IAS - INTRODUCTION TO DATA PRIVACY ACT OF 2012 Flashcards
Lesson 4 (22 cards)
THE STRUCTURE OF THE DATA PRIVACY ACT
Definition and General Provisions
SECTION 1-6
The National Privacy Commission
SECTION 7-10
Rights of Data Subjects and Obligations of Personal Information Controllers and Processors
SECTION 11-21
Provision Specific to Government
SECTION 22-24
Penalties
SHORT HISTORY OF DPA
SECTION 25-37
National Privacy Commission
JUNE 2015
When does Data Privacy Act created?
2012
Month and year the ‘Data Privacy Commissioner’ elected
MARCH 2016
IRR RA No. 10173
AUGUST 2016
Month and year IRR RA NO. 10173 was integrated to Companies
SEPTEMBER 2017
Provide Personal Data
- Personal Information
- Sensitive Personal Information
- Privilege Information
DATA Subject
outsources the processing
Personal Information Controller
share data – third parties
Personal Information Processor
Information directly attributable to an individual
* Name
* Home Address
* Phone Number
Personal Information
Personal information whose leakage could impact the material well being of an individual is considered as sensitive PII
* Race, ethnic origin, marital status, age, color, religious, philosophical or political affillation.
Sensitive Personal Information
Any and all forms of data which under the rules of court or other pertinent laws constituted privileged communication
Privileged Information
Refers to an individual (natural person) whose personal, sensitive personal, or privileged information is processed.
Data Subject
Refers to any natural or juridical person or any other body to whom a personal information controller may outsource or instruct the processing of personal data pertaining to a data subject.
Personal Information Processor (PIP)
Refers to a natural or juridical person, or any other body who controls the processing of personal data, or instructs another to process personal data on its behalf
Personal Information Controller (PIC)
what are the RIGHTS OF DATA SUBJECT?
(I, O, A, C, E,D, D)
- INFORMED CONSENT
- OBJECT
- ACCESS
- CORRECTION
- ERASURE
- DAMAGES
- DATA PORTABILITY
what are the DUTIES OF PIC/PIP?
(T, P, D, L)
- TRANSPARENCY
- PROTECTION
- DATA INTEGRITY
- LAWFUL PROCESSING
Refers to any operation or any set of operation performed upon personal data such as collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.
Content: Processing