[{"data":1,"prerenderedAt":405},["ShallowReactive",2],{"sector-\u002Fservices\u002Fdpo-as-a-service\u002Fsectors\u002Feducation":3,"sectors-other-\u002Fservices\u002Fdpo-as-a-service\u002Fsectors\u002Feducation":106},{"id":4,"title":5,"body":6,"citations":86,"description":90,"extension":91,"hook":92,"icon":93,"meta":94,"navigation":95,"order":96,"path":97,"regulators":98,"sector":102,"seo":103,"stem":104,"__hash__":105},"sectors\u002Fsectors\u002Feducation.md","Education",{"type":7,"value":8,"toc":79},"minimark",[9,14,18,21,25,28,55,59],[10,11,13],"h2",{"id":12},"why-this-sector-is-harder-than-it-looks","Why this sector is harder than it looks",[15,16,17],"p",{},"Schools hold sensitive personal information about minors, which is the most\nscrutinised category of processing there is — and they receive less\nsector-specific guidance than health or finance.",[15,19,20],{},"That combination cuts both ways. There is less prescriptive detail to comply\nwith, and correspondingly more room to get it wrong. A written program that\nstates clearly how the school handles each situation is worth more here than\nalmost anywhere else, because there is no regulator template to fall back on.",[10,22,24],{"id":23},"the-situations-that-come-up","The situations that come up",[15,26,27],{},"Most of a school's privacy risk sits in ordinary daily practice, not in systems:",[29,30,31,35,38,46,49,52],"ul",{},[32,33,34],"li",{},"Honor rolls, awards lists and photographs published without a consent basis",[32,36,37],{},"Learning management systems and video conferencing adopted quickly, with no\nPrivacy Impact Assessment behind them",[32,39,40,41,45],{},"Requests for records from a ",[42,43,44],"strong",{},"non-custodial parent",", where a policy decision\nhas to be made under pressure",[32,47,48],{},"Alumni and marketing communications using data collected for enrollment",[32,50,51],{},"Classroom and corridor CCTV, under NPC Circular 2024-02",[32,53,54],{},"Third-party providers — bus operators, canteen concessionaires, photographers,\nyearbook publishers — receiving student data with no agreement in place",[10,56,58],{"id":57},"what-the-overlay-covers","What the overlay covers",[29,60,61,64,67,70,73,76],{},[32,62,63],{},"Transparency written for children as well as for parents, per NPC Advisory 2024-03",[32,65,66],{},"Consent and legitimate interest mapped for each publication and communication type",[32,68,69],{},"PIAs for the learning platform, the student information system and video conferencing",[32,71,72],{},"A records retention schedule spanning enrollment through alumni relations",[32,74,75],{},"A written procedure for parental and student access requests",[32,77,78],{},"Staff training pitched at teachers and registrars rather than at IT",{"title":80,"searchDepth":81,"depth":81,"links":82},"",2,[83,84,85],{"id":12,"depth":81,"text":13},{"id":23,"depth":81,"text":24},{"id":57,"depth":81,"text":58},[87,88,89],"Data Privacy Act §13","NPC Circular 2024-02","NPC Advisory 2024-03","Data privacy compliance for schools, colleges and universities in the Philippines, covering student records, learning platforms and campus CCTV.","md","The sector with the least regulator-specific guidance — which is exactly why a clear, written program is worth so much here.","i-lucide-graduation-cap",{},true,3,"\u002Fsectors\u002Feducation",[99,100,101],"National Privacy Commission","Department of Education","Commission on Higher Education","education",{"title":5,"description":90},"sectors\u002Feducation","Kmsd1Eegw5N7FoPO13mmbT2es5jpPJGqXBSsXA1P6n8",[107,202,273,327],{"id":108,"title":109,"body":110,"citations":185,"description":189,"extension":91,"hook":190,"icon":191,"meta":192,"navigation":95,"order":193,"path":194,"regulators":195,"sector":198,"seo":199,"stem":200,"__hash__":201},"sectors\u002Fsectors\u002Fhealth.md","Health",{"type":7,"value":111,"toc":180},[112,116,127,134,138,145,148,150],[10,113,115],{"id":114},"why-health-is-different","Why health is different",[15,117,118,119,122,123,126],{},"Under the Data Privacy Act, health information is ",[42,120,121],{},"sensitive personal\ninformation",". That matters more than it sounds, because sensitive personal\ninformation is governed by ",[42,124,125],{},"Section 13",", not Section 12 — and Section 13 is\nconsiderably narrower.",[15,128,129,130,133],{},"The consequence that surprises people most: ",[42,131,132],{},"performance of a contract is not a\nlawful basis for processing sensitive personal information."," A clinic cannot\nrely on \"we need it to treat the patient\" the way a retailer relies on \"we need\nit to ship the order\". The basis has to come from the Section 13 list.",[10,135,137],{"id":136},"two-clocks-not-one","Two clocks, not one",[15,139,140,141,144],{},"A notifiable breach starts the 72-hour clock to the National Privacy Commission.