RA 10173

0.0(0)
studied byStudied by 5 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/88

flashcard set

Earn XP

Description and Tags

Data Privacy Act of 2012

Accounting

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

89 Terms

1
New cards

Commission

shall refer to the National Privacy Commission created by virtue of this Act.

2
New cards

Consent of the data subject

refers to any freely given, specific, informed indication of will, whereby the data subject agrees to the collection and processing of personal information about and/or relating to him or her.

3
New cards

Consent of the data subject

Consent shall be evidenced by written, electronic or recorded means

4
New cards

Consent of the data subject

It may also be given on behalf of the data subject by an agent specifically authorized by the data subject to do so.

5
New cards

Data subject

refers to an individual whose personal information is processed

6
New cards

Direct marketing

refers to communication by whatever means of any advertising or marketing material which is directed to particular individuals.

7
New cards

Filing system

refers to any act of information relating to natural or juridical persons to the extent that, although the information is not processed by equipment operating automatically in response to instructions given for that purpose, the set is structured, either by reference to individuals or by reference to criteria relating to individuals, in such a way that specific information relating to a particular person is readily accessible.

8
New cards

Information and Communications System

refers to a system for generating, sending, receiving, storing or otherwise processing electronic data messages or electronic documents and includes the computer system or other similar device by or which data is recorded, transmitted or stored and any procedure related to the recording, transmission or storage of electronic data, electronic message, or electronic document.

9
New cards

Personal Information

refers to any information whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.

10
New cards

Personal information controller

refers to a person or organization who controls the collection, holding, processing or use of personal information, including a person or organization who instructs another person or organization to collect, hold, process, use, transfer or disclose personal information on his or her behalf.

11
New cards

Personal information processor

refers to any natural or juridical person qualified to act as such under this Act to whom a personal information controller may outsource the processing of personal data pertaining to a data subject.

12
New cards

Processing

refers to any operation or any set of operations performed upon personal information including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.

13
New cards

Priviledged Information

refers to any and all forms of data which under the Rules of Court and other pertinent laws constitute privileged communication.

14
New cards

Sensitive personal information

refers to personal information: (1) About an individual’s race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations.

15
New cards

Sensitive personal information

About an individual’s health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such person, the disposal of such proceedings, or the sentence of any court in such proceedings.

16
New cards

Sensitive personal information

Issued by government agencies peculiar to an individual which includes, but not limited to, social security numbers, previous or cm-rent health records, licenses or its denials, suspension or revocation, and tax returns; and Specifically established by an executive order or an act of Congress to be kept classified.

17
New cards

Scope

This Act applies to the processing of all types of personal information and to any natural and juridical person involved in personal information processing including those personal information controllers and processors who, although not found or established in the Philippines, use equipment that are located in the Philippines, or those who maintain an office, branch or agency in the Philippines subject to the immediately succeeding paragraph: Provided, That the requirements of Section 5 are complied with.

18
New cards

RA 1405

Secrecy of Bank Deposits Act

19
New cards

RA 6426

Foreign Currency Deposit Act

20
New cards

RA 9510

Credit Information System Act (CISA)

21
New cards

Protection Afforded to Journalists and Their Sources

Nothing in this Act shall be construed as to have amended or repealed the provisions of Republic Act No. 53, which affords the publishers, editors or duly accredited reporters of any newspaper, magazine or periodical of general circulation protection from being compelled to reveal the source of any news report or information appearing in said publication which was related in any confidence to such publisher, editor, or reporter.

22
New cards

Extraterritorial Application

This Act applies to an act done or practice engaged in and outside of the Philippines by an entity if the act, practice or processing relates to personal information about a Philippine citizen or a resident.

23
New cards

Extraterritorial Application

The entity has a link with the Philippines, and the entity is processing personal information in the Philippines or even if the processing is outside the Philippines as long as it is about Philippine citizens or residents.

24
New cards

Functions of the National Privacy Commission

To administer and implement the provisions of this Act, and to monitor and ensure compliance of the country with international standards set for data protection, there is hereby created an independent body to be known as the National Privacy Commission.

25
New cards

Confidentiality

The Commission shall ensure at all times the confidentiality of any personal information that comes to its knowledge and possession.

26
New cards

Organizational Structure of the Commission

The Commission shall be attached to the Department of Information and Communications Technology (DICT) and shall be headed by a Privacy Commissioner, who shall also act as Chairman of the Commission.

27
New cards

Organizational Structure of the Commission

The Privacy Commissioner shall be assisted by two (2) Deputy Privacy Commissioners, one to be responsible for Data Processing Systems and one to be responsible for Policies and Planning. The Privacy Commissioner and the two (2) Deputy Privacy Commissioners shall be appointed by the President of the Philippines for a term of three (3) years, and may be reappointed for another term of three (3) years. Vacancies in the Commission shall be filled in the same manner in which the original appointment was made.

28
New cards

Undersecretary

The Deputy Privacy Commissioners must be recognized experts in the field of information and communications technology and data privacy. They shall enjoy the benefits, privileges and emoluments equivalent to the rank of .

29
New cards

The Secretariat

Majority of the members of the Secretariat must have served for at least five (5) years in any agency of the government that is involved in the processing of personal information including, but not limited to, the following offices: Social Security System (SSS), Government Service Insurance System (GSIS), Land Transportation Office (LTO), Bureau of Internal Revenue (BIR), Philippine Health Insurance Corporation (PhilHealth), Commission on Elections (COMELEC), Department of Foreign Affairs (DFA), Department of Justice (DOJ), and Philippine Postal Corporation (Philpost).

30
New cards

General Data Privacy Principles

The processing of personal information shall be allowed, subject to compliance with the requirements of this Act and other laws allowing disclosure of information to the public and adherence to the principles of transparency, legitimate purpose and proportionality.

31
New cards

Criteria for Lawful Processing of Personal Information

The processing of personal information shall be permitted only if not otherwise prohibited by law, and when at least one of the following conditions exists.

32
New cards

Sensitive Personal Information and Priviledged Information

The processing of sensitive personal information and privileged information shall be prohibited.

33
New cards

Sensitive Personal Information and Priviledged Information

The processing of the same is provided for by existing laws and regulations: Provided, That such regulatory enactments guarantee the protection of the sensitive personal information and the privileged information: Provided, further, That the consent of the data subjects are not required by law or regulation permitting the processing of the sensitive personal information or the privileged information.

34
New cards

Sensitive Personal Information and Priviledge Information

The processing is necessary to achieve the lawful and noncommercial objectives of public organizations and their associations: Provided, That such processing is only confined and related to the bona fide members of these organizations or their associations: Provided, further, That the sensitive personal information are not transferred to third parties: Provided, finally, That consent of the data subject was obtained prior to processing.

35
New cards

Subcontract of Personal Information

A personal information controller may subcontract the processing of personal information: Provided, That the personal information controller shall be responsible for ensuring that proper safeguards are in place to ensure the confidentiality of the personal information processed, prevent its use for unauthorized purposes, and generally, comply with the requirements of this Act and other laws for processing of personal information.

36
New cards

Extension of Priviledge Information

Personal information controllers may invoke the principle of privileged communication over privileged information that they lawfully control or process.

37
New cards

Extension of Priviledge Information

Subject to existing laws and regulations, any evidence gathered on privileged information is inadmissible.

38
New cards

Rights of the Data Subject

(a) Be informed whether personal information pertaining to him or her shall be, are being or have been processed; (b) Be furnished the information indicated hereunder before the entry of his or her personal information into the processing system of the personal information controller, or at the next practical opportunity.

39
New cards

Transmissibility of Rights of the Data Subject

The lawful heirs and assigns of the data subject may invoke the rights of the data subject for, which he or she is an heir or assignee at any time after the death of the data subject or when the data subject is incapacitated or incapable of exercising the rights as enumerated in the immediately preceding section.

40
New cards

Rights to Data Portability

The data subject shall have the right, where personal information is processed by electronic means and in a structured and commonly used format, to obtain from the personal information controller a copy of data undergoing processing in an electronic or structured format, which is commonly used and allows for further use by the data subject.

41
New cards

Right to Data Portability

Commission may specify the electronic format referred to above, as well as the technical standards, modalities and procedures for their transfer.

