The Philippine Data Privacy Act and Background Checks What HR Teams Need to Know

The Philippine Data Privacy Act and Background Checks: What HR Teams Need to Know

Republic Act 10173, the Data Privacy Act of the Philippines, has been in force since 2012. Most HR professionals know it exists. Far fewer know exactly how it applies to background screening specifically. This article covers the practical requirements that affect your pre-employment process.

The core principle: consent before collection

Under RA 10173, personal data cannot be collected or processed without a lawful basis. For background screening, the lawful basis is candidate consent. This means you cannot initiate any background check, reference call, credential verification, or database search on a candidate without first obtaining their documented agreement to be screened.

The consent must be specific, informed, and freely given. Specific means the candidate must know what types of data are being collected and for what purpose. Informed means they must understand who will access the information and how it will be handled. Freely given means the screening cannot be presented as a non-negotiable condition with no explanation or recourse.

A blanket line in a job application form that says “I authorize the company to conduct background verification” does not meet this standard on its own. The consent should specify what is being checked, by whom, and for what purpose.

What you need in writing

At minimum, your background screening consent documentation should include the candidate’s full name and signature, the specific types of checks being conducted (identity, employment history, education, criminal records, etc.), the name of any third-party screening provider who will have access to the data, the purpose of the check, how long the data will be retained, and the candidate’s right to withdraw consent and to access or correct their own data.

If you use a third-party provider like Vanguard, the provider handles much of this documentation as part of the standard intake process. But the responsibility for ensuring proper consent ultimately sits with the employer.

Data handling after the check is complete

Collecting consent is only the first step. RA 10173 also governs how you store, access, share, and eventually dispose of screening records.

Background check reports contain sensitive personal information. They cannot be stored in a shared drive accessible to the entire HR department. They cannot be forwarded to a hiring manager’s personal email. They cannot be downloaded to an unprotected device. Access should be restricted to the individuals who have a direct, documented need for the information in connection with the specific hiring decision.

Reports should be retained for only as long as necessary for the purpose they were collected. Once a hiring decision is made and the relevant statutory period for record retention has passed, reports should be disposed of securely.

What happens if you get it wrong

The National Privacy Commission has the authority to impose fines and criminal penalties for DPA violations. More practically, a candidate who believes their personal data was handled improperly can file a complaint with the NPC. For regulated industries like banking and healthcare, a DPA violation can also create regulatory exposure beyond the NPC’s jurisdiction.

The straightforward solution

Work with a background screening provider that treats DPA compliance as a non-negotiable part of the process, not an afterthought. At Vanguard, candidate consent documentation, data handling, and record retention are all managed under our ISO 27001:2013 certified information security system and in full compliance with RA 10173. If you want to review how your current process measures up, message us for a free consultation.

Share this post