MT6313 RA10173 Flashcards

(116 cards)

1
Q

AN ACT PROTECTING INDIVIDUAL PERSONAL INFORMATION IN INFORMATION AND COMMUNICATIONS SYSTEMS IN THE GOVERNMENT AND THE PRIVATE SECTOR, CREATING FOR THIS PURPOSE A NATIONAL PRIVACY COMMISSION, AND FOR OTHER PURPOSES

A

RA 10173

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the title of RA 10173?

A

“Data Privacy Act of 2012′′.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Section 2 of RA 10173?

A

Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does the declaration of policy of RA 10173 state?

A

Protect the fundamental human right of privacy, of communication while ensuring free flow of information

Vital role of information and communications technology in nation- building

To ensure that personal information in information and communications systems in the government and in the private sector are secured and protected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is section 3 of RA 10173?

A

Definition of Terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the terms listed under section 3 of RA 10173?

A

a. Commission
b. Data subject
c. Personal data
d. Personal information
e. Personal information controller
f. Processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does the term “commission” refer to? (RA 10173)

A

National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the term “data subject” refer to? (RA 10173)

A

Individual whose personal information is processed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the term “personal information” refer to? (RA 10173)

A

Information on the identity of the individual in which it is apparent and can be ascertained by the entity holding the information, or when put together with other information would directly identify the individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the term “personal information controller” refer to? (RA 10173)

A

A person or organization who controls the collection, holding, processing or use of personal information, excluding people who have been instructed only to execute these functions and those who hold personal information in connection with the person’s family or household affairs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does the term “processing” refer to? (RA 10173)

A

Any operation performed upon personal information (collection, recording, organizing, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is section 4 of RA 10173?

A

SCOPE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does RA 10173 NOT apply to?

A

Information about any individual who is or was an officer or employee of a government institution

Information about an individual who is or was performing service under contract for a government institution

Information relating to any discretionary benefit of a financial nature

Personal information processed for journalistic, artistic, literary or research purposes

Information necessary in order to carry out the functions of public authority

Information necessary for banks and other financial institutions

Personal information originally collected from residents of foreign jurisdictions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is section 5 of RA 10173?

A

Protection Afforded to Journalists and Their Sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In section 5 of RA 10173, nothing in the act shall be construed as having amended what Republic act?

A

RA 53

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is included in the information about any individual who is or was an officer or employee of a government institution?

A

Fact that s/he was/is an officer of the government institution

Title, business address and office telephone number

Classification, salary range and responsibilities of the position

The name of the individual on a document prepared

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

In section 4(e) of RA 10173, nothing in the act should be construed as amending or repealing what republic acts?

A

RA 1405
RA 6426
RA 9510

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the Secrecy of Bank Deposits Act?

A

RA 1405

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the Foreign Currency Deposit Act?

A

RA 6426

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the Credit Information Systems Act?

A

RA 9510

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

The information necessary for banks and other financial institutions is under the jurisdiction of?

A

Bangko Sentral ng Pilipinas or central monetary authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What RA does the exclusion of the information necessary for banks and other financial institutions comply with in section 4 of RA 10173?

A

RA 9160 Anti-Laundering Act and RA 9510

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Section 6 of RA 10173 is entitled?

A

Extraterritorial Application.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Section 6 of RA 10173 states that the act applies to any action done in or out of the PH by an entity if the action, practice or processing relates to?

