[{"data":1,"prerenderedAt":405},["ShallowReactive",2],{"sector-\u002Fservices\u002Fdpo-as-a-service\u002Fsectors\u002Fhealth":3,"sectors-other-\u002Fservices\u002Fdpo-as-a-service\u002Fsectors\u002Fhealth":112},{"id":4,"title":5,"body":6,"citations":91,"description":96,"extension":97,"hook":98,"icon":99,"meta":100,"navigation":101,"order":102,"path":103,"regulators":104,"sector":108,"seo":109,"stem":110,"__hash__":111},"sectors\u002Fsectors\u002Fhealth.md","Health",{"type":7,"value":8,"toc":84},"minimark",[9,14,27,34,38,45,48,52],[10,11,13],"h2",{"id":12},"why-health-is-different","Why health is different",[15,16,17,18,22,23,26],"p",{},"Under the Data Privacy Act, health information is ",[19,20,21],"strong",{},"sensitive personal\ninformation",". That matters more than it sounds, because sensitive personal\ninformation is governed by ",[19,24,25],{},"Section 13",", not Section 12 — and Section 13 is\nconsiderably narrower.",[15,28,29,30,33],{},"The consequence that surprises people most: ",[19,31,32],{},"performance of a contract is not a\nlawful basis for processing sensitive personal information."," A clinic cannot\nrely on \"we need it to treat the patient\" the way a retailer relies on \"we need\nit to ship the order\". The basis has to come from the Section 13 list.",[10,35,37],{"id":36},"two-clocks-not-one","Two clocks, not one",[15,39,40,41,44],{},"A notifiable breach starts the 72-hour clock to the National Privacy Commission.\nHealth-sector reporting obligations run ",[19,42,43],{},"in addition"," to that, on their own\ntimetable.",[15,46,47],{},"Notifying the NPC does not discharge a separate obligation to notify a sector\nregulator, and the two deadlines are rarely the same.",[10,49,51],{"id":50},"what-the-overlay-covers","What the overlay covers",[53,54,55,59,66,69,72,75,78,81],"ul",{},[56,57,58],"li",{},"Lawful bases mapped to Section 13 rather than Section 12, per processing activity",[56,60,61,62,65],{},"Medical record retention — ",[19,63,64],{},"15 years",", and effectively lifetime where there is\nmedico-legal exposure",[56,67,68],{},"Encryption standards for records at rest and in transit",[56,70,71],{},"Laboratory tiering obligations under DOH AO 2022-0007",[56,73,74],{},"Telemedicine consent and platform assessment under Joint AO 2021-0001",[56,76,77],{},"PhilHealth eClaims record retention",[56,79,80],{},"Consent handling for research, teaching files and case photography",[56,82,83],{},"CCTV in clinical areas, under NPC Circular 2024-02",{"title":85,"searchDepth":86,"depth":86,"links":87},"",2,[88,89,90],{"id":12,"depth":86,"text":13},{"id":36,"depth":86,"text":37},{"id":50,"depth":86,"text":51},[92,93,94,95],"Data Privacy Act §13","DOH AO 2020-0030","DOH AO 2022-0007","Joint AO 2021-0001","Data privacy compliance for hospitals, clinics, laboratories, HMOs and telemedicine providers in the Philippines.","md","Almost everything a health provider holds is sensitive personal information, and the lawful bases for it are narrower than most clinics assume.","i-lucide-stethoscope",{},true,1,"\u002Fsectors\u002Fhealth",[105,106,107],"National Privacy Commission","Department of Health","PhilHealth","health",{"title":5,"description":96},"sectors\u002Fhealth","VDIU2EikxVUCcT81P2YEGQBh-ywAP-rKUHJnqy1Sot4",[113,167,238,327],{"id":4,"title":5,"body":114,"citations":163,"description":96,"extension":97,"hook":98,"icon":99,"meta":164,"navigation":101,"order":102,"path":103,"regulators":165,"sector":108,"seo":166,"stem":110,"__hash__":111},{"type":7,"value":115,"toc":158},[116,118,124,128,130,134,136,138],[10,117,13],{"id":12},[15,119,17,120,22,122,26],{},[19,121,21],{},[19,123,25],{},[15,125,29,126,33],{},[19,127,32],{},[10,129,37],{"id":36},[15,131,40,132,44],{},[19,133,43],{},[15,135,47],{},[10,137,51],{"id":50},[53,139,140,142,146,148,150,152,154,156],{},[56,141,58],{},[56,143,61,144,65],{},[19,145,64],{},[56,147,68],{},[56,149,71],{},[56,151,74],{},[56,153,77],{},[56,155,80],{},[56,157,83],{},{"title":85,"searchDepth":86,"depth":86,"links":159},[160,161,162],{"id":12,"depth":86,"text":13},{"id":36,"depth":86,"text":37},{"id":50,"depth":86,"text":51},[92,93,94,95],{},[105,106,107],{"title":5,"description":96},{"id":168,"title":169,"body":170,"citations":220,"description":225,"extension":97,"hook":226,"icon":227,"meta":228,"navigation":101,"order":86,"path":229,"regulators":230,"sector":234,"seo":235,"stem":236,"__hash__":237},"sectors\u002Fsectors\u002Ffinance.md","Finance and lending",{"type":7,"value":171,"toc":216},[172,176,179,185,188,190],[10,173,175],{"id":174},"where-the-enforcement-actually-is","Where the enforcement actually is",[15,177,178],{},"If you are a lending or financing company, this is the part to read first.",[15,180,181,184],{},[19,182,183],{},"The contact-list prohibition is absolute."," SEC MC 18-2019 bars accessing a\nborrower's phone contacts for collection purposes. Consent does not cure it. An\napp that requests contacts permission is a finding regardless of what the user\nagreed to, and regardless of whether the permission was ever used.",[15,186,187],{},"Online lending has generated more Philippine data privacy enforcement than any\nother sector, and the pattern is consistent: unfair collection practices,\nexcessive permissions, and disclosure to third parties who had no business\nreceiving the data.",[10,189,51],{"id":50},[53,191,192,195,198,201,204,207,210,213],{},[56,193,194],{},"Lawful basis and consent design for loan-related processing, under NPC\nCircular 20-01 as amended by 2022-02",[56,196,197],{},"Mobile app permission review — contacts, location, storage, camera — against\nwhat the service genuinely requires",[56,199,200],{},"Debt collection practices assessed against SEC MC 18-2019",[56,202,203],{},"Credit scoring and automated decision-making, which is itself an NPC\nregistration trigger",[56,205,206],{},"Outsourcing and service provider agreements meeting BSP expectations",[56,208,209],{},"Financial consumer protection obligations under RA 11765",[56,211,212],{},"Cross-border transfer where processing or storage sits offshore",[56,214,215],{},"AMLA record retention reconciled against data minimization",{"title":85,"searchDepth":86,"depth":86,"links":217},[218,219],{"id":174,"depth":86,"text":175},{"id":50,"depth":86,"text":51},[221,222,223,224],"SEC MC 18-2019","NPC Circular 20-01 as amended by 2022-02","BSP Circular 1160","RA 11765","Data privacy compliance for banks, e-money issuers, fintech, lending and financing companies, and insurers in the Philippines.","The highest-enforcement area in the country. Online lending has produced more Philippine data privacy enforcement than any other sector.","i-lucide-landmark",{},"\u002Fsectors\u002Ffinance",[105,231,232,233],"Bangko Sentral ng Pilipinas","Securities and Exchange Commission","Insurance Commission","finance",{"title":169,"description":225},"sectors\u002Ffinance","JP7i0FOSzMMDfhfvWR9u2fZiMArCMZf75E9ISfWaNOs",{"id":239,"title":240,"body":241,"citations":311,"description":314,"extension":97,"hook":315,"icon":316,"meta":317,"navigation":101,"order":318,"path":319,"regulators":320,"sector":323,"seo":324,"stem":325,"__hash__":326},"sectors\u002Fsectors\u002Feducation.md","Education",{"type":7,"value":242,"toc":306},[243,247,250,253,257,260,284,286],[10,244,246],{"id":245},"why-this-sector-is-harder-than-it-looks","Why this sector is harder than it looks",[15,248,249],{},"Schools hold sensitive personal information about minors, which is the most\nscrutinised category of processing there is — and they receive less\nsector-specific guidance than health or finance.",[15,251,252],{},"That combination cuts both ways. There is less prescriptive detail to comply\nwith, and correspondingly more room to get it wrong. A written program that\nstates clearly how the school handles each situation is worth more here than\nalmost anywhere else, because there is no regulator template to fall back on.",[10,254,256],{"id":255},"the-situations-that-come-up","The situations that come up",[15,258,259],{},"Most of a school's privacy risk sits in ordinary daily practice, not in systems:",[53,261,262,265,268,275,278,281],{},[56,263,264],{},"Honor rolls, awards lists and photographs published without a consent basis",[56,266,267],{},"Learning management systems and video conferencing adopted quickly, with no\nPrivacy Impact Assessment behind them",[56,269,270,271,274],{},"Requests for records from a ",[19,272,273],{},"non-custodial parent",", where a policy decision\nhas to be made under pressure",[56,276,277],{},"Alumni and marketing communications using data collected for enrollment",[56,279,280],{},"Classroom and corridor CCTV, under NPC Circular 2024-02",[56,282,283],{},"Third-party providers — bus operators, canteen concessionaires, photographers,\nyearbook publishers — receiving student data with no agreement in place",[10,285,51],{"id":50},[53,287,288,291,294,297,300,303],{},[56,289,290],{},"Transparency written for children as well as for parents, per NPC Advisory 2024-03",[56,292,293],{},"Consent and legitimate interest mapped for each publication and communication type",[56,295,296],{},"PIAs for the learning platform, the student information system and video conferencing",[56,298,299],{},"A records retention schedule spanning enrollment through alumni relations",[56,301,302],{},"A written procedure for parental and student access requests",[56,304,305],{},"Staff training pitched at teachers and registrars rather than at IT",{"title":85,"searchDepth":86,"depth":86,"links":307},[308,309,310],{"id":245,"depth":86,"text":246},{"id":255,"depth":86,"text":256},{"id":50,"depth":86,"text":51},[92,312,313],"NPC Circular 2024-02","NPC Advisory 2024-03","Data privacy compliance for schools, colleges and universities in the Philippines, covering student records, learning platforms and campus CCTV.","The sector with the least regulator-specific guidance — which is exactly why a clear, written program is worth so much here.","i-lucide-graduation-cap",{},3,"\u002Fsectors\u002Feducation",[105,321,322],"Department of Education","Commission on Higher Education","education",{"title":240,"description":314},"sectors\u002Feducation","Kmsd1Eegw5N7FoPO13mmbT2es5jpPJGqXBSsXA1P6n8",{"id":328,"title":329,"body":330,"citations":390,"description":394,"extension":97,"hook":395,"icon":396,"meta":397,"navigation":101,"order":398,"path":399,"regulators":400,"sector":401,"seo":402,"stem":403,"__hash__":404},"sectors\u002Fsectors\u002Fbpo.md","BPO, IT and outsourcing",{"type":7,"value":331,"toc":385},[332,336,339,342,345,349,360,362],[10,333,335],{"id":334},"sell-it-as-sales-enablement-not-as-compliance","Sell it as sales enablement, not as compliance",[15,337,338],{},"Foreign controllers audit their Philippine processors. That is the whole\ncommercial argument.",[15,340,341],{},"An assurance pack that answers a controller's audit in a week rather than a month\nis a competitive advantage you can actually measure — in deals closed, in\nonboarding time, and in how far into the procurement process you get before\nsomeone asks for documentation you do not have.",[15,343,344],{},"Most Philippine BPOs treat privacy as an overhead. The ones that treat it as part\nof the sales collateral win work from the ones that do not.",[10,346,348],{"id":347},"controller-or-processor-usually-both","Controller or processor — usually both",[15,350,351,352,355,356,359],{},"You are a ",[19,353,354],{},"Personal Information Processor"," for your clients' data and a\n",[19,357,358],{},"Personal Information Controller"," for your own employees' data. The obligations\ndiffer, and conflating them is the most common structural error in this sector.",[10,361,51],{"id":50},[53,363,364,367,370,373,376,379,382],{},[56,365,366],{},"Outsourcing agreements meeting IRR Rule X §§43–45, in a form a foreign\ncontroller's counsel will accept without redlining",[56,368,369],{},"A standing assurance pack: security measures, sub-processor list, breach\nprocedure, retention, deletion and return-of-data commitments",[56,371,372],{},"Sub-processor management and flow-down obligations",[56,374,375],{},"Cross-border transfer positions — there is no Philippine adequacy regime, so\nthe controller stays accountable under DPA §21, and the NPC's Model Contractual\nClauses under Advisory 2024-01 are voluntary and will not be reviewed or\nendorsed by the Commission",[56,377,378],{},"Breach notification that satisfies both your client's contract and the NPC clock",[56,380,381],{},"Segregation between client data and your own employee data",[56,383,384],{},"Agent-level access controls, and the evidence that they are enforced",{"title":85,"searchDepth":86,"depth":86,"links":386},[387,388,389],{"id":334,"depth":86,"text":335},{"id":347,"depth":86,"text":348},{"id":50,"depth":86,"text":51},[391,392,393],"Data Privacy Act §21","IRR Rule X §§43–45","NPC Advisory 2024-01","Data privacy compliance for Philippine BPOs, IT service providers and outsourcing firms processing personal data for foreign controllers.","For a BPO, privacy compliance is not a cost of regulation. It is a condition of winning work.","i-lucide-headset",{},4,"\u002Fsectors\u002Fbpo",[105],"bpo",{"title":329,"description":394},"sectors\u002Fbpo","YsZhoX5TOoFB02OR43qkb4skaBHCN1FKC_0byvEjZzE",1785320187282]