42
New cards

Non-applicability

The immediately preceding sections are not applicable if the processed personal information are used only for the needs of scientific and statistical research and, on the basis of such, no activities are carried out and no decisions are taken regarding the data subject.

43
New cards

Non-applicability

Provided, That the personal information shall be held under strict confidentiality and shall be used only for the declared purpose. Likewise, the immediately preceding sections are not applicable to processing of personal information gathered for the purpose of investigations in relation to any criminal, administrative or tax liabilities of a data subject.

44
New cards

Security of Personal Information

The personal information controller must implement reasonable and appropriate organizational, physical and technical measures intended for the protection of personal information against any accidental or unlawful destruction, alteration and disclosure, as well as against any other unlawful processing.

45
New cards

Security of Personal Information

The personal information controller shall implement reasonable and appropriate measures to protect personal information against natural dangers such as accidental loss or destruction, and human dangers such as unlawful access, fraudulent misuse, unlawful destruction, alteration and contamination.

46
New cards

Security of Personal Information

The determination of the appropriate level of security under this section must take into account the nature of the personal information to be protected, the risks represented by the processing, the size of the organization and complexity of its operations, current data privacy best practices and the cost of security implementation. Subject to guidelines as the Commission may issue from time to time

47
New cards

Principle of Accountability

Each personal information controller is responsible for personal information under its control or custody, including information that have been transferred to a third party for processing, whether domestically or internationally, subject to cross-border arrangement and cooperation.

48
New cards

Principle of Accountability

The personal information controller is accountable for complying with the requirements of this Act and shall use contractual or other reasonable means to provide a comparable level of protection while the information are being processed by a third party.

49
New cards

Principle of Accountability

The personal information controller shall designate an individual or individuals who are accountable for the organization’s compliance with this Act. The identity of the individual(s) so designated shall be made known to any data subject upon request.

50
New cards

Responsibility of Heads of Agencies

All sensitive personal information maintained by the government, its agencies and instrumentalities shall be secured, as far as practicable, with the use of the most appropriate standard recognized by the information and communications technology industry, and as recommended by the Commission.

51
New cards

Responsibility of Heads of Agencies

The head of each government agency or instrumentality shall be responsible for complying with the security requirements mentioned herein while the Commission shall monitor the compliance and may recommend the necessary action in order to satisfy the minimum standards.

52
New cards

Requirements Relating to Access by Agency Personnel to Sensitive Personal Information

(a) On-site and Online Access – Except as may be allowed through guidelines to be issued by the Commission, no employee of the government shall have access to sensitive personal information on government property or through online facilities unless the employee has received a security clearance from the head of the source agency. (b) Off-site Access – Unless otherwise provided in guidelines to be issued by the Commission, sensitive personal information maintained by an agency may not be transported or accessed from a location off government property unless a request for such transportation or access is submitted and approved by the head of the agency in accordance with the following guidelines.

53
New cards

On-site and Online Access

Except as may be allowed through guidelines to be issued by the Commission, no employee of the government shall have access to sensitive personal information on government property or through online facilities unless the employee has received a security clearance from the head of the source agency.

54
New cards

Off-site Access

Unless otherwise provided in guidelines to be issued by the Commission, sensitive personal information maintained by an agency may not be transported or accessed from a location off government property unless a request for such transportation or access is submitted and approved by the head of the agency in accordance with the following guidelines.

55
New cards

Deadline for Approval or Disapproval

In the case of any request submitted to the head of an agency, such head of the agency shall approve or disapprove the request within two (2) business days after the date of submission of the request. In case there is no action by the head of the agency, then such request is considered disapproved.

56
New cards

Limitation to One Thousand (1,000) Records

If a request is approved, the head of the agency shall limit the access to not more than one thousand (1,000) records at a time.

57
New cards

Encryption

Any technology used to store, transport or access sensitive personal information for purposes of off-site access approved under this subsection shall be secured by the use of the most secure encryption standard recognized by the Commission.

58
New cards

Applicability to Government Contractors

In entering into any contract that may involve accessing or requiring sensitive personal information from one thousand (1,000) or more individuals, an agency shall require a contractor and its employees to register their personal information processing system with the Commission in accordance with this Act and to comply with the other provisions of this Act including the immediately preceding section, in the same manner as agencies and government employees comply with such requirements.

