Last materially reviewed: September 25, 2026
Direct Answer
Personal information is any information that identifies—or can be combined to identify—an individual. Sensitive personal information is a legally defined, higher-risk subset covering matters such as age, marital status, health, education, genetic or sexual life, offense proceedings, specified government-issued information, and information classified by law. Under Republic Act No. 10173, both require lawful and secure processing, but sensitive information is subject to narrower legal grounds and greater consequences when mishandled.
Evidence and action
Key Takeaways
- Sensitive personal information is a subset of personal information, not a completely separate universe of data.
- Age, marital status and education records are sensitive personal information under the Philippine statute, even if a business treats them as routine form fields.
- A name, email address, phone number, photograph, customer ID or device identifier can be personal information when it identifies or can be linked to an individual.
- Salary and ordinary financial transaction details are personal information but are not automatically sensitive personal information merely because they are confidential; the exact record and other applicable laws still matter.
- Ordinary personal information may be processed under a Section 12 lawful basis. Sensitive personal and privileged information generally requires one of the narrower Section 13 exceptions.
- All personal data requires reasonable and appropriate safeguards. Classification affects access, lawful-basis analysis, breach response and legal exposure.
Personal Information vs Sensitive Personal Information
| Question | Personal information | Sensitive personal information |
|---|---|---|
| Basic meaning | Information that directly identifies a person or can identify the person when combined with other information. | A statutory subset of personal information involving listed personal characteristics, records or government-issued information. |
| Common examples | Name, email, phone number, home or delivery address, employee number, identifiable photograph, customer history and linkable online identifiers. | Age, marital status, race, ethnicity, health, education, genetic or sexual life, offense proceedings, specified government-issued information and legally classified information. |
| Main lawful-processing rule | At least one condition under Section 12 of RA 10173, unless another law prohibits the processing. | Processing is prohibited unless a Section 13 exception applies. |
| Is consent always required? | No. Contract, legal obligation, vital interests, public authority or legitimate interests may apply when their legal conditions are met. | No, but the non-consent exceptions are narrower and must fit Section 13 or another valid law or regulation. |
| Security | Reasonable and appropriate safeguards based on the data, risks, organization and processing. | The same duty applies, but the nature and possible harm commonly justify tighter access, monitoring and technical controls. |
| Breach relevance | A breach may still require escalation, especially when the data could enable identity fraud or serious harm. | Unauthorized acquisition of sensitive personal information is one of the statutory factors in the breach-notification analysis. |
| Potential exposure | Administrative, civil or criminal consequences may apply depending on the violation and facts. | Several RA 10173 criminal provisions impose higher penalty ranges for sensitive personal information. |
What Is Personal Information?
Section 3(g) of the Data Privacy Act of 2012 defines personal information as information, recorded or not, from which an individual’s identity is apparent or can be reasonably and directly ascertained by the holder, or which—when combined with other information—would directly and certainly identify the individual.
The definition is contextual. A number by itself may look anonymous, but it becomes personal information if the organization can connect it to a named customer, employee, patient or user. The same is true of account IDs, device identifiers, transaction histories, location records, photographs and combinations of seemingly ordinary fields.
What Is Sensitive Personal Information?
Section 3(l) of RA 10173 defines sensitive personal information by category. It includes personal information about:
- race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;
- health, education, genetic or sexual life;
- proceedings for an offense allegedly or actually committed, the result of the proceeding, or a court sentence;
- information issued by government agencies that is peculiar to an individual, including social-security numbers, health records, licenses and their denial, suspension or revocation, and tax returns; and
- information specifically established by an executive order or an Act of Congress to be kept classified.
The statutory list produces some results businesses overlook. A job applicant’s age, marital status and education records are sensitive personal information. A government-issued identifier or tax return can also fall into the sensitive category even when the organization collects it routinely.
What Is Privileged Information?
Privileged information is a related but distinct category. RA 10173 describes it as data that constitutes privileged communication under the Rules of Court or other laws. Examples may include communications covered by attorney-client, physician-patient or other legally recognized privileges when their requirements are present.
