Table of Contents of Six (6) Criteria for Lawful Processing of Personal Information

Table of Contents: Six (6) Criteria for Lawful Processing of Personal Information

Six (6) Criteria for Lawful Processing of Personal Information

Personal information, such as your name, home address, and phone number, is precious, and any unlawful collection, storage, and distribution is a blatant violation in the digital age. Privacy is a fundamental human right. That’s why the Data Privacy Act allows processing (collecting, storing, copying) of personal information only on certain lawful grounds.

One of the three (3) foundational principles of data privacy is legitimate purpose, meaning there must always be a lawful basis for processing personal information.

Quick vocab:
• Synonyms for “criteria”: legal justification, legal basis, legitimate purpose.
• “Processing” is the automated or manual manipulation of personal records.
• “Foundational principles” refer to the three principles of transparency, proportionality, and legitimate purpose (TPL), which cover both private controllers and public authorities.

Importance of Having a Basis for Processing of Personal Information

  1. To ensure that one of the three foundational principles of data privacy is upheld: legitimate purpose. Without a legitimate purpose, personal data will be shared unlawfully, leading to stigmatization or traumatization of people’s dignity.
  2. To protect the individual against the gradual expansion, repurposing, or unauthorized sharing of their personal information for incompatible objectives beyond their reasonable expectations.
  3. To avoid “consent fatigue” – getting a data subject’s consent for every activity will lead to “consent fatigue” that desensitizes users. Having criteria other than consent means that there will be situations where requesting consent is unnecessary when another legal basis applies.
  4. If consent is the only basis, then every time a data subject requests data deletion by withdrawing consent, the PIC must comply. However, because other legal bases may apply, a PIC may legally refuse such a request for data deletion.
  5. Documenting lawful criteria such as keeping a record of a Legitimate Interest Assessment or declaring processing bases for NPC Data Processing System (DPS) registration, an organization/PIC demonstrates good faith and accountability during regulatory audits and investigations.

Below are the legal basis/criteria for processing Personal Information:

(a) The Data Subject Has Given Their Consent

Under the Data Privacy Act of 2012 (DPA) and NPC Circular No. 2023-04 (Guidelines on Consent), consent is one of the statutory criteria for lawfully processing personal data, but it is subject to strict legal requisites and operational standards.

1. Core Requisites of Valid Consent . To serve as a valid lawful basis, consent must be a freely given, specific, informed indication of will expressed through a clear assenting action:

  • Freely Given: The data subject must have genuine choice and control. Consent is invalidated if obtained through pressure, intimidation, fear of adverse consequences for refusal, or deceptive design patterns.
  • Specific & Granular: Consent must be given for explicit and declared purposes. Blanket, vague, or bundled consent is strictly prohibited. If data is processed for multiple unrelated purposes, data subjects must be allowed to opt into each purpose separately.
    • In JVA vs. UPESO NPC Case No. 19-498 (last accessed 27 Sept 2026), the online lending platform used a vague, overbroad, and confusing language in its loan agreement. When the complainant failed to pay and UPESO tried to collect the debt, UPESO accessed the complainant’s contacts, and the latter received messages of harassment, threats, and reputational damage from the lending platform. The NPC held that UPESO “obtained a blanket consent to process the information they acquired from Complainant and not informed consent to process specific (granular) information for a specific limited purpose.” The consent was given for client evaluation or verification and not for UPESO to access their contacts.
  • Informed: Before consent is requested, the Personal Information Controller (PIC) must provide key information in plain, straightforward, and understandable language—including the personal data involved, declared purposes, scope, retention period, PIC identity, risks, and data subject rights.
    • Just-in-time and Layered Notices. The usage of just-in-time and layered notices in presenting the relevant information to the data subject shall be the default format. (Section 9C, NPC 2023-04) For example, at the App’s intro, it may contain a summary, but there should be a link that will lead users to read the full text of the privacy notice.
  • Clear Assenting Action: Consent must be actively given through an affirmative act (e.g., ticking an unchecked box, signing, or clicking an agree button). Implied consent, non-response, timed approvals, or pre-ticked default boxes can never constitute valid consent.
  • Evidenced: The PIC must be able to demonstrate that valid consent was obtained and keep records evidenced by written, electronic, or recorded means.

2. Consent is Not Always Required (“Consent Fatigue”). A common compliance misstep is defaulting to consent for every activity. Under NPC guidelines: (a) If processing falls under another lawful criterion under Section 12 or 13 of the DPA (such as contractual necessity, legal obligation, public health mandate, or legitimate interest), a request for consent is unnecessary; (b) Forcing users to sign unnecessary consent forms leads to “consent fatigue,” which desensitizes individuals and undermines meaningful data protection. (Note: While consent may not be required when another lawful basis applies, a Privacy Notice is required at all times to inform data subjects.) (c) PICs are mandated to minimize the risk of consent fatigue of its target data subjects.

3. Right to Withdraw Consent. Data subjects have the right to withdraw their consent at any time, easily and without cost. Once consent is withdrawn, the PIC must stop processing, terminate relying services, and delete or block the personal data unless another valid legal basis justifies continued retention. Withdrawing consent does not affect the lawfulness of any processing conducted prior to the withdrawal.

4. Validity and Duration. Obtaining consent is not a one-time event; it must be an actively managed choice where the PIC provides a mechanism for ongoing preference control. Consent remains valid only as long as the scope, nature, purpose, and extent of the processing remain unchanged. If the purpose evolves significantly or becomes incompatible with the original declaration, the original consent is void, and new consent must be obtained.

5. Special Instances Requiring Consent. PICs must obtain explicit consent when automated processing is the sole basis for a decision that produces legal effects or significantly impacts the data subject. Where data sharing between PICs relies on consent, the affected individuals must be informed of the specific sharing arrangement and third-party recipients before giving consent.

(b) Necessary and related to the fulfillment of a contract

The complete provision under Section 12b, “(b) The processing of personal information is necessary and is related to the fulfillment of a contract with the data subject or in order to take steps at the request of the data subject prior to entering into a contract;”

What happens if, after you buy from an online shopping platform and pay, the online store agent calls to ask your consent to print your name, address, and phone number and stick them on the delivery package? For sure, you will find it absurd, if not annoying. This is what the second criteria contemplates.

This criterion recognizes that delivering goods, executing services, or performing contractual obligations inherently requires handling specific personal data. The core requirement is genuine necessity—the processing must be directly and objectively required to accomplish the primary purpose of the agreement or to provide the specific service sought by the individual. It’s also crucial to establish that there was a valid contract in the first place.

Crucially, under NPC Circular No. 2023-04 (Guidelines on Consent), when personal data processing is legitimately grounded on contractual necessity, obtaining the data subject’s consent is completely unnecessary. Requesting consent in instances where processing is required to perform a contract is considered a compliance misstep that leads to “consent fatigue” and creates misleading expectations, as it falsely implies that the data subject has a choice to opt out while still receiving the contractual service. Instead of requesting consent, the organization satisfies its legal obligations by embedding the relevant processing terms transparently within the contract or service terms and providing a clear Privacy Notice at all times.

This criterion is strictly governed by the principle of proportionality, meaning collection must be limited to what is strictly adequate, relevant, suitable, and not excessive for fulfilling the contractual terms. Any additional or secondary processing activity—such as direct marketing, behavioral profiling, or sharing data with third parties for unbundled products—cannot be justified under the umbrella of contractual performance. Such secondary uses require a distinct, separate lawful basis, such as explicit consent or an established legitimate interest. Furthermore, even in standard-form agreements or contracts of adhesion, processing provisions remain valid only if they are transparent, fair, necessary, and proportionate to the contract’s scope.

Grounding processing in a contract also shapes how data subject rights are exercised and managed. Under NPC Advisory No. 2021-01, the Right to Data Portability specifically applies when processing is based on a contract or consent, giving individuals the right to obtain or transfer their personal data in a structured, commonly used electronic format. On the other hand, an individual’s request for immediate erasure or blocking of their personal data can be legally denied by the organization if retention remains necessary for the fulfillment of the contract, compliance with legal obligations, or the establishment, exercise, or defense of legal claims. Once the underlying contract is terminated, cancelled, or unsubscribed from, processing under this criterion must cease unless another valid statutory basis justifies continued retention.

(c) In compliance with a legal obligation

“The processing is necessary for compliance with a legal obligation to which the personal information controller is subject;”

Under Section 12(c) of the Data Privacy Act of 2012, personal information may be lawfully processed whenever the processing is directly necessary for compliance with a legal obligation to which the personal information controller is subject. This statutory criterion applies whenever a specific law, executive mandate, administrative regulation, or court order imposes a binding duty on an organization to collect, retain, report, or disclose personal data. Grounding processing in a legal obligation ensures that organizations can fulfill their statutory duties while maintaining lawful authority over the personal information they handle.