59
New cards

Unauthorized Processing of Personal Information and Sensitive Personal Information

The unauthorized processing of personal information shall be penalized by imprisonment ranging from one (1) year to three (3) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than Two million pesos (Php2,000,000.00) shall be imposed on persons who process personal information without the consent of the data subject, or without being authorized under this Act or any existing law.

60
New cards

Unauthorized Processing of Personal Information and Sensitive Personal Information

The unauthorized processing of personal sensitive information shall be penalized by imprisonment ranging from three (3) years to six (6) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than Four million pesos (Php4,000,000.00) shall be imposed on persons who process personal information without the consent of the data subject, or without being authorized under this Act or any existing law.

61
New cards

1 to 3 years; 500,000 to 2,000,000

Penalties for unauthorized processing of personal information. (years of imprisonment; fine)

62
New cards

3 to 6 years; 500,000 to 4,000,000

Penalties for unauthorized processing of sensitive personal information. (years of imprisonment; fine)

63
New cards

Accessing Personal Information and Sensitive Personal Information Due to Negligence

(a) Accessing personal information due to negligence shall be penalized by imprisonment ranging from one (1) year to three (3) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than Two million pesos (Php2,000,000.00) shall be imposed on persons who, due to negligence, provided access to personal information without being authorized under this Act or any existing law. (b) Accessing sensitive personal information due to negligence shall be penalized by imprisonment ranging from three (3) years to six (6) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than Four million pesos (Php4,000,000.00) shall be imposed on persons who, due to negligence, provided access to personal information without being authorized under this Act or any existing law.

64
New cards

1 to 3 years; 500,000 to 2,000,000

Accessing personal information due to negligence shall be penalized by imprisonment and a fine.

65
New cards

3 to years; 500,000 to 4,000,000

Accessing sensitive personal information due to negligence shall be penalized by imprisonment and a fine.

66
New cards

Improper Disposal of Personal Information and Sensitive Personal Information

(a) The improper disposal of personal information shall be penalized by imprisonment ranging from six (6) months to two (2) years and a fine of not less than One hundred thousand pesos (Php100,000.00) but not more than Five hundred thousand pesos (Php500,000.00) shall be imposed on persons who knowingly or negligently dispose, discard or abandon the personal information of an individual in an area accessible to the public or has otherwise placed the personal information of an individual in its container for trash collection. 1. b) The improper disposal of sensitive personal information shall be penalized by imprisonment ranging from one (1) year to three (3) years and a fine of not less than One hundred thousand pesos (Php100,000.00) but not more than One million pesos (Php1,000,000.00) shall be imposed on persons who knowingly or negligently dispose, discard or abandon the personal information of an individual in an area accessible to the public or has otherwise placed the personal information of an individual in its container for trash collection.

67
New cards

6 months to 2 years; 100,000 to 500,000

The improper disposal of personal information shall be penalized by imprisonment and a fine.

68
New cards

1 to 3 years; 100,000 to 1,000,000

The improper disposal of sensitive personal information shall be penalized by imprisonment and a fine.

69
New cards

Processing of Personal Information and Sensitive Personal Information for Unauthorize Purposes

The processing of personal information for unauthorized purposes shall be penalized by imprisonment ranging from one (1) year and six (6) months to five (5) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than One million pesos (Php1,000,000.00) shall be imposed on persons processing personal information for purposes not authorized by the data subject, or otherwise authorized under this Act or under existing laws. The processing of sensitive personal information for unauthorized purposes shall be penalized by imprisonment ranging from two (2) years to seven (7) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than Two million pesos (Php2,000,000.00) shall be imposed on persons processing sensitive personal information for purposes not authorized by the data subject, or otherwise authorized under this Act or under existing laws.

70
New cards

1 year and 6 months to 5 years; 500,000 to 1,000,000

The processing of personal information for unauthorized purposes shall be penalized by imprisonment and a fine.

71
New cards

2 to 7 years; 500,000 to 2,000,000

The processing of sensitive personal information for unauthorized purposes shall be penalized by imprisonment and a fine.

