RA 10173 (Data Privacy Act of 2012) Flashcards

(119 cards)

1
Q

An Act Protecting Individual Personal Information In Information And Communications Systems In The Government And The Private Sector, Creating For This Purpose A National Privacy Commission, And For Other Purposes

A

Republic Act 10173
Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the Section 1 of RA 10173?

A

Title:
Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Section 2 of RA 10173?

A

Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Identify what Section:

This section protect the fundamental human right of privacy, of communication while ensuring free flow of information.

A

Section 2: Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Identify what Section:

This section provides vital role of information and communications technology in nation-building.

A

Section 2: Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Identify what section:

This sections ensure that personal information in information and communications systems in the government and in the private sector are secured and protected.

A

Section 2: Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the Section 3 of RA 10173?

A

Definition of Terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the Section 4 of RA 10173?

A

Scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Section 4: Scope

The RA 10173 does not apply to the following:

A
  1. Officer or employee of a government institution
  2. Individual performing service under contract for a government institution
  3. Discretionary benefit of a financial nature
  4. Personal information processed for jounalistic, artistic, literary researches
  5. Information necessary to carry out the functions of public authority
  6. Information necessary for banks and financial institutions
  7. Personal information from residents of foreign jurisdictions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Republic Act of 1405

A

Secretary of Bank Deposits Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Republic Act of 6426

A

Foreign Currency Deposit Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Republic Act of 9510

A

Credit Information System Act (CISA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the Section 5 of RA 10173?

A

Protection Afforded to Jounalists and their Sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Section 5: Protected Afforded to Jounalists and their Sources

Publishers, editors or duly accredited reporters of any newspaper, magazine, or periodical of general circulation protection from being compelled to reveal the source of any news report or information appearing in said publication which was related in any confidence to such publisher, editor, or reporter.

A

Republic Act No. 53

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the Section 6 of RA 10173?

A

Extraterritorial Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Identify what Section:

This section consists of personal information about a Philippine citizen or a resident.

A

Section 6: Extraterritorial Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Section 6: Extraterritorial Application

The entity has a link with the Philippines, and the entity is processing personal information in the Philippines or even if the processing is outside the Philippines as long as it is about Philippine citizens or residents. Who are these entities?

A
  1. A contract is entered in the Philippines
  2. A juridical entity has central management and control in the country
  3. An entity that has a branch, agency, office or subsidiary in the Philippines and the parent or affiliate of the Philippine
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Section 6: Extraterritorial Application

What are the entities that has other links in the Philippines as stated in Section 6?

A
  1. The entity carries on business in the Philippines
  2. The personal information was collected or held by an entity in the Philippines
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the Section 7 of RA 10173?

A

Functions of the National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Section 7: Functions of the National Privacy Commission

What are the functions of the National Privacy Commission?

A
  • Ensure compliance of personal information controllers
  • Receive complaints, institute investigations, facilitate or enable settlement of complaints, prepare reports on disposition of complaints and resolution of any investigation it initiates, and, in cases it deems appropriate, publicize any such report
  • Issue cease and desist orders, impose a temporary or permanent ban
  • Compel or petition any entity, government agency or instrumentality
  • Monitor the compliance of other government agencies or instrumentalities
  • Coordinate with other government agencies and the private sector
  • Publish on a regular basis a guide to all laws relating to data protection
  • Publish a compilation of agency system of records and notices, including index and other finding aids
  • Recommend to the Department of Justice (DOJ) the prosecution and imposition of penalties specified in Section 25 to 29 of this Act
  • Review, approve, reject or require modification of privacy codes voluntarily adhered to by personal information controllers
  • Provide assistance on matters relating to privacy or data protection
  • Comment on the implication on data privacy of proposed national or local statutes, regulations or procedures, issue advisory opinions and interpret the provisions
  • Propose legislation, amendments, or modifications to Philippine laws
  • Ensure proper and effective coordination with data privacy regulators in other countries and private accountability agents, participate in international and regional initiatives for data privacy protection
  • Negotiate and contract with other data privacy authorities of other countries for cross-border application and implementation of respective privacy laws
  • Assist Philippine companies doing business abroad to respond to foreign privacy or data protection laws and regulations
  • Generally perform such acts as may be necessary to facilitate cross-border enforcement of data privacy protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the Section 8 of RA 10173?

A

Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Identify what Section:

The Commission shall ensure at all times the confidentiality of any personal information that comes to its knowledge and possession.

A

Section 8: Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the Section 9 of RA 10173?

A

Organizational Structure of the Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Section 9: Organizational Structure of the Commission

What is the agency that is responsible for the organizational structure of the national privacy commission?

A

Department of Information and Communications Technology (DICT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
# Section 9: Organizational Structure of the Commission Who is the chairman of the Department of Information and Communications Technology (DICT)?
Privacy Comissioner
26
# Section 9: Organizational Structure of the Commission Who assists the Privacy Commissioner (head)?
Two Deputy Privacy Commissioners * Data Processing Systems * Policies and Planning
27
# Section 9: Organizational Structure of the Commission The privacy commissioner or the head is appointed by:
President of the Philippines
28
# Section 9: Organizational Structure of the Commission The privacy comissioner must be at least _ years of age.
35 years
29
# Section 9: Organizational Structure of the Commission The privacy comissioner must meet the following requirements:
* Good moral character * Unquestionable integrity and known probity * Recognized expert in the field of information technology and data privacy
30
# Section 9: Organizational Structure of the Commission The Privacy Commissioner shall enjoy the benefits, privileges, and emoluments equivalent to the rank of?
Secretary
31
# Section 9: Organizational Structure of the Commission Who is the Privacy Commissioner or the Chairman of the National Privacy Comission?
Raymund Enriquez Liboro
32
# Section 9: Organizational Structure of the Commission What are the functions of deputy privacy commissioners?
Recognized experts in the field of information and communications technology and data privacy.
33
# Section 9: Organizational Structure of the Commission The deputy privacy commissioners shall enjoy the benefits, privileges, and emoluments equivalent to the rank of?
Undersecretary
34
# Section 9: Organizational Structure of the Commission Who are the two deputy privacy commissioners in the National Privacy Commissioners?
1. Leandro Angelo Y. Aguirre 2. John Henry Du Naga
35
What is the Section 10 of RA 10173?
Secretariat
36
# Section 10: Secretariat Majority of the members of the Secretariat must have served for at least _ years.
5 years
37
# Section 10: Secretariat Majority of the members of the Secretariat must have served for at least five (5) years in any agency of the government that is involved in the processing of personal information, including:
o Social Security System (SSS) o Government Service Insurance System (GSIS) o Land Transportation Office (LTO) o Bureau of Internal Revenue (BIR) o Philippine Health Insurance Corporation (PhilHealth) o Commission on Elections (COMELEC) o Department of Foreign Affairs (DFA) o Department of Justice (DOJ) o Philippine Postal Corporation (PhilPost)
38
What is the Section 11 of RA 10173?
General Data Privacy Principles
39
# Section 11: General Data Privacy Principles What are the principles stated in Section 11?
● Collected for **specified and legitimate** purposes ● Processed **fairly and lawfully** ● **Accurate, relevant** and, where necessary for purposes for which it is to be used the processing of personal information, **kept up to date** ● **Adequate** and not excessive in relation to the purposes for which they are collected and processed. ● **Retained only for as long as necessary** for the fulfillment of the purposes for which the data was obtained or for the establishment, exercise, or defense of legal claims, or for legitimate business purposes, or as provided by law; and ● **Kept in a form** which permits identification of **data subjects** for no longer than is necessary for the purposes for which the data were collected and processed
40
What is the Section 12 of RA 10173?
Criteria for Lawful Processing of Personal Information
41
# Section 12: Criteria for Lawful Processing of Personal Information What are the following criterias in Section 12?
● The data subject has given his or her **consent.** ● **Personal information is necessary** and is related to the fulfillment of a contract ● For **compliance** with a **legal obligation** ● Necessary to **protect vitally important interests** ● To respond to **national emergency**, to comply with the requirements of **public order and safety,** or to fulfill functions of public authority ● For the **purposes of the legitimate interests** pursued by the personal information controller or by a third party or parties to whom the data is disclosed
42
What is the Section 13 of RA 10173?
Sensitive Personal Information and Privileged Information.
43
# True or False: As stated in Section 13, the **data subject** has given his or her **consent**, specific to the purpose prior to the processing, or in the case of privileged information, **all parties to the exchange** have given their consent prior to processing.
True
44
# Section 10: Sensitive Personal Information and Privileged Information What are the following sensitive personal information and privileged information guaranteed to protect stated in Section 13?
1. Protect the life and health 2. Achieve the lawful and noncommercial objectives 3. Medical treatment 4. Protections of lawful rights
45
What is the Section 14 of RA 10173?
Subcontract of Personal Information
46
# Identify what Section: A personal information controller may subcontract the processing of personal information.
Section 14: Subcontract of Personal Information
47
What is the Section 15 of RA 10173?
Extension of Privileged Communication
48
# Identify what Section: Personal information controllers may **invoke the principle of privileged communication** over privileged information that they lawfully control or process. Subject to existing laws and regulations, any evidence gathered on privileged information is **inadmissible.**
Section 15: Extension of Privileged Communication
49
What is the Section 16 of RA 10173?
Rights of the Data Subject
50
# Identify what Section: Be informed whether personal information pertaining to him or her shall be, are being or have been processed.
Section 16: Rights of the Data Subject
51
# Identify what Section: Be **furnished the information** indicated hereunder **before the entry** of his or her personal information into the processing system of the personal information controller, or at the next practical opportunity.
Section 16: Rights of the Data Subject
52
# Identify what Section: **Dispute the inaccuracy or error** in the personal information and have the personal information controller correct it immediately and accordingly unless the request is vexatious or otherwise unreasonable.
Section 16: Rights of the Data Subject
53
# Identify what Section: * **Suspend, withdraw, or order** the **blocking, removal, or destruction** of his or her personal information from the personal information **controller’s filing system** * Be **indemnified for any damages** sustained due to such inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal information
Section 16: Rights of the Data Subject
54
What is the Section 17 of RA 10173?
Transmissibility of Rights of the Data Subject
55
What is the Section 18 of RA 10173?
Right to Data Portability
56
What is the Section 19 of RA 10173?
Non-applicability
57
What is the Section 20 of RA 10173?
Security of Personal Information
58
# Identify what Section: The personal information controller must **implement** reasonable and appropriate organizational, physical and technical **measures** intended for the **protection of personal information.**
Section 20: Security of Personal Information
59
# Identify what Section: The personal information controller shall implement reasonable and appropriate measures to protect personal information **against natural dangers.**
Section 20: Security of Personal Information
60
# Identify what Section: Nature of the personal information to be protected, the risks represented by the processing, the size of the organization and complexity of its operations, current data privacy best practices and the cost of security implementation. * Safeguards to protect its computer network against accidental, unlawful or unauthorized usage or interference with or hindering of their functioning or availability. * A security policy with respect to the processing of personal information * A process for identifying and accessing reasonably foreseeable vulnerabilities in its computer networks, and for taking preventive, corrective and mitigating action against security incidents that can lead to a security breach * Regular monitoring for security breaches and a process for taking preventive, corrective and mitigating action against security incidents that can lead to a security breach.
Section 20: Security of Personal Information
