Employee monitoring law · Philippines
Transparency, legitimate purpose and proportionality: the three-part NPC test.
Meet the NPC’s three-part test: transparency, legitimate purpose, and proportionality.
- Region
- Asia Pacific
- Instruments
- 3 governing
- Employer duties
- 4 listed
- Last reviewed
- August 22, 2026
Philippines · what the law requires
Notice and proportionality
The Data Privacy Act of 2012 governs, and the National Privacy Commission applies a consistent three-part test: monitoring must be transparent, serve a legitimate purpose, and be proportionate, no more intrusive than needed for the stated purpose. This matters at scale for BPOs, where monitoring is routine and consent is usually taken through the employment contract plus a privacy notice signed at onboarding. The NPC expects a designated Data Protection Officer and registration where thresholds are met.
- TransparencyEmployees are informed of the monitoring, its nature, extent and purpose, typically in the contract plus a privacy notice at onboarding.
- A legitimate purposeProductivity, security or protection of intellectual property all qualify when genuinely the reason.
- ProportionalityNo more intrusive than necessary. This is where blanket continuous capture is most often challenged.
- A designated DPORequired, along with registration of data processing systems where the NPC thresholds are met.
- Proof Ledger
- Outcomes
- Certificates
- Audit log
- Data access
- Disputes
- Data egress
- Export
- What We See
- Controls
- AKAria K. viewed screenshotsLena M. · 3 capturesScreen capturemacOS · London09:42a91f…4c023d7b…91ee
- JMJon M. exported time reportDesign team · CSVmacOS · Berlin09:313d7b…91ee77c5…0ba4
- SDSara D. opened capture reviewRavi P. · one flagged frameWindows · Manchester09:1877c5…0ba4e208…5f13
- wm_live_7f2… read /v1/deliverablesScoped key · read onlyPublic API · allowlisted IP08:57e208…5f13b64a…2d90
- LMLena M. viewed her own recordWhat We SeemacOS · London08:44b64a…2d901cf9…8e77
- AKAria K. changed capture policyBlur set to alwaysmacOS · London08:261cf9…8e7705d2…ae31
The instruments, and which control answers each duty
- Data Privacy Act of 2012: Republic Act No. 10173. Criteria for lawful processing, the transparency/legitimate purpose/proportionality principles, and the rights of the data subject.
- NPC Implementing Rules: IRR of RA 10173. Security measures, DPO designation, registration of data processing systems and breach notification.
- Labor Code: Presidential Decree No. 442. Management prerogative, which Philippine tribunals balance against the DPA's privacy protections.
No product does this part
What you must still do yourself
Compliance is a property of your deployment. These are the steps in Philippines that no vendor can complete on your behalf, and skipping them is what turns a rollout into a finding.
- 1Designate a DPO and register processing systems with the NPC where required.
- 2Put the privacy notice into onboarding and keep the signed record.
- 3Document the proportionality reasoning, particularly if you run continuous capture.
- If you get it wrongCriminal penalties including imprisonment for unauthorised processing and related offences, plus fines; NPC compliance orders and cease-and-desist powers.
Verify the claim
Every control above, on the page that describes it
- Consent and notice record with version and date per personEvidence the onboarding notice and acceptance
- Interval capture with randomised cadenceKeep intrusion proportionate at BPO scale
- Composite foreign keys tying every record to its organisationSeparate each client's data on a shared floor
- Hash-chained audit of access and governance changesSupport breach notification duties
Sources and review date
Last reviewed August 22, 2026This is a summary of how employee-monitoring rules generally work in this jurisdiction, written to help you scope a rollout and brief your own advisers. It is not legal advice, it is not a substitute for it, and law changes. Verify against the primary sources listed and take local counsel before you deploy.
Nearby jurisdictions
Monitoring law elsewhere in Asia Pacific
- JapanSpecify the purpose of use, publish it, and do not exceed it.
- SingaporeEmployment data has a deemed-consent route, but notification is still mandatory.
- AustraliaIn NSW and the ACT: 14 days' written notice, with prescribed content, before you start.
- IndiaDPDP gives employment a legitimate use, but automated monitoring is argued to sit outside it.
- PolandThe Labour Code lists the permitted purposes, and productivity is not one of them.
- United KingdomThe ICO's 2023 monitoring guidance is the operative document, and it expects a DPIA.
Point it at one team for a week.
Create the account, put the agent on a handful of desks, and leave it alone. On Friday you read the week instead of reconstructing it: hours against their projects, focus and idle per person, and the timesheets already filled in.
Free for two seats. No card, and no sales call to sit through.