Aug 14, 2026data privacy actemployee dataphilippinesnational privacy commissionhr compliancepersonal data

Employee Data Privacy Philippines: Employer's Guide to the Data Privacy Act

Learn how the Data Privacy Act of 2012 protects employee data in the Philippines and what employers must do to comply.


The Data Privacy Act of 2012 (Republic Act No. 10173) protects the personal data of employees in the Philippines. Employers are considered personal information controllers and must follow strict rules on how they collect, use, and store employee information. This guide explains the key requirements under the law and its Implementing Rules and Regulations (IRR) so employers can comply and avoid penalties.

What Counts as Employee Personal Data

Under the law, personal information refers to any information from which an individual's identity is apparent or can be reasonably and directly ascertained. For employees, this includes basic details like name, address, contact numbers, and government-issued IDs.

Sensitive personal information receives stronger protection and includes:

  • An individual's race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations
  • Health, education, genetic or sexual life, and any proceeding for an offense committed or alleged to have been committed
  • Government-issued identifiers such as social security numbers, health records, licenses, and tax returns

Employers handling these types of data must implement stricter safeguards.

Lawful Processing of Employee Data

The IRR states that personal information may only be processed if certain conditions are met. For most employment situations, processing is lawful when:

  • The data subject has given consent
  • The processing is necessary for the performance of a contract with the data subject (such as an employment contract)
  • The processing is necessary for compliance with a legal obligation
  • The processing is necessary to protect the life and health of the data subject

For sensitive personal information, the law requires more stringent conditions. Processing is generally allowed if the data subject has given explicit consent, or if the processing is necessary for the establishment, exercise, or defense of legal claims.

Employer Obligations Under the Data Privacy Act

Employers must follow the principles of transparency, legitimate purpose, and proportionality. This means:

  • Employees must be informed of what data is collected and why
  • Data collection must serve a specified and legitimate purpose
  • Only the minimum amount of data necessary should be collected

Employers must also implement organizational, physical, and technical security measures to protect employee data. This includes designating someone responsible for data protection, securing physical records, and using appropriate technical safeguards like encryption and access controls.

Rights of Employees as Data Subjects

Employees have specific rights under the law that employers must respect:

  • Right to be informed about how their data is processed
  • Right to object to processing
  • Right to access their personal data
  • Right to correct inaccurate information
  • Right to rectification, erasure, or blocking of data

Employers should have clear procedures for employees to exercise these rights.

Data Breach Notification Requirements

If a personal data breach occurs—defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data—employers must follow the notification procedures under the IRR. The National Privacy Commission must be notified, and affected data subjects may also need to be informed depending on the circumstances.

Outsourcing and Third-Party Processors

When employers outsource processing of employee data to third parties, the IRR requires proper agreements. The personal information controller (the employer) remains accountable even when a personal information processor handles the data. Contracts must specify the scope of processing and security requirements.

Frequently Asked Questions

Do employers need written consent from employees to process their data? Consent may be given through written, electronic, or recorded means. However, consent is only one basis for lawful processing. If processing is necessary for the employment contract or legal compliance, separate consent may not always be required.

What happens if an employer violates the Data Privacy Act? The National Privacy Commission can investigate complaints and impose administrative fines. The law also provides for criminal penalties for unauthorized processing, malicious disclosure, and other violations.

Does the law apply to small businesses? Yes. The Data Privacy Act applies to all natural and juridical persons in the private sector that process personal data, regardless of company size.

Practical Takeaways

  • Conduct a data inventory to identify what employee personal data your company collects and where it is stored.
  • Review your privacy notices to ensure employees are clearly informed about data collection purposes.
  • Implement security measures appropriate to your organization's size and the sensitivity of the data you handle.
  • Prepare a data breach response plan so your company knows what to do if a security incident occurs.
  • Review outsourcing contracts to ensure third-party processors comply with the Data Privacy Act.

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

This article is general information and not legal advice. For your situation, ask ASG Legal AI or book a consultation.