wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

PAW 2021 Quiz

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

The Data Privacy Law and its IRR was implemented and released on March 2012

a)

True

b)

False

2.

According to the Data Privacy Act of 2012, lawful processing of sensitive and privileged information includes the following EXCEPT:

a)

It is necessary for the purpose of medical treatment.

b)

It is necessary to achieve a private organization’s objective, with or without consent

c)

It is necessary for the protection of lawful rights and interests of natural or legal persons in court proceedings.

d)

It is necessary to protect the life and health of the data subject

3.

The following are ways to protect an individual’s personal information online EXCEPT:

a)

Use a simple password so it’s easy to remember.

b)

Limit the amount of data to be shared online

c)

Do monetary transactions in secured website (https)

d)

Avoid accepting friend requests from people you don’t know

4.

In case an employee found out to be in violation of unauthorized processing of sensitive personal information, he or she will be penalized:

a)

500 Thousand to 2 Million and 1 year to 3 years imprisonment

b)

500 Thousand to 2 Million or 1 year to 3 years imprisonment

c)

500 Thousand to 4 Million and 3 years to 6 years imprisonment

d)

500 Thousand to 4 Million or 3 years to 6 years imprisonment

5.

When doing online transactions, the following are ways to preserve your privacy EXCEPT:

a)

Always log out and delete browsing history

b)

Make sure that you are accessing a secured website. A secured website’s URL usually starts with “http”

c)

Avoid accessing your personal accounts in free or public wifi

d)

Ensure that the computer you are using is installed with anti-virus

6.

While browsing the internet, a new window popped-up asking for your participation in a survey which can benefit employees in the banking industry. Which of the following is the BEST to be done?

a)

Review the security settings of your browser and disallow pop-ups

b)

Click on the “x” mark to ignore

c)

Proceed with answering the survey since this will benefit our colleagues

d)

Close the browser immediately.

7.

The following are principles of the data privacy law which should be observed EXCEPT:

a)

Confidentiality

b)

Proportionality

c)

Legitimate Purpose

d)

Transparency

8.

Personal Information Controller (PIC) refers to:

a)

Any natural or juridical person who oversees enterprise-wide security of personal information.

b)

Any natural or juridical person who controls the processing of personal data.

c)

Any natural or juridical person who oversees the implementation of data privacy law.

d)

Any natural or juridical person, or any other body who controls the processing of personal data, or instructs another to process personal data on its behalf.

9.

One of the principles of data privacy is legitimate purpose. Legitimate purpose means:

a)

Processing of personal data shall be adequate, relevant, suitable, necessary, and not excessive in relation to a declared and specified purpose.

b)

Processing of personal data shall be compatible with a declared and specified purpose which must not be contrary to law, morals, or public policy.

c)

The Data Subject must be aware of the nature, purpose, and extent of the processing of his or her personal data.

d)

Personal data should be processed in accordance with the data privacy law

10.

Refers to any operation or any set of operations performed upon personal data including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.

a)

Consent

b)

Direct Marketing

c)

Processing

d)

Profiling

11.

Refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

a)

Incident

b)

Security Incident

c)

Personal Data Breach

d)

Processing

12.

The employee who has access to few of the critical bank applications has recently resigned. As a data privacy designate, which of the following he/she should do:

a)

Check if applications process personal information.

b)

Ensure that resigned employee’s access to all bank applications are removed

c)

Wait for ITG’s recommendation on what to do

d)

Review the privacy impact assessment

13.

As a general rule, personal data breach should be reported within:

a)

12 hours

b)

24 hours

c)

48 hours

d)

72 hours

14.

It is an approach to the development and implementation of projects, programs, and processes that integrates into the latter’s design or structure safeguards that are necessary to protect and promote privacy, such as appropriate organizational, technical,​ and policy measures

a)

Privacy by Default

b)

Privacy Impact Assessment

c)

Privacy by Design

15.

What is the PAW 2021 Theme?

a)

Valuing Privacy in the Time of Pandemic: Protecting Filipinos. Promoting Economic recovery. Building Trust

b)

Valuing Privacy in the Time of Pandemic: Protecting Filipinos. Promoting Digital. Building Trust

c)

Valuing Privacy in the Time of Digital Transformation: Protecting Filipinos. Promoting Economic recovery. Building Trust

d)

Valuing Privacy in the Time of Digital Transformation: Protecting Filipinos. Promoting Digital. Building Trust