Last materially reviewed: September 25, 2026.
Direct answer
Examples of sensitive personal information under Philippine law include age, marital status, health, education, genetic or sexual life, offense proceedings, and certain government-issued information such as social-security numbers, licenses and tax returns. Section 3(l) of Republic Act No. 10173 lists the categories. A name, email, phone number, salary or delivery address can be personal information without automatically being sensitive personal information. Classify the actual field and context, then choose an appropriate legal basis and safeguards.
Evidence and action
For the underlying legal comparison, read Personal Information vs Sensitive Personal Information. This page focuses on everyday examples for employers, retailers and SaaS teams.
Field-by-field examples
| Information | Classification | Why it matters |
|---|---|---|
| Name, individual email, mobile number, delivery address | Personal | Identifies or can identify an individual; not automatically listed in Section 3(l). |
| Age or date of birth revealing age; marital status | Sensitive | Age and marital status are expressly listed. |
| Medical diagnosis, sick note, genetic test | Sensitive | Health and genetic information are listed. |
| School transcript, grades, educational history | Sensitive | Education is expressly listed. |
| Race, ethnicity, religion, political affiliation or sexual life | Sensitive | These are expressly listed categories. |
| Offense allegation, case outcome or sentence | Sensitive | Proceedings for an alleged or committed offense and their disposition are listed. |
| SSS number, government-issued license or tax return | Sensitive | Government-issued information peculiar to an individual is listed, with these statutory examples. |
| Salary, bank details, purchase history alone | Usually personal | May be confidential or high-risk, but is not automatically a Section 3(l) category. Inspect the full record for listed fields. |
Legal test: RA 10173 Section 3(l) defines sensitive personal information. Sections 12 and 13 set different lawful-processing rules: sensitive and privileged information generally may not be processed unless a Section 13 exception applies. A generic legitimate-interest claim alone is not a Section 13 exception. Section 20 requires reasonable and appropriate security for personal data, including ordinary data.
Examples for employers
- Applicant form: Name, email and address are personal; age, marital status, education records and medical history are sensitive. Ask only for information needed at the relevant recruitment stage. Give an applicant notice, limit recruiter access and document retention.
- Payroll: Salary and bank details are personal; an SSS number or tax return can be sensitive. Keep tax and government identifiers in a restricted payroll system instead of a general HR folder. Review access given to a payroll provider.
- Sick leave: A diagnosis or medical certificate contains health information. The team calendar need not display the diagnosis; give only appropriate HR or health staff access to the document.
- Disciplinary file: Allegations involving an offense may fall within Section 3(l); other workplace conduct records still contain personal data. Classify the particular content and restrict circulation.
One employee file can contain several categories. Label fields separately, record why each is needed, and do not treat employee consent as a shortcut around necessity, proportionality or Section 13.
Examples for retailers
- Checkout: Name, phone, address and order history are personal information. Share only the fields a courier needs and control temporary spreadsheet exports.
- Birthday promotion: Age is sensitive. If the offer only needs a birthday month, consider collecting the month rather than the full birth date. Check whether combined fields still reveal age.
- High-value order: A copy of a government ID may reveal age, license details and other sensitive fields. Decide whether a less intrusive check works; mask unnecessary fields and delete the copy when the documented need ends.
- Health-product sale: An identifiable order or free-text note can reveal health information, depending on its detail and context. Assess what is actually disclosed rather than classifying every product as a diagnosis.
Examples for SaaS and technology teams
- Account profiles and logs: Email and linkable device or IP identifiers are generally personal information. Minimize log fields and retention; examine whether logs contain sensitive free text.
- Customer imports: A payroll, clinic or school customer’s uploads may contain government-issued identifiers, health or education records. Inventory actual customer use cases and document controller-processor roles.
- Support tickets: Users may paste a medical result, ID or tax return into a ticket. Provide a secure upload path, redact unneeded fields, restrict support access and remove attachments under a documented schedule.
- AI and test environments: Production prompts and copied datasets may carry sensitive fields even when the feature never requested them. Review purpose, Section 13 basis, vendor terms, access and minimization before reuse.
A sign-up form asking only for email does not prove a SaaS platform holds no sensitive information. Check imports, attachments, backups, analytics and subprocessors.
Collection, access and storage controls
- Inventory fields: Record source, data subject, purpose, system, recipients, retention and Section 3(l) classification. Mark mixed records.
- Minimize collection: Justify each field, give clear notice, and document a Section 12 basis for ordinary data or a specific Section 13 exception for sensitive data. Consent is neither universally required nor universally sufficient.
- Restrict access: Use roles for HR, marketing, support and engineering; remove shared accounts and former-employee access; review exports and vendors.
- Protect storage and transfer: Apply organizational, physical and technical measures suited to the data and risk, such as MFA, encryption where appropriate, logs, secure transfer, protected backups and vendor safeguards.
- Set a deletion trigger: Include downloaded copies, email attachments, support tickets, test environments and backups in the retention plan.
- Preserve evidence: Keep the inventory, notice version, legal-basis decision, access reviews, vendor agreement and incident assessment.
If an incident exposes sensitive information, escalate and assess it promptly. The presence of sensitive data matters, but not every incident triggers the same notification duty. See how to report a data breach in the Philippines.
Frequently asked questions
Is a date of birth sensitive personal information?
Age is expressly listed in Section 3(l). A full birth date reveals age and should be classified and protected accordingly, especially when linked to a name or ID.
Is salary sensitive personal information?
Salary alone is generally personal information, not automatically sensitive under the statute. A payroll file may also contain sensitive SSS numbers or tax returns.
Can a retailer routinely require a government-ID copy?
It must assess a defined purpose, lawful basis, necessity, less intrusive alternatives, access and retention. ID copies can reveal sensitive fields and raise identity-fraud risk.
Are all health-product purchases sensitive?
No blanket rule applies. Evaluate whether the particular identifiable purchase or accompanying note actually reveals health information.
Can SaaS uploads contain sensitive data even if account fields do not?
Yes. Customer files and support attachments may include health, education or government-issued information. Classify the actual content.
Does “confidential” mean legally sensitive?
No. Confidentiality is a handling decision; sensitive personal information is a defined statutory category. All personal data still requires lawful and secure processing.
Official sources and next steps
- National Privacy Commission: Republic Act No. 10173 — Sections 3(l), 11–13, 20 and 21.
- National Privacy Commission: Glossary of Data Privacy Terms.
- Personal vs Sensitive Personal Information — the classification guide.
- How to Comply With RA 10173 — business implementation.
Disclaimer: Examples are illustrative. The classification depends on the actual record and context. This is general Philippine legal information, not legal advice; verify the statute and current NPC issuances for a specific activity.

