Republic Act 10173 Flashcards

(160 cards)

1
Q

Republic Act 10173

A

Data Privacy Act of
2012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Section 1

A

Short Title

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CHAPTER I

A

GENERAL PROVISIONS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Section 2

A

Declaration of Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Declaration of Policy

Protect the fundamental human right of ________, of communication
while ensuring free flow of information

A

privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Declaration of Policy

Vital role of information and communications technology in ___________

A

nationbuilding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Declaration of Policy

To ensure that personal information and communications systems in the government and in the private
sector are _______ and _______

A

protected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Section 3

A

Definition of terms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

National Privacy Commission created
by virtue of this Act

A

Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

An individual whose personal
information is processed

A

Data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Any information whether recorded in
a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information

A

Personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A person or organization who controls the collection, holding, processing or use of personal information. Including a person or organization who instructs another person or organization to collect, hold, process, use, transfer or disclose personal information on his or her behalf

A

Personal information controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Any operation or any set of
operations performed upon personal
information including, but not limited
to, the collection, recording,
organization, storage, updating or
modification, retrieval, consultation,
use, consolidation, blocking, erasure
or destruction of data

A

Processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Section 4

A

Scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This Act does not apply to the following:

A
  1. Info about government officer/empolyees
  2. Info about individual who perform service with government
  3. Info reltng to discretionary benefit of finacial nature
  4. Personal info processed for journal, artisitc, literary, researrch purpose
  5. Info necessary to carry out public authority functions
  6. Info necessary for banks/finacial institutions
  7. Personal info from residents of foreign jurisdiction
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Section 5

A

Protection Afforded to Journalists and Their Sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Republic Act No. 53

A

Journalist are not compelled to reveal the source of any news

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Section 6

A

Extraterritorial Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

This act also apply even if you are out of the coutry as long as:

A
  • related sa personal info ng philippine citizen
  • a contract is entered in the philippines
  • basta related sa philippines
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CHAPTER II

A

THE NATIONAL PRIVACY COMMISSION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Section 7

A

Functions of the National Privacy Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Functions of the National Privacy Commission

Ensure compliance of

A

personal information controllers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Functions of the National Privacy Commission

Receive complaints, institute investigations, facilitate
or enable settlement of complaints, prepare ______ on disposition of complaints and resolution of any investigation it initiates, and, in cases it deems appropriate, publicize any such report

A

reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Functions of the National Privacy Commission

Issue ___________, impose a temporary or permanent ban

A

cease and desist orders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
# Functions of the National Privacy Commission ____________ or _______ any entity, government agency or instrumentality
Compel or petition
20
# Functions of the National Privacy Commission Monitor the _______ of other government agencies or instrumentalities
compliance
21
# Functions of the National Privacy Commission __________ with other government agencies and the private sector
Coordinate
21
# Functions of the National Privacy Commission Publish on a regular basis a _____ to all laws relating to data protection
guide
22
# Functions of the National Privacy Commission Publish a compilation of _______ of records and notices, including index and other finding aids
agency system
22
# Functions of the National Privacy Commission Recommend to the ______ the prosecution and imposition of penalties
Department of Justice (DOJ)
23
# Functions of the National Privacy Commission Review, approve, reject or require modification of __________ voluntarily adhered to by personal information controllers
privacy codes
23
# Functions of the National Privacy Commission that the privacy codes shall adhere to the underlying _____________
data privacy principles
24
That such privacy codes may include private dispute resolution mechanisms for _______ against any participating personal information controller
complaints
25
# Functions of the National Privacy Commission For this purpose, the Commission shall consult with relevant _________ in the formulation and administration of privacy codes applying the standards in this Act
regulatory agencies
26
# Functions of the National Privacy Commission Provide ______ on matters relating to privacy or data protection
assistance
27
# Functions of the National Privacy Commission ______ on the implication on data privacy of proposed national or local statutes, regulations or procedures, issue advisory opinions and interpret the provisions
Comment
28
# Functions of the National Privacy Commission ______ legislation, amendments or modifications to Philippine laws
Propose
29
# Functions of the National Privacy Commission Ensure proper and effective coordination with _______ in other countries and private accountability agents, participate in international and regional initiatives for data privacy protection
data privacy regulators
30
# Functions of the National Privacy Commission Negotiate and contract with other data privacy authorities of other countries for ________ and implementation of respective privacy laws
cross-border application
31
# Functions of the National Privacy Commission Assist ___________ doing business abroad to respond to foreign privacy or data protection laws and regulations
Philippine companies
32
# Functions of the National Privacy Commission Generally perform such acts as may be necessary to facilitate ______________ of data privacy protection
cross-border enforcement
33
Section 8
Confidentiality
34
Section 9
Organizational structure of the commission
35
Organizational structure of the commission
- Privacy Commissioner - Deputy Privacy Commisioners (2)
36
The Commission shall be attached to the
Department of Information and Communications Technology (DICT)
37
Chairman of the Commission
Privacy Commissione
38
in cahrge of the Data Processing Systems, Policies and Planning. appointed by the President of the Philippine
Deputy Privacy Commissioners
39
How many terms does the The Privacy Commissioner and the two (2) Deputy Privacy Commissioners have?
3 years | may be reaapointed for another 3
40
the privacy commisioner mus be atleast ___ yrs old
35
41
good moral character, unquestionable integrity and known probity, and a recognized expert in the field of information technology and data privacy
Privacy Commissioner
42
The Privacy Commissioner shall enjoy the benefits, privileges and emoluments equivalent to the rank of _________
Secretary
43
Who is the Privacy Commisioner and chairman
Raymund Enriquez Liboro
44
must be recognized experts in the field of information and communications technology and data privacy
Deputy Privacy Commissioners
45
Deputy Privacy Commissioners shall enjoy the benefits, privileges and emoluments equivalent to the rank of _______
Undersecretary
46
Who are the Deputy Privacy commisioners
Leandro Angelo Y. Aguirre, John Henry Du Naga
47
Section 10
The Secretariat
48
Majority of the members of the Secretariat must have served for at least ______ in any agency of the government that is involved in the processing of personal information
five (5) years
49
Majority of the members of the Secretariat must have served for at least five (5) years in any agency of the government that is involved in the processing of personal information including, but not limited to, the following offices:
- Social Security System (SSS) - Government Service Insurance System (GSIS) - Land Transportation Office (LTO) - Bureau of Internal Revenue (BIR) - Philippine Health Insurance Corporation (PhilHealth) - Commission on Elections (COMELEC) - Department of Foreign Affairs (DFA) - Department of Justice (DOJ) - Philippine Postal Corporation (Philpost)
50
CHAPTER III
PROCESSING OF PERSONAL INFORMATION
51
Section 11
General Data Privacy Principles
52
Kept in a form which permits identification of ________ for no longer than is necessary for the purposes for which the data were collected and processed
data subjects
53
Section 12
Criteria for Lawful Processing of Personal Information
54
Section 13
Sensitive Personal Information and Privileged Information
55
The processing of sensitive personal information and privileged information shall be prohibited except if the The data subject has given his or her consent, specific to the purpose _____________
prior to the processing
56
It is okay to proccess sensitive data without consent as long as protection of the info is guranteed?
yes of course
57
The proccesing is necessary to protect the life and health of the data subject or another person, and data sibject cannot consent, are you allowed to process it?
yups
58
# It is okay to process sentisitve info as long as The processing is necessary to achieve the lawful and noncommercial objectives of public organizations and their associations provided that:
- info is confined only to bonafide members of the org - info is not transfered to other parties - there is a consent from the data subject
59
If the processing is necessary for purposes of medical treatment, are you allowed to process sensitive info?
why not?
60
The processing concerns such personal information as is necessary for the protection of lawful rights and interests of natural or legal persons in court proceedings, or the establishment, exercise or defense of legal claims, or when provided to government or public authority. Is it oay to process sensitive info?
yups
61
Section 14
Subcontract of Personal Information
62
A personal information controller may ________ the processing of personal information
subcontract
63
Section 15
Extension of Privileged Communication
64
____________ may invoke the principle of privileged communication over privileged information that they lawfully control or process.
Personal information controllers
65
Subject to existing laws and regulations, any evidence gathered on privileged information is ___________
inadmissible
66
CHAPTER IV
RIGHTS OF THE DATA SUBJECT
67
Section 16
Rights of the Data Subject
68
What are the info need to be furnishe d to the data subject before processing their data:
1. Descroption of personal data 2. Purpose of the processing 3. Scope and method of processing 4. Receipients 5. Methods for automated access 6. Personal information controller Identity and contanct details 7. Period on information stored 8. Rights to access, correction, complaint
69
Data subjects should have reasonable access to, upon demand:
1. contents of personal info 2. sources of personal info 3. Recipients name and address 4. Manner of proccesing of data 5. reason for disclosure of personal info 6. Info on automated processes 7. Date of personal info last accesed 8. Personal information controller designation, name, identity
70
If the personal information have been corrected, the personal information controller shall ensure the accessibility of both the new and the retracted information and the ____________ of the new and the retracted information by recipients
simultaneous receipt
71
If there is a innacuracy or error in the personal info of and it is corrected who should be aso informed about the inacuracy and rectification?
Third parties
72
the data subject can Suspend, withdraw or order the blocking, removal or destruction of his or her personal information from the personal information controller’s _______ upon discovery and substantial proof that the personal information are incomplete, outdated, false, unlawfully obtained, used for unauthorized purposes or are no longer necessary for the purposes for which they were collected.
filing system
73
the data subject should be ______ for any damages sustained due to such inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of personal information
indemnified
74
Section 17
Transmissibility of Rights of the Data Subject. lawful heirs
75
Section 18.
. Right to Data Portability.
76
The data subject shall have the right, where personal information is processed by ______ means and in a structured and commonly used format
electronic
77
Section 19
Non-Applicability
78
The immediately preceding sections are not applicable if the processed personal information are used only for the needs of ____________ and, on the basis of such, no activities are carried out and no decisions are taken regarding the data subject
scientific and statistical research
79
CHAPTER V
SECURITY OF PERSONAL INFORMATION
80
Section 20
Security of Personal Information
81
Who is responsible for the security of personal info
Personal information controller
82
The personal information controller shall promptly notify heth __________affected subjectwhen sensitive personal information or other information that ay, under the circumstances, be used to enable identity fraud are reasonably believed to have been cquired by an unauthorized person
Commission
83
In evaluating if notification is ________, the Commission may take into account compliance by the personal information controller with this section and existence of good faith in the acquisition of personal information
unwarranted
84
The Commission may exempt a personal information controller from notification where, in its reasonable judgment, such notification would __________ or _________
not be in the public interest or in the interests of the affected data subjects
85
The Commission may authorize postponement of notification where it may hinder the progress of a _____________ related to a serious breach.
criminal investigation
86
CHAPTER VI
ACCOUNTABILITY FOR TRANSFER OF PERSONAL INFORMATION
87
Section 21
Principle of Accountability
88
The personal information controller is accountable for complying with the requirements of this Act and shall use _______ or other reasonable means to provide a comparable level of protection while the information are being processed by a third party.
contractual
89
The personal information controller shall designate an __________ who are accountable for the organization’s compliance with this Act.
individual or individuals
90
CHAPTER VII
SECURITY OF SENSITIVE PERSONAL INFORMATION IN GOVERNMENT
91
SECTION 22
Responsibility of Heads of Agencies
92
Who shall be responsible for complying with the security requirements in the ogvernment?
head of each government agency or instrumentality
93
Section 23
Requirements Relating to Access by Agency Personnel to Sensitive Personal Information
94
No ________ shall have access to sensitive personal information on government property or through online facilities
employee of the government
95
sensitive personal information maintained by an agency may not be transported or accessed from a __________
location off government property
96
# access of sensitive info putside gov property request in the case of any request submitted to the head of an agency, such head of the agency shall approve or disapprove the request within _________ after the date of submission of the request.
two (2) business days
97
How many is the limitation of records acces outside gov failities
1000
98
Any technology used to store, transport or access sensitive personal information for purposes of off-site access approved under this subsection shall be secured by the use of the most secure _______ standard recognized by the Commission
encryption
99
Section 24
Applicability to Government Contractors
100
In entering into any contract that may involve accessing or requiring sensitive personal information from one thousand (1,000) or more individuals, an agency shall require a contractor and its employees to register their ________
personal information processing system
101
CHAPTER VIII
PENALTIES
102
Section 25
Unauthorized Processing of Personal Information and Sensitive Personal Information
103
Section 26
Accessing Personal Information and Sensitive Personal Information Due to Negligence.
104
Section 27
Improper Disposal of Personal Information and Sensitive Personal Information.
105
Section 28
Processing of Personal Information and Sensitive Personal Information for Unauthorized Purposes.
106
Section 29
Unauthorized Access or Intentional Breach.
107
Section 30
Concealment of Security Breaches Involving Sensitive Personal Information
108
Section 31
Malicious Disclosure
109
Section 32
Unauthorized Disclosure.
110
Section 33
Combination or Series of Acts.
111
Unauthorized Processing of Personal Information and Sensitive Personal Information
Imprisonment: 1-3 yrs Fine: 500k -2M
112
Accessing Personal Information and Sensitive Personal Information Due to Negligence.
Imprisonment: 3-6 yrs Fine: 500k - 4M
113
Improper Disposal of Personal Information and Sensitive Personal Information.
Personal Imprisonment: 6 mon - 2 yrs Fine: 100k-500k Sentisitve Imprisonment: 1-2 yrs Fine: 100k -1M
114
Processing of Personal Information and Sensitive Personal Information for Unauthorized Purposes.
Personal Imprisonment: 1 yr and 6 mon - 5 yrs Fine: 500k - 1M Sentisitve Imprisonment: 2-7 yrs Fine: 500k - 2M
115
Unauthorized Access or Intentional Breach.
Imprisonment: 1 -3 yrs Fine: 500k - 2M
116
Concealment of Security Breaches Involving Sensitive Personal Information.
Imprisonment: 1 yr and 6 mons - 5 yrs Fine: 500k -1M
117
Malicious Disclosure
Imprisonment: 1 yr and 6 mons - 5 yrs Fine: 500k -1M
118
Unauthorized Disclosure.
Personal Imprisonment: 1 yr - 3 yrs Fine: 500k - 1M Sentisitve Imprisonment: 3-5 yrs Fine: 500k - 2M
119
Combination or Series of Acts
Imprisonment: 3 - 6 yrs Fine: 1-5 M
120
Section 34
Extent of Liability
121
If the offender is a corporation, partnership or any juridical person, the penalty shall be imposed upon the _________, as the case may be, who participated in, or by their gross negligence, allowed the commission of the crime.
responsible officers
122
If the offender is a juridical person, the court may
suspend or revoke any of its rights under this Act.
123
If the offender is an alien, he or she shall, in addition to the penalties herein prescribed, be _________ without further proceedings after serving the penalties prescribed.
deported
124
If the offender is a public official or employee and lie or she is found guilty of acts penalized under Sections 27 and 28 of this Act, he or she shall, in addition to the penalties prescribed herein, suffer perpetual or temporary absolute __________, as the case may be.
disqualification from office
125
Section 35
Large-Scale.
126
The maximum penalty in the scale of penalties respectively provided for the preceding offenses shall be imposed when the personal information of at least __________is harmed, affected or involved as the result of the above mentioned actions.
one hundred (100) persons
127
Section 36
Offense Committed by Public Officer
128
When the offender or the person responsible for theoffense is a public officer as defined in the Administrative Code of the Philippines in the exercise of his or her duties, an accessory penalty consisting in the disqualification to occupy public office for a ___________ imposed shall be applied.
term double the term of criminal penalty
129
SECTION 37
Restitution
130
CHAPTER IX
MISCELLANEOUS PROVISIONS
131
Section 38
Interpretation
132
SECTION 39
Implementing Rules and Regulations (IRR)
133
Within __________ from the effectivity of this Act, the Commission shall promulgate the rules and regulations to effectively implement the provisions of this Act
ninety (90) days
134
SECTION 40
Reports and Information
135
The Commission shall _________ report to the _________ and _________ on its activities in carrying out the provisions of this Act
- annually - President and Congress
136
SECTION 41
Appropriations Clause
137
The Commission shall be provided with an initial appropriation of ______ to be drawn from the national government.
Twenty million pesos (Php20,000,000.00)
138
Appropriations for the succeeding years shall be included in the _____________.
General Appropriations Act
139
It shall likewise receive___________ per year for ________ upon implementation of this Act drawn from the national government.
- Ten million pesos (Php10,000,000.00) - five (5) years
140
Section 42
Transitory Provision.
141
Section 43
Separability Clause
142
Existing industries, businesses and offices affected by the implementation of this Act shall be given ______ transitory period from the effectivity of the IRR or such other period as may be determined by the Commission, to comply with the requirements of this Act.
one (1) year
142
In case that the DICT has not yet been created by the time the law takes full force and effect, the National Privacy Commission shall be attached to the ________
Office of the President.
142
Section 44
Repealing Clause
143
SECTION 45
effectivity Clause
143
What is amended by this act?
Section 7 of Republic Act No. 9372, otherwise known as the “Human Security Act of 2007”
144
This Act shall take effect _________ after its publication in at least _________ of general circulation.
- 15 days - two (2) national newspapers
145
President of the Senate
JUAN PONCE ENRILE
146
Speaker of the House of Representatives
FELICIANO BELMONTE JR
147
Secretary of Senate
EMMA LIRIO-REYES
148
Secretary General (House of Representatives)
MARILYN B. BARUA-YAP