Manila, as the nation's capital and a thriving hub for multinational corporations and local enterprises alike, operates at the forefront of business and innovation. However, this dynamic environment also brings heightened responsibility, particularly concerning the handling of personal data. The Republic Act No. 10173, or the Data Privacy Act of 2012 (DPA), is the cornerstone of legal compliance for all entities processing personal information in the Philippines.
For employers in Manila, this legislation is not an abstract legal concept; it is a critical framework that governs every stage of the hiring process, from application review to background checks. Understanding and adhering to the DPA is paramount to avoiding severe penalties, safeguarding your company's reputation, and building trust with prospective and current employees.
This guide outlines how Manila employers must navigate the DPA when conducting background checks and managing candidate data.
The Data Privacy Act (RA 10173): What Employers Need to Know
The DPA's primary objective is to protect the fundamental right to privacy of individuals by ensuring that personal information is processed fairly, lawfully, and in accordance with the law. The National Privacy Commission (NPC) is mandated to enforce this Act.
When you collect, record, organise, store, or process any information that can identify an individual—such as names, addresses, contact details, NBI clearance results, educational background, or employment history—you are engaging in "processing" of personal information. Therefore, all background checks and related data handling in your hiring process fall under the DPA.
Key Principles of DPA Compliance in Hiring
To conduct compliant background checks and manage candidate data responsibly, Manila employers must adhere to several core principles derived from the DPA:
1. Lawful Basis for Processing: The Primacy of Consent
-
Purpose: You must have a legitimate purpose for collecting personal data. For hiring, this purpose is to assess a candidate's suitability for a role.
-
Consent: In most hiring scenarios, particularly for background checks, informed consent is the lawful basis. This means:
-
Transparency: Clearly inform the candidate what data you intend to collect, why you are collecting it (e.g., for pre-employment verification), how it will be used, and who will have access to it.
-
Specificity: Consent must be specific to the types of data and the purposes stated. A general clause in an employment contract is insufficient. A separate, clear consent form is advisable.
-
Voluntariness: Consent must be freely given. Candidates should not feel coerced or that their application will be automatically rejected if they do not consent to unnecessary data collection.
2. Proportionality: Collect Only What You Need
-
Necessity: The data you collect must be adequate, relevant, and necessary for the declared purpose of assessing the candidate for a specific role.
-
Relevance: A background check's scope should be proportional to the job's responsibilities. For instance, extensive financial checks might be relevant for a finance role but not for a creative position.
3. Data Security: Protecting Candidate Information
-
Reasonable Security Measures: You are obligated to implement organisational, physical, and technical security measures to protect personal data from unauthorised access, disclosure, alteration, or destruction.
-
Secure Handling: This includes using secure platforms for data transfer and storage, limiting access to sensitive information on a need-to-know basis, and ensuring your third-party vendors (like background check providers) also adhere to strict security protocols.
4. Rights of the Data Subject
Candidates, as data subjects, have rights under the DPA, including:
-
Right to be Informed: They have the right to know about the data processing.
-
Right to Access: They can request access to the personal data you hold about them.
-
Right to Rectification: They can request correction of inaccurate data.
-
Right to Erasure/Blocking: Under certain circumstances, they can request data deletion.
-
Right to Object: They can object to processing if it infringes on their rights.
Your hiring and screening processes must accommodate these rights.
Consequences of Non-Compliance for Manila Employers
Failure to comply with the DPA can result in severe repercussions:
-
Significant Fines: Penalties can range from PHP 50,000 to PHP 5,000,000, depending on the violation and the number of data subjects affected.
-
Reputational Damage: A data breach or privacy violation can severely damage your company's brand image and erode trust among clients and employees.
-
Legal Action: Data subjects can file complaints with the NPC or pursue legal remedies.
-
Operational Disruptions: Investigations by the NPC can be time-consuming and resource-intensive.
How Avvanz Supports Your DPA Compliance
Navigating these legal requirements can be complex, especially with the volume of hiring many Manila businesses undertake. Avvanz is committed to ensuring that your background screening processes are not only thorough but also fully compliant with the Data Privacy Act.
Our secure platform, Avvanz Screen™, is designed with data privacy and security at its core. We assist you by:
-
Facilitating Informed Consent: Providing clear mechanisms for obtaining candidate consent.
-
Ensuring Data Security: Implementing robust security measures for all data processed.
-
Providing Compliant Verification: Conducting checks in a manner that respects the DPA's stipulations.
-
Offering Expert Guidance: Advising on best practices for data handling throughout the hiring lifecycle.
Building Trust Through Responsible Hiring
In Manila's competitive business environment, demonstrating a commitment to data privacy is as important as verifying qualifications. By prioritizing DPA compliance in your background check procedures, you not only mitigate legal risks but also build a foundation of trust and respect with your potential workforce.
Ensure your hiring practices are legally sound and data-privacy compliant. Contact Avvanz today for expert guidance on navigating the Data Privacy Act for your recruitment needs in Manila.