[{"data":1,"prerenderedAt":392},["ShallowReactive",2],{"sector-\u002Fservices\u002Fdpo-as-a-service\u002Fsectors\u002Ffinance":3,"sectors-other-\u002Fservices\u002Fdpo-as-a-service\u002Fsectors\u002Ffinance":87},{"id":4,"title":5,"body":6,"citations":66,"description":71,"extension":72,"hook":73,"icon":74,"meta":75,"navigation":76,"order":62,"path":77,"regulators":78,"sector":83,"seo":84,"stem":85,"__hash__":86},"sectors\u002Fsectors\u002Ffinance.md","Finance and lending",{"type":7,"value":8,"toc":60},"minimark",[9,14,18,25,28,32],[10,11,13],"h2",{"id":12},"where-the-enforcement-actually-is","Where the enforcement actually is",[15,16,17],"p",{},"If you are a lending or financing company, this is the part to read first.",[15,19,20,24],{},[21,22,23],"strong",{},"The contact-list prohibition is absolute."," SEC MC 18-2019 bars accessing a\nborrower's phone contacts for collection purposes. Consent does not cure it. An\napp that requests contacts permission is a finding regardless of what the user\nagreed to, and regardless of whether the permission was ever used.",[15,26,27],{},"Online lending has generated more Philippine data privacy enforcement than any\nother sector, and the pattern is consistent: unfair collection practices,\nexcessive permissions, and disclosure to third parties who had no business\nreceiving the data.",[10,29,31],{"id":30},"what-the-overlay-covers","What the overlay covers",[33,34,35,39,42,45,48,51,54,57],"ul",{},[36,37,38],"li",{},"Lawful basis and consent design for loan-related processing, under NPC\nCircular 20-01 as amended by 2022-02",[36,40,41],{},"Mobile app permission review — contacts, location, storage, camera — against\nwhat the service genuinely requires",[36,43,44],{},"Debt collection practices assessed against SEC MC 18-2019",[36,46,47],{},"Credit scoring and automated decision-making, which is itself an NPC\nregistration trigger",[36,49,50],{},"Outsourcing and service provider agreements meeting BSP expectations",[36,52,53],{},"Financial consumer protection obligations under RA 11765",[36,55,56],{},"Cross-border transfer where processing or storage sits offshore",[36,58,59],{},"AMLA record retention reconciled against data minimization",{"title":61,"searchDepth":62,"depth":62,"links":63},"",2,[64,65],{"id":12,"depth":62,"text":13},{"id":30,"depth":62,"text":31},[67,68,69,70],"SEC MC 18-2019","NPC Circular 20-01 as amended by 2022-02","BSP Circular 1160","RA 11765","Data privacy compliance for banks, e-money issuers, fintech, lending and financing companies, and insurers in the Philippines.","md","The highest-enforcement area in the country. Online lending has produced more Philippine data privacy enforcement than any other sector.","i-lucide-landmark",{},true,"\u002Fsectors\u002Ffinance",[79,80,81,82],"National Privacy Commission","Bangko Sentral ng Pilipinas","Securities and Exchange Commission","Insurance Commission","finance",{"title":5,"description":71},"sectors\u002Ffinance","JP7i0FOSzMMDfhfvWR9u2fZiMArCMZf75E9ISfWaNOs",[88,184,225,314],{"id":89,"title":90,"body":91,"citations":166,"description":171,"extension":72,"hook":172,"icon":173,"meta":174,"navigation":76,"order":175,"path":176,"regulators":177,"sector":180,"seo":181,"stem":182,"__hash__":183},"sectors\u002Fsectors\u002Fhealth.md","Health",{"type":7,"value":92,"toc":161},[93,97,108,115,119,126,129,131],[10,94,96],{"id":95},"why-health-is-different","Why health is different",[15,98,99,100,103,104,107],{},"Under the Data Privacy Act, health information is ",[21,101,102],{},"sensitive personal\ninformation",". That matters more than it sounds, because sensitive personal\ninformation is governed by ",[21,105,106],{},"Section 13",", not Section 12 — and Section 13 is\nconsiderably narrower.",[15,109,110,111,114],{},"The consequence that surprises people most: ",[21,112,113],{},"performance of a contract is not a\nlawful basis for processing sensitive personal information."," A clinic cannot\nrely on \"we need it to treat the patient\" the way a retailer relies on \"we need\nit to ship the order\". The basis has to come from the Section 13 list.",[10,116,118],{"id":117},"two-clocks-not-one","Two clocks, not one",[15,120,121,122,125],{},"A notifiable breach starts the 72-hour clock to the National Privacy Commission.\nHealth-sector reporting obligations run ",[21,123,124],{},"in addition"," to that, on their own\ntimetable.",[15,127,128],{},"Notifying the NPC does not discharge a separate obligation to notify a sector\nregulator, and the two deadlines are rarely the same.",[10,130,31],{"id":30},[33,132,133,136,143,146,149,152,155,158],{},[36,134,135],{},"Lawful bases mapped to Section 13 rather than Section 12, per processing activity",[36,137,138,139,142],{},"Medical record retention — ",[21,140,141],{},"15 years",", and effectively lifetime where there is\nmedico-legal exposure",[36,144,145],{},"Encryption standards for records at rest and in transit",[36,147,148],{},"Laboratory tiering obligations under DOH AO 2022-0007",[36,150,151],{},"Telemedicine consent and platform assessment under Joint AO 2021-0001",[36,153,154],{},"PhilHealth eClaims record retention",[36,156,157],{},"Consent handling for research, teaching files and case photography",[36,159,160],{},"CCTV in clinical areas, under NPC Circular 2024-02",{"title":61,"searchDepth":62,"depth":62,"links":162},[163,164,165],{"id":95,"depth":62,"text":96},{"id":117,"depth":62,"text":118},{"id":30,"depth":62,"text":31},[167,168,169,170],"Data Privacy Act §13","DOH AO 2020-0030","DOH AO 2022-0007","Joint AO 2021-0001","Data privacy compliance for hospitals, clinics, laboratories, HMOs and telemedicine providers in the Philippines.","Almost everything a health provider holds is sensitive personal information, and the lawful bases for it are narrower than most clinics assume.","i-lucide-stethoscope",{},1,"\u002Fsectors\u002Fhealth",[79,178,179],"Department of Health","PhilHealth","health",{"title":90,"description":171},"sectors\u002Fhealth","VDIU2EikxVUCcT81P2YEGQBh-ywAP-rKUHJnqy1Sot4",{"id":4,"title":5,"body":185,"citations":221,"description":71,"extension":72,"hook":73,"icon":74,"meta":222,"navigation":76,"order":62,"path":77,"regulators":223,"sector":83,"seo":224,"stem":85,"__hash__":86},{"type":7,"value":186,"toc":217},[187,189,191,195,197,199],[10,188,13],{"id":12},[15,190,17],{},[15,192,193,24],{},[21,194,23],{},[15,196,27],{},[10,198,31],{"id":30},[33,200,201,203,205,207,209,211,213,215],{},[36,202,38],{},[36,204,41],{},[36,206,44],{},[36,208,47],{},[36,210,50],{},[36,212,53],{},[36,214,56],{},[36,216,59],{},{"title":61,"searchDepth":62,"depth":62,"links":218},[219,220],{"id":12,"depth":62,"text":13},{"id":30,"depth":62,"text":31},[67,68,69,70],{},[79,80,81,82],{"title":5,"description":71},{"id":226,"title":227,"body":228,"citations":298,"description":301,"extension":72,"hook":302,"icon":303,"meta":304,"navigation":76,"order":305,"path":306,"regulators":307,"sector":310,"seo":311,"stem":312,"__hash__":313},"sectors\u002Fsectors\u002Feducation.md","Education",{"type":7,"value":229,"toc":293},[230,234,237,240,244,247,271,273],[10,231,233],{"id":232},"why-this-sector-is-harder-than-it-looks","Why this sector is harder than it looks",[15,235,236],{},"Schools hold sensitive personal information about minors, which is the most\nscrutinised category of processing there is — and they receive less\nsector-specific guidance than health or finance.",[15,238,239],{},"That combination cuts both ways. There is less prescriptive detail to comply\nwith, and correspondingly more room to get it wrong. A written program that\nstates clearly how the school handles each situation is worth more here than\nalmost anywhere else, because there is no regulator template to fall back on.",[10,241,243],{"id":242},"the-situations-that-come-up","The situations that come up",[15,245,246],{},"Most of a school's privacy risk sits in ordinary daily practice, not in systems:",[33,248,249,252,255,262,265,268],{},[36,250,251],{},"Honor rolls, awards lists and photographs published without a consent basis",[36,253,254],{},"Learning management systems and video conferencing adopted quickly, with no\nPrivacy Impact Assessment behind them",[36,256,257,258,261],{},"Requests for records from a ",[21,259,260],{},"non-custodial parent",", where a policy decision\nhas to be made under pressure",[36,263,264],{},"Alumni and marketing communications using data collected for enrollment",[36,266,267],{},"Classroom and corridor CCTV, under NPC Circular 2024-02",[36,269,270],{},"Third-party providers — bus operators, canteen concessionaires, photographers,\nyearbook publishers — receiving student data with no agreement in place",[10,272,31],{"id":30},[33,274,275,278,281,284,287,290],{},[36,276,277],{},"Transparency written for children as well as for parents, per NPC Advisory 2024-03",[36,279,280],{},"Consent and legitimate interest mapped for each publication and communication type",[36,282,283],{},"PIAs for the learning platform, the student information system and video conferencing",[36,285,286],{},"A records retention schedule spanning enrollment through alumni relations",[36,288,289],{},"A written procedure for parental and student access requests",[36,291,292],{},"Staff training pitched at teachers and registrars rather than at IT",{"title":61,"searchDepth":62,"depth":62,"links":294},[295,296,297],{"id":232,"depth":62,"text":233},{"id":242,"depth":62,"text":243},{"id":30,"depth":62,"text":31},[167,299,300],"NPC Circular 2024-02","NPC Advisory 2024-03","Data privacy compliance for schools, colleges and universities in the Philippines, covering student records, learning platforms and campus CCTV.","The sector with the least regulator-specific guidance — which is exactly why a clear, written program is worth so much here.","i-lucide-graduation-cap",{},3,"\u002Fsectors\u002Feducation",[79,308,309],"Department of Education","Commission on Higher Education","education",{"title":227,"description":301},"sectors\u002Feducation","Kmsd1Eegw5N7FoPO13mmbT2es5jpPJGqXBSsXA1P6n8",{"id":315,"title":316,"body":317,"citations":377,"description":381,"extension":72,"hook":382,"icon":383,"meta":384,"navigation":76,"order":385,"path":386,"regulators":387,"sector":388,"seo":389,"stem":390,"__hash__":391},"sectors\u002Fsectors\u002Fbpo.md","BPO, IT and outsourcing",{"type":7,"value":318,"toc":372},[319,323,326,329,332,336,347,349],[10,320,322],{"id":321},"sell-it-as-sales-enablement-not-as-compliance","Sell it as sales enablement, not as compliance",[15,324,325],{},"Foreign controllers audit their Philippine processors. That is the whole\ncommercial argument.",[15,327,328],{},"An assurance pack that answers a controller's audit in a week rather than a month\nis a competitive advantage you can actually measure — in deals closed, in\nonboarding time, and in how far into the procurement process you get before\nsomeone asks for documentation you do not have.",[15,330,331],{},"Most Philippine BPOs treat privacy as an overhead. The ones that treat it as part\nof the sales collateral win work from the ones that do not.",[10,333,335],{"id":334},"controller-or-processor-usually-both","Controller or processor — usually both",[15,337,338,339,342,343,346],{},"You are a ",[21,340,341],{},"Personal Information Processor"," for your clients' data and a\n",[21,344,345],{},"Personal Information Controller"," for your own employees' data. The obligations\ndiffer, and conflating them is the most common structural error in this sector.",[10,348,31],{"id":30},[33,350,351,354,357,360,363,366,369],{},[36,352,353],{},"Outsourcing agreements meeting IRR Rule X §§43–45, in a form a foreign\ncontroller's counsel will accept without redlining",[36,355,356],{},"A standing assurance pack: security measures, sub-processor list, breach\nprocedure, retention, deletion and return-of-data commitments",[36,358,359],{},"Sub-processor management and flow-down obligations",[36,361,362],{},"Cross-border transfer positions — there is no Philippine adequacy regime, so\nthe controller stays accountable under DPA §21, and the NPC's Model Contractual\nClauses under Advisory 2024-01 are voluntary and will not be reviewed or\nendorsed by the Commission",[36,364,365],{},"Breach notification that satisfies both your client's contract and the NPC clock",[36,367,368],{},"Segregation between client data and your own employee data",[36,370,371],{},"Agent-level access controls, and the evidence that they are enforced",{"title":61,"searchDepth":62,"depth":62,"links":373},[374,375,376],{"id":321,"depth":62,"text":322},{"id":334,"depth":62,"text":335},{"id":30,"depth":62,"text":31},[378,379,380],"Data Privacy Act §21","IRR Rule X §§43–45","NPC Advisory 2024-01","Data privacy compliance for Philippine BPOs, IT service providers and outsourcing firms processing personal data for foreign controllers.","For a BPO, privacy compliance is not a cost of regulation. It is a condition of winning work.","i-lucide-headset",{},4,"\u002Fsectors\u002Fbpo",[79],"bpo",{"title":316,"description":381},"sectors\u002Fbpo","YsZhoX5TOoFB02OR43qkb4skaBHCN1FKC_0byvEjZzE",1785320187282]