·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

Employee Data Retention in the Philippines: How Long Can Employers Keep Records

Employee data retention in the Philippines follows the Data Privacy Act rule that personal data must not be kept longer than necessary for its purpose.


Employers in the Philippines may keep employee data only for as long as it is necessary for the purpose it was collected. The Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations (IRR) do not set a single fixed number of years for all employment records. Instead, the governing rule is stated in the IRR's principles on collection, processing, and retention: personal data shall not be retained longer than necessary. Once the purpose is served, the data should be securely destroyed or disposed of.

The governing rule: retention must not exceed what is necessary

The IRR of the Data Privacy Act lays down principles for collecting, processing, and retaining personal data. Among these is the rule that personal data shall not be retained longer than necessary. This applies to all personal data an employer processes, including resumes, application forms, contracts, payroll records, attendance logs, performance evaluations, medical certificates, and government numbers.

The law does not say "keep everything for ten years." It says retention must be tied to a legitimate purpose. If the employer no longer needs the data for that purpose, keeping it becomes unnecessary retention.

What counts as employee personal data

Under the IRR, personal information refers to any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained, or which, combined with other information, would directly and certainly identify an individual. Employee names, addresses, contact details, and identification numbers fall under this definition.

Sensitive personal information is a narrower category. It includes information about an individual's race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations; health, education, genetic or sexual life; and information issued by government agencies peculiar to an individual, such as social security numbers, health records, licenses, and tax returns. Employers routinely hold these for payroll, benefits, and statutory reporting — which means retention decisions must be handled with greater care.

Why "longer than necessary" is the standard, not a fixed year

The IRR defines processing broadly: it covers collection, recording, organization, storage, updating, retrieval, use, consolidation, blocking, erasure or destruction of data. Retention is therefore part of processing, and it must follow the same principles of transparency, legitimate purpose, and proportionality.

The IRR also defines a personal data breach to include the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. This matters for retention: keeping records indefinitely increases the risk of a breach and expands the harm if one occurs. Proper disposal is not optional housekeeping — it is part of compliance.

How employers should approach retention and destruction

A defensible retention program generally follows these steps:

  1. Map the data. Identify every category of employee personal data the company holds, where it is stored, and who can access it.
  2. Tie each category to a purpose. For every category, state the legitimate purpose — payroll, statutory contributions, benefits administration, performance management, or legal defense.
  3. Set a retention period per purpose. Keep data only while the purpose is live. Where another law or regulation requires a specific retention period, follow that law; the Data Privacy Act rule operates alongside these requirements.
  4. Destroy securely once the period ends. Destruction must be part of the processing lifecycle, not an afterthought. Paper records should be shredded; electronic records should be deleted or anonymized so they can no longer identify the individual.
  5. Document everything. A written retention schedule and destruction log show the National Privacy Commission that retention decisions were deliberate.

The rights that back this up

The IRR lists the rights of data subjects, including the right to be informed, the right to object, the right to access, the right to correct, and the right to rectification, erasure or blocking. An employee who no longer wants outdated or unnecessary data kept can invoke the right to erasure or blocking, and the employer must be able to justify why it is still holding the data.

The IRR also provides for transmissibility of rights of the data subject and a right to data portability, which matter when employees move to a new employer or seek copies of their own records.

Frequently asked questions

How long can an employer keep employee records in the Philippines? There is no single fixed period. The IRR requires that personal data shall not be retained longer than necessary. Employers must set retention periods based on the purpose for which the data was collected and destroy the data once that purpose ends, unless another law requires a longer period.

Can an employer keep the records of resigned employees indefinitely? No. Keeping them indefinitely is inconsistent with the rule that personal data shall not be retained longer than necessary. Once the legitimate purpose ends — for example, after any applicable legal, tax, or benefits obligations are resolved — the records should be securely destroyed or anonymized.

What is improper disposal of personal data? The IRR includes improper disposal of personal information and sensitive personal information among the acts it addresses. Disposal must be secure: paper records should be shredded and electronic records deleted or anonymized so that individuals can no longer be identified.

Practical takeaways

  • The core rule is simple: do not retain employee personal data longer than necessary for the purpose it was collected.
  • Retention periods should be set per category of data and per purpose — not as one blanket period for all records.
  • Sensitive personal information, such as health records, social security numbers, and tax returns, deserves stricter handling and shorter retention where possible.
  • Destruction is part of processing, and improper disposal is addressed under the IRR.
  • Employees can exercise the right to erasure or blocking, so employers should be ready to justify any continued retention.

Primary sources

The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.

  • NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016

  • IRR OF REPUBLIC ACT NO. 10173 - IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 10173, KNOWN AS THE “DATA PRIVACY ACT OF 2012”

  • OMNIBUS RULES IMPLEMENTING THE LABOR CODE - OMNIBUS RULES IMPLEMENTING THE LABOR CODE

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

This topic sits within our Data Privacy & Cybersecurity practice.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.