A

Personal information about a Philippine citizen or a resident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Section 6 of RA 10173 states that the act applies to any action done in or out of the PH by an entity if the entity has?
Other links in the PH, or has links in the PH, where the entity is processing personal information in the Philippines or even if the processing is outside the Philippines as long as it is about Philippine citizens or residents
26
What is section 7 of RA 10173 entitled?
Functions of the National Privacy Commission
27
The National Privacy Commission should review, approve, reject or require modification of privacy codes voluntarily adhered to by personal information controllers, provided that? (3)
- That the privacy codes shall adhere to the underlying data privacy principles - Privacy codes may include private dispute resolution mechanisms for complaints against any participating personal information controller - The Commission shall consult with relevant regulatory agencies in the formulation and administration of privacy codes applying the standards in this Act
28
Can the commission propose legislation, amendments or modifications to Philippine laws?
Yes
29
What section of RA 10173 is Confidentiality?
8
30
What section is the Organizational Structure of the Commission?
9
31
The commission (RA 10173) shall be attached to?
Department of Information and Communications Technology (DICT)
32
Who is the chairman of the National Privacy Commission?
Privacy Commissioner
33
The chairman of the commission (RA 10173) shall be aided by?
Two Deputy Privacy Commissioners, 1 for Data Processing Systems and the other for Policies and Planning.
34
Who appoints the chairman and the 2 deputy officers?
President of the Philippines
35
How long is the term of the chairman and deputy officers?
3 yrs and then can extend to 3 more if appointed again
36
Requirements for the privacy commissioner?
must be at least thirty-five y/o good moral character, unquestionable integrity and known probity, and a recognized expert in the field of information technology and data privacy shall enjoy the benefits, privileges and emoluments equivalent to the rank of Secretary
37
Who is the present Privacy Commissioner or Chairman of the Commission?
Raymund Enriquez Liboro
38
What are the requirements for the Dept. Privacy Commissioners?
recognized experts in the field of information and communications technology and data privacy. shall enjoy the benefits, privileges and emoluments equivalent to the rank of Undersecretary.
39
Who are the current Dept. Privacy Commissioners?
Leandro Angelo Aguirre John Henry Du Naga
40
What is section 10 of RA10173 entitled?
The Secretariat.
41
Major members of the Secretariat must serve for how many years in what government agencies?
5 yrs in any of the following: SSS GSIS LTO BIR PHILHEALTH COMELEC DFA DOJ PHILPOST
42
What section is the General Data Privacy Principles?
11
43
What section states that: "The processing of personal information shall be allowed, subject to compliance with the requirements of this Act and other laws allowing disclosure of information to the public and adherence to the principles of transparency, legitimate purpose and proportionality."
11
44
In section 11 of RA 10173, personal information must be?
1. Collected for specified and legitimate purposes 2. Processed fairly and lawfully 3. Accurate, relevant and kept up to date for processing personal information 4. Adequate and not excessive in relation to the purposes for which they are collected and processed 5. Retained only for as long as necessary 6. Kept in a form which permits identification of data subjects for no longer than is necessary
45
Section 12 is entitled?
Criteria for Lawful Processing of Personal Information
46
Lawful processing of information is permissible under what conditions?
1. Data subject has given consent 2. Personal information is necessary and is related to the fulfillment of a contract 3. For compliance with a legal obligation 4. To protect vitally important interests 5. To respond to national emergency, to comply with the requirements of public order and safety, or to fulfill functions of public authority 6. Legitimate interests pursued by the personal information controller or by a third party or parties to whom the data is disclosed
47
What section is entitled, "Sensitive Personal Information and Privileged Information"?
13
48
What is Section 14 and 15 entitled in RA 10173?
Sec 14 - Subcontract of Personal Information Sec 15 - Extension of Privileged Communication
49
According to Section 15, subject to existing laws and regulations, any evidence gathered on privileged information is inadmissible or admissible?
Inadmissible
50
What is the title of Section 16?
Rights of the Data Subject
51
The data subject should be furnished on what information before encoding their personal information into a processing system?
1. Description 2. Purpose 3. Scope and method 4. Recipients 5. Methods utilized for automated access 6. Identity and contact details of controller 7. Period of storage 8. Existence of their rights
52
The data subject also has reasonable access to?
1. Contents of own personal information 2. Sources from where it was obtained 3. Names and addresses or recipients 4. Manner by which it was processed 5. Reasons for disclosure 6. Information on automated processes 7. Date of access and modification 8. Designation, name, identity of controller
53
What is section 17 entitled?
Transmissibility of the Rights of the Data Subject
54
Who can the rights of the data subject be transmitted to?
Lawful heirs
55
What is section 18 entitled?
Right to Data Portability
56
How is data portable?
Electronic means in structured and commonly used format
57
What is section 19 entitled?
Non-applicability
58
What section is the Security of Personal Information?
20
59
In section 20, it states that the personal information controller must implement _____ and ______ ______,______ and _______ measures intended for the protection of personal information
reasonable and appropriate organizational, physical and technical
60
In section 20, it states that the personal information controller shall implement reasonable and appropriate measures to protect personal information against?
natural dangers
61
In section 20, the determination of the appropriate level of security under this section must take into account the _____ of the personal information to be protected, the ______ represented by the processing, the ____ of the organization and _____ of its operations, current data privacy best practices and the cost of security implementation.
nature risks size complexity
62
The _____________ of a personal information controller who are involved in the processing of personal information shall operate and hold personal information ________ if the personal information are not intended for public disclosure. This obligation shall continue even after leaving the public service, transfer to another position or upon termination of employment or contractual relations.
employees, agents or representatives under strict confidentiality
63
The personal information controller shall promptly notify the Commission and affected data subjects when?
information or other information are reasonably believed to have been acquired by an unauthorized person
64
Section 21 is entitled?
Principle of Accountability.
65
Each personal information controller is responsible for?
personal information under its control or custody, including information that have been transferred to a third party for processing, whether domestically or internationally, subject to cross-border arrangement and cooperation.
66
What section is Responsibility of Heads of Agencies?
22
67
All sensitive personal information maintained by the government, its agencies and instrumentalities shall be?
secured
68
Who shall be responsible for complying with the security requirements?
The head of each government agency or instrumentality
69
What is Section 23 entitled?
Requirements Relating to Access by Agency Personnel to Sensitive Personal Information.
70
No employee of the government shall have access to sensitive personal information on government property or through what type of facilities?
Online
71
What kind of access is violated by sensitive personal information is being transported or accessed from a location off government property?
Off-site access
72
In the deadline of approval or disapproval, In the case of any request submitted to the head of an agency, such head of the agency shall approve or disapprove the request within ______ after the date of submission of the request.
two (2) business days
73
When do you know if the request sent to the agency is disapproved?
If there is no action by the head of the agency
74
If a request is approved, the head of the agency shall limit the access to not more than _______ at a time.
one thousand (1,000) records
75
What is referred to as technology used to store, transport or access sensitive personal information for purposes of off-site access?
Encryption
76
What is the title of Section 24?
Applicability to Government Contractors
77
In entering into any contract that may involve accessing or requiring sensitive personal information from _______ individuals, an agency shall require a contractor and its employees to __________
one thousand (1,000) or more register their personal information processing system
78
What is Section 25 entitled?
Unauthorized Processing of Personal Information and Sensitive Personal Information
79
What is Section 26 entitled?
Accessing Personal Information and Sensitive Personal Information Due to Negligence.
80
What is Section 27 entitled?
Improper Disposal of Personal Information and Sensitive Personal Information.
81
What is Section 28 entitled?
Processing of Personal Information and Sensitive Personal Information for Unauthorized Purposes.
82
What is Section 29 entitled?
Unauthorized Access or Intentional Breach.
83
What is Section 30 entitled?
Concealment of Security Breaches Involving Sensitive Personal Information.
84
What is Section 31 entitled?
Malicious Disclosure
85
What is Section 32 entitled?
Unauthorized Disclosure
86
What is Section 33 entitled?
Combination or Series of Acts.
87
What is the penalty for Sec 25?
1 year to 3 years AND 500,000 to Php2,000,000 OR 3-6yrs AND 500,000 - 4,000,000
88
What is the penalty for Sec 26?
1 year to 3 years AND Php500,000 to Php2,000,000 OR 3-6yrs AND 500,000 - 4,000,000
89
What is the penalty for Sec 27?
6mos to 2yrs AND 100,000 to 500,000 OR 1yr-3yrs AND 100,000 to 1,000,000
90
What is the penalty for Sec 28?
1yr and 6mos - 5yrs AND 500,000 to 1,000,000 OR 2yrs-7yrs 500,000 to 2,000,000
91
What is the penalty for Sec 29?
1yr - 3yrs AND 500,000 to 2,000,000
92
What is the penalty for Sec 30?
1yr and 6mos to 5yrs AND 500,000 to 1,000,000
93
What is the penalty for Sec 31?
1yr and 6mos - 5yrs 500,000 - 1,000,000
94
What is the penalty for Sec 32?
1yr - 3yrs 500,000 - 1,000,000 OR 3yrs-5yrs 500,000-2,000,000
95
What is the penalty for Sec 33?
3yrs - 6yrs 1,000,000 - 5,000,000
96
What is section 34?
The extent of liability
97
What is contained in the extent of liability?
If the offender is a corporation, partnership or any juridical person If the offender is a juridical person If the offender is an alien If the offender is a public official or employee (Sections 27 and 28)
98
What section is entitled Large-scale?
35
99
How is the act considered large-scale?
at least one hundred (100) persons is harmed, affected or involved
100
What is section 36?
Offense Committed by Public Officer.
101
What is section 37?
Restitution
102
What section is entitled Interpretation?
38
103
What section is Implementing Rules and Regulations (IRR)?
39
104
When should the rules and regulations be implemented?
90 days from the effectivity of this Act
105
What is section 40?
Reports and Information.
106
Who shall receive reports of this act?
President and Congress
107
What is the appropriation clause?
Sec 41
108
The Commission shall be provided with an initial appropriation of?
20M drawn from the national government
109
The Commission shall likewise receive ____ per year for ____ years upon implementation of this Act drawn from the national government.
Ten million pesos (Php10,000,000.00) five (5)
110
What is Section 42 of this act?
Transitory Provision
111
Existing industries, businesses and offices affected by the implementation of this Act shall be given ______ transitory period from the effectivity of the IRR or such other period as may be determined by the Commission, to comply with the requirements of this Act.
one (1) year
112
In case that the DICT has not yet been created by the time the law takes full force and effect, the National Privacy Commission shall be attached to the?
the Office of the President.
113
What are the sections for the separability clause, repealing clause and effectivity clause?
Sep - 43 Rep - 44 Eff - 45
114
The provision of _________, otherwise known as the _________, is hereby amended.
Section 7 of Republic Act No. 9372 “Human Security Act of 2007”
115
Signatories of 10173?
President of the Senate : JUAN PONCE ENRILE Speaker of the House of Representatives: FELICIANO BELMONTE JR. Secretary of Senate: EMMA LIRIO-REYES Secretary General (House of Representatives): MARILYN B. BARUA-YAP (Sgd.) BENIGNO S. AQUINO III President of the Philippines
116