RA 10173 (Data Privacy Act of 2012) Flashcards

1
Q

An Act Protecting Individual Personal Information In Information And Communications Systems In The Government And The Private Sector, Creating For This Purpose A National Privacy Commission, And For Other Purposes

A

Republic Act 10173
Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the Section 1 of RA 10173?

A

Title:
Data Privacy Act of 2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Section 2 of RA 10173?

A

Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Identify what Section:

This section protect the fundamental human right of privacy, of communication while ensuring free flow of information.

A

Section 2: Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Identify what Section:

This section provides vital role of information and communications technology in nation-building.

A

Section 2: Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Identify what section:

This sections ensure that personal information in information and communications systems in the government and in the private sector are secured and protected.

A

Section 2: Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the Section 3 of RA 10173?

A

Definition of Terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the Section 4 of RA 10173?

A

Scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Section 4: Scope

The RA 10173 does not apply to the following:

A
  1. Officer or employee of a government institution
  2. Individual performing service under contract for a government institution
  3. Discretionary benefit of a financial nature
  4. Personal information processed for jounalistic, artistic, literary researches
  5. Information necessary to carry out the functions of public authority
  6. Information necessary for banks and financial institutions
  7. Personal information from residents of foreign jurisdictions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Republic Act of 1405

A

Secretary of Bank Deposits Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Republic Act of 6426

A

Foreign Currency Deposit Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Republic Act of 9510

A

Credit Information System Act (CISA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the Section 5 of RA 10173?

A

Protection Afforded to Jounalists and their Sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Section 5: Protected Afforded to Jounalists and their Sources

Publishers, editors or duly accredited reporters of any newspaper, magazine, or periodical of general circulation protection from being compelled to reveal the source of any news report or information appearing in said publication which was related in any confidence to such publisher, editor, or reporter.

A

Republic Act No. 53

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the Section 6 of RA 10173?

A

Extraterritorial Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Identify what Section:

This section consists of personal information about a Philippine citizen or a resident.

A

Section 6: Extraterritorial Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Section 6: Extraterritorial Application

The entity has a link with the Philippines, and the entity is processing personal information in the Philippines or even if the processing is outside the Philippines as long as it is about Philippine citizens or residents. Who are these entities?

A
  1. A contract is entered in the Philippines
  2. A juridical entity has central management and control in the country
  3. An entity that has a branch, agency, office or subsidiary in the Philippines and the parent or affiliate of the Philippine
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Section 6: Extraterritorial Application

What are the entities that has other links in the Philippines as stated in Section 6?

A
  1. The entity carries on business in the Philippines
  2. The personal information was collected or held by an entity in the Philippines
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the Section 7 of RA 10173?

A

Functions of the National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Section 7: Functions of the National Privacy Commission

What are the functions of the National Privacy Commission?

A
  • Ensure compliance of personal information controllers
  • Receive complaints, institute investigations, facilitate or enable settlement of complaints, prepare reports on disposition of complaints and resolution of any investigation it initiates, and, in cases it deems appropriate, publicize any such report
  • Issue cease and desist orders, impose a temporary or permanent ban
  • Compel or petition any entity, government agency or instrumentality
  • Monitor the compliance of other government agencies or instrumentalities
  • Coordinate with other government agencies and the private sector
  • Publish on a regular basis a guide to all laws relating to data protection
  • Publish a compilation of agency system of records and notices, including index and other finding aids
  • Recommend to the Department of Justice (DOJ) the prosecution and imposition of penalties specified in Section 25 to 29 of this Act
  • Review, approve, reject or require modification of privacy codes voluntarily adhered to by personal information controllers
  • Provide assistance on matters relating to privacy or data protection
  • Comment on the implication on data privacy of proposed national or local statutes, regulations or procedures, issue advisory opinions and interpret the provisions
  • Propose legislation, amendments, or modifications to Philippine laws
  • Ensure proper and effective coordination with data privacy regulators in other countries and private accountability agents, participate in international and regional initiatives for data privacy protection
  • Negotiate and contract with other data privacy authorities of other countries for cross-border application and implementation of respective privacy laws
  • Assist Philippine companies doing business abroad to respond to foreign privacy or data protection laws and regulations
  • Generally perform such acts as may be necessary to facilitate cross-border enforcement of data privacy protection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the Section 8 of RA 10173?