\nHealth-sector reporting obligations run ",[42,142,143],{},"in addition"," to that, on their own\ntimetable.",[15,146,147],{},"Notifying the NPC does not discharge a separate obligation to notify a sector\nregulator, and the two deadlines are rarely the same.",[10,149,58],{"id":57},[29,151,152,155,162,165,168,171,174,177],{},[32,153,154],{},"Lawful bases mapped to Section 13 rather than Section 12, per processing activity",[32,156,157,158,161],{},"Medical record retention — ",[42,159,160],{},"15 years",", and effectively lifetime where there is\nmedico-legal exposure",[32,163,164],{},"Encryption standards for records at rest and in transit",[32,166,167],{},"Laboratory tiering obligations under DOH AO 2022-0007",[32,169,170],{},"Telemedicine consent and platform assessment under Joint AO 2021-0001",[32,172,173],{},"PhilHealth eClaims record retention",[32,175,176],{},"Consent handling for research, teaching files and case photography",[32,178,179],{},"CCTV in clinical areas, under NPC Circular 2024-02",{"title":80,"searchDepth":81,"depth":81,"links":181},[182,183,184],{"id":114,"depth":81,"text":115},{"id":136,"depth":81,"text":137},{"id":57,"depth":81,"text":58},[87,186,187,188],"DOH AO 2020-0030","DOH AO 2022-0007","Joint AO 2021-0001","Data privacy compliance for hospitals, clinics, laboratories, HMOs and telemedicine providers in the Philippines.","Almost everything a health provider holds is sensitive personal information, and the lawful bases for it are narrower than most clinics assume.","i-lucide-stethoscope",{},1,"\u002Fsectors\u002Fhealth",[99,196,197],"Department of Health","PhilHealth","health",{"title":109,"description":189},"sectors\u002Fhealth","VDIU2EikxVUCcT81P2YEGQBh-ywAP-rKUHJnqy1Sot4",{"id":203,"title":204,"body":205,"citations":255,"description":260,"extension":91,"hook":261,"icon":262,"meta":263,"navigation":95,"order":81,"path":264,"regulators":265,"sector":269,"seo":270,"stem":271,"__hash__":272},"sectors\u002Fsectors\u002Ffinance.md","Finance and lending",{"type":7,"value":206,"toc":251},[207,211,214,220,223,225],[10,208,210],{"id":209},"where-the-enforcement-actually-is","Where the enforcement actually is",[15,212,213],{},"If you are a lending or financing company, this is the part to read first.",[15,215,216,219],{},[42,217,218],{},"The contact-list prohibition is absolute."," SEC MC 18-2019 bars accessing a\nborrower's phone contacts for collection purposes. Consent does not cure it. An\napp that requests contacts permission is a finding regardless of what the user\nagreed to, and regardless of whether the permission was ever used.",[15,221,222],{},"Online lending has generated more Philippine data privacy enforcement than any\nother sector, and the pattern is consistent: unfair collection practices,\nexcessive permissions, and disclosure to third parties who had no business\nreceiving the data.",[10,224,58],{"id":57},[29,226,227,230,233,236,239,242,245,248],{},[32,228,229],{},"Lawful basis and consent design for loan-related processing, under NPC\nCircular 20-01 as amended by 2022-02",[32,231,232],{},"Mobile app permission review — contacts, location, storage, camera — against\nwhat the service genuinely requires",[32,234,235],{},"Debt collection practices assessed against SEC MC 18-2019",[32,237,238],{},"Credit scoring and automated decision-making, which is itself an NPC\nregistration trigger",[32,240,241],{},"Outsourcing and service provider agreements meeting BSP expectations",[32,243,244],{},"Financial consumer protection obligations under RA 11765",[32,246,247],{},"Cross-border transfer where processing or storage sits offshore",[32,249,250],{},"AMLA record retention reconciled against data minimization",{"title":80,"searchDepth":81,"depth":81,"links":252},[253,254],{"id":209,"depth":81,"text":210},{"id":57,"depth":81,"text":58},[256,257,258,259],"SEC MC 18-2019","NPC Circular 20-01 as amended by 2022-02","BSP Circular 1160","RA 11765","Data privacy compliance for banks, e-money issuers, fintech, lending and financing companies, and insurers in the Philippines.","The highest-enforcement area in the country. Online lending has produced more Philippine data privacy enforcement than any other sector.","i-lucide-landmark",{},"\u002Fsectors\u002Ffinance",[99,266,267,268],"Bangko Sentral ng Pilipinas","Securities and Exchange Commission","Insurance Commission","finance",{"title":204,"description":260},"sectors\u002Ffinance","JP7i0FOSzMMDfhfvWR9u2fZiMArCMZf75E9ISfWaNOs",{"id":4,"title":5,"body":274,"citations":323,"description":90,"extension":91,"hook":92,"icon":93,"meta":324,"navigation":95,"order":96,"path":97,"regulators":325,"sector":102,"seo":326,"stem":104,"__hash__":105},{"type":7,"value":275,"toc":318},[276,278,280,282,284,286,302,304],[10,277,13],{"id":12},[15,279,17],{},[15,281,20],{},[10,283,24],{"id":23},[15,285,27],{},[29,287,288,290,292,296,298,300],{},[32,289,34],{},[32,291,37],{},[32,293,40,294,45],{},[42,295,44],{},[32,297,48],{},[32,299,51],{},[32,301,54],{},[10,303,58],{"id":57},[29,305,306,308,310,312,314,316],{},[32,307,63],{},[32,309,66],{},[32,311,69],{},[32,313,72],{},[32,315,75],{},[32,317,78],{},{"title":80,"searchDepth":81,"depth":81,"links":319},[320,321,322],{"id":12,"depth":81,"text":13},{"id":23,"depth":81,"text":24},{"id":57,"depth":81,"text":58},[87,88,89],{},[99,100,101],{"title":5,"description":90},{"id":328,"title":329,"body":330,"citations":390,"description":394,"extension":91,"hook":395,"icon":396,"meta":397,"navigation":95,"order":398,"path":399,"regulators":400,"sector":401,"seo":402,"stem":403,"__hash__":404},"sectors\u002Fsectors\u002Fbpo.md","BPO, IT and outsourcing",{"type":7,"value":331,"toc":385},[332,336,339,342,345,349,360,362],[10,333,335],{"id":334},"sell-it-as-sales-enablement-not-as-compliance","Sell it as sales enablement, not as compliance",[15,337,338],{},"Foreign controllers audit their Philippine processors. That is the whole\ncommercial argument.",[15,340,341],{},"An assurance pack that answers a controller's audit in a week rather than a month\nis a competitive advantage you can actually measure — in deals closed, in\nonboarding time, and in how far into the procurement process you get before\nsomeone asks for documentation you do not have.",[15,343,344],{},"Most Philippine BPOs treat privacy as an overhead. The ones that treat it as part\nof the sales collateral win work from the ones that do not.",[10,346,348],{"id":347},"controller-or-processor-usually-both","Controller or processor — usually both",[15,350,351,352,355,356,359],{},"You are a ",[42,353,354],{},"Personal Information Processor"," for your clients' data and a\n",[42,357,358],{},"Personal Information Controller"," for your own employees' data. The obligations\ndiffer, and conflating them is the most common structural error in this sector.",[10,361,58],{"id":57},[29,363,364,367,370,373,376,379,382],{},[32,365,366],{},"Outsourcing agreements meeting IRR Rule X §§43–45, in a form a foreign\ncontroller's counsel will accept without redlining",[32,368,369],{},"A standing assurance pack: security measures, sub-processor list, breach\nprocedure, retention, deletion and return-of-data commitments",[32,371,372],{},"Sub-processor management and flow-down obligations",[32,374,375],{},"Cross-border transfer positions — there is no Philippine adequacy regime, so\nthe controller stays accountable under DPA §21, and the NPC's Model Contractual\nClauses under Advisory 2024-01 are voluntary and will not be reviewed or\nendorsed by the Commission",[32,377,378],{},"Breach notification that satisfies both your client's contract and the NPC clock",[32,380,381],{},"Segregation between client data and your own employee data",[32,383,384],{},"Agent-level access controls, and the evidence that they are enforced",{"title":80,"searchDepth":81,"depth":81,"links":386},[387,388,389],{"id":334,"depth":81,"text":335},{"id":347,"depth":81,"text":348},{"id":57,"depth":81,"text":58},[391,392,393],"Data Privacy Act §21","IRR Rule X §§43–45","NPC Advisory 2024-01","Data privacy compliance for Philippine BPOs, IT service providers and outsourcing firms processing personal data for foreign controllers.","For a BPO, privacy compliance is not a cost of regulation. It is a condition of winning work.","i-lucide-headset",{},4,"\u002Fsectors\u002Fbpo",[99],"bpo",{"title":329,"description":394},"sectors\u002Fbpo","YsZhoX5TOoFB02OR43qkb4skaBHCN1FKC_0byvEjZzE",1785320187282]