Verihubs Logo
Home Blog Data Privacy Act Philippines: KYC and Biometric Data Compliance
16 min read Face Recognition Published on August 19, 2026

Data Privacy Act Philippines: KYC and Biometric Data Compliance

Data Privacy Act Philippines: KYC and Biometric Data Compliance

The Data Privacy Act of 2012, or Republic Act No. 10173 (RA 10173), sets the privacy requirements that Philippine organisations need to consider when collecting and processing personal data for KYC and identity verification.

For banks, fintechs, lending companies, e-wallets, crypto platforms, and other regulated businesses, this becomes particularly important when KYC workflows involve government-issued IDs, facial images, liveness checks, biometric verification, and other customer information.

One important distinction under Philippine law is that biometric data is classified as personal information under RA 10173, rather than sensitive personal information under the Act’s definition. However, a typical KYC record can still contain sensitive personal information because government-issued identifiers, age, licence details, and other information may fall within Section 3(l).

This distinction affects how organisations establish a lawful basis for processing, obtain consent, minimise the data they collect, determine retention periods, manage KYC vendors, and respond to privacy incidents.

What Does the Data Privacy Act Cover?

RA 10173 took effect in 2012, with its Implementing Rules and Regulations following in 2016. The National Privacy Commission (NPC) has enforced the Act since 2017.

The law has broad coverage. It applies to government and private organisations that process personal data in the Philippines. It can also apply to organisations outside the country where Philippine personal data is processed under circumstances covered by the Act.

For KYC operations, two roles are particularly important:

  • Personal Information Controller (PIC)

The PIC determines why and how personal data is processed. In an eKYC workflow, this will typically be the bank, fintech, lender, e-wallet, or other business using the verification service.

  • Personal Information Processor (PIP)

The PIP processes personal data on behalf of the PIC. A third-party identity verification or eKYC provider will generally operate in this role.

Using a third-party verification provider does not remove the controller’s accountability. The organisation using the service remains responsible for ensuring that personal data is processed appropriately.

What KYC Data Is Considered Sensitive Personal Information?

This is an important distinction for Philippine KYC teams.

Section 3(l) of RA 10173 identifies specific categories of sensitive personal information. These include information relating to race, ethnic origin, marital status, age, colour, religious, philosophical or political affiliations, health, education, genetic or sexual life, proceedings for an offence, and information issued by government agencies that is peculiar to an individual.

Government-issued information can include social security numbers, health records, licences and their denial, suspension or revocation, and tax returns.

Biometric data is not specifically listed as sensitive personal information under Section 3(l). Under Section 3(g), it falls within personal information because a person’s identity is apparent or can reasonably be ascertained from it.

This is different from the GDPR approach, where biometric data processed for uniquely identifying an individual is treated as special category data.

For Philippine businesses, the practical issue is that a KYC record can still contain sensitive personal information even when biometric verification is not involved.

Data collected during KYCClassification under RA 10173
Name, address, contact detailsPersonal information
Facial image, selfie, liveness capture, biometric templatePersonal information
Date of birth, ageSensitive personal information
Marital statusSensitive personal information
SSS number, TIN, and licence detailsSensitive personal information
PRC licence informationSensitive personal information
NBI or police clearance contentSensitive personal information

Read that table and the practical conclusion follows quickly. Almost every KYC file contains sensitive personal information regardless of whether biometrics are collected, because valid IDs carry government identifiers and age. The stricter regime engages either way.

Lawful Basis for KYC Data Processing

The lawful basis for processing personal information is not identical to the basis for processing sensitive personal information.

Personal information versus sensitive personal information in a Philippine KYC file showing which data triggers stricter processing rules
Lawful basisPersonal informationSensitive personal information
ConsentAvailableAvailable, subject to the requirements under the DPA
Necessary for a contractAvailableNot listed
Compliance with a legal obligationAvailableAvailable as processing provided for by existing laws and regulations
Vital interestsAvailableAvailable where the subject cannot give consent
Legitimate interestsAvailable, subject to a balancing testNot available

Processing sensitive personal information is generally prohibited unless one of the listed exceptions applies. Legitimate interests is not among them, which removes the fallback that many privacy programmes lean on elsewhere.

For KYC the useful basis is usually the third row. AMLA and BSP rules require covered persons to identify and verify customers, so the collection is processing provided for by existing laws and regulations. Our guide to customer due diligence covers what those rules actually mandate.

Institutions routinely default to consent for everything, and for AML-mandated collection that is the weaker choice.

Consent under the DPA must be freely given, specific, informed, and evidenced in writing, electronically, or by recorded means. It can also be withdrawn. Build your AML identity verification on consent and you have created a scenario where a customer withdraws consent for processing you are legally required to perform, leaving a contradiction with no clean resolution.

The cleaner design separates the two. Collection required by AML rules rests on existing law. Anything beyond that minimum, such as marketing use or optional enrichment, is where consent belongs, and it should be capable of refusal without blocking the account.

On 8 October 2025 the NPC issued a cease and desist order against Tools for Humanity over the World App and its Orb iris-scanning verification.

Anyone collecting biometrics in the Philippines should read the findings closely. The NPC held that consent obtained through financial inducement cannot be considered freely given under the DPA; that the company failed to provide adequate notice of the nature and extent of biometric data collection; that data subjects were denied meaningful rights to access, withdrawal of consent, and erasure; and that the scope of biometric collection was disproportionate.

The order directed the company to stop all related processing in the Philippines, remove the app from Philippine app stores, and cease further transfer or disclosure of data already collected. Tools for Humanity filed a motion for reconsideration, and the matter remained under review as of mid-2026.

Three lessons carry across to commercial eKYC. Incentivised consent is fragile. Notice must describe what is actually collected, not gesture at it. And proportionality is assessed independently of whether consent was obtained, so a valid consent does not license collecting more than the purpose requires.

Data Minimisation Requirements for KYC

The DPA’s proportionality principle asks whether the data collected is adequate, relevant, and not excessive for the declared purpose. Verification flows fail this quietly, by hoovering up whatever the document happens to show.

Common excess in Philippine KYC: capturing and storing the full document image indefinitely when the extracted fields were what the process needed; collecting a second ID where BSP rules make one sufficient, particularly where the customer presented a PhilID; retaining raw selfie video after a liveness decision has been reached; and copying the reverse of a PhilID when BSP guidance directs that only the front should be photocopied or scanned.

Minimisation also governs who inside the organisation can see what. Sensitive personal information visible to every support agent raises a proportionality problem even where the collection itself was justified.

KYC Data Retention: DPA Requirements vs. the AMLA Five-Year Rule

Here two regimes pull in opposite directions, and teams often resolve the tension in the wrong direction.

AML rules require covered persons to retain records for at least five years and to produce them for AMLC inspection. The DPA requires that personal data not be retained longer than necessary for the declared purpose.

These are reconcilable, because the AML obligation is itself the declared purpose and a legal requirement, so retention for that period is justified. What is not justified is treating five years as a licence to keep everything for five years. The obligation attaches to records needed for the AML purpose, not to every artefact the verification process generated along the way.

A defensible retention schedule distinguishes between them: identity records and verification outcomes retained under the AML rule, and intermediate artefacts such as raw video, discarded captures, and duplicate images deleted once the decision is made. Our guide to the AML compliance program covers the record-keeping element in full.

DPO, NPC Registration, PIA, and Breach Notification Requirements

Philippine organisations processing personal data also need to consider their broader privacy governance obligations.

Data Protection Officer

Organisations covered by the applicable requirements need to designate a Data Protection Officer (DPO) who oversees privacy compliance and related responsibilities.

NPC Registration

Personal Information Controllers and Personal Information Processors that meet the applicable registration requirements need to register qualifying data processing systems and relevant information with the NPC.

Privacy Impact Assessment

High-risk processing activities require additional privacy risk assessment. Biometric processing and profiling are examples of activities that can require closer scrutiny.

For an organisation deploying eKYC involving identity documents, facial verification, liveness detection, or other biometric-related processing, a Privacy Impact Assessment can help identify risks before the system is deployed at scale.

Breach Notification

Where a personal data breach meets the applicable notification requirements, including situations involving sensitive personal information or a real risk of serious harm, notification to the NPC and affected data subjects may be required within 72 hours of discovery.

For KYC operations, this makes incident response particularly important because identity documents and verification data can contain information that could expose customers to fraud or identity-related risks if compromised.

Cross-Border KYC Data Transfers and Vendor Accountability

Most Philippine institutions use verification technology that processes data outside the country, which is permitted but does not transfer responsibility.

