[{"data":1,"prerenderedAt":351},["ShallowReactive",2],{"sectors-nav":3},[4,113,184,273],{"id":5,"title":6,"body":7,"citations":92,"description":97,"extension":98,"hook":99,"icon":100,"meta":101,"navigation":102,"order":103,"path":104,"regulators":105,"sector":109,"seo":110,"stem":111,"__hash__":112},"sectors\u002Fsectors\u002Fhealth.md","Health",{"type":8,"value":9,"toc":85},"minimark",[10,15,28,35,39,46,49,53],[11,12,14],"h2",{"id":13},"why-health-is-different","Why health is different",[16,17,18,19,23,24,27],"p",{},"Under the Data Privacy Act, health information is ",[20,21,22],"strong",{},"sensitive personal\ninformation",". That matters more than it sounds, because sensitive personal\ninformation is governed by ",[20,25,26],{},"Section 13",", not Section 12 — and Section 13 is\nconsiderably narrower.",[16,29,30,31,34],{},"The consequence that surprises people most: ",[20,32,33],{},"performance of a contract is not a\nlawful basis for processing sensitive personal information."," A clinic cannot\nrely on \"we need it to treat the patient\" the way a retailer relies on \"we need\nit to ship the order\". The basis has to come from the Section 13 list.",[11,36,38],{"id":37},"two-clocks-not-one","Two clocks, not one",[16,40,41,42,45],{},"A notifiable breach starts the 72-hour clock to the National Privacy Commission.\nHealth-sector reporting obligations run ",[20,43,44],{},"in addition"," to that, on their own\ntimetable.",[16,47,48],{},"Notifying the NPC does not discharge a separate obligation to notify a sector\nregulator, and the two deadlines are rarely the same.",[11,50,52],{"id":51},"what-the-overlay-covers","What the overlay covers",[54,55,56,60,67,70,73,76,79,82],"ul",{},[57,58,59],"li",{},"Lawful bases mapped to Section 13 rather than Section 12, per processing activity",[57,61,62,63,66],{},"Medical record retention — ",[20,64,65],{},"15 years",", and effectively lifetime where there is\nmedico-legal exposure",[57,68,69],{},"Encryption standards for records at rest and in transit",[57,71,72],{},"Laboratory tiering obligations under DOH AO 2022-0007",[57,74,75],{},"Telemedicine consent and platform assessment under Joint AO 2021-0001",[57,77,78],{},"PhilHealth eClaims record retention",[57,80,81],{},"Consent handling for research, teaching files and case photography",[57,83,84],{},"CCTV in clinical areas, under NPC Circular 2024-02",{"title":86,"searchDepth":87,"depth":87,"links":88},"",2,[89,90,91],{"id":13,"depth":87,"text":14},{"id":37,"depth":87,"text":38},{"id":51,"depth":87,"text":52},[93,94,95,96],"Data Privacy Act §13","DOH AO 2020-0030","DOH AO 2022-0007","Joint AO 2021-0001","Data privacy compliance for hospitals, clinics, laboratories, HMOs and telemedicine providers in the Philippines.","md","Almost everything a health provider holds is sensitive personal information, and the lawful bases for it are narrower than most clinics assume.","i-lucide-stethoscope",{},true,1,"\u002Fsectors\u002Fhealth",[106,107,108],"National Privacy Commission","Department of Health","PhilHealth","health",{"title":6,"description":97},"sectors\u002Fhealth","VDIU2EikxVUCcT81P2YEGQBh-ywAP-rKUHJnqy1Sot4",{"id":114,"title":115,"body":116,"citations":166,"description":171,"extension":98,"hook":172,"icon":173,"meta":174,"navigation":102,"order":87,"path":175,"regulators":176,"sector":180,"seo":181,"stem":182,"__hash__":183},"sectors\u002Fsectors\u002Ffinance.md","Finance and lending",{"type":8,"value":117,"toc":162},[118,122,125,131,134,136],[11,119,121],{"id":120},"where-the-enforcement-actually-is","Where the enforcement actually is",[16,123,124],{},"If you are a lending or financing company, this is the part to read first.",[16,126,127,130],{},[20,128,129],{},"The contact-list prohibition is absolute."," SEC MC 18-2019 bars accessing a\nborrower's phone contacts for collection purposes. Consent does not cure it. An\napp that requests contacts permission is a finding regardless of what the user\nagreed to, and regardless of whether the permission was ever used.",[16,132,133],{},"Online lending has generated more Philippine data privacy enforcement than any\nother sector, and the pattern is consistent: unfair collection practices,\nexcessive permissions, and disclosure to third parties who had no business\nreceiving the data.",[11,135,52],{"id":51},[54,137,138,141,144,147,150,153,156,159],{},[57,139,140],{},"Lawful basis and consent design for loan-related processing, under NPC\nCircular 20-01 as amended by 2022-02",[57,142,143],{},"Mobile app permission review — contacts, location, storage, camera — against\nwhat the service genuinely requires",[57,145,146],{},"Debt collection practices assessed against SEC MC 18-2019",[57,148,149],{},"Credit scoring and automated decision-making, which is itself an NPC\nregistration trigger",[57,151,152],{},"Outsourcing and service provider agreements meeting BSP expectations",[57,154,155],{},"Financial consumer protection obligations under RA 11765",[57,157,158],{},"Cross-border transfer where processing or storage sits offshore",[57,160,161],{},"AMLA record retention reconciled against data minimization",{"title":86,"searchDepth":87,"depth":87,"links":163},[164,165],{"id":120,"depth":87,"text":121},{"id":51,"depth":87,"text":52},[167,168,169,170],"SEC MC 18-2019","NPC Circular 20-01 as amended by 2022-02","BSP Circular 1160","RA 11765","Data privacy compliance for banks, e-money issuers, fintech, lending and financing companies, and insurers in the Philippines.","The highest-enforcement area in the country. Online lending has produced more Philippine data privacy enforcement than any other sector.","i-lucide-landmark",{},"\u002Fsectors\u002Ffinance",[106,177,178,179],"Bangko Sentral ng Pilipinas","Securities and Exchange Commission","Insurance Commission","finance",{"title":115,"description":171},"sectors\u002Ffinance","JP7i0FOSzMMDfhfvWR9u2fZiMArCMZf75E9ISfWaNOs",{"id":185,"title":186,"body":187,"citations":257,"description":260,"extension":98,"hook":261,"icon":262,"meta":263,"navigation":102,"order":264,"path":265,"regulators":266,"sector":269,"seo":270,"stem":271,"__hash__":272},"sectors\u002Fsectors\u002Feducation.md","Education",{"type":8,"value":188,"toc":252},[189,193,196,199,203,206,230,232],[11,190,192],{"id":191},"why-this-sector-is-harder-than-it-looks","Why this sector is harder than it looks",[16,194,195],{},"Schools hold sensitive personal information about minors, which is the most\nscrutinised category of processing there is — and they receive less\nsector-specific guidance than health or finance.",[16,197,198],{},"That combination cuts both ways. There is less prescriptive detail to comply\nwith, and correspondingly more room to get it wrong. A written program that\nstates clearly how the school handles each situation is worth more here than\nalmost anywhere else, because there is no regulator template to fall back on.",[11,200,202],{"id":201},"the-situations-that-come-up","The situations that come up",[16,204,205],{},"Most of a school's privacy risk sits in ordinary daily practice, not in systems:",[54,207,208,211,214,221,224,227],{},[57,209,210],{},"Honor rolls, awards lists and photographs published without a consent basis",[57,212,213],{},"Learning management systems and video conferencing adopted quickly, with no\nPrivacy Impact Assessment behind them",[57,215,216,217,220],{},"Requests for records from a ",[20,218,219],{},"non-custodial parent",", where a policy decision\nhas to be made under pressure",[57,222,223],{},"Alumni and marketing communications using data collected for enrollment",[57,225,226],{},"Classroom and corridor CCTV, under NPC Circular 2024-02",[57,228,229],{},"Third-party providers — bus operators, canteen concessionaires, photographers,\nyearbook publishers — receiving student data with no agreement in place",[11,231,52],{"id":51},[54,233,234,237,240,243,246,249],{},[57,235,236],{},"Transparency written for children as well as for parents, per NPC Advisory 2024-03",[57,238,239],{},"Consent and legitimate interest mapped for each publication and communication type",[57,241,242],{},"PIAs for the learning platform, the student information system and video conferencing",[57,244,245],{},"A records retention schedule spanning enrollment through alumni relations",[57,247,248],{},"A written procedure for parental and student access requests",[57,250,251],{},"Staff training pitched at teachers and registrars rather than at IT",{"title":86,"searchDepth":87,"depth":87,"links":253},[254,255,256],{"id":191,"depth":87,"text":192},{"id":201,"depth":87,"text":202},{"id":51,"depth":87,"text":52},[93,258,259],"NPC Circular 2024-02","NPC Advisory 2024-03","Data privacy compliance for schools, colleges and universities in the Philippines, covering student records, learning platforms and campus CCTV.","The sector with the least regulator-specific guidance — which is exactly why a clear, written program is worth so much here.","i-lucide-graduation-cap",{},3,"\u002Fsectors\u002Feducation",[106,267,268],"Department of Education","Commission on Higher Education","education",{"title":186,"description":260},"sectors\u002Feducation","Kmsd1Eegw5N7FoPO13mmbT2es5jpPJGqXBSsXA1P6n8",{"id":274,"title":275,"body":276,"citations":336,"description":340,"extension":98,"hook":341,"icon":342,"meta":343,"navigation":102,"order":344,"path":345,"regulators":346,"sector":347,"seo":348,"stem":349,"__hash__":350},"sectors\u002Fsectors\u002Fbpo.md","BPO, IT and outsourcing",{"type":8,"value":277,"toc":331},[278,282,285,288,291,295,306,308],[11,279,281],{"id":280},"sell-it-as-sales-enablement-not-as-compliance","Sell it as sales enablement, not as compliance",[16,283,284],{},"Foreign controllers audit their Philippine processors. That is the whole\ncommercial argument.",[16,286,287],{},"An assurance pack that answers a controller's audit in a week rather than a month\nis a competitive advantage you can actually measure — in deals closed, in\nonboarding time, and in how far into the procurement process you get before\nsomeone asks for documentation you do not have.",[16,289,290],{},"Most Philippine BPOs treat privacy as an overhead. The ones that treat it as part\nof the sales collateral win work from the ones that do not.",[11,292,294],{"id":293},"controller-or-processor-usually-both","Controller or processor — usually both",[16,296,297,298,301,302,305],{},"You are a ",[20,299,300],{},"Personal Information Processor"," for your clients' data and a\n",[20,303,304],{},"Personal Information Controller"," for your own employees' data. The obligations\ndiffer, and conflating them is the most common structural error in this sector.",[11,307,52],{"id":51},[54,309,310,313,316,319,322,325,328],{},[57,311,312],{},"Outsourcing agreements meeting IRR Rule X §§43–45, in a form a foreign\ncontroller's counsel will accept without redlining",[57,314,315],{},"A standing assurance pack: security measures, sub-processor list, breach\nprocedure, retention, deletion and return-of-data commitments",[57,317,318],{},"Sub-processor management and flow-down obligations",[57,320,321],{},"Cross-border transfer positions — there is no Philippine adequacy regime, so\nthe controller stays accountable under DPA §21, and the NPC's Model Contractual\nClauses under Advisory 2024-01 are voluntary and will not be reviewed or\nendorsed by the Commission",[57,323,324],{},"Breach notification that satisfies both your client's contract and the NPC clock",[57,326,327],{},"Segregation between client data and your own employee data",[57,329,330],{},"Agent-level access controls, and the evidence that they are enforced",{"title":86,"searchDepth":87,"depth":87,"links":332},[333,334,335],{"id":280,"depth":87,"text":281},{"id":293,"depth":87,"text":294},{"id":51,"depth":87,"text":52},[337,338,339],"Data Privacy Act §21","IRR Rule X §§43–45","NPC Advisory 2024-01","Data privacy compliance for Philippine BPOs, IT service providers and outsourcing firms processing personal data for foreign controllers.","For a BPO, privacy compliance is not a cost of regulation. It is a condition of winning work.","i-lucide-headset",{},4,"\u002Fsectors\u002Fbpo",[106],"bpo",{"title":275,"description":340},"sectors\u002Fbpo","YsZhoX5TOoFB02OR43qkb4skaBHCN1FKC_0byvEjZzE",1785320187282]