Do not label every internal, confidential or “for official use only” record as privileged information. Business confidentiality and legal privilege are not interchangeable. Section 13 applies to both sensitive personal information and privileged information, but classification must be grounded in the actual law and facts.
Philippine Business Examples
| Business situation | Usually personal information | Usually sensitive or requires special analysis |
|---|---|---|
| Recruitment | Name, email, phone number, address and applicant ID. | Age, marital status, education records, health information and offense proceedings. |
| Employment | Work email, employee number, attendance and salary information. | SSS or other government identifiers, tax returns, medical records, age and marital status. |
| E-commerce | Customer name, delivery address, contact details and purchase history. | A government-ID image or number used for verification. Payment credentials are high-risk personal data and may trigger separate financial-security and breach duties even when they do not fall neatly within the Section 3(l) list. |
| Clinic or pharmacy | Contact and appointment details. | Diagnosis, prescriptions, medical history, test results and genetic information. |
| School or training provider | Contact details and account information. | Grades, transcripts and other education records, plus health information or government identifiers. |
| Building security | An identifiable CCTV image, visitor name, plate number or access log. | Records revealing health, offense proceedings or government identifiers; audio recording may raise additional legal issues. |
Why the Classification Changes the Lawful Basis
For ordinary personal information, Section 12 permits processing when at least one lawful condition exists. These include consent, contractual necessity, legal obligation, vital interests, national emergency or public authority, and legitimate interests that are not overridden by the data subject’s fundamental rights and freedoms.
Section 13 starts from a stricter position: processing sensitive personal information and privileged information is prohibited unless a listed exception applies. These exceptions include purpose-specific prior consent, processing authorized by protective laws or regulations, life-and-health emergencies where consent cannot be expressed, qualifying activities of public organizations, medical treatment with adequate protection, and processing necessary for legal claims or provision to government or public authority.
A lawful basis is not a blank check. Section 11 still requires transparency, legitimate purpose, proportionality, accuracy, data minimization and limited retention. Collecting a sensitive field “just in case” can remain excessive even if a consent box appears on the form.
How Should Businesses Handle the Two Categories?
RA 10173 requires reasonable and appropriate organizational, physical and technical safeguards for personal information generally. The nature of the data and the risks of processing help determine the appropriate level of protection. Sensitive information usually warrants stricter controls because misuse can create discrimination, identity theft, medical harm, reputational damage or other serious consequences.
- Access: Give personnel access only when their role requires it; use separate permissions for health, government-ID, disciplinary and education records.
- Collection: Remove sensitive fields that are not necessary for the declared purpose.
- Storage: Use encryption, logging, secure backups and controlled exports appropriate to the risk.
- Sharing: Confirm the recipient, lawful basis, purpose, minimum fields and contractual protection before disclosure.
- Retention: Apply a defensible schedule by record type; do not keep sensitive records indefinitely because storage is inexpensive.
- Incidents: Escalate suspected unauthorized access promptly so the organization can assess containment, serious harm and any notification duty.
For the broader implementation process, use CyberCode’s RA 10173 business compliance guide. For field-by-field employer, retailer and SaaS scenarios, see examples of sensitive personal information under Philippine law. Responsibility also depends on whether the organization is the Personal Information Controller or Personal Information Processor.
Short Data-Classification Checklist
- Can the field identify a natural person by itself? If yes, treat it as personal information.
- Can it identify the person when combined with information you already hold? If yes, it is still personal information.
- Does it fall within a Section 3(l) category? Check age, marital status, health, education, genetics, sexual life, offense proceedings, government-issued information and legally classified records.
- Is it privileged under a specific rule or law? Do not confuse ordinary confidentiality with legal privilege.
- What exact purpose requires it? Remove fields that are unrelated, excessive or collected merely out of habit.
- Which lawful basis applies? Use Section 12 for ordinary personal information and test Section 13 separately for sensitive or privileged information.
- Who can access, receive or export it? Limit access by role and document all third-party processing.
