Sensitive Personal Information in the Philippines: Stricter Rules Under the Data Privacy Act
Sensitive personal information in the Philippines covers race, health, education, genetic data, and government-issued numbers, and the Data Privacy Act applies stricter rules to it.
Sensitive personal information in the Philippines refers to personal information about a person's race, ethnic origin, marital status, age, color, and religious, philosophical, or political affiliations; health, education, genetic or sexual life, or any proceeding for an offense, its disposal, or the sentence of any court in such proceedings; information issued by government agencies peculiar to an individual, such as social security numbers, health records, licenses and their denials, suspension or revocation, and tax returns; and information specifically established by an executive order or an act of Congress to be kept classified. This definition appears in Section 3 of the Implementing Rules and Regulations of Republic Act No. 10173, the Data Privacy Act of 2012.
Why sensitive personal information gets stricter treatment
The law treats all personal data with care, but sensitive personal information sits in a special category. The IRR of the Data Privacy Act devotes a separate provision — Section 22 — to the lawful processing of sensitive personal information and privileged information, distinct from the general rules for personal information in Section 21. The IRR also devotes an entire rule, Rule VII, to the security of sensitive personal information in government.
The practical effect is that organizations handling this category of data must meet a higher bar before processing it, and must apply security measures proportionate to the risk. The National Privacy Commission, created under the IRR, is the body mandated to administer the Act and enforce these rules.
When processing sensitive personal information is allowed
Under the Data Privacy Act framework, processing sensitive personal information requires a lawful basis. The most familiar basis is the consent of the data subject — defined in Section 3 of the IRR as any freely given, specific, informed indication of will, whereby the data subject agrees to the collection and processing of his or her personal, sensitive personal, or privileged information. Consent must be evidenced by written, electronic, or recorded means, and may be given by a lawful representative or an agent specifically authorized by the data subject.
Because the IRR lists consent alongside other lawful criteria in Section 22, organizations should confirm which specific basis applies to their activity before collecting or using sensitive personal information. Relying on consent alone, without documenting it, is a common compliance gap.
Rights of the data subject
A person whose sensitive personal information is processed remains a data subject under Rule VIII of the IRR, with rights that include:
- Right to be informed that his or her data will be, is being, or was processed.
- Right to object to the processing of his or her data.
- Right to access the contents of his or her data that were processed.
- Right to correct any error in the data.
- Right to rectification, erasure, or blocking of data.
These rights are not absolute. Rule VIII itself provides for limitations on the rights of data subjects, and separately addresses their transmissibility and the right to data portability. The specific section numbers for those provisions are not reproduced in the source text available here, so they are described generally rather than cited by number.
Security obligations for organizations
Rule VI of the IRR requires personal information controllers and personal information processors to implement organizational, physical, and technical security measures. Section 29 speaks of an appropriate level of security, taking into account the nature of the personal data to be protected and the risks presented by the processing.
For government agencies, Rule VII imposes additional duties. It places responsibility on heads of agencies, sets requirements relating to access by agency personnel to sensitive personal information, and extends the security requirements to government contractors. The specific section numbers within Rule VII are not reproduced in the source text available here.
Where an organization engages another to process data on its behalf, Rule X on outsourcing and subcontracting agreements applies, including the duty of a personal information processor.
Breach notification and penalties
A personal data breach is defined in Section 3 of the IRR as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. Rule IX of the IRR governs data breach notification, covering the notification itself, its contents, when notification may be delayed, the breach report, and the procedure for notification. The individual section numbers within Rule IX are not reproduced in the source text available here.
Rule XIII of the IRR lists penalties tied specifically to this category of data, including unauthorized processing of personal information and sensitive personal information, accessing personal information and sensitive personal information due to negligence, improper disposal, processing for unauthorized purposes, concealment of security breaches involving sensitive personal information, and malicious disclosure. The National Privacy Commission may impose administrative fines, issue compliance or enforcement orders, and issue cease and desist orders under Section 9 of the IRR.
Frequently asked questions
Is a person's age considered sensitive personal information in the Philippines? Yes. Section 3 of the IRR lists age among the categories of sensitive personal information, together with race, ethnic origin, marital status, color, and religious, philosophical, or political affiliations.
Is a TIN or SSS number sensitive personal information? Government-issued identifiers peculiar to an individual fall under the definition. Section 3 expressly includes social security numbers, previous or current health records, licenses or their denials, suspension or revocation, and tax returns.
What is the difference between personal information and sensitive personal information? Personal information is any information from which an individual's identity is apparent or can be reasonably and directly ascertained. Sensitive personal information is a narrower, enumerated subset listed in Section 3 of the IRR, and it is subject to the separate lawful processing rule in Section 22 and the government security requirements in Rule VII.
Practical takeaways
- Sensitive personal information is a closed list under Section 3 of the IRR — race, ethnic origin, marital status, age, color, religious, philosophical or political affiliations, health, education, genetic or sexual life, offense proceedings, government-issued identifiers, and data classified by executive order or statute.
- Processing it requires a lawful basis, and consent must be freely given, specific, informed, and documented in written, electronic, or recorded form.
- Organizations must apply an appropriate level of security under Section 29, with government agencies facing added duties under Rule VII.
- Breaches involving this category of data trigger notification duties under Rule IX and specific penalties under Rule XIII.
- Data subjects retain rights under Rule VIII, subject to the limitations the IRR itself provides.
Primary sources
The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.
-
NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016
-
IRR OF REPUBLIC ACT NO. 10173 - IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 10173, KNOWN AS THE “DATA PRIVACY ACT OF 2012”
-
NPC CIRCULAR NO. 2014-014, April 25, 2014
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
This topic sits within our Data Privacy & Cybersecurity practice.
Related reading
NPC enforcement fines in the Philippines are administrative penalties the National Privacy Commission may impose for violations of the Data Privacy Act of 2012.
Employee data retention in the Philippines follows the Data Privacy Act rule that personal data must not be kept longer than necessary for its purpose.
Employee monitoring in the Philippines is governed by the Data Privacy Act of 2012 and its IRR, which require transparency, legitimate purpose, and proportionality.
Learn how the Data Privacy Act of 2012 protects employee data in the Philippines and what employers must do to comply.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.