERAL PROVISIONS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Section 2

A

Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Declaration of Policy

Protect the fundamental human right of ________, of communication
while ensuring free flow of information

A

privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Declaration of Policy

Vital role of information and communications technology in ___________

A

nationbuilding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Declaration of Policy

To ensure that personal information and communications systems in the government and in the private
sector are _______ and _______

A

protected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Section 3

A

Definition of terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

National Privacy Commission created
by virtue of this Act

A

Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

An individual whose personal
information is processed

A

Data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Any information whether recorded in
a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information

A

Personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A person or organization who controls the collection, holding, processing or use of personal information. Including a person or organization who instructs another person or organization to collect, hold, process, use, transfer or disclose personal information on his or her behalf

A

Personal information controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Any operation or any set of
operations performed upon personal
information including, but not limited
to, the collection, recording,
organization, storage, updating or
modification, retrieval, consultation,
use, consolidation, blocking, erasure
or destruction of data

A

Processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Section 4

A

Scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This Act does not apply to the following:

A
  1. Info about government officer/empolyees
  2. Info about individual who perform service with government
  3. Info reltng to discretionary benefit of finacial nature
  4. Personal info processed for journal, artisitc, literary, researrch purpose
  5. Info necessary to carry out public authority functions
  6. Info necessary for banks/finacial institutions
  7. Personal info from residents of foreign jurisdiction
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Section 5

A

Protection Afforded to Journalists and Their Sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Republic Act No. 53

A

Journalist are not compelled to reveal the source of any news

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Section 6

A

Extraterritorial Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

This act also apply even if you are out of the coutry as long as:

A
  • related sa personal info ng philippine citizen
  • a contract is entered in the philippines
  • basta related sa philippines
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CHAPTER II

A

THE NATIONAL PRIVACY COMMISSION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Section 7

A

Functions of the National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Functions of the National Privacy Commission

Ensure compliance of

A

personal information controllers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Functions of the National Privacy Commission

Receive complaints, institute investigations, facilitate
or enable settlement of complaints, prepare ______ on disposition of complaints and resolution of any investigation it initiates, and, in cases it deems appropriate, publicize any such report

A

reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Functions of the National Privacy Commission

Issue ___________, impose a temporary or permanent ban

A

cease and desist orders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Functions of the National Privacy Commission

____________ or _______ any entity, government agency or instrumentality

A

Compel or petition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Functions of the National Privacy Commission

Monitor the _______ of other government agencies
or instrumentalities

A

compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Functions of the National Privacy Commission

__________ with other government agencies and the
private sector

A

Coordinate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Functions of the National Privacy Commission

Publish on a regular basis a _____ to all laws relating to data protection

A

guide

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Functions of the National Privacy Commission

Publish a compilation of _______ of records and notices, including index and other finding aids

A

agency system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Functions of the National Privacy Commission

Recommend to the ______ the prosecution and imposition of penalties

A

Department of Justice (DOJ)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Functions of the National Privacy Commission

Review, approve, reject or require modification of __________
voluntarily adhered to by personal information controllers

A

privacy codes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Functions of the National Privacy Commission

that the privacy codes shall adhere to the underlying _____________

A

data privacy principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

That such privacy codes may include private dispute resolution mechanisms for _______ against any participating personal information controller

A

complaints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Functions of the National Privacy Commission

For this purpose, the Commission shall consult with relevant _________ in the formulation and administration of privacy codes applying the standards in this Act

A

regulatory agencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Functions of the National Privacy Commission

Provide ______ on matters relating to privacy or data protection

A

assistance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Functions of the National Privacy Commission

______ on the implication on data privacy of proposed national or local statutes, regulations or procedures, issue advisory opinions and interpret the provisions

A

Comment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Functions of the National Privacy Commission

______ legislation, amendments or modifications to Philippine laws

A

Propose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Functions of the National Privacy Commission