A

Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Identify what Section:

The Commission shall ensure at all times the confidentiality of any personal information that comes to its knowledge and possession.

A

Section 8: Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the Section 9 of RA 10173?

A

Organizational Structure of the Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Section 9: Organizational Structure of the Commission

What is the agency that is responsible for the organizational structure of the national privacy commission?

A

Department of Information and Communications Technology (DICT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Section 9: Organizational Structure of the Commission

Who is the chairman of the Department of Information and Communications Technology (DICT)?

A

Privacy Comissioner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Section 9: Organizational Structure of the Commission

Who assists the Privacy Commissioner (head)?

A

Two Deputy Privacy Commissioners

  • Data Processing Systems
  • Policies and Planning
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Section 9: Organizational Structure of the Commission

The privacy commissioner or the head is appointed by:

A

President of the Philippines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Section 9: Organizational Structure of the Commission

The privacy comissioner must be at least _ years of age.

A

35 years

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Section 9: Organizational Structure of the Commission

The privacy comissioner must meet the following requirements:

A
  • Good moral character
  • Unquestionable integrity and known probity
  • Recognized expert in the field of information technology and data privacy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Section 9: Organizational Structure of the Commission

The Privacy Commissioner shall enjoy the benefits, privileges, and emoluments equivalent to the rank of?

A

Secretary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Section 9: Organizational Structure of the Commission

Who is the Privacy Commissioner or the Chairman of the National Privacy Comission?

A

Raymund Enriquez Liboro

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Section 9: Organizational Structure of the Commission

What are the functions of deputy privacy commissioners?

A

Recognized experts in the field of information and communications technology and data privacy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Section 9: Organizational Structure of the Commission

The deputy privacy commissioners shall enjoy the benefits, privileges, and emoluments equivalent to the rank of?

A

Undersecretary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Section 9: Organizational Structure of the Commission

Who are the two deputy privacy commissioners in the National Privacy Commissioners?

A
  1. Leandro Angelo Y. Aguirre
  2. John Henry Du Naga
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What is the Section 10 of RA 10173?

A

Secretariat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Section 10: Secretariat

Majority of the members of the Secretariat must have served for at least _ years.

A

5 years

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Section 10: Secretariat

Majority of the members of the Secretariat must have served for at least five (5) years in any agency of the government that is involved in the processing of personal information, including:

A

o Social Security System (SSS)
o Government Service Insurance System (GSIS)
o Land Transportation Office (LTO)
o Bureau of Internal Revenue (BIR)
o Philippine Health Insurance Corporation (PhilHealth)
o Commission on Elections (COMELEC)
o Department of Foreign Affairs (DFA)
o Department of Justice (DOJ)
o Philippine Postal Corporation (PhilPost)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What is the Section 11 of RA 10173?

A

General Data Privacy Principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Section 11: General Data Privacy Principles

What are the principles stated in Section 11?

A

● Collected for specified and legitimate purposes
● Processed fairly and lawfully
Accurate, relevant and, where necessary for purposes for which it is to be used the processing of personal information, kept up to date
Adequate and not excessive in relation to the purposes for which they are collected and processed.
Retained only for as long as necessary for the fulfillment of the purposes for which the data was obtained or for the establishment, exercise, or defense of legal claims, or for legitimate business purposes, or as provided by law; and
Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected and processed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What is the Section 12 of RA 10173?

A

Criteria for Lawful Processing of Personal Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Section 12: Criteria for Lawful Processing of Personal Information

What are the following criterias in Section 12?

A

● The data subject has given his or her consent.
Personal information is necessary and is related to the fulfillment of a contract
● For compliance with a legal obligation
● Necessary to protect vitally important interests
● To respond to national emergency, to comply with the requirements of public order and safety, or to fulfill functions of public authority
● For the purposes of the legitimate interests pursued by the personal information controller or by a third party or parties to whom the data is disclosed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What is the Section 13 of RA 10173?