61
# Identify what Section: The personal information controller must further ensure that third parties processing personal information on its behalf shall implement the security measures.
Section 20: Security of Personal Information
62
# Identify what Section: The employees, agents or representatives of a personal information controller who are involved in the processing of personal information shall operate and hold personal information under strict confidentiality if the personal information is not intended for public disclosure.
Section 20: Security of Personal Information
63
# Identify what Section: The personal information controller shall promptly notify the Commission and affected data subjects when sensitive personal information or other information that may, under the circumstances, be used to enable identity fraud are reasonably believed to have been acquired by an unauthorized person.
Section 20: Security of Personal Information
64
What is the Section 21 of RA 10173?
Principle of Accountability
65
# Identify what Section: **Each personal information controller is responsible for personal information under its control or custody**, including information that have been transferred to a third party for processing, whether domestically or internationally, subject to cross-border arrangement and cooperation. * Complying with the requirements * Designate an individual or individuals who are *accountable* for the organization’s compliance
Section 21: Principle of Accountability
66
What is the Section 22 of RA 10173?
Responsibility of Heads of Agencies
67
# Identify what Section: All sensitive personal information maintained by the government, its agencies and instrumentalities shall be **secured.**
Section 22: Responsibility of Heads of Agencies
68
# Identify what Section: The **head** of each government agency or instrumentality shall be **responsible for complying with the security requirements.**
Section 22: Responsibility of Heads of Agencies
69
What is the Section 23 of RA 10173?
Requirements Relating to Access by Agency Personnel to Sensitive Personal Information
70
# Section 23 **No employee of the government shall have access** to sensitive personal information on government property or through online facilities. This is defined by what kind of access?
On-site and Online Access
71
# Section 23 Sensitive personal information maintained by an agency may **not be transported or accessed from a location off government property** * **Deadline for Approval or Disapproval** * **Limitation to One thousand (1,000) Records** * **Encryption** This is defined by what access?
Off-site Access
72
What is the Section 24 of RA 10173?
Applicability to Government Contractor
73
# Section 24: Applicability to Government Contractor In entering into any contract that may involve accessing or requiring sensitive personal information from ____ or more individuals, an agency shall require a contractor and its employees to register their personal information processing system.
1000 of more individuals
74
What is the Section 25 of RA 10173?
**Unauthorized Processing** of Personal Information and Sensitive Personal Information **(without consent)**
75
# Section 25 Penalty for **unauthorized processing** of personal and sensitive information without consent shall be imprisoned and fined for?
**Imprisonment:** 1 year to 3 years **Fine:** Php 500,000 to Php 2,000,000
76
# Section 26: Penalty for accessing personal and sensitive information due to **negligence** shall be imprisoned and fined for?
**Imprisonment:** 3 years to 6 years **Fine:** Php 500,000 to Php 4,000,000
77
What is the Section 26 of RA 10173?
Accessing Personal Information and Sensitive Personal Information Due to **Negligence**
78
What is the Section 27 of RA 10173?
**Improper Disposal** of Personal Information and Sensitive Personal Information
79
# Section 27 Penalty for **improper disposal** of **personal information** shall be fined and imprisoned for?
**Imprisonment:** 6 months to 2 years **Fine:** Php 100,000 to Php 500,000
80
# Section 27 Penalty for improper disposal of sensitive information shall be fined and imprisoned for?
**Imprisonment:** 1 year to 3 years **Fine:** Php 100,000 to Php 1,000,000
81
What is the Section 28 of RA 10173?
Processing of Personal Information and Sensitive Personal Information for **Unathorized Purposes**
82
# Section 28 Penalty for **processing** of **personal information** for **unauthorized purposes** shall be fined and imprisoned for?
**Imprisonment:** 1 year and 6 months to 5 years **Fine:** Php 500,000 to Php 1,000,000
83
# Section 28 Penalty for **processing** of **sensitive information** for **unathorized purposes** shall be fined and imprisoned for?
**Imprisonment:** 2 years to 7 years **Fine:** Php 500,000 to Php 2,000,000
84
What is the Section 29 of RA 10173?
Unathorized Access or **Intentional Breach**
85
# Section 29 Penalty for **unauthorized access or intentional breach** shall be fined and imprisoned for?
**Imprisonment:** 1 year to 3 years **Fine:** Php 500,000 to Php 2,000,000
86
What is the Section 30 of RA 10173?
**Concealment of Security Breaches** Involving Sensitive Personal Information
87
# Section 30 Penalty for concealment of security breaches involving sensitive personal information shall be fined and imprisoned for?
**Imprisonment:** 1 year and 6 months to 5 years **Fine:** Php 500,000 to Php 1,000,000
88
What is the Section 31 of RA 10173?
Malicious Disclosure
89
# Section 31 Penalty for **malicious disclosure** shall be fined and imprisoned for?
**Imprisonment:** 1 year and 6 months to 5 years **Fine:** Php 500,000 to Php 1,000,000
90
What is the Section 32 of RA 10173?
Unauthorized Disclosure
91
# Section 32 Penalty for **unathorized disclosure** for **personal information** shall be fined and imprisoned for?
**Imprisonment:** 1 year to 3 years **Fine:** Php 500,000 to Php 1,000,000
92
# Section 32 Penalty for **unathorized disclosure** for **sensitive information** shall be fined and imprisoned for?
**Imprisonment:** 3 years to 5 years **Fine:** Php 500,000 to Php 2,000,000
93
What is the Section 33 of RA 10173?
Combination or Series of Acts
94
# Section 33 Penalty for violating the series of acts shall be fined and imprisoned for?
**Imprisonment:** 3 years to 6 years **Fine:** Php 1,000,000 to Php 5,000,000
95
What is the Section 34 of RA 10173?
Extent of Liability
96
# Section 34: Extent of Liability Who are the offenders of the extent of liability?
If the offenders are: * Corporation, partnership, or any juridicial person * Juridicial person * Alien * Public official or employee (Section 27&28)
97
What is the Section 35 of RA 10173?
Large-scale
98
What is the Section 36 of RA 10173?
Offense Committed by Public Officer
99
# Identify what Section: When the offender or the responsible for the offense is a **public officer** as defined in the Administrative Code of the Philippines in the exercise of his or her duties, an accessory penalty consisting in the **disqualification to occupy public office** for a term **double the term** of criminal penalty imposed shall he applied.
Section 36: Offense Committed by Public Officer
100
What is the Section 37 of RA 10173?
Restitution
101
# Identify what Section: Restitution for any aggrieved party shall be governed by the provisions of the **New Civil Code.**
Section 37: Restitution
102
What is the Section 38 of RA 10173?
Interpretation
103
What is the Section 39 of RA 10173?
Implementing Rules and Regulations (IRR)
104
# Section 39: Implementing Rules and Regulation (IRR) This Act shall take effect _ days.
90 days
105
What is the Section 40 of RA 10173?
Reports and Information
106
# Section 40: Reports and Information
1. Report to the President and Congress 2. Inform and educate the public
107
What is the Section 41 of RA 10173?
Appropriation Clause
108
# Section 40: Appropriations Clause Expenses for appropriations clause:
Php 20,000,000 Php 10,000,000 per year for 5 years
109
What is the Section 42 of RA 10173?
Transitory Provision
110
# Section 42: Transitory Provision _ year transitory period
1 year
111
What is the Section 43 of RA 10173?
Separability Clause
112
What is the Section 44 of RA 10173?
Repealing Clause
113
# Section 44: Repealing Clause Section 7 was repealed by what Republic Act?
**Republic Act No. 9372** *Human Security Act of 2007*
114
What is the Section 45 of RA 10173?
Effectivity Clause
115
Who was the Senate President during the approval of RA 10173?
Juan Ponce Enrile
116
Who was the Speaker of the House of Representatives during the approval of RA 10173?
Feliciano Belmonte, Jr.
117
Who was the Secretary of Senate during the approval of RA 10173?
Emma Lirio-Reyes
118
Who was the Secretar General (House of Representatives) during the approval of RA 10173?
Marilyn B. Barua-Yap
119
Who was the President of the Phillipines during the approval of RA 10173?
Benigno S. Aquino III