Can Philippine Consumers Demand Permanent Data Deletion?

Can Philippine Consumers Demand Permanent Data Deletion?

Introduction

Customers increasingly provide personal information to companies when opening accounts, purchasing products, subscribing to services, applying for financing, or using digital platforms. When the original transaction ends, however, the company may continue retaining names, contact details, identification records, transaction histories, biometric information, or other personal data.

Philippine law recognizes a consumer’s right to request the suspension, withdrawal, blocking, removal, or destruction of personal information from a personal information controller’s filing system. This right is commonly described as the right to erasure or the right to be forgotten.

The right is not an unconditional demand for the deletion of every record. A request must generally be supported by substantial proof of a legally recognized ground, and deletion may be refused when continued retention is necessary to comply with law, establish or defend a legal claim, fulfill the original purpose, or serve another recognized interest.

What Is the Right to Be Forgotten?

The right to be forgotten concerns a person’s ability to prevent the continued storage, use, publication, or dissemination of personal information when its continued processing is no longer lawful or necessary.

In Cadajas v. People of the Philippines, General Register No. 247348, 2021, the Supreme Court discussed informational privacy as including the right to keep personal information private, prevent its first disclosure, prevent further dissemination after disclosure, and, in appropriate situations, prevent the continued storage of the information.

The right therefore involves more than deleting a record from a company’s active database. Depending on the circumstances, reasonable measures may also be required to remove or restrict copies in backup systems, public webpages, third-party indexes, or other systems controlled by the same or related entities.

What Law Governs Customer Data Deletion Requests?

The principal statute is the Data Privacy Act of 2012, or R.A. No. 10173. Section 16(e) recognizes the right of a data subject to suspend, withdraw, or order the blocking, removal, or destruction of personal information from a personal information controller’s filing system.

The right may be invoked upon the discovery and substantial proof that the personal information is:

  • Incomplete, outdated, false, or unlawfully obtained;
  • Used for an unauthorized purpose;
  • No longer necessary for the purposes for which it was collected;
  • Subject to an objection or withdrawal of consent where no other lawful basis or overriding legitimate interest exists;
  • Private information that is prejudicial to the data subject, unless justified by speech, expression, press freedom, or another authorization;
  • Processed unlawfully; or
  • Processed in a manner that violates the data subject’s rights.

The implementing rules likewise recognize erasure or blocking as a data subject right. Section 34 of the IRR of R.A. No. 10173 states that a data subject may seek the suspension, withdrawal, blocking, removal, or destruction of personal data upon substantial proof of the grounds identified in the law and implementing rules.

Is Consent Withdrawal Enough to Require Deletion?

Not always. Withdrawal of consent removes consent as a legal basis for processing, but it does not automatically require the destruction of every record if another lawful basis for retention applies.

For example, a company may still need to retain certain information to comply with a statutory recordkeeping obligation, respond to a subpoena, establish or defend a legal claim, complete an accounting or audit requirement, or prevent fraud. The company should have informed the customer, through an appropriate privacy notice, of any applicable purpose and retention period.

Where consent is the only legal basis for processing and no continuing legal or legitimate purpose exists, continued processing after consent is withdrawn may be unlawful. In JBA v. FNT and NNT, NPC 20-026, 2022, the National Privacy Commission found that a former agent’s personal information should no longer have been used in advertisements after the agent resigned and withdrew consent, because there was no remaining reason to continue the publication.

When Must a Corporate Database Delete Personal Information?

A personal information controller should grant a deletion or blocking request when the request is supported by substantial proof and the processing is unlawful, unauthorized, unnecessary, or violates the data subject’s rights.

NPC Advisory No. 2021-01 identifies circumstances in which the request should be granted, including unlawful processing, use for an unauthorized purpose, and violation of data subject rights. The personal information controller must evaluate the request carefully rather than reject it automatically or require the customer to pursue an unnecessarily difficult procedure.

The company must also observe the principles of transparency, legitimate purpose, and proportionality. Under Section 18 of the IRR of R.A. No. 10173, collected personal data must be necessary and compatible with a declared, specified, and legitimate purpose. Personal data should be adequate, relevant, and limited to what is necessary, and should not be retained longer than necessary.

When May a Company Refuse Deletion?

A request may be denied, wholly or partly, when the information remains necessary for a legally recognized purpose. The denial should identify the specific reason for retention and, where appropriate, explain whether the information will be restricted from further use.

Recognized grounds for refusing or limiting erasure include:

  • Fulfillment of the purpose for which the information was obtained;
  • Compliance with a legal obligation requiring continued processing;
  • Establishment, exercise, or defense of a legal claim;
  • A legitimate business purpose consistent with applicable retention standards;
  • Protection of speech, expression, or press freedom, or publication on a matter of overriding public interest; and
  • Another ground provided by law, rules, or regulations.

A company should not rely on a general statement that it has a “business need” to retain data. The claimed need must be connected to a lawful purpose, proportionate to that purpose, and consistent with the company’s privacy notice and applicable retention requirements.

What Happens to Data Shared With Third Parties?

Deletion from the company’s own database may not be sufficient if the information was previously disclosed to affiliates, service providers, advertising platforms, data brokers, public webpages, or search indexes.

The IRR of R.A. No. 10173 and NPC Advisory No. 2021-01 recognize duties concerning recipients and third parties that previously received personal data. Where personal information is publicly available online, reasonable and appropriate measures should be taken to communicate with other personal information controllers, including third-party indexes, and request the erasure of copies or the removal or de-listing of search results or links.

The measures required will depend on available technology, cost, the company’s control over the information, the extent of dissemination, and the seriousness of the privacy risk. A company that has no control over an independent third party may not be able to guarantee deletion from that third party’s system, but it should be able to show that it made reasonable efforts to request removal.

How Should a Customer Make a Deletion Request?

A customer should submit the request in writing through the company’s designated privacy contact, data protection officer, customer portal, or other stated channel. The request should identify the account or transaction involved and clearly specify the information sought to be deleted or restricted.

The request should include:

  • The customer’s full name and reliable contact details;
  • Information sufficient to verify the customer’s identity and ownership of the data;
  • A description of the personal information involved;
  • The requested action, such as deletion, blocking, restriction, or removal from online publication;
  • The legal or factual basis for the request; and
  • Supporting documents, when available.

The customer should retain proof of submission, acknowledgment, follow-up communications, and the company’s response. These records may become important if the matter is later brought before the National Privacy Commission or another competent authority.

Why Must the Customer Prove Ownership of the Data?

The right to erasure applies to the personal data of the requesting data subject. The company may therefore require reasonable identity verification and substantial proof that the information sought to be deleted pertains to the requester.

In BSB v. Meta Platforms, Inc., NPC 25-176, 2026, the National Privacy Commission emphasized that a complainant seeking deletion must first establish, by substantial evidence, that the personal data concerned actually belongs to or pertains to the complainant.

Identity verification must remain proportionate. A company should not demand excessive additional personal information merely to process a deletion request, because doing so may create a new privacy risk and conflict with the principle of data minimization.

What Must a Company Do After Receiving the Request?

The company should first verify the requester’s identity, locate the relevant records, determine the purposes and legal bases for continued processing, and identify recipients or systems to which the data was disclosed.

It should then decide whether to:

  • Delete or destroy the information;
  • Block or restrict further processing;
  • Correct inaccurate information;
  • Remove the information from public-facing platforms;
  • Notify recipients or third parties of the deletion or correction; or
  • Deny the request in whole or in part, stating the legal and factual basis.

Deletion should cover live systems and, where appropriate, backup systems. If immediate deletion from a backup is technically impracticable, the company should restrict access and ensure that the information is not restored for ordinary processing except where legally necessary.

Are Publicly Available Records Excluded From Deletion Rights?

No. The fact that information was obtained from a public government source does not automatically authorize unlimited republication or continued online display.

In National Privacy Commission v. PH-Check.com, NPC CDO 22-001, 2022, the Commission found that the republication of publicly available government information remained subject to the requirements of transparency, legitimate purpose, proportionality, and data subject rights. The absence of a privacy notice and a meaningful mechanism for requesting removal weighed against the website operator.

Public availability is therefore relevant to the assessment of lawful processing, but it does not by itself eliminate the consumer’s right to object, seek removal, or request erasure where the statutory conditions are present.

What If the Information Is Needed for a Legal Claim?

A company may retain information necessary to establish, exercise, or defend a legal claim. This exception may apply to records concerning a pending complaint, threatened litigation, audit, investigation, chargeback, fraud inquiry, or regulatory proceeding.

Retention should nevertheless be limited to the information reasonably necessary for the claim and for the period reasonably required by the proceeding or applicable rule. A legal dispute does not give a company unrestricted authority to continue using the customer’s information for unrelated marketing, profiling, or promotional activities.

How Does the Right Apply to Online Marketing?

Customers may object to the use of their information for direct marketing, automated processing, or profiling. When a customer withdraws consent or objects, the company should stop the affected processing unless a recognized exception applies, such as processing required by subpoena, a contract, an employer-employee relationship, or a legal obligation.

Deletion from a marketing database should be distinguished from retention in a suppression or “do not contact” list. A company may need to retain minimal information solely to ensure that the customer’s objection is respected and that marketing messages are not sent again. Such retention should be limited, secure, and used only for that purpose.

What Remedies Are Available When a Request Is Ignored?

If the company does not respond appropriately, the customer may preserve the communications and pursue the available complaint or regulatory remedies before the National Privacy Commission. The customer may also consider judicial remedies when the circumstances satisfy the requirements of the applicable procedural rules.

The writ of habeas data is an independent judicial remedy designed to protect informational privacy and related rights against unlawful acts or omissions involving the gathering, collecting, or storing of personal data. It may provide relief such as updating, rectification, suppression, or destruction of data, subject to the requirements of the Rule on the Writ of Habeas Data and the facts of the case.

In evaluating any remedy, the customer should distinguish between a refusal based on a valid retention obligation and a refusal that merely ignores the request, provides no reason, or continues unauthorized processing after the lawful basis has ended.

Examples of Common Customer Data Requests

Closed customer account. A customer who has terminated a subscription may request deletion of contact information and marketing profiles. The company may still retain limited transaction or billing records when required by law or necessary to defend a claim.

Former employee or agent. A former representative may request removal of their name, photograph, and contact information from advertisements after leaving the company. Continued publication may be unauthorized when there is no remaining business or legal purpose.

Online directory or database. A person may request removal of an address or contact number displayed on a public-facing website. The operator should examine the source, purpose, notice, public interest, and the individual’s right to object or seek erasure.

Fraud investigation. A company may refuse immediate deletion of data reasonably needed to investigate suspected fraud, but should restrict access, document the retention purpose, and delete or anonymize the information when the need ends.

Recommended Steps for Consumers

  1. Review the company’s privacy notice and identify the stated retention period and deletion procedure.
  2. Submit a clear written request through the company’s privacy or data protection channel.
  3. Provide reasonable proof of identity and ownership of the information.
  4. State whether the request concerns deletion, blocking, correction, withdrawal of consent, objection, or removal from public display.
  5. Ask the company to identify any legal basis for continued retention.
  6. Request confirmation of deletion, restriction, or notification to third-party recipients.
  7. Keep all documents and communications if escalation becomes necessary.

Recommended Steps for Companies

  1. Maintain a clear, accessible, and secure process for receiving data subject requests.
  2. Verify identity without collecting excessive additional information.
  3. Record the request, the assessment, the decision, and the implementation steps.
  4. Separate information that must be retained from information that can be deleted.
  5. Stop unrelated marketing, profiling, or other processing when consent is withdrawn or a valid objection is made.
  6. Coordinate deletion or restriction requests with processors, affiliates, vendors, and relevant third parties.
  7. Apply retention and disposal policies consistent with the Data Privacy Act of 2012 and its implementing rules.

Conclusion

Philippine consumers have a statutory right to seek the deletion, blocking, removal, or destruction of personal information when the legal conditions for erasure are present. The right is particularly strong when processing is unlawful, unauthorized, unnecessary, or continued after the original purpose or lawful basis has ended.

The right to be forgotten is not an absolute power to erase every corporate record. Companies may retain information when necessary for legal compliance, legitimate claims, fraud prevention, or another recognized purpose, but retention must remain lawful, proportionate, secure, and limited to what is necessary.

Consumers should make specific written requests and preserve proof of their communications. Companies should provide clear procedures, conduct individualized assessments, document their decisions, and ensure that data is not retained or republished merely because it was once collected or made publicly available.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH