How Should Philippine Employers Draft Social Media Policies?

How Should Philippine Employers Draft Social Media Policies?

Introduction

A social media policy helps an employer protect its reputation, confidential information, customers, and workplace relationships. It must, however, be written and enforced consistently with Philippine labor standards, data privacy rules, and the constitutional protection of freedom of expression.

A lawful policy should regulate work-related conduct, misuse of company information, harassment, threats, fraud, and conduct that improperly represents the employer. It should not impose a blanket prohibition on criticism, require employees to surrender personal account access, or punish lawful off-duty expression without a sufficient connection to the employment relationship.

What Should a Social Media Policy Cover?

The policy should clearly distinguish between personal social media activity and official company communication. Employees who are authorized to speak for the company should be identified, together with the subjects they may discuss and the approval process for official posts.

A policy may properly address the following matters:

  • Use of company names, logos, trademarks, uniforms, and official images;
  • Disclosure of confidential, proprietary, personal, or commercially sensitive information;
  • Impersonation of the company or its officers;
  • Harassment, threats, bullying, discrimination, and unlawful content;
  • False statements made in an official capacity or in connection with company business;
  • Use of company devices, systems, networks, and working time; and
  • Reporting and investigation of suspected violations.

The policy should avoid vague phrases such as “posting anything negative about the company” or “making statements that management dislikes.” These provisions may be applied arbitrarily and may improperly restrict legitimate complaints, workplace discussions, or participation in lawful labor activities.

How Can the Policy Protect Company Reputation?

The employer may require employees to state that personal opinions are their own and do not represent the company. A disclaimer, however, does not excuse unlawful conduct, nor does its absence automatically make an employee’s personal post an official company statement.

The policy may also prohibit employees from falsely claiming to be company representatives, publishing nonpublic business information, or using company branding in a manner that misleads the public. It should identify the company’s authorized spokespersons and provide a designated channel for media inquiries.

For court officials and personnel, the 2025 Code of Conduct and Accountability for Court Officials and Personnel requires restraint and caution in using social media and artificial intelligence. It also prohibits using the prestige of office through online posts to advance personal or another person’s interests and requires online posts to respect the law, uphold the Judiciary’s dignity, and protect it from disrepute. These requirements apply specifically to court officials and personnel, not automatically to private-sector employees. See The 2025 Code of Conduct and Accountability for Court Officials and Personnel (2025).

How Should Free Expression Be Protected?

A private employer may regulate workplace conduct and the use of company resources, but the policy should not treat every criticism of management as misconduct. A distinction should be made between protected or legitimate expression and conduct that creates a genuine workplace, legal, or business-related harm.

For example, an employee’s good-faith complaint about wages, working conditions, safety, discrimination, or unlawful conduct should not automatically be punished merely because it is unfavorable to the employer. The employer should assess whether the post is truthful or made in good faith, whether it concerns a legitimate workplace issue, whether it discloses confidential information, and whether it involves threats, harassment, fraud, or other unlawful conduct.

As a drafting matter, the policy should use objective standards rather than prohibiting “negative,” “embarrassing,” or “disloyal” comments. It should also state that nothing in the policy is intended to prevent employees from exercising rights granted by law, including lawful association, collective bargaining, and concerted activities.

What Privacy Rules Apply to Employee Posts?

The employer should collect, access, use, and retain only information reasonably necessary for a legitimate employment or business purpose. The Data Privacy Act of 2012 and its implementing rules should be considered whenever the employer monitors employee accounts, investigates online activity, processes screenshots, or handles information about customers, co-workers, or other individuals. See Implementing Rules and Regulations of the Data Privacy Act of 2012 (2016).

The policy should explain:

  • What company systems and devices may be monitored;
  • What business purposes justify monitoring;
  • Who may access collected information;
  • How long records will be retained;
  • How employees may raise privacy concerns; and
  • How personal information will be secured and disposed of.

An employer should not require an employee to provide a personal account password as a routine condition of employment. Investigations should rely, when possible, on publicly available posts, company systems, voluntarily submitted records, or properly authorized processes.

How Should Confidential Information Be Defined?

“Confidential information” should be defined with sufficient precision. It may include trade secrets, nonpublic financial data, customer information, passwords, unpublished business plans, internal investigations, personal employee records, and information subject to a confidentiality agreement.

The policy should distinguish confidential information from facts that are already public or information that an employee may lawfully use to pursue a legal claim. In Yonzon v. Coca-Cola Bottlers Philippines, Inc., G.R. No. 226244, November 17, 2021, the Supreme Court discussed the processing of personal information in connection with the protection of lawful rights and interests in court proceedings and the establishment, exercise, or defense of legal claims. The decision also illustrates why an employer should not rely on vague descriptions of “confidential information” when imposing discipline. See Yonzon v. Coca-Cola Bottlers Philippines, Inc. (2021).

A carefully drafted clause may prohibit unauthorized disclosure while allowing disclosures made to courts, government agencies, counsel, auditors, or other authorized persons for legitimate purposes.

Should the Policy Regulate Work-Related Harassment?

Yes. The policy should prohibit online threats, sexual harassment, gender-based online harassment, discriminatory remarks, doxxing, stalking, bullying, and retaliation connected with the workplace. It should provide confidential reporting channels and a fair investigation process.

For movie and television industry employers, the implementing rules of Republic Act No. 11996 require protection against abuse, physical violence, harassment, and acts degrading a worker’s dignity. They also require workplace policies addressing sexual harassment and gender-based violence in conformity with Republic Act No. 7877, Republic Act No. 11313, and Republic Act No. 11036. See Implementing Rules of Republic Act No. 11996 (2024).

Employers in other industries should likewise align their policies with applicable anti-sexual harassment, safe spaces, occupational safety, and labor regulations. The policy should not be limited to posts made during office hours if the conduct has a sufficient connection to the workplace or affects workplace safety and relationships.

What About Employees Working Remotely?

If employees use personal devices or home internet connections for work, the policy should separately address company property, system security, personal information, and working-time expectations. The telecommuting rules require data protection arrangements and recognize that employees working remotely should not receive less favorable employment terms than comparable on-site employees. See Revised Implementing Rules and Regulations of the Telecommuting Act (2022).

The policy should identify whether the employer may monitor company-issued devices, business accounts, messaging platforms, or files stored in company systems. It should avoid unrestricted monitoring of personal devices and personal accounts.

How Should Violations Be Investigated?

A defensible procedure should include written notice of the alleged violation, a reasonable opportunity to respond, an impartial review of the evidence, and a written decision explaining the applicable rule and penalty. The employer should preserve the original post, its date and context, the account involved, and the manner in which the material was obtained.

Not every violation warrants dismissal. The employer should consider the employee’s position, the seriousness of the conduct, actual or probable harm, intent, prior violations, whether company resources were used, whether confidential information was disclosed, and whether the rule was clearly communicated.

For lawyers, the Code of Professional Responsibility and Accountability requires dignified, gender-fair, child- and culturally-sensitive language in personal and professional dealings, including electronic and social media communications. It also requires lawyers to understand the benefits, risks, and ethical implications of social media use. These professional duties apply to lawyers because of their status as members of the bar and should not be treated as a general rule governing all employees. See Baltao v. Falcis III (2025) and Code of Professional Responsibility and Accountability (2023).

Suggested Policy Provisions

A company may consider provisions substantially similar to the following:

  • Personal accounts: Employees may use personal social media accounts in their private capacity, subject to applicable law and the prohibition against unlawful conduct.
  • Official statements: Only designated representatives may issue statements on behalf of the company.
  • Confidentiality: Employees shall not disclose nonpublic company information or personal information without authorization or a lawful basis.
  • Respectful conduct: Threats, harassment, discrimination, sexual harassment, bullying, and retaliation are prohibited.
  • Accuracy: Employees shall not knowingly make false statements while claiming to represent the company or while using company communication channels.
  • Disclaimers: Employees who discuss work-related matters in a personal capacity should make clear that their views do not represent the company, when appropriate.
  • Reporting: Suspected violations may be reported through designated HR, compliance, or ethics channels.
  • Non-interference: Nothing in the policy shall be construed to prohibit lawful employee rights or the filing of complaints with government agencies or courts.

Common Drafting Errors

HR departments should avoid policies that prohibit all discussion of the company, require approval before employees express personal opinions, authorize access to personal passwords, or impose automatic dismissal for any online criticism.

Another error is applying the same rule to all employees without considering their functions. A designated spokesperson, data custodian, human resources officer, or employee handling confidential investigations may be subject to stricter rules concerning disclosure than an employee with no access to sensitive information.

The company should also avoid selective enforcement. A policy applied only against employees who criticize management may be viewed as arbitrary or retaliatory. Consistent enforcement, adequate notice, and proportional sanctions are essential.

Recommended HR Compliance Process

  1. Identify the company’s legitimate interests, including confidentiality, security, reputation, and workplace safety.
  2. Map the information and systems that may be monitored or processed.
  3. Consult labor, privacy, information-security, and employee-relations personnel.
  4. Use specific definitions and objective standards.
  5. Include safeguards for lawful complaints, labor rights, and legitimate reporting.
  6. Publish the policy and obtain documented acknowledgment.
  7. Train managers and investigators on consistent enforcement.
  8. Review the policy after significant changes in technology, law, or company operations.

Conclusion

A legally sound social media policy should protect the employer without attempting to control every statement made by an employee. The most defensible policy regulates official representation, confidential information, unlawful harassment, misuse of company resources, and conduct with a genuine workplace connection.

Before implementation, HR should review the policy against employment contracts, company rules, collective bargaining agreements, data privacy practices, and applicable industry regulations. Any disciplinary action should be based on a clear rule, reliable evidence, fair procedure, and a proportionate penalty.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH