Can Parent Companies Share Philippine Employee Data?

Can Parent Companies Share Philippine Employee Data?

Introduction

Parent companies and Philippine subsidiaries often exchange employee, customer, and business information for payroll, human resources, compliance, fraud prevention, finance, information technology, and group reporting. These transfers are not automatically lawful merely because the entities belong to the same corporate group.

The transfer must have a valid legal basis, a declared purpose, appropriate safeguards, and a process that respects the rights of data subjects. A written internal privacy agreement is useful for documenting these matters, but the agreement itself does not create authority to process or disclose personal data where no lawful basis exists.

Governing Philippine Privacy Rules

The principal statute is the Data Privacy Act of 2012, or R.A. No. 10173. It applies to the processing of personal information by Philippine entities and, in appropriate circumstances, to entities outside the Philippines that use equipment located in the Philippines or maintain an office, branch, or agency in the country.

The implementing rules require processing to comply with the principles of transparency, legitimate purpose, and proportionality. Personal information must not be retained indefinitely for an undetermined future use, and disposal must be secure. These requirements appear in the [IRR of R.A. No. 10173 (2016)](#L1.40).

Where a parent company and a Philippine subsidiary independently determine the purposes and means of processing, they will generally be treated as separate personal information controllers. Where the parent merely processes information on the subsidiary’s instructions, the parent may instead be a personal information processor, subject to the rules on outsourcing and subcontracting.

Is a Data Sharing Agreement Required?

The answer depends on the parties, the legal basis, and the nature of the arrangement.

NPC Circular No. 2020-03 addresses data sharing arrangements between or among personal information controllers. It defines a data sharing agreement as a contract or similar instrument setting out the parties’ obligations, responsibilities, liabilities, privacy safeguards, and measures for protecting data-subject rights. The circular also requires parties to maintain records of data sharing arrangements, including the legal bases for sharing and proof of consent where consent is relied upon.

However, NPC Advisory No. 2025-01 clarified that the execution of a data sharing agreement is optional and is not, by itself, a prerequisite for lawful data sharing. Sharing may proceed when it is already authorized or required by law, or when it satisfies a lawful-processing condition under Sections 12 or 13 of R.A. No. 10173. The Advisory also states that a data sharing agreement does not itself confer legal authority to share personal data.

Accordingly, corporate groups should treat the agreement as a record of accountability and a mechanism for allocating responsibilities—not as a substitute for a lawful basis.

Distinguishing Data Sharing from Outsourcing

The first drafting question is whether the parent and subsidiary are both controllers or whether one entity is processing data only for the other.

Data sharing generally occurs when one controller discloses or transfers personal data to another controller that will use the information for its own authorized purposes. Examples include a parent company using Philippine employee information for group-wide compliance reporting or a subsidiary sharing customer records with a parent for fraud investigations.

Outsourcing or subcontracting occurs when a controller retains control over the processing but appoints another entity to process personal data on its behalf and according to its instructions. Examples include a parent company operating a centralized payroll system for the subsidiary or providing a group human-resources platform.

NPC Circular No. 2020-03 provides that data sharing arrangements are between personal information controllers. A processor should generally be covered by a subcontracting or processing agreement containing the required obligations and safeguards, rather than being treated as an independent controller without analysis.

Identifying the Lawful Basis

The agreement should identify the legal basis for each category of data and each processing purpose. A general statement that the transfer is “for business purposes” is insufficient because it does not establish a specific, legitimate, and proportionate purpose.

Possible bases include the following:

  • Consent, when consent is freely given, specific, informed, evidenced, and capable of being withdrawn.
  • Contractual necessity, when processing is necessary to perform an agreement with the data subject or to take steps requested before entering into one.
  • Legal obligation, when processing is necessary to comply with a legal requirement.
  • Public authority or public function, when applicable to the organization and the processing activity.
  • Legitimate interests, when the interest is lawful and genuine, the processing is necessary, and the interest is not overridden by the fundamental rights and freedoms of the data subject.

For sensitive personal information, the stricter requirements under Section 13 of R.A. No. 10173 apply. Processing may be permitted when necessary for the protection of lawful rights and interests in court proceedings, the establishment, exercise, or defense of legal claims, or when provided to a government or public authority, among other statutory exceptions.

In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., General Register No. 273720, 2025, the Supreme Court discussed the use of legitimate interests and other lawful-processing grounds for disclosure of identifying information to law-enforcement authorities. The decision illustrates that a lawful purpose and statutory basis must be assessed separately from confidentiality obligations and other applicable laws.

Consent Is Not Always the Best Basis

Employee consent should not automatically be used for every intra-group transfer. In an employment relationship, the employer may have greater bargaining power, which can affect whether consent is genuinely voluntary. If processing is necessary for payroll, benefits administration, or compliance, another lawful basis may be more appropriate.

If consent is used, it should be separate from unrelated employment terms where necessary, describe the specific purposes, identify the recipients, state the types of data involved, and explain how withdrawal will operate. Withdrawal does not necessarily invalidate processing that was lawfully completed before withdrawal, but the organization must stop future processing that depends solely on that consent unless another lawful basis applies.

NPC Circular No. 2023-04 recognizes that consent in a contract of adhesion may be valid when the contract is transparent, the processing is necessary for a legitimate purpose, the processing is not excessive, and the manner of processing is fair and lawful.

What the Internal Agreement Should Contain

A well-drafted agreement between a parent company and a Philippine subsidiary should contain, at minimum, the following provisions:

1. Parties and Corporate Roles

Identify the parent, the Philippine subsidiary, their addresses, and their respective data protection officers. State whether each party is a personal information controller, personal information processor, or both for particular activities.

2. Purpose and Scope

Describe each permitted purpose with sufficient precision. Separate human-resources administration, payroll, benefits, compliance, internal audit, fraud prevention, customer support, information-technology administration, and group reporting rather than placing them under one broad business-purpose clause.

3. Categories of Data Subjects and Information

Identify whether the information concerns employees, applicants, contractors, customers, suppliers, dependents, or other persons. List the categories of personal information and sensitive personal information involved, such as identification details, contact information, employment records, compensation information, health information, government identifiers, financial details, and disciplinary records.

4. Legal Basis Per Processing Activity

Include a schedule matching each processing activity with its legal basis. The schedule should identify whether the basis is consent, contract, legal obligation, legitimate interest, or another statutory ground. It should also explain why the processing is necessary and proportionate.

5. Transparency and Privacy Notices

Require the relevant controller to provide a privacy notice before or at the time of collection, or as soon as reasonably practicable when information is obtained from another source. The notice should identify the purpose, recipients, retention period or retention criteria, rights of data subjects, and contact details for privacy concerns.

6. Data Minimization and Proportionality

Limit the transfer to information reasonably necessary for the stated purpose. For example, a parent company reviewing workforce headcount may not need individual medical records, full compensation details, or copies of identity documents.

Where possible, use aggregated, anonymized, pseudonymized, or de-identified information. The agreement should prohibit the receiving entity from attempting to re-identify data unless the re-identification is specifically authorized and necessary.

7. Access Controls and Security

The agreement should require reasonable and appropriate organizational, physical, and technical safeguards. These may include role-based access, multi-factor authentication, encryption in transit and at rest, access logging, secure file-transfer systems, vulnerability management, employee confidentiality obligations, and periodic access reviews.

NPC Circular No. 2020-03 recognizes secure access measures such as encrypted links or middleware where online access to personal information is provided. Security controls should be proportionate to the nature of the data, the risks of processing, the size and complexity of the organization, current security practices, and the cost of implementation.

8. Retention and Disposal

State the retention period or the objective criteria for determining it. Data should be retained only for as long as necessary for the declared, specified, and legitimate purpose, unless a longer period is required by law or is justified for historical, statistical, or scientific purposes with appropriate safeguards.

The agreement should require secure deletion, destruction, anonymization, or return of information when the purpose ends, subject to legal holds, regulatory retention duties, litigation, audit requirements, and documented retention policies.

9. Further Disclosure and Subcontractors

Prohibit the receiving entity from disclosing the information to affiliates, vendors, consultants, or other third parties unless the disclosure has a lawful basis and satisfies the agreement’s safeguards. Require prior notice or approval when appropriate, together with due diligence and written obligations for vendors and processors.

Sharing with an affiliate or parent company is not automatically exempt from consent or other lawful-processing requirements. The IRR of R.A. No. 10173 specifically recognizes that private-sector data sharing with an affiliate or parent company may still require compliance with applicable legal conditions.

10. Cross-Border Transfers

If the parent company is outside the Philippines, the agreement should identify the countries, systems, personnel, and vendors that may receive or access the data. It should require safeguards that provide a level of protection consistent with R.A. No. 10173 and Philippine privacy regulations.

The agreement should also address onward transfers, government requests, remote access, storage locations, encryption, cooperation with the Philippine subsidiary, and the ability of data subjects and regulators to obtain information about the processing.

The ASEAN Model Contractual Clauses and ASEAN Data Management Framework may be adopted voluntarily, but NPC Advisory No. 2021-02 states that they do not create additional legal obligations and are not mandatory under Philippine law.

11. Data-Subject Rights

The agreement should allocate responsibility for responding to requests involving access, correction, objection, restriction, deletion or blocking, data portability where applicable, and complaints. It should establish response timelines, escalation procedures, identity-verification requirements, and cooperation duties between the parent and subsidiary.

12. Security Incidents and Breach Response

Require prompt internal reporting of actual or suspected unauthorized access, loss, disclosure, alteration, or destruction. The parties should designate a 24-hour or otherwise suitable incident channel, establish investigation duties, preserve evidence, coordinate regulatory assessment, and allocate responsibility for notifying affected data subjects and the National Privacy Commission when notification is required.

The agreement should not state that the parties may delay notification indefinitely while completing an internal investigation. The parties should instead establish a process for making a timely and documented determination under the Data Privacy Act and its implementing rules.

13. Audit and Accountability

Each party should maintain records of processing and data-sharing arrangements, legal bases, privacy notices, consent records where applicable, access logs, security assessments, training, incidents, and corrective actions.

NPC Circular No. 2020-03 provides that each party remains responsible for personal data under its control or custody, including data processed through an outsourced or subcontracted provider. The agreement should therefore avoid language that attempts to transfer all statutory accountability to the other party.

14. Liability and Indemnity

Allocate responsibility according to each party’s conduct, control, and legal duties. Indemnity provisions may address breach-related losses, regulatory costs, claims, and remediation expenses, but they should not be drafted as though a private contract can eliminate statutory liability or restrict the authority of the National Privacy Commission.

15. Term, Review, and Termination

State the effective date, duration, review schedule, termination rights, and post-termination obligations. Termination of the agreement should not automatically authorize destruction where retention is required by law, nor should it permit continued use for unrelated purposes.

Common Drafting Errors

  • Assuming that common ownership removes the need for a lawful basis.
  • Using a single blanket consent for all present and future group activities.
  • Describing the purpose only as “business operations” or “legitimate business purposes.”
  • Failing to distinguish controller-to-controller sharing from controller-to-processor outsourcing.
  • Transferring entire employee or customer databases when aggregated or limited data would suffice.
  • Ignoring onward transfers by the parent company or its service providers.
  • Allowing indefinite retention or unrestricted reuse of transferred information.
  • Stating that the agreement itself is the legal basis for processing.

Illustrative Applications

Centralized Payroll

A Philippine subsidiary may transmit employee identification, payroll, tax, and bank-account information to a parent company that operates payroll services. If the parent acts only on the subsidiary’s instructions, the arrangement should be documented as outsourcing or processing, with strict limits on use and access.

If the parent uses the information for independent group-wide analytics or employment decisions, it may also act as a controller for those activities. The agreement and privacy notices should reflect the separate purposes and responsibilities.

Group Compliance Review

A parent company conducting an internal compliance review may receive selected employee or customer information when the review is necessary, lawful, and proportionate. The parties should restrict access to the investigation team, record the legal basis, preserve confidentiality, and avoid transferring unrelated information.

Customer Fraud Investigation

A Philippine subsidiary may share customer contact or transaction-related information with a parent company’s fraud team when a lawful basis exists and the disclosure is necessary for a genuine investigation. The transfer should be limited to the information needed to assess the suspected fraud and should be subject to access, retention, and disclosure controls.

The decision in Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., General Register No. 273720, 2025, also demonstrates that privacy rules must be considered together with sector-specific confidentiality laws. A lawful basis under the Data Privacy Act does not automatically override bank secrecy, professional confidentiality, or another statute.

Employee Salary Information

Employee salary data is personal information and may be confidential within the organization. In Yonzon v. Coca-Cola Bottlers Philippines, Inc., General Register No. 226244, 2021, the Supreme Court considered the treatment of employee salary information and recognized the relevance of the Data Privacy Act’s protection for information necessary to establish, exercise, or defend legal claims.

The case does not authorize unrestricted internal distribution of salary information. A group transfer should still have a defined purpose, limited recipients, appropriate notice or other lawful basis, and safeguards against unauthorized disclosure.

Recommended Review Process

  1. Map the information flow between the parent, subsidiary, affiliates, and vendors.
  2. Identify the controller or processor role of every participating entity.
  3. Classify the data, including sensitive personal information and confidential business information.
  4. Document the purpose, legal basis, necessity, proportionality, and retention period for each transfer.
  5. Prepare or update privacy notices and consent materials where required.
  6. Conduct a privacy impact assessment for high-risk, large-scale, sensitive, or cross-border processing.
  7. Draft the agreement with security, access, incident, retention, audit, rights, and termination provisions.
  8. Verify the parent company’s vendors, onward-transfer practices, and security controls.
  9. Maintain a current record of the arrangement and review it after changes in purpose, systems, recipients, or applicable regulation.

Conclusion

A Philippine subsidiary may exchange employee and client information with its parent company when the transfer is supported by a lawful basis, serves a specific and legitimate purpose, is proportionate, and is protected by appropriate organizational, physical, and technical measures.

An internal privacy agreement should accurately identify the parties’ roles, limit the information and purposes, regulate cross-border access and onward transfers, protect data-subject rights, and allocate operational responsibilities. Following NPC Advisory No. 2025-01, the parties should not assume that a data sharing agreement is always mandatory; they should first establish the legal basis for the processing and then use the agreement to document accountability and safeguards.

Corporate legal departments should review existing group agreements in light of the controller-processor distinction, the treatment of sensitive personal information, retention limits, cross-border transfers, breach response, and the continuing responsibility of each party for data under its custody or control.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH