Lean Solutions Group Acquires SupportZebra.

Supplementary document to the Lean Solutions Group Global Corporate Policy
This Annex develops the local aspects of the personal data protection regime applicable to LEAN OUTSOURCING SOLUTIONS GROUP PHIL. INC. (LOSGI), pursuant to Republic Act No. 10173, also known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations (IRR), and the issuances of the National Privacy Commission (NPC).
This Annex supplements the Global Corporate Policy on the Processing of Personal Data of Lean Solutions Group (LSG). In the interest of regulatory economy and to avoid divergences:
In the event of any conflict between this Annex and the Global Policy, the provisions of this Annex shall prevail to the extent they reflect applicable Philippine legal or regulatory obligations.
LOSGI is the entity responsible for the processing of personal data collected and used in connection with its operations in the Philippines.
| Instrument | Reference |
| Data Privacy Act of 2012 | Republic Act No. 10173 |
| Implementing Rules and Regulations | IRR of R.A. 10173 (2016, as amended) |
| NPC Advisory Opinions and Circulars | Including NPC Circular 16-03 (Breach Notification), NPC Circular 17-01 (Registration) |
| Supervisory Authority | National Privacy Commission (NPC) |
| Related Legislation | Cybercrime Prevention Act (R.A. 10175), Electronic Commerce Act (R.A. 8792), Labor Code of the Philippines |
All processing of personal data by LOSGI shall comply with the following principles under Section 11 of the DPA and its IRR:
LOSGI shall process personal data only upon a lawful basis under the DPA. The following bases are applicable to LOSGI’s operations:
5.1 For General Personal Data
5.2 For Sensitive Personal Information
The processing of sensitive personal information, including data pertaining to race, ethnic origin, marital status, age, color, religious, philosophical or political affiliations, health, education, genetic or sexual life, and specifically biometric data, requires one of the following:
5.3. Biometric Data (Voice and Facial Recognition)
LOSGI may process voice and image biometric data for employee identity verification, access control, and operational security purposes, strictly with the explicit, informed, and separate consent of the data subject. Such data is subject to the enhanced security measures set forth in the Global Policy.
Under the DPA and its IRR, data subjects have the following rights with respect to their personal data processed by LOSGI:
| Channel | Details |
| In-person attendance | [Insert address] — Business hours: Monday to Friday, 9:00 a.m. to 6:00 p.m. (Philippine Time) |
| Official data subject channel | tratamientodedatos@leangroup.com |
| Corporate website | https://www.leangroup.com |
Whether submitted physically or electronically, data subject requests must contain the following information:
9.1. Inquiries (Access Requests)
When a data subject wishes to know what personal information is stored in LOSGI’s systems:
9.2. Complaints (Correction, Erasure, Objection, or Alleged Violations)
Filing and admission:
Tacit withdrawal for failure to remedy:
Response period:
9.3. Escalation to Supervisory Authority
If a data subject does not receive a response within the applicable periods or considers the response unsatisfactory, they may file a complaint with the National Privacy Commission (NPC) through its official channels at www.privacy.gov.ph.
Where consent is the lawful basis for processing, LOSGI shall ensure that consent is:
LOSGI shall maintain a centralized, digitized record of all consent forms. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Personal data shall not be retained in a form that permits identification of data subjects for longer than is necessary to fulfill the stated purposes, subject to the following minimum periods:
| Category | Retention Period |
| Employee data (employment records) | Duration of employment relationship + 10 years (or as required by the Labor Code and applicable Philippine law) |
| Applicant/candidate data | 12 months from end of recruitment process, or longer if the data subject consents to inclusion in talent database |
| Commercial and accounting data (clients, suppliers, contractors, shareholders) | Duration of relationship + 10 years (or as required by applicable tax, accounting, and corporate legislation) |
| Video surveillance recordings | 90 calendar days (general rule). Extended retention permitted in connection with active investigations, administrative or judicial proceedings, or competent authority requests |
| Biometric data (voice and facial) | Duration of employment relationship or consent; automated deletion upon termination or revocation of consent, subject to evidentiary preservation requirements |
| Web portal user activity logs | 12 months from last activity, or as required by applicable law |
Upon expiration of the applicable retention period, personal data shall be securely disposed of, anonymized, or destroyed, in accordance with LOSGI’s information retention and disposal procedures and applicable NPC guidelines.
LOSGI may deny or limit requests for erasure, blocking, or withdrawal of consent in any of the following circumstances:
In such cases, LOSGI shall restrict the use of the data to the purpose that justifies its continued retention and shall maintain strict confidentiality of the information.
Pursuant to the DPA and its IRR, LOSGI may transfer personal data outside the Philippines only where:
In the context of LOSGI’s global service delivery model, personal data, particularly employee and operational data, may be transferred to Lean Staffing Solutions Inc. (United States), to other entities within Lean Solutions Group, or to client organizations located in the United States and other countries. Such transfers are carried out for the purpose of managing the employment relationship, allocating resources to international client projects, auditing services, and conducting internal corporate governance. LOSGI shall ensure that recipient entities comply with security standards equivalent to those described in the Global Policy.
In accordance with the Data Privacy Act of 2012 and its IRR, LOSGI shall designate a Data Protection Officer (DPO) who is responsible for:
The DPO must be registered with the NPC. LOSGI shall ensure the DPO has the necessary resources to carry out their tasks, maintains the required level of expert knowledge, and is not placed in a position of conflict of interest in relation to LOSGI’s data processing activities.
Pursuant to NPC Circular 17-01 (as amended), LOSGI shall register its data processing systems with the National Privacy Commission where registration is required, specifically where LOSGI employs two hundred fifty (250) or more persons, or processes personal data of one thousand (1,000) or more data subjects, or processes sensitive personal information. LOSGI shall ensure that its registration is filed within the prescribed periods and kept current at all times.
LOSGI undertakes to:
LOSGI has implemented a Personal Data Breach Response Procedure that includes the following stages:
LOSGI shall conduct a Privacy Impact Assessment (PIA) prior to commencing any processing activity that involves sensitive personal information, large-scale processing of personal data, systematic monitoring of data subjects, use of new technologies, biometric processing, or any other high-risk processing as determined by the NPC. The PIA shall be documented and reviewed periodically.