Lean Solutions Group Acquires SupportZebra.

Learn More
LEAN GROUP
Hero Image

Legal Center

ANNEX FOR PERSONAL DATA PROCESSING IN THE PHILIPPINES

Supplementary document to the Lean Solutions Group Global Corporate Policy 

  1. Object, Scope, and Relationship with the Global Policy

This Annex develops the local aspects of the personal data protection regime applicable to LEAN OUTSOURCING SOLUTIONS GROUP PHIL. INC. (LOSGI), pursuant to Republic Act No. 10173, also known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations (IRR), and the issuances of the National Privacy Commission (NPC). 

This Annex supplements the Global Corporate Policy on the Processing of Personal Data of Lean Solutions Group (LSG). In the interest of regulatory economy and to avoid divergences: 

  • Purposes and categories of data are not reproduced here; they are incorporated by reference from the Global Policy. 
  • This Annex exclusively incorporates: identification of the local controller, lawful bases for processing, data subject rights and procedures under Philippine law, retention periods, security obligations, breach notification requirements, NPC registration, the mandatory Data Protection Officer (DPO) regime, cross-border data transfers, and change control. 

In the event of any conflict between this Annex and the Global Policy, the provisions of this Annex shall prevail to the extent they reflect applicable Philippine legal or regulatory obligations. 

  1. Identification of the Personal Information Controller in the Philippines
  • Company Name: Lean Outsourcing Solutions Group Phil. Inc. 
  • Registered Address:  
  • Data Protection Officer (DPO):  

LOSGI is the entity responsible for the processing of personal data collected and used in connection with its operations in the Philippines. 

  1. Applicable Regulatory Framework
Instrument  Reference 
Data Privacy Act of 2012  Republic Act No. 10173 
Implementing Rules and Regulations  IRR of R.A. 10173 (2016, as amended) 
NPC Advisory Opinions and Circulars  Including NPC Circular 16-03 (Breach Notification), NPC Circular 17-01 (Registration) 
Supervisory Authority  National Privacy Commission (NPC) 
Related Legislation  Cybercrime Prevention Act (R.A. 10175), Electronic Commerce Act (R.A. 8792), Labor Code of the Philippines 

 

  1. Guiding Principles of Processing

All processing of personal data by LOSGI shall comply with the following principles under Section 11 of the DPA and its IRR: 

  • Transparency: Data subjects must be informed of the nature, purpose, and extent of processing of their personal data, including the risks and safeguards involved. 
  • Legitimate Purpose: Processing shall be compatible with a declared and specified purpose that is not contrary to law, morals, or public policy. 
  • Proportionality: Processing shall be adequate, relevant, suitable, necessary, and not excessive in relation to a declared and specified purpose. 

  • Accuracy: Personal data shall be accurate, kept up to date, and corrected or deleted if inaccurate or irrelevant for the declared purpose. 
  • Security: Personal data shall be protected by reasonable and appropriate organizational, physical, and technical measures against natural dangers and unauthorized processing. 
  • Retention: Data shall be kept only for as long as necessary for the fulfillment of the purposes for which it was collected. 
  • Accountability: LOSGI, as PIC, is responsible for personal data under its control and shall implement appropriate policies and procedures for the protection of personal data. 
  1. Lawful Basies for Processing

LOSGI shall process personal data only upon a lawful basis under the DPA. The following bases are applicable to LOSGI’s operations: 

5.1 For General Personal Data 

  • Consent: The data subject has given consent to the processing of their personal data for one or more specific purposes. 
  • Contract: Processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract. 
  • Legal Obligation: Processing is necessary for compliance with a legal obligation to which the PIC is subject. 
  • Vital Interests: Processing is necessary to protect vitally important interests of the data subject. or of another person. 
  • Legitimate Interests: Processing is necessary for the purposes of the legitimate interests pursued by LOSGI or by a third party, except where such interests are overridden by fundamental rights and freedoms of the data subject. 

5.2 For Sensitive Personal Information 

The processing of sensitive personal information, including data pertaining to race, ethnic origin, marital status, age, color, religious, philosophical or political affiliations, health, education, genetic or sexual life, and specifically biometric data, requires one of the following: 

  • Explicit consent of the data subject. 
  • Processing is necessary for medical treatment or health services carried out by a health professional. 
  • Processing is necessary to protect the life and health of the data subject or another person in an emergency situation. 
  • Processing is necessary for employment purposes and authorized by law. 
  • Processing is carried out pursuant to a statutory obligation on LOSGI. 

5.3. Biometric Data (Voice and Facial Recognition) 

LOSGI may process voice and image biometric data for employee identity verification, access control, and operational security purposes, strictly with the explicit, informed, and separate consent of the data subject. Such data is subject to the enhanced security measures set forth in the Global Policy. 

  1. Rights of Data Subjects

Under the DPA and its IRR, data subjects have the following rights with respect to their personal data processed by LOSGI: 

  • Right to be Informed: To be informed whether personal data pertaining to them shall be, are being, or have been processed, including the purposes, scope, and method of processing. 
  • Right of Access: To have reasonable access to their personal data being processed by LOSGI, including the sources from which personal data were obtained, the recipients thereof, and the manner of processing. 
  • Right to Object: To object to the processing of their personal data, including processing for direct marketing, automated processing, or profiling. LOSGI shall cease processing unless it demonstrates compelling legitimate grounds which override the interests, rights, and freedoms of the data subject. 
  • Right to Erasure or Blocking: To suspend, withdraw, or order the blocking, removal, or destruction of personal data that is incomplete, outdated, false, unlawfully obtained, used for unauthorized purposes, or no longer necessary for the declared purpose, subject to applicable legal retention obligations. 
  • Right to Rectification: To dispute the inaccuracy or error in their personal data and have LOSGI correct it immediately upon request, unless the request is vexatious or unreasonable. 
  • Right to Data Portability: To obtain a copy of their personal data in an electronic or structured format that is commonly used and allows further use by the data subject, where processing is carried out by automated means. 
  • Right to Damages: To be indemnified for any damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal data, subject to applicable law. 
  • Right to File a Complaint: To lodge a complaint before the National Privacy Commission (NPC) if the data subject believes their rights under the DPA have been violated. 

  1. Channels and Means for Exercising Rights
Channel  Details 
In-person attendance  [Insert address] — Business hours: Monday to Friday, 9:00 a.m. to 6:00 p.m. (Philippine Time) 
Official data subject channel  tratamientodedatos@leangroup.com 
Corporate website  https://www.leangroup.com 

 

  1. Minimum Requirements for Data Subject Requests

Whether submitted physically or electronically, data subject requests must contain the following information: 

  1. a) Full name of the data subject or authorized representative.
  2. b) Type and number of valid government-issued identification.
  3. c) Physical address or email address for responses, and contact telephone number.
  4. d) Subject and grounds of the request, with a clear description of the right being exercised.
  5. e) Signature of the data subject or authorized representative.
  6. f) Copy of valid identification of the data subject and/or representative.
  7. g) Document evidencing authority to represent, when applicable.
  8. h) Relevant annexes or supporting documents.
  9. Procedures for Handling Requests

9.1. Inquiries (Access Requests) 

When a data subject wishes to know what personal information is stored in LOSGI’s systems: 

  • Response period: Within fifteen (15) calendar days from the date of receipt of the request. 
  • Extension: If unable to respond within the period, LOSGI shall notify the data subject of the cause of delay and the new date of compliance, which shall not exceed an additional fifteen (15) calendar days. 
  • Medium: Response shall be provided through the same channel used by the data subject or through the channel indicated by them, ensuring traceability. 

9.2. Complaints (Correction, Erasure, Objection, or Alleged Violations) 

Filing and admission: 

  • Upon receipt of a complete complaint, LOSGI shall record the entry as “request under review” in the relevant database within two (2) business days. 
  • If the complaint is incomplete, LOSGI shall notify the data subject within five (5) business days to remedy the deficiency. 

Tacit withdrawal for failure to remedy: 

  • If two (2) months elapse from the notification requesting remediation without a response from the data subject, the request shall be considered withdrawn and the proceeding shall be archived. 

Response period: 

 

  • Maximum thirty (30) calendar days from the date of receipt. LOSGI may extend this period by an additional fifteen (15) calendar days upon notification to the data subject stating the reasons for the extension. 

9.3. Escalation to Supervisory Authority 

If a data subject does not receive a response within the applicable periods or considers the response unsatisfactory, they may file a complaint with the National Privacy Commission (NPC) through its official channels at www.privacy.gov.ph. 

  1. Consent Management

Where consent is the lawful basis for processing, LOSGI shall ensure that consent is: 

  • Freely given: Not coerced and not made a condition of employment or service provision, unless strictly necessary for the performance of a contract or compliance with a legal obligation. 
  • Specific: Obtained for one or more specific purposes that are clearly described at the time of collection. 
  • Informed: The data subject has been provided with all relevant information about the processing prior to giving consent. 
  • Unambiguous: Evidenced by a written, electronic, or recorded declaration, or by another clear affirmative action. 

LOSGI shall maintain a centralized, digitized record of all consent forms. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. 

  1. Data Retention

Personal data shall not be retained in a form that permits identification of data subjects for longer than is necessary to fulfill the stated purposes, subject to the following minimum periods: 

Category  Retention Period 
Employee data (employment records)  Duration of employment relationship + 10 years (or as required by the Labor Code and applicable Philippine law) 
Applicant/candidate data  12 months from end of recruitment process, or longer if the data subject consents to inclusion in talent database 
Commercial and accounting data (clients, suppliers, contractors, shareholders)  Duration of relationship + 10 years (or as required by applicable tax, accounting, and corporate legislation) 
Video surveillance recordings  90 calendar days (general rule). Extended retention permitted in connection with active investigations, administrative or judicial proceedings, or competent authority requests 
Biometric data (voice and facial)  Duration of employment relationship or consent; automated deletion upon termination or revocation of consent, subject to evidentiary preservation requirements 
Web portal user activity logs  12 months from last activity, or as required by applicable law 

Upon expiration of the applicable retention period, personal data shall be securely disposed of, anonymized, or destroyed, in accordance with LOSGI’s information retention and disposal procedures and applicable NPC guidelines. 

  1. Erasure, Blocking, and Objection to Processing

LOSGI may deny or limit requests for erasure, blocking, or withdrawal of consent in any of the following circumstances: 

  • A legal or contractual obligation of retention is applicable. 
  • The erasure may obstruct judicial or administrative proceedings related to tax obligations, investigation or prosecution of criminal offenses, or enforcement of sanctions. 
  • The data is necessary to protect the legally recognized interests of the data subject or to fulfill a legally acquired obligation. 
  • The data subject has exercised a contractual right whose performance requires the continued processing of the information. 

In such cases, LOSGI shall restrict the use of the data to the purpose that justifies its continued retention and shall maintain strict confidentiality of the information. 

  1. Cross-Border Data Transfers and Transmissions

Pursuant to the DPA and its IRR, LOSGI may transfer personal data outside the Philippines only where: 

  • The recipient country provides an adequate level of protection pursuant to the standards set by the NPC. 
  • LOSGI has obtained the prior consent of the data subject to the transfer. 
  • The transfer is necessary for the performance of a contract between LOSGI and the data subject, or the implementation of pre-contractual measures taken at the data subject’s request. 
  • The transfer is necessary for the conclusion or performance of a contract in the interest of the data subject between LOSGI and a third party. 
  • The transfer is necessary for reasons of public interest, or for the establishment, exercise, or defense of legal claims. 

  • Appropriate contractual safeguards have been entered into with the recipient. 

In the context of LOSGI’s global service delivery model, personal data, particularly employee and operational data, may be transferred to Lean Staffing Solutions Inc. (United States), to other entities within Lean Solutions Group, or to client organizations located in the United States and other countries. Such transfers are carried out for the purpose of managing the employment relationship, allocating resources to international client projects, auditing services, and conducting internal corporate governance. LOSGI shall ensure that recipient entities comply with security standards equivalent to those described in the Global Policy. 

  1. 14. Publicación, vigencia y control de cambios

In accordance with the Data Privacy Act of 2012 and its IRR, LOSGI shall designate a Data Protection Officer (DPO) who is responsible for: 

  • Monitoring LOSGI’s compliance with the Data Privacy Act, the IRR, and NPC issuances. 
  • Acting as the primary point of contact for data subjects and the NPC. 
  • Implementing and maintaining the data protection and privacy management program. 
  • Conducting Privacy Impact Assessments (PIAs) for high-risk processing activities. 
  • Managing and coordinating the response to personal data breaches. 
  • Ensuring that LOSGI’s registration with the NPC is filed and kept current. 
  • Providing training and awareness programs for personnel involved in processing. 
  • Reporting periodically to senior management on the state of data protection compliance. 

The DPO must be registered with the NPC. LOSGI shall ensure the DPO has the necessary resources to carry out their tasks, maintains the required level of expert knowledge, and is not placed in a position of conflict of interest in relation to LOSGI’s data processing activities. 

  1. NPC Registration

Pursuant to NPC Circular 17-01 (as amended), LOSGI shall register its data processing systems with the National Privacy Commission where registration is required, specifically where LOSGI employs two hundred fifty (250) or more persons, or processes personal data of one thousand (1,000) or more data subjects, or processes sensitive personal information. LOSGI shall ensure that its registration is filed within the prescribed periods and kept current at all times. 

  1. Obligations of the Personal Information Controller

LOSGI undertakes to: 

  • Implement reasonable and appropriate organizational, physical, and technical security measures for the protection of personal data against natural dangers and unauthorized processing. 
  • Ensure that its employees, agents, and contractors who access personal data are bound by confidentiality obligations and trained in data protection. 
  • Collect personal data only to the minimum extent necessary for the declared purpose. 
  • Inform data subjects of their rights and the relevant information regarding the processing at the time of data collection. 
  • Conduct a Privacy Impact Assessment (PIA) prior to implementing any new processing activity or system involving sensitive personal information, large-scale processing, use of new technologies, biometric processing, or any other high-risk processing as determined by the NPC. 
  • Maintain a record of processing activities as required by the NPC. 
  • Notify the NPC and affected data subjects of personal data breaches in accordance with Section 17 of this Annex. 
  • Comply with the instructions and requirements of the NPC. 
  1. Personal Data Breach Management and Notification

LOSGI has implemented a Personal Data Breach Response Procedure that includes the following stages: 

  • Detection and classification: Identification, initial assessment, and classification of the incident as a personal data breach. 
  • Containment and mitigation: Immediate technical and organizational measures to limit the impact of the breach. 
  • Internal reporting: Immediate communication to the DPO and Compliance department. 
  • Impact assessment: Evaluation of the nature, scope, context, and consequences of the breach, including the number and categories of data subjects affected. 
  • Notification to the NPC: Where the breach involves sensitive personal information or information that may be used to enable identity fraud, LOSGI shall notify the NPC within seventy-two (72) hours of becoming awareknowledge of or reasonable belief of the breach, in accordance with NPC Circular 16-03. 
  • Notification to data subjects: Where the breach is likely to give rise to a real risk of serious harm to the affected data subjects, LOSGI shall notify those data subjects promptly, in a clear and concise manner. 
  • Documentation and lessons learned: Recording of the incident, actions taken, and analysis to prevent recurrence. 
  1. Privacy Impact Assessments (PIA)

LOSGI shall conduct a Privacy Impact Assessment (PIA) prior to commencing any processing activity that involves sensitive personal information, large-scale processing of personal data, systematic monitoring of data subjects, use of new technologies, biometric processing, or any other high-risk processing as determined by the NPC. The PIA shall be documented and reviewed periodically. 

  1. Publication, Validity, and Change Control
  • Entrada en vigor: [Completar fecha de publicación] 
  • Control de versiones: [Versión 1.0 / Fecha]; [Versión 1.1 / Fecha]; etc.
    La versión vigente será la disponible en los canales oficiales.