Skip to content
ERPat System
ERPat System
Software

Data Privacy for HR: Protecting Employee Information

HR holds the most sensitive records in the company, from government ID numbers to medical certificates. This guide walks through your duties under the Data Privacy Act and the access controls and audit trails that make them workable.

CCChelsea Cuevas6 min read

In this guide

TopicSoftware
Time6 min read
Best forOperations leaders comparing disconnected tools with a more unified business system.

What to watch for

Use the article to identify repeat work, handoff gaps and places where one source of truth would help.

  1. 01What the Data Privacy Act asks of an HR team
  2. 02Most of an HR file is sensitive personal information
  3. 03Access control is the safeguard you can actually enforce
In this article

Every HR office in the country sits on a pile of information it would rather not lose: TINs, SSS and PhilHealth numbers, bank details, medical certificates, disciplinary records, salary histories. Most of it is collected without much ceremony, filed in a shared folder or a spreadsheet, and then quietly copied around the company as people ask for it. The Data Privacy Act treats that pile as a serious responsibility, and a small HR team can meet that responsibility — but only if the systems holding the records are set up for it.

What the Data Privacy Act asks of an HR team

Under the Data Privacy Act of 2012, a company that decides what employee data to collect and why is a personal information controller. That role carries obligations you cannot delegate to a vendor: collect only what you actually need, tell employees what you are collecting and why, keep the data accurate, hold it only as long as there is a reason to, and put real security measures around it.

Consent is not the only lawful basis, and in employment it is usually not the main one. A great deal of HR processing rests on the employment contract itself and on obligations the employer already carries by law — remitting SSS, PhilHealth and Pag-IBIG contributions, withholding tax and issuing the certificates BIR requires, keeping employment records for DOLE inspection. What that means in practice is that you rarely need to ask permission to run payroll, but you do need to be able to explain, on request, what you hold, where it came from, and who inside the company can see it.

Most of an HR file is sensitive personal information

The law draws a line between personal information and sensitive personal information, and HR sits mostly on the wrong side of that line. Government-issued identifiers, health information, and records of any offence charged or resolved are all in the stricter category. A single 201 file can contain an SSS number, a TIN, a medical certificate supporting a sick leave, and a written explanation from a disciplinary case.

That matters because the ordinary habits of an HR office are usually where the exposure comes from. The payroll register emailed to a department head so they can "check something." The spreadsheet of employee numbers, birthdays and salaries kept on a laptop for convenience. The shared drive folder that was opened to a project team two years ago and never closed. None of these feel like incidents while they are happening, and all of them are the reason a company later cannot say with confidence who has seen an employee's records.

Access control is the safeguard you can actually enforce

Policies about confidentiality are necessary, but they are promises. Access control is the part you can enforce without depending on anyone's memory or goodwill. The working principle is least privilege: a person gets the narrowest view of employee data that still lets them do their job, and nothing beyond it.

Applied to HR, that usually means a supervisor can see their own team's attendance and leave balances but not compensation; a payroll officer can see compensation but not disciplinary records; a department head can approve a request without opening the underlying employee file. ERPat's Security module is built for exactly this kind of separation — accounts, sessions, roles and granular access control that carry across every module, so the boundary you set for HR data is the same boundary that applies everywhere else in the platform. It also handles the unglamorous half of the job: sessions that end, and accounts that are disabled the day someone resigns rather than the month after.

Audit trails are what turn a policy into evidence

The Data Privacy Act does not only ask you to be careful; it asks you to be able to show that you were. That is the difference between a company that says its payroll data is restricted and one that can demonstrate it, with a record of who opened which employee record, who changed a salary field, and when.

Audit trails also change how internal disputes end. When an employee asks how their salary figure reached a colleague, or when a manager insists they never touched a leave balance, a log settles the question in minutes instead of leaving HR to arbitrate between two accounts of events. The Compliance module in ERPat covers this ground — policy tracking, audit trails and the documentation regulators ask for — so the evidence accumulates as a by-product of normal work rather than being reconstructed under pressure. Logs are only useful if they are complete and nobody can quietly edit them, which is why this belongs in the system of record rather than in a separate file someone maintains by hand.

Registration, a data protection officer, and the paperwork behind it

Some obligations depend on your size and your processing. Under NPC Circular No. 2022-04, which took effect on 11 January 2023, a personal information controller or processor must register its data processing systems and its data protection officer with the National Privacy Commission if it employs 250 or more persons, or processes the sensitive personal information of 1,000 or more individuals, or carries out processing likely to pose a risk to the rights and freedoms of data subjects. The circular's 180-day transitory period ended on 10 July 2023, so registration is now simply part of the baseline for covered organisations.

Falling below those thresholds does not exempt a smaller employer from anything else. You still need a designated data protection officer, a privacy notice employees have actually seen, a retention schedule, and a documented view of your processing.

!
Software does not discharge the duty

Roles and audit trails cover the technical and organisational controls, not the legal ones. You still have to name a data protection officer, publish a privacy notice, and answer employees who ask to see or correct their records.

When something goes wrong, the clock is short

Breach handling is where preparation shows. Under NPC Circular No. 16-03, a personal information controller must notify the National Privacy Commission within 72 hours of knowledge of, or reasonable belief in, a personal data breach — and affected employees have to be told as well. Seventy-two hours is not long enough to build a picture from scratch.

What makes that window survivable is knowing, on the first day, whose records were involved and who had access to them. Without access records and logs, the honest answer to "how many employees were affected" is usually "we cannot say," which is the worst answer to give a regulator and the worst one to give your own staff. Decide in advance who declares a breach, who drafts the notification, and where the access history lives.

Making this routine rather than a project

Data privacy in HR is less about a one-time compliance exercise than about a handful of habits that hold up over years: collect less, restrict who can see what, log what happens, and review both when people change roles. Start with an inventory of where employee data actually sits today, including the spreadsheets and shared folders nobody officially owns. Then narrow the access lists and make sure the system of record keeps a trail. If you would like to see how the platform's access control and audit features fit an HR workflow, the product overview is a reasonable place to begin.

Compliance context

Turn "Data Privacy for HR: Protecting Employee Information" into a compliance checklist

Compliance-heavy articles are most useful when they become a repeatable review habit. Treat the guidance as a way to confirm evidence, ownership and timing before reports or payroll records are submitted.

Part 1Documents and records to prepare

Before the team reviews compliance requirements, make sure the supporting records are complete and traceable.

  • Employee master records, pay history, schedules, leaves and attendance logs
  • Contribution, tax, deduction and adjustment summaries
  • Approval records, exception notes and revision history
Part 2Common gaps to prevent

Compliance gaps often come from missing evidence rather than missing intent. The system should make proof easy to find.

  • Late updates to employee status, salary rates or tax/contribution details
  • Manual corrections without a reason or reviewer attached
  • Reports generated from data that does not match the approved payroll run
Part 3How to make review repeatable

Create a simple rhythm: prepare records, run checks, document exceptions, approve, then lock the final version.

  • Use the same checklist every cutoff or reporting period
  • Assign one owner for exceptions and one owner for final approval
  • Keep final reports and supporting details together for later audit review
CC

Chelsea Cuevas

Content & Marketing Associate

Covers business growth, HR best practices, and the technology behind modern operations.

Relevant solution

Running operations across disconnected tools?

See how ERPat brings HR, payroll, accounting, inventory and sales into one connected platform built for Philippine businesses.

Explore ERPat

Comments

Leave a comment

Questions or thoughts on this article? Send a comment and our team will follow up by email.

Continue exploring

Clinic and Health Records: Handling Sensitive Data

Company clinics and hospitals hold the most sensitive category of personal data there is. Here is how Philippine employers can structure health records, restrict access and keep the documentation the National Privacy Commission expects.

6 min read

Data Security in Cloud Business Systems

A practical look at how cloud business systems are actually secured: role design, session control, tenant separation and the paperwork a breach demands. Written for Philippine companies keeping payroll and HR data online.

7 min read

ERPat System

See how these workflows come together inside ERPat.

Walk through ERPat using your actual process as the reference — one connected system for HR, payroll, accounting, inventory, sales and daily operations.

01Map your current operational workflow
02Identify repeated manual steps and handoff gaps
03Preview a more connected and controlled process