Commission
- National Privacy Commission
Consent
- freely given will
Data Subject
- individual whose info is processed
Direct Marketing
- communication
- advertising or marketing
Filing System
- specific info is readily accessible
Info and Communication System
- system for processing electronic data message
Personal Info Controller
- controls
- instruct another
Personal Info Processor
- natural or juridical
- outsource by controller
Journalist
- protected
- from being compelled to reveal source
Structure:
Principles
Proportionality
- adequate and relevant
Legitimate Purpose
- legit purpose
Transparency
- data subject is aware
Onsite and Online Access
- no employee can access
- need security clearance
Offsite Access
- cannot transport
- need request
- decision within 2 days
- if no decision, disapprove
- limit to 1k records
- need encyrption
Government Contractor
- need to register personal info system
- if involves 1k data subject
Personal Information
- identity is apparent and ascertained
- will identify individual
Privileged Information
- privileged communication
- secret
Sensitive Personal Information
- race,ethnic,age,color,marital status,religious,philosophical,political
Period to Report Data Breach
- 72 days
- can be delay for scope purposes
- cannot if data subject is 100
- full report submit within 5 days