A

Sensitive Personal Information and Privileged Information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

True or False:

As stated in Section 13, the data subject has given his or her consent, specific to the purpose prior to the processing, or in the case of privileged information, all parties to the exchange have given their consent prior to processing.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Section 10: Sensitive Personal Information and Privileged Information

What are the following sensitive personal information and privileged information guaranteed to protect stated in Section 13?

A
  1. Protect the life and health
  2. Achieve the lawful and noncommercial objectives
  3. Medical treatment
  4. Protections of lawful rights
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

What is the Section 14 of RA 10173?

A

Subcontract of Personal Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Identify what Section:

A personal information controller may subcontract the processing of personal information.

A

Section 14: Subcontract of Personal Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

What is the Section 15 of RA 10173?

A

Extension of Privileged Communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

Identify what Section:

Personal information controllers may invoke the principle of privileged communication over privileged information that they lawfully control or process. Subject to existing laws and regulations, any evidence gathered on privileged information is inadmissible.

A

Section 15: Extension of Privileged Communication

49
Q

What is the Section 16 of RA 10173?

A

Rights of the Data Subject

50
Q

Identify what Section:

Be informed whether personal information pertaining to him or her shall be, are being or have been processed.

A

Section 16: Rights of the Data Subject

51
Q

Identify what Section:

Be furnished the information indicated hereunder before the entry of his or her personal information into the processing system of the personal information controller, or at the next practical opportunity.

A

Section 16: Rights of the Data Subject

52
Q

Identify what Section:

Dispute the inaccuracy or error in the personal information and have the personal information controller correct it immediately and accordingly unless the request is vexatious or otherwise unreasonable.

A

Section 16: Rights of the Data Subject

53
Q

Identify what Section:

  • Suspend, withdraw, or order the blocking, removal, or destruction of his or her personal information from the personal information controller’s filing system
  • Be indemnified for any damages sustained due to such inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal information
A

Section 16: Rights of the Data Subject

54
Q

What is the Section 17 of RA 10173?

A

Transmissibility of Rights of the Data Subject

55
Q

What is the Section 18 of RA 10173?

A

Right to Data Portability

56
Q

What is the Section 19 of RA 10173?

A

Non-applicability

57
Q

What is the Section 20 of RA 10173?

A

Security of Personal Information

58
Q

Identify what Section:

The personal information controller must implement reasonable and appropriate organizational, physical and technical measures intended for the protection of personal information.

A

Section 20: Security of Personal Information

59
Q

Identify what Section:

The personal information controller shall implement reasonable and appropriate measures to protect personal information against natural dangers.

A

Section 20: Security of Personal Information

60
Q

Identify what Section:

Nature of the personal information to be protected, the risks represented by the processing, the size of the organization and complexity of its operations, current data privacy best practices and the cost of security implementation.

  • Safeguards to protect its computer network against accidental, unlawful or unauthorized usage or interference with or hindering of their functioning or availability.
  • A security policy with respect to the processing of personal information
  • A process for identifying and accessing reasonably foreseeable vulnerabilities in its computer networks, and for taking preventive, corrective and mitigating action against security incidents that can lead to a security breach
  • Regular monitoring for security breaches and a process for taking preventive, corrective and mitigating action against security incidents that can lead to a security breach.
A

Section 20: Security of Personal Information

61
Q

Identify what Section:

The personal information controller must further ensure that third parties processing personal information on its behalf shall implement the security measures.

A

Section 20: Security of Personal Information

62
Q

Identify what Section:

The employees, agents or representatives of a personal information controller who are involved in the processing of personal information shall operate and hold personal information under strict confidentiality if the personal information is not intended for public disclosure.

A

Section 20: Security of Personal Information

63
Q

Identify what Section:

The personal information controller shall promptly notify the Commission and affected data subjects when sensitive personal information or other information that may, under the circumstances, be used to enable identity fraud are reasonably believed to have been acquired by an unauthorized person.

A

Section 20: Security of Personal Information

64
Q

What is the Section 21 of RA 10173?

A

Principle of Accountability

65
Q

Identify what Section:

Each personal information controller is responsible for personal information under its control or custody, including information that have been transferred to a third party for processing, whether domestically or internationally, subject to cross-border arrangement and cooperation.

  • Complying with the requirements
  • Designate an individual or individuals who are accountable for the organization’s compliance
A

Section 21: Principle of Accountability

66
Q

What is the Section 22 of RA 10173?

A

Responsibility of Heads of Agencies

67
Q

Identify what Section:

All sensitive personal information maintained by the government, its agencies and instrumentalities shall be secured.

A

Section 22: Responsibility of Heads of Agencies

68
Q

Identify what Section:

The head of each government agency or instrumentality shall be responsible for complying with the security requirements.

A

Section 22: Responsibility of Heads of Agencies

69
Q

What is the Section 23 of RA 10173?

A

Requirements Relating to Access by Agency Personnel to Sensitive Personal Information

70
Q

Section 23

No employee of the government shall have access to sensitive personal information on government property or through online facilities. This is defined by what kind of access?

A

On-site and Online Access

71
Q

Section 23

Sensitive personal information maintained by an agency may not be transported or accessed from a location off government property

  • Deadline for Approval or Disapproval
  • Limitation to One thousand (1,000) Records
  • Encryption

This is defined by what access?

A

Off-site Access

72
Q

What is the Section 24 of RA 10173?

A

Applicability to Government Contractor

73
Q

Section 24: Applicability to Government Contractor

In entering into any contract that may involve accessing or requiring sensitive personal information from ____ or more individuals, an agency shall require a contractor and its employees to register their personal information processing system.

A

1000 of more individuals

74
Q

What is the Section 25 of RA 10173?

A

Unauthorized Processing of Personal Information and Sensitive Personal Information (without consent)

75
Q

Section 25

Penalty for unauthorized processing of personal and sensitive information without consent shall be imprisoned and fined for?

A

Imprisonment:
1 year to 3 years

Fine:
Php 500,000 to Php 2,000,000

76
Q

Section 26:

Penalty for accessing personal and sensitive information due to negligence shall be imprisoned and fined for?

A

Imprisonment:
3 years to 6 years

Fine:
Php 500,000 to Php 4,000,000

77
Q

What is the Section 26 of RA 10173?

A

Accessing Personal Information and Sensitive Personal Information Due to Negligence

78
Q

What is the Section 27 of RA 10173?

A

Improper Disposal of Personal Information and Sensitive Personal Information

79
Q

Section 27

Penalty for improper disposal of personal information shall be fined and imprisoned for?

A

Imprisonment:
6 months to 2 years

Fine:
Php 100,000 to Php 500,000

80
Q

Section 27

Penalty for improper disposal of sensitive information shall be fined and imprisoned for?

A

Imprisonment:
1 year to 3 years

Fine:
Php 100,000 to Php 1,000,000

81
Q

What is the Section 28 of RA 10173?

A

Processing of Personal Information and Sensitive Personal Information for Unathorized Purposes

82
Q

Section 28

Penalty for processing of personal information for unauthorized purposes shall be fined and imprisoned for?

A

Imprisonment:
1 year and 6 months to 5 years

Fine:
Php 500,000 to Php 1,000,000

83
Q

Section 28

Penalty for processing of sensitive information for unathorized purposes shall be fined and imprisoned for?

A

Imprisonment:
2 years to 7 years

Fine:
Php 500,000 to Php 2,000,000

84
Q

What is the Section 29 of RA 10173?

A

Unathorized Access or Intentional Breach

85
Q

Section 29

Penalty for unauthorized access or intentional breach shall be fined and imprisoned for?

A

Imprisonment:
1 year to 3 years

Fine:
Php 500,000 to Php 2,000,000

86
Q

What is the Section 30 of RA 10173?

A

Concealment of Security Breaches Involving Sensitive Personal Information

87
Q

Section 30

Penalty for concealment of security breaches involving sensitive personal information shall be fined and imprisoned for?

