NEW
Font size
WorksheetsPAW 2021 Quiz
Total questions: 15
Worksheet time: 8mins
The Data Privacy Law and its IRR was implemented and released on March 2012
True
False
According to the Data Privacy Act of 2012, lawful processing of sensitive and privileged information includes the following EXCEPT:
It is necessary for the purpose of medical treatment.
It is necessary to achieve a private organization’s objective, with or without consent
It is necessary for the protection of lawful rights and interests of natural or legal persons in court proceedings.
It is necessary to protect the life and health of the data subject
The following are ways to protect an individual’s personal information online EXCEPT:
Use a simple password so it’s easy to remember.
Limit the amount of data to be shared online
Do monetary transactions in secured website (https)
Avoid accepting friend requests from people you don’t know
In case an employee found out to be in violation of unauthorized processing of sensitive personal information, he or she will be penalized:
500 Thousand to 2 Million and 1 year to 3 years imprisonment
500 Thousand to 2 Million or 1 year to 3 years imprisonment
500 Thousand to 4 Million and 3 years to 6 years imprisonment
500 Thousand to 4 Million or 3 years to 6 years imprisonment
When doing online transactions, the following are ways to preserve your privacy EXCEPT:
Always log out and delete browsing history
Make sure that you are accessing a secured website. A secured website’s URL usually starts with “http”
Avoid accessing your personal accounts in free or public wifi
Ensure that the computer you are using is installed with anti-virus
While browsing the internet, a new window popped-up asking for your participation in a survey which can benefit employees in the banking industry. Which of the following is the BEST to be done?
Review the security settings of your browser and disallow pop-ups
Click on the “x” mark to ignore
Proceed with answering the survey since this will benefit our colleagues
Close the browser immediately.
The following are principles of the data privacy law which should be observed EXCEPT:
Confidentiality
Proportionality
Legitimate Purpose
Transparency
Personal Information Controller (PIC) refers to:
Any natural or juridical person who oversees enterprise-wide security of personal information.
Any natural or juridical person who controls the processing of personal data.
Any natural or juridical person who oversees the implementation of data privacy law.
Any natural or juridical person, or any other body who controls the processing of personal data, or instructs another to process personal data on its behalf.
One of the principles of data privacy is legitimate purpose. Legitimate purpose means:
Processing of personal data shall be adequate, relevant, suitable, necessary, and not excessive in relation to a declared and specified purpose.
Processing of personal data shall be compatible with a declared and specified purpose which must not be contrary to law, morals, or public policy.
The Data Subject must be aware of the nature, purpose, and extent of the processing of his or her personal data.
Personal data should be processed in accordance with the data privacy law
Refers to any operation or any set of operations performed upon personal data including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.
Consent
Direct Marketing
Processing
Profiling
Refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
Incident
Security Incident
Personal Data Breach
Processing
The employee who has access to few of the critical bank applications has recently resigned. As a data privacy designate, which of the following he/she should do:
Check if applications process personal information.
Ensure that resigned employee’s access to all bank applications are removed
Wait for ITG’s recommendation on what to do
Review the privacy impact assessment
As a general rule, personal data breach should be reported within:
12 hours
24 hours
48 hours
72 hours
It is an approach to the development and implementation of projects, programs, and processes that integrates into the latter’s design or structure safeguards that are necessary to protect and promote privacy, such as appropriate organizational, technical, and policy measures
Privacy by Default
Privacy Impact Assessment
Privacy by Design
What is the PAW 2021 Theme?
Valuing Privacy in the Time of Pandemic: Protecting Filipinos. Promoting Economic recovery. Building Trust
Valuing Privacy in the Time of Pandemic: Protecting Filipinos. Promoting Digital. Building Trust
Valuing Privacy in the Time of Digital Transformation: Protecting Filipinos. Promoting Economic recovery. Building Trust
Valuing Privacy in the Time of Digital Transformation: Protecting Filipinos. Promoting Digital. Building Trust