72
New cards

Unauthorized Access or Intentional Breach

The penalty of imprisonment ranging from one (1) year to three (3) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than Two million pesos (Php2,000,000.00) shall be imposed on persons who knowingly and unlawfully, or violating data confidentiality and security data systems, breaks in any way into any system where personal and sensitive personal information is stored.

73
New cards

1 to 3 years; 500,000 to 2,000,000

Imprisonment and a fine for authorized access or intentional breach.

74
New cards

Concealment of Security Breach Involving Sensitive Personal Information

The penalty of imprisonment of one (1) year and six (6) months to five (5) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than One million pesos (Php1,000,000.00) shall be imposed on persons who, after having knowledge of a security breach and of the obligation to notify the Commission pursuant to Section 20(f), intentionally or by omission conceals the fact of such security breach.

75
New cards

1 year and 6 months to 5 years; 500,000 to 1,000,000

The penalty of imprisonment and a fine for concealment of security breach involving sensitive personal information.

76
New cards

Malicious Disclosure

Any personal information controller or personal information processor or any of its officials, employees or agents, who, with malice or in bad faith, discloses unwarranted or false information relative to any personal information or personal sensitive information obtained by him or her, shall be subject to imprisonment ranging from one (1) year and six (6) months to five (5) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than One million pesos (Php1,000,000.00).

77
New cards

1 year and 6 months to 5 years; 500,000 to 1,000,000

Penalty of imprisonment and a fine for malicious disclosure

78
New cards

Unauthorized Disclosure

(a) Any personal information controller or personal information processor or any of its officials, employees or agents, who discloses to a third party personal information not covered by the immediately preceding section without the consent of the data subject, shall he subject to imprisonment ranging from one (1) year to three (3) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than One million pesos (Php1,000,000.00). (b) Any personal information controller or personal information processor or any of its officials, employees or agents, who discloses to a third party sensitive personal information not covered by the immediately preceding section without the consent of the data subject, shall be subject to imprisonment ranging from three (3) years to five (5) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than Two million pesos (Php2,000,000.00).

79
New cards

1 to 3 years; 500,000 to 1,000,000

Penalty of imprisonment and a fine for unauthorized disclosure of personal information.

80
New cards

3 to 5 years; 500,000 to 2,000,000

Penalty of imprisonment and a fine for unauthorized disclosure of personal information.

81
New cards

Combination or Series of Acts

Any combination or series of acts as defined in Sections 25 to 32 shall make the person subject to imprisonment ranging from three (3) years to six (6) years and a fine of not less than One million pesos (Php1,000,000.00) but not more than Five million pesos (Php5,000,000.00).

82
New cards

3 to 6 years; 1,000,000 to 5,000,000

Penalty of imprisonment and a fine for combination or series of acts.

83
New cards

Extent of Liability

If the offender is a corporation, partnership or any juridical person, the penalty shall be imposed upon the responsible officers, as the case may be, who participated in, or by their gross negligence, allowed the commission of the crime. If the offender is a juridical person, the court may suspend or revoke any of its rights under this Act.

84
New cards

Extent of Liability

If the offender is an alien, he or she shall, in addition to the penalties herein prescribed, be deported without further proceedings after serving the penalties prescribed. If the offender is a public official or employee and lie or she is found guilty of acts penalized under Sections 27 and 28 of this Act, he or she shall, in addition to the penalties prescribed herein, suffer perpetual or temporary absolute disqualification from office, as the case may be.

85
New cards

Large-Scale

The maximum penalty in the scale of penalties respectively provided for the preceding offenses shall be imposed when the personal information of at least one hundred (100) persons is harmed, affected or involved as the result of the above mentioned actions.

86
New cards

Offense Committed by Public Officer

When the offender or the person responsible for the offense is a public officer as defined in the Administrative Code of the Philippines in the exercise of his or her duties, an accessory penalty consisting in the disqualification to occupy public office for a term double the term of criminal penalty imposed shall he applied.

87
New cards

Reports and Information

The Commission shall annually report to the President and Congress on its activities in carrying out the provisions of this Act. The Commission shall undertake whatever efforts it may determine to be necessary or appropriate to inform and educate the public of data privacy, data protection and fair information rights and responsibilities.

88
New cards
89
New cards