When personal data processing is required by law, obtaining the data subject’s consent is completely unnecessary. Like letter b, tequesting consent when processing is legally mandated is a compliance misstep that leads to consent fatigue, which desensitizes individuals and undermines the requisites of valid consent by misleading data subjects into believing they have a choice to refuse. Nevertheless, the absence of a consent requirement does not exempt the controller from adhering to the general data privacy principle of transparency, as a clear privacy notice remains mandatory in all processing instances to inform data subjects of the legal basis and scope of collection.

Grounding processing in a legal obligation also shapes how data subject rights are exercised and evaluated. Under National Privacy Commission guidelines on data subject rights, a controller may legally deny a data subject’s request for the immediate erasure or blocking of their personal data if retaining that information remains necessary for compliance with a legal obligation. Similarly, while a data subject has the right to object to processing, the controller is not required to cease processing if the activity is anchored on a statutory requirement rather than consent or legitimate interest. Even with a statutory command, the controller remains bound by the principle of proportionality, ensuring that data collection is restricted strictly to what is adequate, relevant, and necessary to satisfy the specific legal mandate.

Practical examples of this criterion span across multiple regulatory sectors in everyday business operations. In employment settings, companies process employee tax identification numbers and salary details to comply with statutory tax withholding rules under the Bureau of Internal Revenue, as well as mandatory contributions for social benefits. In the financial sector, banks and financial institutions handle customer identification records and transaction histories to comply with know-your-customer verification rules and anti-money laundering reporting obligations. Furthermore, transportation platforms, health institutions, and public facilities collect regulatory inspection logs, disease surveillance data, or surveillance footage to satisfy statutory safety, public health, or court-issued mandates.

(d) Vital interests

Under Section 12(d) of the Data Privacy Act of 2012, personal information may be lawfully processed when the processing is necessary to protect vitally important interests of the data subject, including life and health. This statutory criterion establishes a legal justification specifically tailored for urgent, critical, or emergency situations where an individual’s physical well-being, bodily integrity, or survival is at immediate risk. It serves as a necessary safety net within data protection law, ensuring that privacy rules do not impede life-saving interventions or emergency medical care when rapid action is paramount.

In these emergency scenarios, requiring prior consent is often impossible due to the data subject’s physical incapacity, loss of consciousness, or the extreme time sensitivity of the crisis. The law deliberately waives the consent requirement in such circumstances so that first responders, healthcare personnel, or protective authorities can act without legal delay. Nevertheless, the processing remains strictly governed by the principle of proportionality, meaning that even during a crisis, entities may only collect and handle the minimum personal data strictly necessary to mitigate the immediate threat to life and health.

Practical applications of this criterion frequently arise in emergency medical care, such as paramedics retrieving an unconscious accident victim’s health history, medical conditions, or blood type. It also covers emergency responses during natural disasters, search and rescue operations, or severe public health emergencies where identifying individuals is crucial to administering immediate medical intervention or preventing grave physical harm. Once the immediate emergency has passed and the threat to life or health is resolved, continued processing or long-term retention of that personal data can no longer be justified under vital interests alone and must be anchored on another valid legal basis.

Relying on vital interests also impacts the exercise of data subject rights during the crisis. While data privacy rights are upheld to the fullest extent possible, an individual cannot use the right to object or request immediate data erasure to halt critical processing that is actively preserving their own life or health. Organizations that process personal information under this emergency basis are required to maintain strict confidentiality, implement appropriate security measures to safeguard the data, and document the specific emergency context to demonstrate accountability after the crisis has been managed.

(e) National emergency, public order or public safety

Under Section 12(e) of the Data Privacy Act of 2012, personal information may be lawfully processed when it is necessary to respond to a national emergency, to comply with the requirements of public order and safety, or to fulfill the functions of a public authority which necessarily includes the processing of personal data for the fulfillment of its mandate. This criterion provides state agencies, local government units, law enforcement, and regulatory bodies with explicit statutory authority to perform their constitutional or statutory functions without administrative obstruction. It establishes a clear legal foundation balancing state governance and individual rights, affirming that while data privacy is fundamental, public entities must possess the legal tools necessary to promote the general welfare and maintain societal stability.

Unlike private controllers operating for commercial objectives, a public authority relies on this criterion to execute sovereign duties directly tied to statutory mandates. Under National Privacy Commission guidelines, when a government body processes personal data pursuant to its public mandate, national emergency response, or public order measures, obtaining the consent of the data subject is not required. Requiring consent in these public governance contexts would be incompatible with state functions, as individuals cannot opt out of statutory oversight, official regulatory checks, or public safety operations. Nevertheless, public authorities remain strictly bound by the foundational principles of transparency, legitimate purpose, and proportionality, ensuring that government power is exercised lawfully without collecting data beyond what is strictly necessary.

Practical applications of this criterion are clearly seen during national declarations of emergency, such as natural disasters, state-wide crises, or public health emergencies, where public health authorities and government agencies must rapidly process data to deploy relief, manage containment, and mobilize national resources. Similarly, in maintaining public order and safety, law enforcement agencies deploy operational tools—such as video surveillance in public spaces or body-worn cameras during police operations—to safeguard communities, prevent criminality, and enforce traffic and public safety laws. Grounding processing in Section 12(e) ensures that public authorities remain accountable to their legally defined mandates while effectively serving the public interest.

(f) Legitimate interests

Under Section 12(f) of the Data Privacy Act of 2012, personal information may be lawfully processed when the processing is necessary for the purposes of the legitimate interests pursued by the personal information controller or by a third party to whom the data is disclosed. A legitimate interest is defined by the National Privacy Commission as any actual, real, and clear interest, benefit, or gain that a controller or third party may derive from a specific processing activity. Crucially, regulations specify that legitimate interest applies exclusively to personal information and cannot serve as the legal basis for processing sensitive personal information or privileged information. This criterion provides private entities with flexible lawful authority for operational, commercial, or security activities, provided the processing is strictly justified and balanced against individual privacy rights.

To lawfully rely on this criterion, personal information controllers are required under NPC Circular No. 2023-07 to conduct and document a Legitimate Interest Assessment, which consists of a mandatory three-part test. The first component, known as the Purpose Test, requires the controller or third party to establish a specific, clearly defined, and lawful objective that is communicated to the data subject prior to processing or at the next practical opportunity in accordance with transparency mandates. The second component, the Necessity Test, evaluates whether the chosen means to accomplish the interest are necessary, lawful, and proportional—meaning the collection and processing must be adequate, relevant, suitable, and not excessive relative to the declared purpose.

The third and most critical element is the Balancing Test, which mandates that the established legitimate interest must not be overridden by the fundamental rights and freedoms of the data subject protected under the Philippine Constitution. In conducting this balancing exercise, controllers must evaluate several factors, including the potential adverse effect or impact of the processing on the individual, the availability of less intrusive alternative methods to achieve the objective, and the technical or organizational safeguards implemented to mitigate risks. Additionally, controllers must evaluate the reasonable expectations of the data subject based on the context of their relationship, determining whether an average person would find such processing acceptable under the specific circumstances.

Grounding processing in legitimate interest encompasses various practical organizational functions, such as internal security monitoring, fraud prevention, and the protection of lawful rights or the establishment, exercise, or defense of legal claims before or during judicial proceedings. While government authorities generally cannot rely on legitimate interest for their core statutory duties, they may apply it to ancillary administrative functions. Because processing under Section 12(f) depends on balancing competing interests, data subjects retain the explicit right to object to the processing at any time, obligating the controller to cease processing unless compelling, legitimate grounds override the individual’s objection. Controllers are legally required to retain written records of their Legitimate Interest Assessment to prove compliance during regulatory checks or investigations.

Legitimate Interest Assessment: What it is and What it is for

A Legitimate Interest Assessment (LIA) is the systematic evaluation and balancing exercise undertaken by a Personal Information Controller (PIC) or third party to determine whether personal information can be lawfully processed under Section 12(f) of the Data Privacy Act of 2012. Rather than following a rigid or prescribed template, National Privacy Commission (NPC) Circular No. 2023-07 permits controllers to use any suitable structure, form, or existing methodology, provided the assessment rigorously evaluates three mandatory requisites: establishing a specific, lawful, and declared purpose (the Purpose Test), ensuring the chosen processing method is adequate, relevant, necessary, and lawful (the Necessity Test), and verifying that the interest does not override the fundamental rights and freedoms of data subjects protected under the Philippine Constitution (the Balancing Test).

The primary purpose of conducting a Legitimate Interest Assessment is to establish lawful authorization and ensure organizational accountability before relying on legitimate interest as a processing basis. Through the LIA, a PIC systematically evaluates the potential impact of the processing on individuals, determines whether the objective could be achieved through less intrusive alternative means, considers what a reasonable person would expect under the circumstances, and identifies necessary safeguards—such as privacy-enhancing technologies—to mitigate risks. Furthermore, the LIA fulfills a crucial regulatory documentation duty, as PICs are legally required to record and regularly evaluate their assessments, maintaining them as verifiable proof of compliance that must be submitted to the NPC upon request during investigations or compliance checks.