Data Privacy Flashcards

(7 cards)

1
Q

Definition of Terms
- PIP → outsourced by PIC
- PIC → controls the processing, EXCLUDES
(1) instructed by others
(2) for personal / family affairs

Scope or Applicability
- processing of all types of personal information
- XPN : relates to government, public authority
- XPN : banks, foreign residents
- XPN : discretionary benefit of financial nature (e.g. list of passers)
- XPN : JAR-L purposes → journalistic, artistic, research, literary

Journalists → protected from being compelled to reveal sources

A

Extraterritorial Application
- if related to PH citizen or resident
- if with link to PH (e.g. PH branch of MCDO, call centers)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Principles of Data Privacy
1. Legitimate Purpose
2. Proportionality
3. Transparency

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of Personal Data
1. Personal Information → related to identity (apparent or directly ascertained)
2. Sensitive Personal Information → MARE CPR SHE
3. Privileged Information
(1) attorney-client
(2) doctor-patient
(3) priest-confessor

Extension of Privileged Information → e.g. hospital
May be subcontracted by PIC → PIC is still the one liable

A

MARE CPR SHE
- Marital Status, Age
- Race, Ethnicity, Color
- Philosophical or Religious affiliation
- Sexual life, Health, Education
- issued by gov’t → e.g. SSS, ITR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

PROCESSING OF PERSONAL INFORMATION

Allowed if
- with waiver
- necessary and related to
(1) fulfillment of contract
(2) compliance with laws
(3) vitally important interests, legitimate interests
(4) national emergency, public order, and safety

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PROCESSING OF SENSITIVE / PRIVILEGED INFORMATION

General Rule : Prohibited

XPN : Allowed if
- with waiver
- necessary and related to
(1) lawful objectives of public org
(2) compliance with laws
(3) lawful rights and interests
(4) medical emergency or treatment

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Rights of a Data Subject
- Informed Consent
- Withhold Consent → in case of changes (XPN : subpoena, law, contract)
- Access
- Erasure → notify 3rd parties
- Object
- Correct
- Damages
- Data Portability → electronic means, standardized format

These rights are transmissible to heirs and assigns

A

These rights are not applicable in case of
- scientific or statistical research
- investigation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Notification to Commission
- if with data breach → within ? from knowledge
(1) no delay → if involves at least ? data subjects
(2) adversely affect the data subject

within ? → provide full report to the commission

A
  • 72 hours
  • 100 (large-scale)

5 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly