CyberCode.ph · Philippines

What Is Personal Information Under the Philippine Data Privacy Act?

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 2, 2026

Direct Answer

Under the Philippine Data Privacy Act of 2012, personal information is information from which an individual’s identity is apparent, can reasonably and directly be determined, or can be identified when the information is combined with other data (RA 10173, Sec. 3). This means a name is not the only type of information that can be personal information. Contact details, account information, online identifiers, photographs, transaction records and other data may also qualify depending on context.

The governing law is Republic Act No. 10173, the Data Privacy Act of 2012, administered by the National Privacy Commission. If personal information about you is being processed, see Data Privacy Rights in the Philippines for the rights you may exercise as a data subject.

Primary authority: Republic Act No. 10173 — Data Privacy Act of 2012.

Key Takeaways

  • Personal information is not limited to a person’s name.
  • Information can still be personal information if it identifies someone only when combined with other data.
  • Some personal information is classified separately as sensitive personal information.
  • Organizations should classify the personal data they collect before deciding how it should be processed, stored, shared or protected.
  • Whether a data point identifies a person can depend heavily on context.

Jump to a Section

What Is the Legal Definition of Personal Information?

Section 3 of Republic Act No. 10173 defines personal information broadly. In practical terms, the definition covers information where the identity of an individual is already apparent, can reasonably and directly be determined by the entity holding the information, or becomes identifiable when combined with other information.

This is an important rule because it prevents organizations from treating information as anonymous merely because a person’s full name is missing.

Decision Snapshot

InformationCan it be personal information?Why?
Full nameYesIt may directly identify an individual.
Email addressYesIt may identify or be linked to a specific person.
Mobile numberYesIt may be associated with an identifiable individual.
Customer account IDOftenThe organization may be able to connect it to a customer record.
PhotographOftenA recognizable image can identify a person.
IP address or device identifierPotentiallyContext and the ability to associate it with a person matter.
Anonymous aggregate statisticsNot necessarilyProperly anonymized data may no longer identify an individual.

Examples of Personal Information

Personal information can appear throughout ordinary business systems. Common examples may include:

  • name
  • home or delivery address
  • email address
  • mobile or telephone number
  • customer or employee account number
  • photographs or video images
  • transaction history
  • support tickets and customer correspondence
  • online account identifiers
  • location or device information that can be connected to an individual

The correct question is not simply, “Does this field contain a name?” The more useful question is:

Can this information identify a person directly, or can our organization identify that person by combining it with other information we possess?

Can Information Become Personal Information When Combined With Other Data?

Yes. This is one of the most important parts of the Philippine definition.

Imagine an exported database containing only:

  • Customer ID 84721
  • Purchase date
  • Product purchased

Someone outside the company may not know who Customer ID 84721 is. But if the company can look up that identifier in its CRM and immediately connect it to a named customer, the information should not automatically be treated as anonymous.

This matters when organizations export data for analytics, marketing, AI systems, testing environments or third-party vendors.

Personal Information Is Context-Dependent

The same data point can present different privacy implications depending on who holds it and what additional information is available.

For example, a random transaction reference may mean nothing to the public. To the payment platform that can connect the reference to a named account holder, it may form part of identifiable personal data.

This is why organizations should assess identifiability based on their actual systems and data relationships rather than judging fields in isolation.

What Is the Difference Between Personal Information and Sensitive Personal Information?

Sensitive personal information is a specially protected category of personal information under the Data Privacy Act. The law lists categories that include information about matters such as race, ethnic origin, marital status, age, religious or political affiliations, health, education, genetic or sexual life, certain legal proceedings and government-issued information peculiar to an individual.

Government-issued identifiers can therefore deserve particular attention. Depending on the circumstances, examples may include social-security information, tax records, licenses and similar records specifically described by law.

The processing rules for sensitive personal information are stricter than the general rules for ordinary personal information. See What Is Sensitive Personal Information Under RA 10173? for the dedicated definition and processing guide.

What Is Privileged Information?

The Data Privacy Act also recognizes privileged information. This generally refers to information that constitutes privileged communication under the Rules of Court or other applicable laws.

Privileged information should not simply be treated as another synonym for sensitive personal information. It is a distinct legal category.

Is Publicly Available Information Still Personal Information?

Information does not automatically stop being personal information merely because someone has posted it online or because it can be found publicly.

The privacy analysis should instead consider the applicable processing activity, lawful basis, purpose, context and any relevant exceptions under the Data Privacy Act.

A public social-media profile, for example, should not be interpreted as unlimited permission for every organization to collect, combine, profile and reuse the information for any purpose.

Is an Email Address Personal Information?

It can be. An email address that identifies or can readily be associated with an individual can fall within the concept of personal information.

A personal address such as maria.santos@example.com may obviously identify a person. Even a less descriptive address may still be personal information where an organization can connect it with a specific account holder.

Is a Phone Number Personal Information?

Often, yes. A mobile number can be linked to an identifiable individual, particularly where it is stored together with customer, employee or account records.

Are Photos and CCTV Images Personal Information?

Images can constitute personal information when an individual is identifiable from them. This makes privacy considerations relevant to photographs, surveillance footage, workplace CCTV and other video systems.

The legality of CCTV use involves additional questions about purpose, notice, proportionality, access and retention and should be addressed separately from the basic definition of personal information.

Are IP Addresses, Cookies and Device IDs Personal Information?

They can be, depending on context. The key issue is whether the information can identify or be associated with an individual, either by itself or together with other information reasonably available to the organization.

Businesses should therefore avoid assuming that digital identifiers are automatically anonymous simply because they are technical rather than human-readable.

Does Pseudonymized Data Stop Being Personal Information?

Not necessarily.

If identifiers have merely been replaced with codes but the organization retains a key or other information that allows individuals to be reidentified, privacy obligations may still remain relevant.

True anonymization is different because properly anonymized information should no longer identify an individual. Whether anonymization is effective is a factual and technical question, not simply a label placed on a dataset.

What Should Businesses Do With Personal Information?

A practical privacy program starts by knowing what data the organization actually holds.

Minimum Practical Data Inventory

  1. List the categories of personal information you collect.
  2. Identify whose data it is: customers, employees, applicants, vendors or others.
  3. Record why each category is needed.
  4. Identify which systems and vendors receive the information.
  5. Determine whether any data is sensitive personal information or privileged information.
  6. Document who can access the information.
  7. Establish retention and deletion rules.
  8. Review appropriate organizational, physical and technical safeguards.

This inventory becomes the foundation for privacy notices, access control, retention schedules, vendor reviews, data breach response and privacy impact assessments.

Why This Definition Matters During a Data Breach

When an incident occurs, one of the first questions is whether the affected systems contained personal data and what type of personal data was involved.

An organization that has already classified its information can investigate more quickly than one that does not know what data resides in each system.

This is why data classification is not merely administrative housekeeping. It directly affects incident response and regulatory analysis.

Why This Definition Matters for AI

Organizations increasingly send information into generative AI, analytics and automation tools. Before doing so, they should determine whether prompts, uploaded documents, customer conversations or training datasets contain personal information.

Removing a customer’s name does not necessarily make the information anonymous if account identifiers, transaction details or other information still allow the person to be identified.

Frequently Asked Questions

Is a name always personal information?

A name can be personal information when it identifies an individual, but identifiability depends on context. The Data Privacy Act is not limited to names.

Can information be personal even if the person’s name is removed?

Yes. Information can still be personal information if an individual can be identified when it is combined with other information.

Is health information personal information?

Yes, and health information can fall within the more protected category of sensitive personal information under the Data Privacy Act.

Is an employee ID number personal information?

It can be when the employer can use the identifier to connect the record to a specific employee.

Is public information exempt from the Data Privacy Act?

Not automatically. Public availability does not by itself create unrestricted permission for every type of processing.

What should a business do first?

Start with a data inventory identifying what personal information is collected, why it is needed, where it is stored, who receives it and how long it is retained.

Related Cybercode Guides

Official Sources

Cybercode.ph provides general educational information about privacy, cybersecurity and technology law. It is not a substitute for legal or professional advice for a specific situation.