CyberCode.ph · Philippines

What Is Sensitive Personal Information Under RA 10173?

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 2, 2026

Direct Answer

Sensitive personal information under the Philippine Data Privacy Act, Republic Act No. 10173, is a protected category of personal information that includes data about matters such as a person’s race or ethnic origin, marital status, age, religion or political affiliations, health, education, genetic or sexual life, certain offense or court-proceeding information, government-issued identifiers and information specifically classified by law (RA 10173, Sec. 3(l)).

The key distinction is that sensitive personal information receives stricter treatment than ordinary personal information. Section 13 of RA 10173 generally prohibits its processing unless a specific legal basis or exception applies.

Primary authority: Republic Act No. 10173 — Data Privacy Act of 2012.

Key Takeaways

  • Sensitive personal information is a defined legal category under RA 10173.
  • Health, education, genetic and sexual-life information are expressly included.
  • Government-issued information peculiar to an individual can also be sensitive, including social security numbers, licenses and tax returns.
  • Consent may be one lawful basis, but it is not the only possible basis.
  • Processing sensitive personal information is generally prohibited unless one of the statutory exceptions applies.
  • Businesses should use stronger access, security, retention and disclosure controls for this category of data.

Jump to a Section

Decision Snapshot

Question Practical Answer
Is health information sensitive personal information? Yes.
Is education information sensitive personal information? Yes.
Is age sensitive personal information? Yes, under the statutory definition.
Are government-issued identifiers sensitive? They can be, when they are information issued by government agencies peculiar to an individual.
Is every email address sensitive personal information? No. An email may be personal information without falling into the sensitive category.
Can sensitive personal information be processed without consent? Potentially yes, but only when another specific exception under law applies.

What Does RA 10173 Define as Sensitive Personal Information?

Section 3(l) of the Data Privacy Act defines sensitive personal information by category. The National Privacy Commission repeats the same categories in its official glossary and implementing rules.

The law covers information about an individual’s:

  • race
  • ethnic origin
  • marital status
  • age
  • color
  • religious affiliations
  • philosophical affiliations
  • political affiliations
  • health
  • education
  • genetic information
  • sexual life
  • certain criminal or offense proceedings
  • certain government-issued information peculiar to the individual
  • information specifically classified by executive order or an act of Congress

This is more specific than the broader concept of personal information, which covers information that identifies or can identify an individual.

Examples of Sensitive Personal Information

Depending on context, common examples include:

  • medical diagnoses and treatment records
  • laboratory results
  • disability information
  • school records and educational history
  • religious affiliation
  • political affiliation
  • marital status
  • age
  • genetic information
  • information about sexual life
  • records concerning alleged or committed offenses
  • court dispositions and sentencing information
  • SSS or other government-issued identifying numbers
  • tax returns
  • professional licenses or information about their denial, suspension or revocation

Not every piece of personal data is automatically sensitive. The legal classification depends on whether the data falls within the protected categories listed by law.

Personal Information vs Sensitive Personal Information

Personal information is the broader category. It includes data from which an individual can be identified directly or by combining it with other information.

Sensitive personal information is a narrower category expressly identified by RA 10173 because of the nature of the information and the potential consequences of misuse.

For example:

Data Typical Classification
Name Personal information
Work email address Personal information
Home address Personal information
Age Sensitive personal information
Medical diagnosis Sensitive personal information
Religious affiliation Sensitive personal information
Tax return Sensitive personal information

Businesses should therefore classify the information they hold rather than treating every data field the same.

Are Government IDs Sensitive Personal Information?

RA 10173 includes information issued by government agencies that is peculiar to an individual. The statute specifically mentions social security numbers, health records, licenses and tax returns as examples.

This means organizations should be careful when asking customers or employees to submit government IDs. Before collecting a copy, ask:

  • Is the ID actually necessary?
  • What legal or business purpose requires it?
  • Can verification be completed without retaining a full copy?
  • Who can access it?
  • How long will it be retained?

Collecting government IDs simply because an online form has an upload field is not a sound privacy practice.

Is Health Information Sensitive Personal Information?

Yes. Health information is expressly included in the statutory definition.

This can include more than a formal medical record. Depending on context, health-related information may appear in:

  • employee sick-leave records
  • medical certificates
  • insurance documents
  • wellness applications
  • fitness or biometric systems
  • hospital or clinic records
  • benefits administration

Organizations should limit access to health information and avoid exposing it in ordinary shared folders, group chats or unrestricted HR systems.

What Sensitive Information Do Employers Commonly Hold?

Employers can hold substantial amounts of sensitive personal information, including:

  • age and marital status
  • government numbers
  • tax records
  • health and medical information
  • educational background
  • professional licenses
  • disciplinary or legal records where relevant

This makes employee-data governance an important privacy issue even for businesses that do not operate consumer-facing websites.

Access should be based on job responsibility. A manager who needs attendance information, for example, may not automatically need access to an employee’s complete medical or tax records.

When Can Sensitive Personal Information Be Processed?

Section 13 of the Data Privacy Act begins from a stricter position: processing sensitive personal information and privileged information is generally prohibited unless an exception applies.

Those exceptions include circumstances such as:

  • the data subject giving consent specific to the purpose before processing
  • processing being provided for by existing laws or regulations that protect the information
  • processing being necessary to protect life and health when the person cannot legally or physically express consent
  • certain processing carried out by non-stock, non-profit organizations relating to their lawful activities and members
  • processing necessary for medical treatment under appropriate professional or institutional safeguards
  • processing necessary for lawful rights and interests in court proceedings, legal claims, or when provided to government or public authority

The exact legal basis matters. Organizations should not assume that a generic consent checkbox automatically fixes every sensitive-data processing activity.

Does Legitimate Interest Automatically Allow Sensitive Data Processing?

No. The legitimate-interest basis commonly discussed for ordinary personal information should not be treated as a universal basis for sensitive personal information. Sensitive personal information follows the more specific conditions in Section 13.

This distinction is important for privacy notices, HR systems, customer verification, profiling and AI projects.

What Security Controls Should Businesses Use?

The Data Privacy Act and its implementing rules require appropriate organizational, physical and technical measures for personal data. Sensitive information normally deserves heightened attention because misuse can create greater harm.

A practical control set includes:

  • role-based access
  • multi-factor authentication for sensitive systems
  • encryption where appropriate
  • restricted download and export permissions
  • audit logs
  • documented retention periods
  • secure deletion procedures
  • vendor due diligence
  • employee confidentiality and privacy training
  • incident-response procedures

Minimum SME Checklist

  • Identify every system containing sensitive personal information.
  • List the legal purpose and lawful basis for each processing activity.
  • Remove unnecessary fields from forms.
  • Restrict access to staff who actually need the information.
  • Review where government IDs and medical documents are stored.
  • Set retention periods.
  • Review cloud and SaaS vendors handling sensitive data.
  • Prepare for breach investigation and notification decisions.

Why Does Sensitive Personal Information Matter During a Data Breach?

The type of data affected is a critical part of breach assessment. A leak involving medical information, government identifiers or other sensitive categories may create significantly greater risk than exposure of less sensitive information.

When investigating a possible breach, organizations should document:

  • what information was involved
  • whether sensitive or privileged information was affected
  • how many individuals were affected
  • whether data was encrypted or otherwise protected
  • whether unauthorized access actually occurred
  • the likely risk of harm
  • whether notification obligations are triggered

Does Sensitive Personal Information Apply to AI Systems?

Yes. If an AI system processes health information, government identifiers, education records or other sensitive categories, Philippine privacy obligations still apply.

Businesses should be especially careful about employees pasting sensitive customer or employee information into public generative-AI tools without an approved policy, vendor assessment and appropriate processing basis.

Frequently Asked Questions

Is a person’s age sensitive personal information?

Yes. Age is expressly included in the statutory definition of sensitive personal information under RA 10173.

Is marital status sensitive personal information?

Yes. Marital status is specifically listed in the law.

Is an email address sensitive personal information?

Not ordinarily by itself. An email address can be personal information, but it does not automatically fall into the sensitive categories listed in RA 10173.

Are medical certificates sensitive personal information?

They can contain health information, which is expressly sensitive personal information.

Is an SSS number sensitive personal information?

Government-issued information peculiar to an individual, including social security numbers, is included in the statutory definition.

Can a business ask for a government ID?

Potentially, but the organization should have a legitimate and lawful reason, collect only what is necessary, protect the information and avoid retaining more than needed.

Is consent always required?

No. Consent is one statutory condition, but Section 13 contains other specific circumstances in which processing may be allowed.

Related Cybercode Guides

Official Sources

Cybercode.ph provides general educational information and does not substitute for legal advice for a specific situation.