[06.19] Data Privacy Act and its Implication to Research V2.pdf

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/147

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:38 AM on 6/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

148 Terms

1
New cards

Individual rights pertaining to one’s personal information

What rights does the Data Privacy Act of 2012 strengthen?

2
New cards

Unauthorized processing of personal information

What activity does Republic Act 10173 penalize?

3
New cards

European Union’s Data Protection Directive

What is the Data Privacy Act patterned after?

4
New cards

9 chapters and 45 sections

How many chapters and sections does the Data Privacy Act have?

5
New cards

Processing of all types of personal information

What does the Data Privacy Act apply to, according to Section 4?

6
New cards

Personal information controllers and processors who, although not found or established in the Philippines, use equipment located in the Philippines

To whom does the Act apply, even if they are not established in the Philippines, provided they use equipment there?

7
New cards

Processing for journalistic, artistic, literary or research purposes

What type of processing is the Act generally stated NOT to apply to, according to Section 4?

8
New cards

Subject to the requirements of applicable laws, regulations, and ethical standards

What qualifier applies to the processing of personal information for research purposes?

9
New cards

14 rules and 75 sections

How many rules and sections does the Implementing Rules and Regulations (IRR) have?

10
New cards

Personal information that will be processed for research purposes

What type of information is exempt from the Act and Rules, but only to the minimum extent necessary?

11
New cards

Intended for a public benefit

What must the research purposes be intended for, as a qualifier for non-applicability of the Act?

12
New cards

Upholding the strict confidentiality of participants’ personal information

What is a limitation set on the non-applicability of certain privacy rights on research?

13
New cards

The declared purpose found in the original consent

For what purpose only can data be used, according to the IRR limitations?

14
New cards

It is publicly available OR Has the consent of the data subject for purpose of research

What two conditions allow for further processing of Personal Data collected from a party other than the Data Subject for research purposes?

15
New cards

Adequate safeguards are in place AND no decision directly affecting the data subject shall be made on the basis of the data collected or processed

What two provisions must be met when allowing further processing of personal data for research?

16
New cards

Scientific and statistical research

The limitations on rights (preceding sections) are not applicable if processed personal data are used only for the needs of this type of research.

17
New cards

No activities are carried out and no decisions are taken regarding the data subject

What is the condition applied to the use of personal data for scientific and statistical research, limiting the rights of the data subject?

18
New cards

Review by the Commission

What body may review the processing of personal data for research purposes, public functions, or commercial activities?

19
New cards

The minimum extent necessary

To what extent shall any limitations on the rights of the data subject be applied to achieve the purpose of said research or investigation?

20
New cards

To uncover issues and concerns relating to the impact of the Data Privacy Act on research involving human participants AND to offer practical guidance to Filipino researchers and ethics review committees

What are the twofold objectives of the 2021 primer and its companion data privacy toolkit?

21
New cards

Ethical standards

The processing of data when it comes to research is subject to this.

22
New cards

Ethics review committee

What committee mitigates the potential assault on the privacy of individuals and/or groups in research?

23
New cards

Balance between the protection of the right to privacy, and the need to generate knowledge or foster innovation

What does ethics review seek to achieve regarding personal information processing in research?

24
New cards

Human participants

What term is used interchangeably with human subjects?

25
New cards

A living individual about whom an investigator conducting research obtains information or biospecimens through intervention or interaction

What is one definition of a human participant?

26
New cards

Personal information

What term refers to any information from which the identity of an individual is apparent or can be reasonably and directly ascertained, or when put together with other information would directly and certainly identify the individual?

27
New cards

Sensitive personal information

What category of information includes details about an individual’s race, ethnic origin, marital status, age, color, religion, philosophical, or political affiliations?

28
New cards

Health, education, genetic or sexual life

What three sensitive life details are included in sensitive personal information?

29
New cards

Previous or current health records

What specific government-issued information is classified as sensitive personal information?

30
New cards

Personal data

What ad hoc term in the Implementing Rules and Regulations refers to personal information, sensitive personal information, and privileged information?

31
New cards

Privileged information

What refers to any and all forms of data which, under the Rules of Court and other pertinent laws, constitute privileged communication?

32
New cards

Patient-doctor, lawyers-client, husband-wife communications

What are three examples of privileged information?

33
New cards

Data subject

What is an individual whose personal information is processed?

34
New cards

Research participants

Who could be simultaneously research subjects and data subjects?

35
New cards

Third-party data subjects

What group of data subjects in research may not be research subjects and have unlikely consented to the processing of their personal information?

36
New cards

Copying, deleting, sharing, storing, transferring of personal data

What are five examples of activities that constitute "processing" of personal data?

37
New cards

Right to be informed, Right to object, Right to access, Right to rectification, Right to erasure or blocking, Right to damages, Right to data portability, Right to file a complaint

What are the eight privacy rights of study participants under the Data Privacy Act?

38
New cards

Right to be Informed

What fundamental privacy right empowers data subjects to consider courses of action to protect their own privacy and interest?

39
New cards

Without consent

Under what condition should personal data never be collected, processed, and stored by the researcher?

40
New cards

Purpose of the research, risks and benefits, data utilization plan during the study, storage, dissemination, publishing, and archival

What are four key pieces of information participants need to be informed of regarding the research?

41
New cards

Before the entry of his or her personal data into the processing system

When should the data subject be notified and furnished with information, or at the next practical opportunity?

42
New cards

Description of the personal data to be entered into the system

What specific information must the data subject be notified of regarding their personal data?

43
New cards

Identity and contact details of the personal data controller or its representative

What specific contact information must the data subject be notified of?

44
New cards

The existence of their rights as data subjects, including the right to access, correction, and object to the processing, as well as the right to lodge a complaint before the Commission

What specific rights must the data subject be notified of?

45
New cards

Right to Access

What right allows data subjects to obtain from an organization or a researcher a copy of any information relating to them?

46
New cards

Right to Rectification

What right allows individuals to have inaccurate records or personal data corrected or completed if incomplete?

47
New cards

Right to Erasure or Blocking

What right allows the data subject to suspend, withdraw, or order the blocking, removal, or destruction of his or her personal data from the filing system?

48
New cards

The personal data is incomplete, outdated, false, or unlawfully obtained

What is one condition that allows a data subject to exercise the right to erasure or blocking?

49
New cards

The personal data is being used for purpose not authorized by the data subject

What is one condition that allows a data subject to exercise the right to erasure or blocking related to unauthorized use?

50
New cards

Right to Damages and Right to File a Complaint

What right do data subjects have if they feel their information has been misused or improperly disclosed, violating the Data Privacy Act?

51
New cards

Right to Data Portability

What right enables data subjects to copy or transmit personal data from one device to another in an electronic or structured format?

52
New cards

Right to Object

What right allows a person to object if the data processing is not part of the agreement?

53
New cards

The investigator or researcher must stop their research work and the use of personal information or data of the study subject

What must the investigator or researcher do when data subjects object or withhold their consent?

54
New cards

When the participant decided to withdraw consent

What is one time that data subjects can object, which they can do at any time?

55
New cards

When data concerns information that is prejudicial

What is one instance where the data subject can exercise the right to erasure or blocking related to prejudicial information?

56
New cards

When they were a child at the time of data collection

When can a data subject, now an adult, decide whether they would still be part of the research or not, using their right to object?

57
New cards

Lawful heirs and assigns

Who may invoke the rights of the data subject after their death or incapacitation?

58
New cards

Strict confidentiality

Under what condition should personal information be used for scientific and statistical research, limiting the rights of the data subject?

59
New cards

Transparency, Legitimacy of Purpose, Proportionality, Limited Use, Disclosure, and Retention, Consent, Accountability, Security

What are the seven principles of data privacy covered by the Data Privacy Act?

60
New cards

Transparency

What principle requires that the purpose of processing a person’s data should be determined and disclosed before its collection?

61
New cards

Legitimacy of Purpose

What principle requires that the collection and processing of information must be compatible with the declared and specific purpose, and not contrary to the law, morals, or public policy?

62
New cards

Proportionality

What principle requires that data subject information must be adequate and not excessive in relation to the purposes for which they were collected and processed?

63
New cards

Limited Use, Disclosure, and Retention

What principle mandates that retention of data must only be for as long as necessary?

64
New cards

Consent

What principle provides an important legal basis for processing personal data in research?

65
New cards

Accountability

What principle lies with the personal information controller?

66
New cards

Personal information controller

Who is a person or an organization who controls the collection, holding, processing, or use of personal information?

67
New cards

Personal information processor

Who is a natural or juridical person qualified to act as such, to whom a personal information controller may outsource the processing of personal data?

68
New cards

Security

What principle requires a researcher to implement reasonable and appropriate physical, technical, and organizational security measures?

69
New cards

Accidental loss, Accidental Destruction

What are two examples of "Natural Dangers" against which personal information must be protected?

70
New cards

Unlawful access, Fraudulent misuse, Unlawful destruction, alteration, and contamination

What are three examples of "Human Dangers" against which personal information must be protected?

71
New cards

Selection bias

What operational issue arises from compliance with privacy regulation, where individuals who give consent do not accurately reflect the target population?

72
New cards

Filipino culture

What is one factor related to selection bias, due to being a highly relational society where people tend to help friends (e.g., pakikisama)?

73
New cards

Lengthy and complicated consent forms

What specific operational factor can be a deterrent for participant participation?

74
New cards

Additional costs and staff hours

What is one operational issue related to the resources required for privacy compliance?

75
New cards

Timely access to health or other vital information

What is one operational issue regarding accessibility that can burden research efficiency?

76
New cards

Scholarly integrity of the research output

What does transparency and openness in sharing data help ensure?

77
New cards

Data sharing agreements

What enables collaboration and data sharing involving human subjects?

78
New cards

Information life cycle, Privacy by Design, Security, Data Protection Officer

What are the four components of Privacy and Welfare Protection in Research?

79
New cards

Collection, Handling, Risk assessment, Protection, Disposal

What are the five steps in the Information Life Cycle?

80
New cards

Collection

What step in the Information Life Cycle involves considering whether it is necessary to collect and hold that much personal information?

81
New cards

Disposal

What step in the Information Life Cycle involves reidentifying and destroying personal information when it is no longer needed?

82
New cards

Privacy by Design

What concept compels heads of institutions, project lead researchers, or principal investigators to make privacy protection an integral part of the research operations and procedures?

83
New cards

Physical, Technical, and Organizational

What are the three types of security measures in Privacy by Design?

84
New cards

Filing cabinets that are locked

What is an example of a physical security measure for paper-based data?

85
New cards

Use of passwords and/or encryption

What is an example of a physical security measure for digital data?

86
New cards

Pseudonymization

What is a technical security measure that involves processing personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information?

87
New cards

Monitor for security breaches, Security software for data protection, Encryption

What are three examples of technical security measures?

88
New cards

Organizational security measures

What security measure is needed for the smooth employment of the security system agreed upon with the institution?

89
New cards

Data Protection Officer

Who is needed to oversee all of the security measures mentioned?

90
New cards

De-identification

What measure should be given utmost importance in cases where information is to be shared or released, allowing other researchers to use the dataset for secondary use?

91
New cards

Confidentiality

What factor helps people trust in the investigator or study team?

92
New cards

Quality and integrity

Aside from privacy and security, what two elements are needed in data governance?

93
New cards

Opt-in format

What format is used in the Philippines, where citizens have the right to say whether they want their data to be included in a research study/project?

94
New cards

Opt-out format

What format is used in other countries (e.g., UK), where all citizens' health data can be used for research unless they choose otherwise?

95
New cards

Generalizability of findings

What is limited in the Philippines due to the opt-in format and selection bias?

96
New cards

PhilHealth

What government institution was mentioned in the context of needing further security measures to prevent data breach?

97
New cards

To provide an overall framework for compliance with the privacy regulations in a manner facilitative of scientific research as a general public interest

What is the purpose of the data privacy principles?

98
New cards

Data privacy is just a component of data governance

What is the relationship between data privacy and data governance?

99
New cards

Risk assessment

What step in the Information Life Cycle involves assessing the risks associated with the collection of personal information?

100
New cards

Obtaining information or biospecimens through intervention or interaction

What is one way a researcher obtains information from a human participant?