The controller remains accountable for personal data it transfers to a processor, including a foreign one. The contract has to carry that accountability: what the processor may do with the data, which security measures apply, how long it retains anything, what happens on termination, and how quickly it reports breaches back so the controller can meet its own 72-hour obligation.

One practical exposure worth auditing sits outside the vendor contract entirely. Staff who paste customer details into third-party websites during verification, such as the many unofficial sites offering NBI clearance verification, are disclosing personal data to processors nobody assessed and no contract covers. The organisation carries that exposure regardless of which tool an individual employee happened to open.

Penalties Under the Data Privacy Act

Criminal penalties under the Act range from six months to seven years of imprisonment with fines from PHP 100,000 to PHP 5 million, depending on the offence.

Three features of the penalty structure matter for KYC operations. Offences involving sensitive personal information carry heavier ranges than those involving personal information alone, so the government-issued identifiers in a KYC file can increase the compliance and enforcement exposure.

Penalties increase by one degree where violations involve sensitive personal information or affect vulnerable persons such as minors or the elderly. And where the offender is a juridical person, the penalty falls on the responsible officers who participated in the violation or whose gross negligence allowed it.

The NPC’s enforcement toolkit reaches further than fines. As the World App order demonstrated, it can direct an organisation to stop processing entirely, which for a verification-dependent business means stopping onboarding.

Frequently Asked Questions About the Data Privacy Act and KYC

Is biometric data sensitive personal information under Philippine law?

No. Section 3(l) of RA 10173 enumerates sensitive personal information in four categories and biometric data is not among them. It falls under personal information at Section 3(g), since identity is apparent or can reasonably be ascertained from it. This differs from GDPR, where biometric data processed for unique identification is special category data.

What data in a KYC file is sensitive personal information?

Government-issued identifiers such as SSS numbers, TIN, and licence details, together with age, marital status, and any information about proceedings for an offence. Most KYC files therefore contain sensitive personal information whether or not biometrics are collected.
Usually not as the primary basis. Where identity verification is required by AMLA and BSP rules, the appropriate basis is processing provided for by existing laws and regulations. Relying on consent for legally mandated collection creates a conflict if the customer later withdraws it. Consent is better reserved for processing beyond the regulatory minimum.

Can we rely on legitimate interests for sensitive personal information?

No. Legitimate interests is available as a basis for processing personal information subject to a balancing test, but it is not among the exceptions permitting processing of sensitive personal information.

How does the five-year AML retention rule interact with data minimisation?

They are reconcilable. The AML obligation is a legal requirement and a declared purpose, so retention for that period is justified for the records the rule covers. It does not justify retaining every artefact the verification process generated, such as raw video or discarded captures, once the verification decision has been made.

What did the NPC decide in the World App case?

In a cease and desist order issued on 8 October 2025, the NPC held that consent obtained through financial inducement is not freely given and cannot serve as a lawful basis, that notice of the nature and extent of biometric collection was inadequate, that data subjects were denied access, withdrawal, and erasure rights, and that the scope of collection was disproportionate. A motion for reconsideration was filed and the matter remained under review as of mid-2026.

Building a More Privacy-Aware KYC Workflow

Privacy programmes concentrate on securing what has been collected: encryption, access control, breach response. All necessary, all defeatable. Data you never collected cannot leak, cannot sit past its retention window, and cannot appear in a proportionality finding.

In identity verification that principle is unusually actionable, because the purpose is narrow. You need to establish that a person is who they claim to be. Once you establish that, the raw materials behind it have largely served their function, and keeping them becomes a decision rather than a requirement.

Verihubs eKYC supports Philippine identity verification workflows across government-issued IDs, biometric verification, liveness detection, and deepfake detection. The platform is designed to return the verification outcome and relevant information required by the workflow rather than creating an unnecessarily broad data set.

For organisations evaluating an eKYC solution, the right question is therefore not only whether the technology can verify an identity.

It is also whether the entire verification workflow supports the organisation’s obligations under the Data Privacy Act of 2012, applicable AML requirements, and other Philippine regulatory requirements.

Talk to the Verihubs team about building an identity verification workflow designed with privacy, security, and proportionality in mind.

Client Verihubs
Find out how accurate Verihubs Face Recognition
Get FREE Trial
View Blog