data privacy act Flashcards

1
Q

Its purpose is to ensure that personal information and communications systems in
government and in the private sector are secured and protected.

A

Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

the other name of data privacy?

A

Information privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

R.A is also known as “Data Privacy Act of 2012”

A

R.A 10173

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When was the Data Privacy Act of 2012 approved?

A

a. August 15, 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

total number of sections under the “Data Privacy Act of 2012”

A

45

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  1. Who is the president who signed the approval of “Data Privacy Act of 2012”
A

Gloria Macapagal Arroyo

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
  1. Who is in charge of administering and implementing the DPA?
A

National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is one of the major functions of NPC?
a.

A

Policymaking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

is to educate the public about data privacy, data protection, and fair information rights
and responsibilities.

A

Advisory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

It is to manage the registration of personal data processing systems.

A

Compliance and monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

refers to the commission that is created by virtue of the RA 10173.

A

National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

It refers to a system for generating, sending, receiving, storing or otherwise processing
electronic data messages or electronic documents.

A

Information and Communications System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  1. It refers to a person or organization who controls the collection, holding, processing, or
    use of personal information.
A

Personal Information Controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

It refers to any natural or juridical person qualified to act as such under this Act to
whom a personal information controller may outsource the processing of personal data
pertaining to a data subject.

A

Personal Information Processor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

It refers to any and all forms of data which under the Rules of Court and other pertinent
laws constitute privileged communication.

A

Privileged Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q
  1. Data privacy does not apply to clinical laboratories because they handle sensitive data or
    information related to their patients.
    t or f
A

f

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Data privacy is connected with data security
t or f

A

true

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Data Privacy Act of 2012 requires each organization to appoint Data Protection Officer (DPO)

A

(TRUE)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

DOH is tasked to monitor and ensure compliance of the Philippines with international standards
for personal data protection. ()

A

FALSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Data privacy is a subset of data protection that focuses on the proper handling of data ()

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

ra 10173 is also known as the “Data Privacy Act of 2010” (

A

false

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

the policy of the State to protect the fundamental human right of privacy and communication
to promote innovation and growth. ()

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

The consent of the data subject can be evidenced by written, electronic, or recorded means.
()

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

ra 10173 does not apply to the processing of all types of personal information and to any natural
and juridical person involved in personal information processing. ()

A

false

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Data Privacy Act of 2012 does not apply to personal information processed for journalists,
artistic, literary, or research purposes. ()

A

TRUE

26
Q

It refers to any freely given, specific, informed indication of will, whereby the data
subject agrees to the collection and processing of personal information relating to them.

A

coinsent

27
Q

It refers to an individual whose personal information is processed. (

A

A. Data Subject)

28
Q

It refers to any operation or any set of operations performed upon personal information.
(E. )

A

Processing

29
Q

It refers to communication by whatever means of any advertising or marketing material
which is directed to particular individuals. (

A

C. Direct Marketing)

30
Q

It refers to any information whether recorded in a material form or not, from which the
identity of an individual is apparent or can be directly ascertained. (

A

D. Personal
Information)

31
Q

What does the Data Privacy Act of 2012 primarily aim to protect?

A

Answer: b) Personal data privacy

32
Q

Which government agency in the Philippines is responsible for implementing the provisions of
the Data Privacy Act?

A

b) National Privacy Commission

33
Q

What is the maximum fine, in Philippine Pesos, for offenses under Section 37 (Unauthorized
Processing of Personal Information) of the Data Privacy Act?

A

b) ₱1,000,000

34
Q

Sensitive personal information, as defined by the Data Privacy Act, includes details such as:

A

c) Credit card number

35
Q

The individual to whom personal data pertains is referred to as:

A

data subject

36
Q

An entity or person who determines the purpose and means of processing personal
information.

A

Personal Information Controller

37
Q

Permission provided by the data subject for the processing of their personal data.

A

Consent

38
Q

An individual appointed by a personal information controller to ensure compliance with the
Data Privacy Act.

A

Data Privacy Officer

39
Q

The person to whom the personal data pertains.

A

_____ Data Subject

40
Q

The government agency responsible for enforcing the Data Privacy Act.

A

National Privacy Commission

41
Q

The Data Privacy Act of 2012 only applies to large corporations.
Answer:

A

False

42
Q

Data subjects have the right to request access to their personal data and have it
corrected if it’s inaccurate.
Answer:

A

True

43
Q

Consent of the data subject is not required when processing sensitive personal
information.
Answer:

A

False

44
Q

The National Privacy Commission is responsible for enforcing the provisions of
the Data Privacy Act.

A

Answer: True

45
Q

True or False: Data privacy rights under the Data Privacy Act may not be waived or forfeited by
the data subject.
Answer:

A

False

46
Q

Subjected to the guidelines that the Commission issued in Section 20. Security of
Personal Information is the regular monitoring and implementation of preventive,
corrective, and mitigation processes for any security breaches. (t o f)

A

TRUE

47
Q

The employees, agents or representatives of a personal information controller who are
involved in the processing of personal information shall operate and hold personal
information under strict confidentiality if the personal information is not intended for
public disclosure. ()

A

TRUE

48
Q

The Commission can authorize postponement of notification to determine the scope of
the breach, to prevent further disclosures, or to restore reasonable integrity to the
information and communications system. ()

A

TRUE

49
Q

It was stated in Section 20. Principle of Accountability that each personal information
controller is responsible for personal information under its control or custody, including
information that has been transferred to a third party for processing, whether domestically
or internationally, subject to cross-border arrangement and cooperation. (t or f)

A

FALSE

50
Q

As recommended by the Commission, all sensitive personal information maintained by
the government, its agencies and instrumentalities shall be secured with the use of the
least appropriate standard recognized by the information and communications technology
industry. )

A

(FALSE

51
Q

A request of approval is an important requirement for accessing agency personnel and
sensitive personal information. (t or f )

A

TRUE

52
Q

Even without the approval and security clearance from the head of the agency, employees
of the government can still access sensitive personal information. (t or f )

A

FALSE

53
Q

Any technology used to store, transport or access sensitive personal information for
purposes of off-site access approved under this subsection shall be secured by the use of
the most secure encryption standard recognized by the Commission. (t or f )

A

TRUE

54
Q

Any technology used to store, transport or access sensitive personal information for
purposes of on-site access approved under this subsection shall be secured by the use of
the most secure encryption standard recognized by the Commission. (t or f )

A

FALSE

55
Q
  1. The improper disposal of personal information shall be penalized by imprisonment
    ranging from one (1) month to three (3) years and a fine of not less than One hundred
    thousand pesos (Php100,000.00) but not more than Five hundred thousand pesos
    (Php500,000.00). ()
A

FALSE

56
Q

What section indicates the “Responsibility of the Heads of Agencies”?

A

Section 22

57
Q
  1. What type of access should be applied when sensitive personal information is transported
    and maintained from a location off government property?
A

Off-site Access

58
Q

If a request is approved, the head of the agency shall limit the access to ________ records
at a time.

A

Not more than 1, 000

59
Q
  1. The __________ is accountable for complying with the requirements of this Act and shall
    use contractual or other reasonable means to provide a comparable level of protection while the
    information is being processed by a third party.
A

Personal Information Controller

60
Q

What type of access should be applied if sensitive personal information is maintained on
government property and online facilities?

A

On-site and Online Access