Ensure proper and effective coordination with _______ in other countries and private accountability agents,
participate in international and regional initiatives for data
privacy protection

A

data privacy
regulators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Functions of the National Privacy Commission

Negotiate and contract with other data privacy authorities of
other countries for ________ and implementation of respective privacy laws

A

cross-border application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Functions of the National Privacy Commission

Assist ___________ doing business abroad to respond to foreign privacy or data protection laws and regulations

A

Philippine companies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Functions of the National Privacy Commission

Generally perform such acts as may be necessary to facilitate ______________ of data privacy protection

A

cross-border enforcement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Section 8

A

Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Section 9

A

Organizational structure of the commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Organizational structure of the commission

A
  • Privacy Commissioner
  • Deputy Privacy Commisioners (2)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

The Commission shall be attached to the

A

Department
of Information and Communications Technology
(DICT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Chairman of the
Commission

A

Privacy Commissione

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

in cahrge of the Data Processing Systems, Policies and Planning.
appointed by the President of the Philippine

A

Deputy Privacy Commissioners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

How many terms does the The Privacy Commissioner and the two (2) Deputy Privacy Commissioners have?

A

3 years

may be reaapointed for another 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

the privacy commisioner mus be atleast ___ yrs old

A

35

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

good moral character, unquestionable integrity and known probity, and a recognized expert in the field of information technology and data privacy

A

Privacy Commissioner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

The Privacy Commissioner shall enjoy
the benefits, privileges and emoluments equivalent to the rank of _________

A

Secretary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

Who is the Privacy Commisioner and chairman

A

Raymund
Enriquez Liboro

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

must be recognized experts in the field of information and
communications technology and data privacy

A

Deputy Privacy Commissioners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Deputy Privacy Commissioners shall enjoy the benefits, privileges and
emoluments equivalent to the rank of _______

A

Undersecretary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Who are the Deputy Privacy commisioners

A

Leandro Angelo Y. Aguirre, John Henry Du Naga

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

Section 10

A

The Secretariat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

Majority of the members of the Secretariat must have served for at least ______ in any agency of the government that is involved in the processing of personal information

A

five (5) years

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

Majority of the members of the Secretariat must have served for at least five (5) years in any agency of the government that is involved in the processing of personal information including, but not limited to, the following offices:

A
  • Social Security System (SSS)
  • Government Service Insurance System (GSIS)
  • Land Transportation Office (LTO)
  • Bureau of Internal Revenue (BIR)
  • Philippine Health Insurance Corporation (PhilHealth)
  • Commission on Elections (COMELEC)
  • Department of Foreign Affairs (DFA)
  • Department of Justice (DOJ)
  • Philippine Postal Corporation (Philpost)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

CHAPTER III

A

PROCESSING OF PERSONAL
INFORMATION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

Section 11

A

General Data Privacy Principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

Kept in a form which permits identification of ________ for no longer than is necessary for the purposes for which the data were collected and processed

A

data subjects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

Section 12

A

Criteria for Lawful Processing of
Personal Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

Section 13

A

Sensitive Personal Information and Privileged Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

The processing of sensitive personal information and privileged information shall be prohibited except if the The data subject has given his or her consent, specific
to the purpose _____________

A

prior to the processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

It is okay to proccess sensitive data without consent as long as protection of the info is guranteed?

A

yes of course

57
Q

The proccesing is necessary to protect the life and health of the data subject or another person, and data sibject cannot consent, are you allowed to process it?

A

yups

58
Q

It is okay to process sentisitve info as long as

The processing is necessary to achieve the lawful and noncommercial objectives of public organizations and their associations provided that:

A
  • info is confined only to bonafide members of the org
  • info is not transfered to other parties
  • there is a consent from the data subject
59
Q

If the processing is necessary for purposes of medical treatment, are you allowed to process sensitive info?

A

why not?

60
Q

The processing concerns such personal information as is necessary for the protection of lawful rights and interests of natural or legal persons in court proceedings, or the establishment, exercise or defense of legal claims, or when provided to government or public authority. Is it oay to process sensitive info?

A

yups

61
Q

Section 14

A

Subcontract of Personal Information

62
Q

A personal information controller may ________ the processing of personal information

A

subcontract

63
Q

Section 15

A

Extension of Privileged Communication

64
Q

____________ may invoke the principle of privileged communication over privileged information that they lawfully control or process.

A

Personal information controllers

65
Q

Subject to existing laws and regulations, any evidence
gathered on privileged information is ___________

A

inadmissible

66
Q

CHAPTER IV

A

RIGHTS OF THE DATA SUBJECT

67
Q

Section 16

A

Rights of the Data Subject

68
Q

What are the info need to be furnishe d to the data subject before processing their data:

A
  1. Descroption of personal data
  2. Purpose of the processing
  3. Scope and method of processing
  4. Receipients
  5. Methods for automated access
  6. Personal information controller Identity and contanct details
  7. Period on information stored
  8. Rights to access, correction, complaint
69
Q

Data subjects should have reasonable access to, upon demand:

A
  1. contents of personal info
  2. sources of personal info
  3. Recipients name and address
  4. Manner of proccesing of data
  5. reason for disclosure of personal info
  6. Info on automated processes
  7. Date of personal info last accesed
  8. Personal information controller designation, name, identity
70
Q

If the personal information have been corrected, the personal information controller shall ensure the accessibility of both the new and the retracted information and the ____________ of the new and the retracted information by recipients

A

simultaneous receipt

71
Q

If there is a innacuracy or error in the personal info of and it is corrected who should be aso informed about the inacuracy and rectification?

A

Third parties

72
Q

the data subject can Suspend, withdraw or order the blocking, removal or destruction of his or her personal information from the
personal information controller’s _______ upon discovery and substantial proof that the personal information are incomplete, outdated, false, unlawfully obtained, used for unauthorized purposes
or are no longer necessary for the purposes for which
they were collected.

A

filing system

73
Q

the data subject should be ______ for any damages sustained due to such inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of personal information

A

indemnified

74
Q

Section 17

A

Transmissibility of Rights of the Data Subject.
lawful heirs

75
Q

Section 18.

A

. Right to Data Portability.

76
Q

The data subject shall have the right, where personal information is processed by ______ means and in a structured and commonly used format

A

electronic

77
Q

Section 19

A

Non-Applicability

78
Q

The immediately preceding sections are not applicable if the processed personal information are used only for the needs of ____________ and, on the basis of such, no activities are carried out and no decisions are taken regarding the data subject

A

scientific and statistical research

79
Q

CHAPTER V

A

SECURITY OF PERSONAL
INFORMATION

80
Q

Section 20

A

Security of Personal Information

81
Q

Who is responsible for the security of personal info

A

Personal information controller

82
Q

The personal information controller shall promptly notify heth __________affected subjectwhen sensitive personal information or other information that ay, under the circumstances, be used to enable identity fraud are reasonably believed to have been cquired by an unauthorized person

A

Commission

83
Q

In evaluating if notification is ________, the Commission may take into account compliance by the personal information controller with this section and existence of
good faith in the acquisition of personal information

A

unwarranted

84
Q

The Commission may exempt a personal information controller from notification where, in its reasonable judgment, such notification would __________ or _________

A

not be in the public interest or in the interests of the affected data subjects

85
Q

The Commission may authorize postponement of notification where it may hinder the progress of a _____________ related to a serious breach.

A

criminal investigation

86
Q

CHAPTER VI

A

ACCOUNTABILITY FOR
TRANSFER OF PERSONAL INFORMATION

87
Q

Section 21

A

Principle of Accountability

88
Q

The personal information controller is accountable for complying with the requirements of this Act and shall
use _______ or other reasonable means to provide a comparable level of protection while the information are being processed by a third party.

