The National Privacy Commission recently issued Circular No. 2023-03, which provides guidelines to all personal information controllers that issue identification cards to data subjects.
In brief
The National Privacy Commission (NPC) recently issued NPC Circular No. 2023-03 (“Circular“), which sets out guidelines on the issuance of identification (ID) cards to data subjects.
The Circular took effect on 30 November 2023.
In more detail
The Circular applies to all personal information controllers (PICs) that issue ID cards to data subjects, excluding government-issued ID cards. For this purpose, ID cards shall refer to any physical or digital ID card that identifies a data subject, including, without limit, company IDs, school IDs, insurance cards, membership cards, and rewards or loyalty cards.
ID cards shall only indicate necessary personal data in relation to the primary purpose of identifying the data subject.
For ID cards with additional functionalities, PICs shall ensure that all other personal data included are reasonable and necessary for the specified and declared purposes of the specific ID card. In all cases, PICs shall bear the burden of demonstrating that the inclusion of a particular category of personal data is proportionate to the legitimate purpose.
PICs shall implement reasonable and appropriate safeguards to protect personal data on ID cards, and ensure that such security features are at par with technological advances, best practices, and industry standards. PICs shall also educate data subjects on appropriate physical security measures for issued ID cards.
Affected PICs shall be given 120 calendar days from the effectivity of the Circular, or until 29 March 2024, to comply with the foregoing requirements. Noncompliance with the Circular may result in the imposition of criminal, civil and administrative liability.
Recommended action
Clients are advised to take note of the requirements in issuing ID cards. Existing ID cards must be revised to comply with the Circular ahead of the deadline on 29 March 2024.
Please feel free to reach out to Quisumbing Torres’ Intellectual Property, Data and Technology Practice Group for assistance in these data privacy compliance matters.
* * * * *
Please contact QTInfoDesk@quisumbingtorres.com for inquiries.