What does ‘Commission’ refer to?
The National Privacy Commission created by virtue of this Act.
What is the definition of ‘Consent of the data subject’?
Any freely given, specific, informed indication of will, whereby the data subject agrees to the collection and processing of personal information about and/or relating to him or her.
How can consent be evidenced?
By written, electronic or recorded means.
Who can give consent on behalf of the data subject?
An agent specifically authorized by the data subject.
What is a ‘Data subject’?
An individual whose personal information is processed.
Define ‘Direct marketing’.
Communication by whatever means of any advertising or marketing material which is directed to particular individuals.
What does ‘Filing system’ refer to?
Any act of information relating to natural or juridical persons structured for specific information to be readily accessible.
What is an ‘Information and Communications System’?
A system for generating, sending, receiving, storing or processing electronic data messages or electronic documents.
True or False: A data subject can be a juridical person.
False.
What is a personal information controller?
A person or organization who controls the collection, holding, processing, or use of personal information.
What does a personal information controller exclude?
What is a personal information processor?
Any natural or juridical person qualified to act as such under this Act to whom a personal information subject controller may outsource the processing of personal data.
True or False: A personal information processor can be an organization.
True
What role does a personal information processor serve in relation to a personal information controller?
They process personal data pertaining to a data subject as outsourced by the controller.
What is the scope of personal information processing?
Data Privacy Act does not apply to:
What does Republic Act No. 53 protect?
It protects publishers, editors, or duly accredited reporters from being compelled to reveal their sources of news reports or information.
This protection applies to publications of general circulation that receive information in confidence.
What is the extraterritorial application of the Data Privacy Act?
It applies to acts done or practices engaged in outside the Philippines by an entity if:
What must the Commission ensure regarding personal information?
The Commission shall ensure at all times the confidentiality of any personal information that comes to its knowledge and possession.
This emphasizes the importance of protecting personal data from unauthorized access or disclosure.
To which department is the Commission attached?
The Commission shall be attached to the Department of Information and Communications Technology (DICT).
This indicates the Commission’s alignment with governmental oversight in information and communications.
Who heads the Commission?
The Commission shall be headed by a Privacy Commissioner, who shall also act as Chairman of the Commission.
The dual role highlights the importance of leadership in privacy governance.
What benefits does the Privacy Commissioner enjoy?
The Privacy Commissioner shall enjoy the benefits, privileges, and emoluments equivalent to the rank of Secretary.
This ensures that the position is respected and adequately compensated within the governmental structure.
Who assists the Privacy Commissioner?
Two (2) Deputy Privacy Commissioners
What are the responsibilities of the two Deputy Privacy Commissioners?
One for Data Processing Systems and one for Policies and Planning