CyberCode.ph · Philippines

Personal Information vs Sensitive Personal Information in the Philippines

Last updated September 25, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 25, 2026

Direct Answer

Personal information is any information that identifies—or can be combined to identify—an individual. Sensitive personal information is a legally defined, higher-risk subset covering matters such as age, marital status, health, education, genetic or sexual life, offense proceedings, specified government-issued information, and information classified by law. Under Republic Act No. 10173, both require lawful and secure processing, but sensitive information is subject to narrower legal grounds and greater consequences when mishandled.

Key Takeaways

  • Sensitive personal information is a subset of personal information, not a completely separate universe of data.
  • Age, marital status and education records are sensitive personal information under the Philippine statute, even if a business treats them as routine form fields.
  • A name, email address, phone number, photograph, customer ID or device identifier can be personal information when it identifies or can be linked to an individual.
  • Salary and ordinary financial transaction details are personal information but are not automatically sensitive personal information merely because they are confidential; the exact record and other applicable laws still matter.
  • Ordinary personal information may be processed under a Section 12 lawful basis. Sensitive personal and privileged information generally requires one of the narrower Section 13 exceptions.
  • All personal data requires reasonable and appropriate safeguards. Classification affects access, lawful-basis analysis, breach response and legal exposure.

Personal Information vs Sensitive Personal Information

What Is Personal Information?

Section 3(g) of the Data Privacy Act of 2012 defines personal information as information, recorded or not, from which an individual’s identity is apparent or can be reasonably and directly ascertained by the holder, or which—when combined with other information—would directly and certainly identify the individual.

The definition is contextual. A number by itself may look anonymous, but it becomes personal information if the organization can connect it to a named customer, employee, patient or user. The same is true of account IDs, device identifiers, transaction histories, location records, photographs and combinations of seemingly ordinary fields.

What Is Sensitive Personal Information?

Section 3(l) of RA 10173 defines sensitive personal information by category. It includes personal information about:

  • race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;
  • health, education, genetic or sexual life;
  • proceedings for an offense allegedly or actually committed, the result of the proceeding, or a court sentence;
  • information issued by government agencies that is peculiar to an individual, including social-security numbers, health records, licenses and their denial, suspension or revocation, and tax returns; and
  • information specifically established by an executive order or an Act of Congress to be kept classified.

The statutory list produces some results businesses overlook. A job applicant’s age, marital status and education records are sensitive personal information. A government-issued identifier or tax return can also fall into the sensitive category even when the organization collects it routinely.

What Is Privileged Information?

Privileged information is a related but distinct category. RA 10173 describes it as data that constitutes privileged communication under the Rules of Court or other laws. Examples may include communications covered by attorney-client, physician-patient or other legally recognized privileges when their requirements are present.

Do not label every internal, confidential or “for official use only” record as privileged information. Business confidentiality and legal privilege are not interchangeable. Section 13 applies to both sensitive personal information and privileged information, but classification must be grounded in the actual law and facts.

Philippine Business Examples

Why the Classification Changes the Lawful Basis

For ordinary personal information, Section 12 permits processing when at least one lawful condition exists. These include consent, contractual necessity, legal obligation, vital interests, national emergency or public authority, and legitimate interests that are not overridden by the data subject’s fundamental rights and freedoms.

Section 13 starts from a stricter position: processing sensitive personal information and privileged information is prohibited unless a listed exception applies. These exceptions include purpose-specific prior consent, processing authorized by protective laws or regulations, life-and-health emergencies where consent cannot be expressed, qualifying activities of public organizations, medical treatment with adequate protection, and processing necessary for legal claims or provision to government or public authority.

A lawful basis is not a blank check. Section 11 still requires transparency, legitimate purpose, proportionality, accuracy, data minimization and limited retention. Collecting a sensitive field “just in case” can remain excessive even if a consent box appears on the form.

How Should Businesses Handle the Two Categories?

RA 10173 requires reasonable and appropriate organizational, physical and technical safeguards for personal information generally. The nature of the data and the risks of processing help determine the appropriate level of protection. Sensitive information usually warrants stricter controls because misuse can create discrimination, identity theft, medical harm, reputational damage or other serious consequences.

  • Access: Give personnel access only when their role requires it; use separate permissions for health, government-ID, disciplinary and education records.
  • Collection: Remove sensitive fields that are not necessary for the declared purpose.
  • Storage: Use encryption, logging, secure backups and controlled exports appropriate to the risk.
  • Sharing: Confirm the recipient, lawful basis, purpose, minimum fields and contractual protection before disclosure.
  • Retention: Apply a defensible schedule by record type; do not keep sensitive records indefinitely because storage is inexpensive.
  • Incidents: Escalate suspected unauthorized access promptly so the organization can assess containment, serious harm and any notification duty.

For the broader implementation process, use CyberCode’s RA 10173 business compliance guide. For field-by-field employer, retailer and SaaS scenarios, see examples of sensitive personal information under Philippine law. Responsibility also depends on whether the organization is the Personal Information Controller or Personal Information Processor.

Short Data-Classification Checklist

  1. Can the field identify a natural person by itself? If yes, treat it as personal information.
  2. Can it identify the person when combined with information you already hold? If yes, it is still personal information.
  3. Does it fall within a Section 3(l) category? Check age, marital status, health, education, genetics, sexual life, offense proceedings, government-issued information and legally classified records.
  4. Is it privileged under a specific rule or law? Do not confuse ordinary confidentiality with legal privilege.
  5. What exact purpose requires it? Remove fields that are unrelated, excessive or collected merely out of habit.
  6. Which lawful basis applies? Use Section 12 for ordinary personal information and test Section 13 separately for sensitive or privileged information.
  7. Who can access, receive or export it? Limit access by role and document all third-party processing.
  8. When will it be deleted or anonymized? Connect every retained field to a legal, operational or claims-related reason.

Hypothetical Examples

A restaurant loyalty form

A restaurant collects a customer’s name, mobile number and birthday month for a loyalty program. The name and number are personal information. If it collects the customer’s full age or date of birth, the age component falls within the statutory sensitive category. The restaurant should still ask whether the full date is necessary when a month-only promotion would achieve the purpose.

A job application form

An employer collects a name, email, address, age, marital status, transcript and medical certificate. The contact fields are personal information; the remaining listed fields include sensitive personal information. Calling the whole form “basic applicant information” does not change the legal categories.

An online seller verifies a high-value order

The seller already holds the buyer’s contact and delivery details as personal information. Asking for a government-ID image introduces sensitive personal information and additional identity-theft risk. The seller should determine whether the ID is necessary, whether a less intrusive verification method works, who can view it and when it will be deleted.

A breached customer account database

A database exposes email addresses, password hashes and payment-related identifiers but no health or government records. The absence of a Section 3(l) field does not make the incident harmless. Information that can enable identity fraud or create a real risk of serious harm can still require urgent breach assessment under Section 20.

Common Classification Mistakes

  • “Public information is no longer personal information.” Public availability does not erase identifiability or automatically authorize every new use.
  • “Confidential means sensitive.” A business may treat salary, pricing or internal notes as confidential without automatically converting them into statutory sensitive personal information.
  • “Consent makes any collection lawful.” Consent does not cure an excessive, deceptive, incompatible or insecure processing operation.
  • “Encrypted data is no longer personal data.” Encryption is a safeguard. If the organization or another party can restore the link to an individual, the data remains personal.
  • “Only databases count.” Paper forms, voice recordings, photos, emails and manually maintained files can fall within the law.

Frequently Asked Questions

Is an email address personal information?

Usually yes when it identifies or can be linked to an individual. A generic address such as support@company.example may describe a function rather than one natural person, but account records can still connect it to identifiable users.

Is age sensitive personal information in the Philippines?

Yes. Section 3(l) expressly includes age. Businesses should not assume it is an ordinary demographic field simply because forms commonly request it.

Is salary sensitive personal information?

Salary is personal information and is commonly treated as confidential, but salary by itself is not expressly listed in Section 3(l). The surrounding record may contain sensitive fields, and employment, tax, contractual or sector-specific rules can add obligations.

Are government ID numbers sensitive personal information?

Government-issued information peculiar to an individual—including social-security numbers and licenses—is within the statutory sensitive category. Copies of IDs may also reveal age, marital status, address and other personal data.

Is a photograph personal information?

It can be when the person is identifiable. A photograph may also reveal sensitive characteristics or be processed with other identifiers, so context and purpose matter.

Is publicly posted information free for a business to reuse?

No blanket rule makes every reuse lawful. The business should still assess its purpose, lawful basis, transparency, proportionality, source, expectations and any applicable exception or sector rule.

Is consent always required for personal information?

No. Section 12 recognizes several lawful bases. Sensitive information requires a separate Section 13 analysis, where prior purpose-specific consent is one exception but not the only possible one.

Does anonymized information remain personal information?

Truly anonymized data that cannot reasonably be linked back to an individual falls outside the ordinary identification logic. Pseudonymized or coded data generally remains personal information when a key or other information can restore the link.

Does sensitive information always require a separate database?

The law does not impose one universal database design. Organizations should choose controls appropriate to risk, which may include segmentation, field-level permissions, encryption, logging and separate retention rules.

Do data subjects have rights over both categories?

Yes, subject to the Act’s conditions and exceptions. These include rights to be informed, access, object, rectify, seek erasure or blocking in qualifying circumstances, portability, damages and complaint. See CyberCode’s data-subject rights guide.

Disclaimer

Important: This article provides general educational information about Philippine law, regulation, cybersecurity, technology and business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, agency procedures, technical standards, platform rules and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when your rights, deadlines, money, safety or legal exposure may be affected.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.