A

contractual

89
Q

The personal information controller shall designate an __________ who are accountable for the organization’s compliance with this Act.

A

individual or individuals

90
Q

CHAPTER VII

A

SECURITY OF SENSITIVE
PERSONAL INFORMATION IN GOVERNMENT

91
Q

SECTION 22

A

Responsibility of Heads of Agencies

92
Q

Who shall be responsible for complying with the security requirements in the ogvernment?

A

head of each government agency or instrumentality

93
Q

Section 23

A

Requirements Relating to Access by Agency Personnel to Sensitive Personal Information

94
Q

No ________ shall have access to sensitive personal information on government property or through online facilities

A

employee of the government

95
Q

sensitive personal information maintained by an agency may not be transported or accessed from a
__________

A

location off government property

96
Q

access of sensitive info putside gov property request

in the case of any request submitted to the head of an agency, such head of the agency shall approve or disapprove the request within _________ after the date of submission of the request.

A

two (2) business days

97
Q

How many is the limitation of records acces outside gov failities

A

1000

98
Q

Any technology used to store, transport or access sensitive
personal information for purposes of off-site access approved under this subsection shall be secured by the
use of the most secure _______ standard recognized by
the Commission

A

encryption

99
Q

Section 24

A

Applicability to Government Contractors

100
Q

In entering into any contract that may involve accessing or requiring sensitive personal information from one thousand (1,000) or more
individuals, an agency shall require a contractor and its employees to register their ________

A

personal information processing system

101
Q

CHAPTER VIII

A

PENALTIES

102
Q

Section 25

A

Unauthorized Processing of
Personal Information and Sensitive
Personal Information

103
Q

Section 26

A

Accessing Personal Information
and Sensitive Personal Information
Due to Negligence.

104
Q

Section 27

A

Improper Disposal of Personal
Information and Sensitive Personal
Information.

105
Q

Section 28

A

Processing of Personal Information
and Sensitive Personal Information
for Unauthorized Purposes.

106
Q

Section 29

A

Unauthorized Access or Intentional
Breach.

107
Q

Section 30

A

Concealment of Security Breaches
Involving Sensitive Personal
Information

108
Q

Section 31

A

Malicious Disclosure

109
Q

Section 32

A

Unauthorized Disclosure.

110
Q

Section 33

A

Combination or Series of Acts.

111
Q

Unauthorized Processing of
Personal Information and Sensitive
Personal Information

A

Imprisonment: 1-3 yrs
Fine: 500k -2M

112
Q

Accessing Personal Information
and Sensitive Personal Information
Due to Negligence.

A

Imprisonment: 3-6 yrs
Fine: 500k - 4M

113
Q

Improper Disposal of Personal
Information and Sensitive Personal
Information.

A

Personal
Imprisonment: 6 mon - 2 yrs
Fine: 100k-500k
Sentisitve
Imprisonment: 1-2 yrs
Fine: 100k -1M

114
Q

Processing of Personal Information
and Sensitive Personal Information
for Unauthorized Purposes.

A

Personal
Imprisonment: 1 yr and 6 mon - 5 yrs
Fine: 500k - 1M
Sentisitve
Imprisonment: 2-7 yrs
Fine: 500k - 2M

115
Q

Unauthorized Access or Intentional Breach.

A

Imprisonment: 1 -3 yrs
Fine: 500k - 2M

116
Q

Concealment of Security Breaches
Involving Sensitive Personal
Information.

A

Imprisonment: 1 yr and 6 mons - 5 yrs
Fine: 500k -1M

117
Q

Malicious Disclosure

A

Imprisonment: 1 yr and 6 mons - 5 yrs
Fine: 500k -1M

118
Q

Unauthorized Disclosure.

A

Personal
Imprisonment: 1 yr - 3 yrs
Fine: 500k - 1M
Sentisitve
Imprisonment: 3-5 yrs
Fine: 500k - 2M

119
Q

Combination or Series of Acts

A

Imprisonment: 3 - 6 yrs
Fine: 1-5 M

120
Q

Section 34

A

Extent of Liability

121
Q

If the offender is a corporation, partnership or any juridical person, the penalty shall be imposed upon
the _________, as the case may be, who participated in, or by their gross negligence, allowed the commission of the crime.

A

responsible officers

122
Q

If the offender is a juridical person, the court may

A

suspend or revoke any of its rights under this Act.

123
Q

If the offender is an alien, he or she shall, in addition to the penalties herein prescribed, be _________
without further proceedings after serving the penalties prescribed.

A

deported

124
Q

If the offender is a public official or employee and lie or she is found guilty of acts penalized under Sections 27 and 28 of this Act, he or she shall, in addition to the penalties prescribed herein, suffer perpetual or temporary absolute __________, as the case may be.

A

disqualification from office

125
Q

Section 35

A

Large-Scale.

126
Q

The maximum penalty in the scale of penalties respectively provided for the preceding offenses shall
be imposed when the personal information of at least __________is harmed, affected or involved as the result of the above mentioned actions.

A

one hundred (100) persons

127
Q

Section 36

A

Offense Committed by Public Officer

128
Q

When the offender or the person responsible for theoffense is a public officer as defined in the Administrative Code of the Philippines in the exercise
of his or her duties, an accessory penalty consisting in the disqualification to occupy public office for a ___________ imposed shall be
applied.

A

term double the term of criminal penalty

129
Q

SECTION 37

A

Restitution

130
Q

CHAPTER IX

A

MISCELLANEOUS PROVISIONS

131
Q

Section 38

A

Interpretation

132
Q

SECTION 39

A

Implementing Rules and Regulations (IRR)

133
Q

Within __________ from the effectivity of this Act,
the Commission shall promulgate the rules and
regulations to effectively implement the provisions of
this Act

A

ninety (90) days

134
Q

SECTION 40

A

Reports and Information

135
Q

The Commission shall _________ report to the _________ and _________ on its activities in carrying out the
provisions of this Act

A
  • annually
  • President and Congress
136
Q

SECTION 41

A

Appropriations Clause

137
Q

The Commission shall be provided with an initial appropriation of ______ to be drawn from the national government.

A

Twenty million pesos (Php20,000,000.00)

138
Q

Appropriations for the succeeding years shall be
included in the _____________.

A

General Appropriations Act

139
Q

It shall likewise receive___________ per year for ________ upon implementation of this Act drawn from the national government.

A
  • Ten million pesos (Php10,000,000.00)
  • five (5) years
140
Q

Section 42

A

Transitory Provision.

141
Q

Section 43

A

Separability Clause

142
Q

Existing industries, businesses and offices affected by the implementation of this Act shall be given ______ transitory period from the effectivity of the IRR or
such other period as may be determined by the Commission, to comply with the requirements of this
Act.

A

one (1) year

142
Q

In case that the DICT has not yet been created by the time the law takes full force and effect, the National Privacy Commission shall be attached to the ________

A

Office of the President.

142
Q

Section 44

A

Repealing Clause

143
Q

SECTION 45

A

effectivity Clause

143
Q

What is amended by this act?

A

Section 7 of Republic Act No. 9372,
otherwise known as the “Human Security Act of 2007”

144
Q

This Act shall take effect _________ after its publication in at least _________ of general circulation.

A
  • 15 days
  • two (2) national newspapers
145
Q

President of the Senate

A

JUAN PONCE ENRILE

146
Q

Speaker of the House of Representatives

A

FELICIANO BELMONTE JR

147
Q

Secretary of Senate

A

EMMA LIRIO-REYES

148
Q

Secretary General (House of Representatives)

A

MARILYN B. BARUA-YAP