A

Imprisonment:
1 year and 6 months to 5 years

Fine:
Php 500,000 to Php 1,000,000

88
Q

What is the Section 31 of RA 10173?

A

Malicious Disclosure

89
Q

Section 31

Penalty for malicious disclosure shall be fined and imprisoned for?

A

Imprisonment:
1 year and 6 months to 5 years

Fine:
Php 500,000 to Php 1,000,000

90
Q

What is the Section 32 of RA 10173?

A

Unauthorized Disclosure

91
Q

Section 32

Penalty for unathorized disclosure for personal information shall be fined and imprisoned for?

A

Imprisonment:
1 year to 3 years

Fine:
Php 500,000 to Php 1,000,000

92
Q

Section 32

Penalty for unathorized disclosure for sensitive information shall be fined and imprisoned for?

A

Imprisonment:
3 years to 5 years

Fine:
Php 500,000 to Php 2,000,000

93
Q

What is the Section 33 of RA 10173?

A

Combination or Series of Acts

94
Q

Section 33

Penalty for violating the series of acts shall be fined and imprisoned for?

A

Imprisonment:
3 years to 6 years

Fine:
Php 1,000,000 to Php 5,000,000

95
Q

What is the Section 34 of RA 10173?

A

Extent of Liability

96
Q

Section 34: Extent of Liability

Who are the offenders of the extent of liability?

A

If the offenders are:

  • Corporation, partnership, or any juridicial person
  • Juridicial person
  • Alien
  • Public official or employee (Section 27&28)
97
Q

What is the Section 35 of RA 10173?

A

Large-scale

98
Q

What is the Section 36 of RA 10173?

A

Offense Committed by Public Officer

99
Q

Identify what Section:

When the offender or the responsible for the offense is a public officer as defined in the Administrative Code of the Philippines in the exercise of his or her duties, an accessory penalty consisting in the disqualification to occupy public office for a term double the term of criminal penalty imposed shall he applied.

A

Section 36: Offense Committed by Public Officer

100
Q

What is the Section 37 of RA 10173?

A

Restitution

101
Q

Identify what Section:

Restitution for any aggrieved party shall be governed by the provisions of the New Civil Code.

A

Section 37: Restitution

102
Q

What is the Section 38 of RA 10173?

A

Interpretation

103
Q

What is the Section 39 of RA 10173?

A

Implementing Rules and Regulations (IRR)

104
Q

Section 39: Implementing Rules and Regulation (IRR)

This Act shall take effect _ days.

A

90 days

105
Q

What is the Section 40 of RA 10173?

A

Reports and Information

106
Q

Section 40: Reports and Information

A
  1. Report to the President and Congress
  2. Inform and educate the public
107
Q

What is the Section 41 of RA 10173?

A

Appropriation Clause

108
Q

Section 40: Appropriations Clause

Expenses for appropriations clause:

A

Php 20,000,000 Php 10,000,000 per year for 5 years

109
Q

What is the Section 42 of RA 10173?

A

Transitory Provision

110
Q

Section 42: Transitory Provision

_ year transitory period

A

1 year

111
Q

What is the Section 43 of RA 10173?

A

Separability Clause

112
Q

What is the Section 44 of RA 10173?

A

Repealing Clause

113
Q

Section 44: Repealing Clause

Section 7 was repealed by what Republic Act?

A

Republic Act No. 9372
Human Security Act of 2007

114
Q

What is the Section 45 of RA 10173?

A

Effectivity Clause

115
Q

Who was the Senate President during the approval of RA 10173?

A

Juan Ponce Enrile

116
Q

Who was the Speaker of the House of Representatives during the approval of RA 10173?

A

Feliciano Belmonte, Jr.

117
Q

Who was the Secretary of Senate during the approval of RA 10173?

A

Emma Lirio-Reyes

118
Q

Who was the Secretar General (House of Representatives) during the approval of RA 10173?

A

Marilyn B. Barua-Yap

119
Q

Who was the President of the Phillipines during the approval of RA 10173?

A

Benigno S. Aquino III