- When will it be deleted or anonymized? Connect every retained field to a legal, operational or claims-related reason.
Hypothetical Examples
A restaurant loyalty form
A restaurant collects a customer’s name, mobile number and birthday month for a loyalty program. The name and number are personal information. If it collects the customer’s full age or date of birth, the age component falls within the statutory sensitive category. The restaurant should still ask whether the full date is necessary when a month-only promotion would achieve the purpose.
A job application form
An employer collects a name, email, address, age, marital status, transcript and medical certificate. The contact fields are personal information; the remaining listed fields include sensitive personal information. Calling the whole form “basic applicant information” does not change the legal categories.
An online seller verifies a high-value order
The seller already holds the buyer’s contact and delivery details as personal information. Asking for a government-ID image introduces sensitive personal information and additional identity-theft risk. The seller should determine whether the ID is necessary, whether a less intrusive verification method works, who can view it and when it will be deleted.
A breached customer account database
A database exposes email addresses, password hashes and payment-related identifiers but no health or government records. The absence of a Section 3(l) field does not make the incident harmless. Information that can enable identity fraud or create a real risk of serious harm can still require urgent breach assessment under Section 20.
Common Classification Mistakes
- “Public information is no longer personal information.” Public availability does not erase identifiability or automatically authorize every new use.
- “Confidential means sensitive.” A business may treat salary, pricing or internal notes as confidential without automatically converting them into statutory sensitive personal information.
- “Consent makes any collection lawful.” Consent does not cure an excessive, deceptive, incompatible or insecure processing operation.
- “Encrypted data is no longer personal data.” Encryption is a safeguard. If the organization or another party can restore the link to an individual, the data remains personal.
- “Only databases count.” Paper forms, voice recordings, photos, emails and manually maintained files can fall within the law.
Frequently Asked Questions
Is an email address personal information?
Usually yes when it identifies or can be linked to an individual. A generic address such as support@company.example may describe a function rather than one natural person, but account records can still connect it to identifiable users.
Is age sensitive personal information in the Philippines?
Yes. Section 3(l) expressly includes age. Businesses should not assume it is an ordinary demographic field simply because forms commonly request it.
Is salary sensitive personal information?
Salary is personal information and is commonly treated as confidential, but salary by itself is not expressly listed in Section 3(l). The surrounding record may contain sensitive fields, and employment, tax, contractual or sector-specific rules can add obligations.
Are government ID numbers sensitive personal information?
Government-issued information peculiar to an individual—including social-security numbers and licenses—is within the statutory sensitive category. Copies of IDs may also reveal age, marital status, address and other personal data.
Is a photograph personal information?
It can be when the person is identifiable. A photograph may also reveal sensitive characteristics or be processed with other identifiers, so context and purpose matter.
Is publicly posted information free for a business to reuse?
No blanket rule makes every reuse lawful. The business should still assess its purpose, lawful basis, transparency, proportionality, source, expectations and any applicable exception or sector rule.
Is consent always required for personal information?
No. Section 12 recognizes several lawful bases. Sensitive information requires a separate Section 13 analysis, where prior purpose-specific consent is one exception but not the only possible one.
Does anonymized information remain personal information?
Truly anonymized data that cannot reasonably be linked back to an individual falls outside the ordinary identification logic. Pseudonymized or coded data generally remains personal information when a key or other information can restore the link.
Does sensitive information always require a separate database?
The law does not impose one universal database design. Organizations should choose controls appropriate to risk, which may include segmentation, field-level permissions, encryption, logging and separate retention rules.
Do data subjects have rights over both categories?
Yes, subject to the Act’s conditions and exceptions. These include rights to be informed, access, object, rectify, seek erasure or blocking in qualifying circumstances, portability, damages and complaint. See CyberCode’s data-subject rights guide.
Official Sources
Disclaimer
Important: This article provides general educational information about Philippine law, regulation, cybersecurity, technology and business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, agency procedures, technical standards, platform rules and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when your rights, deadlines, money, safety or legal exposure may be affected.

