DPA Flashcards
(44 cards)
Who is a Data Protection Officer (DPO)?
- A designated person responsible for ensuring compliance with data protection laws.
- Main point of contact for data breaches and privacy concerns.
- Oversees data security policies and impact assessments.
- Liaises with regulatory authorities like the National Privacy Commission (NPC).
What is the objective of the Data Privacy Act?
- Protect personal data from misuse and unauthorized access.
- Ensure the free flow of information for innovation and economic growth.
- Applies to public and private entities handling personal data.
Who does the Data Privacy Act apply to?
It covers all persons involved in the processing of personal information, although these persons are not found or established in the Philippines, provided they use equipment located in the Philippines or they maintain an office, branch, or agency in the Philippines.
- Government and private sector organizations.
- Companies processing personal or sensitive information.
- Individuals or businesses collecting personal data in the Philippines.
What is personal information?
Personal information refers to any information whether recorded in a material form or not,
from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information,
or when put together with other information would directly and certainly identify an individual.
What is personal data?
“Personal Data” is used when personal information, sensitive personal information, and privileged information are referred to collectively. On the other hand, personal information forms part of the broader concept of personal data.
What is a data subject?
- An individual whose personal information is being collected, processed, or stored.
What is processing of personal information?
CROSUM RCUCBED
It refers to any operation or set of operations performed upon personal information including, but not limited to, the collection, recording, organization, storage, updating, modification, retrieval, consultation, use, consolidation, blocking, erasure, or destruction of data.
What is privileged information?
It refers to any and all forms of data which under the Rules of Court and other pertinent laws constitute privileged communication.
Examples: Attorney-Client Privilege; Physician-Patient Privilege; Marital Privilege Rule
What constitutes valid consent for data processing?
- Consent must be freely given, specific, and informed.
- Documented in writing, electronically, or through recorded means.
- Not required if processing is mandated by law, court order, or public safety reasons.
Who is a Personal Information Controller (PIC)?
- Entity that decides why and how personal data is processed.
- Responsible for ensuring compliance with the Data Privacy Act.
Who is a Personal Information Processor (PIP)?
- Processes data on behalf of a PIC under contractual agreement.
- Must follow data security protocols and privacy laws.
What are the three main data privacy principles?
- Transparency – Data subjects must be informed of how their data is used.
- Legitimate Purpose – Data should only be collected for a lawful purpose.
- Proportionality – Only collect and store the minimum data necessary.
What is a Data Sharing Agreement (DSA)?
- A contract between organizations outlining conditions for sharing personal data.
- Only Personal Information Controllers (PICs) can enter into DSAs.
- Ensures compliance with data privacy laws and security measures.
What are the three main kinds of privacy?
- Locational Privacy – Protection of physical spaces.
- Informational Privacy – Control over personal data.
- Decisional Privacy – Freedom to make personal choices.
What is locational privacy?
- Also called situational privacy.
- Protects against physical intrusions (e.g., unlawful searches, trespassing)
What is informational privacy?
- The right to control how personal data is collected, stored, and used.
- Prevents unauthorized access or data misuse.
What is decisional privacy?
- The right to make personal life choices without interference.
- Includes reproductive rights, medical decisions, lifestyle choices.
What are the rights of the data subject?
DIE-RADO
Right to be Informed – the right to be informed in a timely manner by the PIC if his data have been compromised
Right to Access – the right to know if an organization holds his data, and if so, the right to gain access to them
Right to Object – the right to contest any unlawful processing of data against him
Right to Rectify – the right to dispute and compel correction of inaccurate data a PIC has about him
Right to Erasure and Blocking – the right to withdraw or order the removal or blocking of his personal data
Right to Damages – the right to claim compensation arising from inaccurate or unauthorized use of personal data
Right to Data Portability – right to electronically move, copy, or transfer his data in a secure manner for further use. It enables the free flow of his personal information in the internet according to his preference.
What is the definition of the right to privacy?
- The right to be free from unwarranted exploitation or intrusion into private activities.
- Protects individuals from unwanted public exposure.
Two-part test for privacy violations
- Did the individual exhibit an expectation of privacy?
- Would society recognize it as reasonable?
Cadajas issue on privacy
If a person voluntarily shares their password, they have limited privacy rights over the shared account.
What does Section 19 of the Data Privacy Act state?
- Exemptions from privacy protections, including:
- Investigations related to criminal, administrative, or tax liabilities.
- Processing of data for scientific and statistical research.
When can personal data be used in legal proceedings?
- If data is collected for court cases or to determine criminal, administrative or tax liability.
Outsourcing or Subcontracting
- A PIC or PIP may outsource or subcontract the functions of its DPO or COP.
DPO or COP must oversee the performance of his or her functions by the third-party service provider or providers