Table of Contents of Processing of Personal Information

Table of Contents: Processing of Personal Information

Processing of Personal Information

1. Introduction: Defining “Processing” in Data Privacy Law

Under Republic Act No. 10173, also known as the Data Privacy Act of 2012 (DPA), and the procedural framework enforced by the National Privacy Commission (NPC), the legal threshold of “processing” is the fundamental trigger for data privacy governance. Regulatory compliance is not an isolated event restricted to the moment personal data enters an API endpoint or the moment a database row is dropped. Instead, data privacy law governs the technical and operational handling of personal data across its entire information lifecycle—from ingestion and transformation to storage, utilization, and final sanitization.

From an information architecture perspective, any automated or manual manipulation of personal records constitutes processing. Legal liabilities, technical controls, and compliance obligations attach at every state transition within an enterprise data pipeline. To establish a legally sound and architecturally compliant data governance framework, organizations must anchor their operations in the foundational statutory definition under Section 3(j) of Republic Act No. 10173 and the procedural definitions under NPC Circular No. 2021-01:

Foundational Legal Definitions (RA No. 10173 & NPC Circular No. 2021-01, Rule I, Sec. 4)

  • Processing: Refers to any operation or any set of operations performed upon personal information including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data (RA No. 10173, Sec. 3(j)).
  • Data Subject: Refers to an individual whose personal information is processed (NPC Circular 2021-01, Sec. 4(f)).
  • Personal Information: Refers to any information whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual (NPC Circular 2021-01, Sec. 4(n)).
  • Electronically-Stored Information (ESI): Refers to any information which is received, recorded, transmitted, stored, processed, retrieved, or produced electronically. It shall include any print-out or output that accurately reflects the electronically-stored information (NPC Circular 2021-01, Sec. 4(h)).

2. Deconstructing the 12 Core Operations of Processing

The statutory definition of processing breaks down into twelve explicit operational phases. System architects and privacy counsel must map each phase to specific database state changes, infrastructure components, and organizational workflows.

2.1 Collection

  • Conceptual Definition: The entry point of the data lifecycle, representing the initial act of gathering, receiving, or acquiring personal data from data subjects or external third-party systems via network ingress, manual entry, or automated interface payloads.
  • Practical Example: Ingestion of user attributes via an HTTPS POST request on a web client intake form or the formal submission of an administrative privacy complaint payload to a regulatory ingestion gateway.

2.2 Recording

  • Conceptual Definition: The persistent writing, capturing, or logging of incoming personal data into structured, semi-structured, or physical datastores, establishing a baseline transactional entry or audit log record.
  • Practical Example: An NPC receiving officer stamping and logging the precise date and hour of physical pleading receipt into the official docket registry (Rule III, Sec. 1), or a database write-ahead log (WAL) appending a timestamped entry of an incoming filing.

2.3 Organization

  • Conceptual Definition: The systematic structuring, indexing, partitioning, or categorizing of recorded personal data within datastore schemas to optimize searchability, relational mapping, and administrative retrieval.
  • Practical Example: Structuring and indexing filed data subject complaints within a relational database using case numbers, statutory causes of action, and assigned investigating officer IDs as indexed foreign keys.

2.4 Storage

  • Conceptual Definition: The long-term or ephemeral retention of personal data across physical filing cabinets, localized block storage, relational databases, object storage buckets, or cloud infrastructure environments at rest.
  • Practical Example: Maintaining encrypted Electronically-Stored Information (ESI) across secure, redundant database clusters operated under routine, good-faith electronic information system maintenance policies (Rule V, Sec. 4).

2.5 Updating or Modification

  • Conceptual Definition: Performing write mutations, amendments, or state revisions on existing records within a database to preserve data accuracy, completeness, and contextual alignment with operational facts.
  • Practical Example: Executing an UPDATE query on a case record to amend a formal complaint pleading, correcting material factual allegations or updating a respondent’s official service address (Rule IV, Sec. 2).

2.6 Retrieval

  • Conceptual Definition: Querying, filtering, and extracting specific stored personal data records from physical storage media or persistent digital databases for operational execution, reporting, or evidentiary review.
  • Practical Example: Executing database query scripts to extract historical ESI pursuant to an official discovery order issued during an NPC preliminary conference (Rule V, Sec. 4).

2.7 Consultation

  • Conceptual Definition: Accessing and inspecting personal data in a read-only state for analysis, evaluation, or legal assessment without triggering record mutation, data extraction, or state transformation.
  • Practical Example: An evaluating or investigating officer conducting a read-only examination of submitted evidence, witness affidavits, and supporting documents to evaluate if a privacy complaint is sufficient in form and substance (Rule IV, Sec. 1).

2.8 Use

  • Conceptual Definition: Applying personal data within active operational workflows, business logic microservices, automated communication systems, or quasi-judicial functions to fulfill a specific operational purpose.
  • Practical Example: Consuming party contact details within an automated SMTP gateway to issue official notices of preliminary conferences or serve administrative orders via electronic mail (Rule III, Sec. 2 & 6).

2.9 Consolidation

  • Conceptual Definition: Aggregating, merging, or joining disparate datasets, tables, or case files from multiple sources into a single unified record, datastore, or procedural proceeding.
  • Practical Example: Performing a procedural join or record merge to consolidate two or more separate privacy complaints that share common questions of law, fact, or identity into a single unified proceeding (Rule II, Sec. 7).

2.10 Blocking

  • Conceptual Definition: Applying access control lists (ACLs), dynamic row-level security (RLS), or administrative overrides to isolate and restrict access to personal data, freezing further processing while preserving the underlying data integrity.
  • Practical Example: Enforcing an administrative lock or system quarantine on a respondent’s data infrastructure pursuant to an order for a Temporary Ban on Processing granted by the Commission (Rule IX, Sec. 1).

2.11 Erasure

  • Conceptual Definition: The logical deletion, table truncation, or software-level purging of personal data from active operational databases and index tables when processing grounds expire.
  • Practical Example: Executing soft-deletes or automated database purge scripts to clear personal data from an active live application after the primary processing purpose has been fulfilled or pursuant to an NPC compliance order.

2.12 Destruction

  • Conceptual Definition: The permanent, irreversible physical or cryptographic obliteration of data storage media or encryption keys, rendering data recovery technically impossible.
  • Practical Example: Executing cryptographic key destruction (crypto-shredding) or physical media shredding to destroy personal notes taken during confidential mediation proceedings immediately upon mediation termination (Rule VI, Sec. 17).

Summary of Processing Operations and Technical Domains

OperationReal-World Practical ExampleData State / Architectural Domain
CollectionIngesting user data via web forms or complaint filing endpoints.Data in Transit / Ingress Network Layer
RecordingLogging date, time, and payload attributes into transaction registries.Data Ingestion / Audit & Write-Ahead Logs
OrganizationIndexing and partitioning case files by case number and officer ID.Metadata Indexing / Database Schema Architecture
StorageRetaining ESI on encrypted cloud volumes or local database servers.Data at Rest / Persistent Storage Infrastructure
Updating or ModificationAmending a complaint to update a party’s legal service address.Data Mutation / State Transition Management
RetrievalRunning SQL queries to extract historical ESI for discovery production.Data Extraction / Query Execution Layer
ConsultationAn investigating officer inspecting read-only affidavits and pleadings.Data in Use / Read-Only Inspection Layer
UseDispatching automated notices of hearing to email addresses.Data in Processing / Workflow Execution Layer
ConsolidationMerging separate complaints involving common facts into one file.Data Integration / Aggregation & ETL Pipelines
BlockingImplementing dynamic access restrictions during a regulatory stay.Access Control / Quarantine & Security Governance
ErasureExecuting logical soft-deletes or database row purges.Data Sanitization / Logical Lifecycle Purging
DestructionShredding physical notes or executing crypto-shredding key destruction.Media Sanitization / Permanent Hardware & Cryptographic Destruction

3. Regulatory Enforcement and Special Rules Governing Processing

Data processing operations within the jurisdiction of Republic Act No. 10173 are subject to direct regulatory supervision by the National Privacy Commission. The 2021 NPC Rules of Procedure (NPC Circular No. 2021-01) and specialized advisories establish strict mechanisms governing processing bans, forensic discovery, and heightened transparency.

Temporary and Permanent Bans on Processing

The NPC possesses statutory authority under NPC Circular No. 2021-01 to issue administrative injunctions halting data processing operations to prevent irreparable harm:

  • Temporary Ban on Processing (Rule IX, Sec. 1–4): A complainant may file a motion for a temporary ban on a respondent’s data processing operations at the inception of a complaint or at any point before a decision becomes final and executory.
    • Procedural Suspension: Filing an application for a temporary ban automatically suspends the main complaint proceedings until the application is resolved (Rule IX, Sec. 2).
    • Requisites for Grant: A temporary ban requires a showing that: (1) it is necessary to preserve the complainant’s rights, protect national security, or safeguard public interest and data subject rights; (2) the motion contains clear supporting facts; (3) the moving party posts a bond fixed by the investigating officer (unless exempt under Rule II, Sec. 4); and (4) the parties participate in a summary hearing (Rule IX, Sec. 3).
    • Cost of Service Mandate: Under Rule IX, Section 4, the complainant must shoulder the cost of personal service for the notice of summary hearing and ensure the respondent receives notice at least five (5) calendar days prior to the hearing date.
  • Permanent Ban on Processing (Rule VIII, Sec. 3(b)): The Commission may issue a permanent ban on data processing as an administrative sanction incorporated directly into its final Decision resolving a privacy dispute.

Discovery, Preservation, and Confidentiality of ESI

Rule V of the 2021 NPC Rules of Procedure sets rigorous forensic and procedural standards for the discovery of Electronically-Stored Information (ESI):

  • Mandatory Response Window: When a party receives an ex parte request for the production, inspection, copying, testing, or sampling of ESI, that party must respond within ten (10) calendar days (or within a timeframe ordered to preserve data integrity), either consenting to inspection or setting forth explicit technical objections (Rule V, Sec. 4).
  • Routine Good-Faith System Operations Exception: Sanctions for failure to produce ESI will not be imposed if the responding party proves that the data was lost as a result of the routine, good-faith operation of an electronic information system executed in accordance with established, documented data retention policies (Rule V, Sec. 4).
  • Mandatory Limitations on ESI Discovery: Under Rule V, Section 4, the investigating officer must limit the frequency or extent of ESI discovery—even from accessible sources—if it is determined that:
    1. The ESI can be obtained from another source that is more convenient, less burdensome, or less expensive;
    2. The discovery request is unreasonably cumulative or duplicative;
    3. The requesting party had ample prior opportunity in the proceeding to obtain the information; or
    4. The likely burden or expense of the proposed discovery outweighs its likely benefit, considering the amount in controversy, party resources, the impact on the data subject, and the importance of the issues.
  • Strict Confidentiality Mandate (Rule V, Sec. 6): Any party receiving ESI or records through discovery is strictly mandated to preserve its confidentiality. Discovered ESI may be utilized solely for legal purposes within the immediate proceedings and by the NPC in fulfilling its statutory mandate.
       ESI Discovery Request Received
                     │
                     ▼
  ┌─────────────────────────────────────┐
  │ Response Required Within 10 Days    │
  └──────────────────┬──────────────────┘
                     │
         ┌───────────┴───────────┐
         ▼                       ▼
┌──────────────────┐    ┌──────────────────┐
│ Allow Inspection │    │ Formal Objection │
└──────────────────┘    └────────┬─────────┘
                                 │
                                 ▼
                   ┌───────────────────────────┐
                   │ Investigating Officer     │
                   │ Evaluates Undue Burden &  │
                   │ Mandatory Limitations     │
                   │ (Rule V, Sec. 4 a-d)      │
                   └───────────────────────────┘

Child-Oriented Processing Transparency

When processing operations target or impact children, Personal Information Controllers (PICs) must adhere to heightened transparency standards set forth in NPC Advisory Guidelines (Advisory-2024.12.17):

  • Granular Activity Disclosure: PICs must explicitly inform children of the specific and precise processing activities performed on their personal data, avoiding boilerplate legal phrasing.
  • Multimodal Delivery Formats: Privacy notices must be rendered using age-appropriate, accessible alternative formats tailored to the intended age demographic. Recommended modalities include videos, infographics, visual animations, and audio recordings.
  • Architectural UI/UX Integration: Data architecture and front-end user experience (UI/UX) workflows must incorporate age-gating, clear consent mechanisms, and contextual, bite-sized privacy notices embedded directly within the user interaction layer.

4. Key Takeaways for Data Controllers, Processors, and Data Subjects

  1. Map and Audit the Entire Operational Lifecycle: Compliance cannot be treated as a point-in-time documentation exercise. Organizations must establish comprehensive data lineage tracking from initial API ingestion (Collection) down to permanent cryptographic media sanitization (Destruction).
  2. Architect Systems to Support Injunctions and Administrative Bans: Enterprise data architecture must support granular access control restrictions (Blocking). Technical teams must maintain the capability to dynamically quarantine specific datasets without causing database corruption or violating legal preservation mandates.
  3. Establish Defensible ESI Preservation and Automated Backup Policies: To qualify for the “routine, good-faith operation” exception under Rule V, Section 4, organizations must maintain documented automated data retention schedules, immutable audit trails, and strict 10-day ESI discovery response protocols.
  4. Implement Multimodal Transparency Frameworks for Minor Data: When architecting platforms utilized by children, compliance teams and software engineers must deploy age-appropriate, visual, and audio-based transparency interfaces under NPC Advisory-2024.12.17, moving beyond traditional text-heavy privacy policies.