KAMI Workforce
← All guides/Data Privacy

Cloud payroll Philippines: is your data safe? (Data Privacy Act & RA 10173 explained)

Payroll data is among the most sensitive personal data a company holds — salaries, tax IDs, bank accounts, government numbers. Philippine law is specific about how it must be protected. Here is what employers and their HRIS vendors are required to do.

Data Privacy11 min readUpdated May 2026

In this guide

  1. Why payroll data is high-risk personal data
  2. What the Data Privacy Act (RA 10173) requires
  3. Your obligations as a personal information controller
  4. What to require from your HRIS vendor
  5. Cloud vs on-premise: which is more secure?
  6. Questions to ask your payroll software vendor
  7. What a data breach in payroll costs
  8. FAQs

Why payroll data is high-risk personal data

Payroll records contain a concentration of sensitive personal information that exists almost nowhere else in a business: full legal name, date of birth, home address, SSS number, PhilHealth ID, Pag-IBIG MID, TIN, bank account details, salary history, deduction history, and loan balances. A payroll data breach does not just expose the company to NPC fines — it exposes every employee to identity theft, financial fraud, and loss of financial privacy.

For this reason, payroll data sits firmly within the scope of RA 10173 (the Data Privacy Act of 2012) and its implementing rules. The National Privacy Commission (NPC) treats payroll data breaches seriously — they are not treated as administrative oversights.

What the Data Privacy Act (RA 10173) requires

RA 10173 applies to any organisation that collects, processes, or stores personal data about Philippine residents — regardless of whether the organisation is Philippine-based. For employers with Philippine staff, payroll data processing is squarely covered.

DPA principleWhat it means for payroll data
Legitimate purposePayroll data is collected and processed only for payroll, compliance, and related HR purposes — not for marketing, analytics, or sharing with third parties without consent
ProportionalityCollect only the data needed. Payroll requires TIN and bank details — not passport photos or social media accounts.
TransparencyEmployees must be informed what payroll data is collected, how it is used, and who it is shared with (e.g. SSS, BIR, PhilHealth)
SecurityAppropriate physical, technical, and organisational measures must protect payroll data from unauthorised access, disclosure, or loss
Retention limitsPayroll data must not be kept longer than legally required (BIR: 10 years; Labor Code: 3 years)
Data subject rightsEmployees have the right to access their own payroll data, correct errors, and request deletion of data no longer required

Your obligations as a personal information controller

As an employer, you are the personal information controller (PIC) for your employees' payroll data. Your HRIS vendor is a personal information processor (PIP) — they process data on your behalf. The legal accountability stays with you, the employer, not with the vendor.

ObligationWhat you must do
Data Protection Officer (DPO)Designate a DPO (required for companies processing sensitive personal data). Register the DPO with the NPC.
Privacy Management ProgrammeImplement a documented privacy management programme covering payroll data handling
Privacy Impact AssessmentConduct a PIA before implementing a new payroll system or migrating to cloud
Data Processing AgreementExecute a Data Processing Agreement with your HRIS vendor before they process any employee data
Breach notificationNotify the NPC within 72 hours of discovering a personal data breach affecting payroll records; notify affected employees within a reasonable time
Employee privacy noticeIssue a privacy notice to all employees explaining how their payroll data is collected, used, and protected

The DPA is not optional

NPC enforcement has increased significantly. Fines range from ₱500,000 to ₱5,000,000 per violation for wilful non-compliance. Imprisonment of 1–6 years applies to malicious disclosure of personal data. The NPC investigates employer complaints filed by employees about payroll data mishandling.

What to require from your HRIS vendor

Your vendor processes payroll data on your behalf. Their security posture directly affects your NPC exposure. Before signing any contract, require these in writing:

RequirementWhy it matters
Signed Data Processing Agreement (DPA)Legally required under RA 10173 before any data processing begins. Non-negotiable.
Data centre locationPhilippine NPC guidance prefers Philippine or adequately-protected data centres. Ask where data is stored.
Encryption at rest and in transitPayroll data must be encrypted when stored and when transmitted. Ask for the encryption standard (minimum AES-256).
Access control documentationWho at the vendor can access your employee data? Under what circumstances? With what audit trail?
Penetration testing and security certificationsAsk for the most recent pen test report date and any ISO 27001 or SOC 2 certifications.
Breach notification commitmentVendor must commit to notifying you within 24 hours of discovering a breach so you can meet your 72-hour NPC obligation.
Data return and deletion on contract endYou must be able to export all payroll data in a usable format when you leave the platform.

Cloud vs on-premise: which is more secure?

This question is asked often — and the honest answer is that security depends on implementation, not on whether data is in the cloud or on a server under your desk.

Most Philippine SMEs operating on-premise payroll servers have: no dedicated IT security staff, no regular patch management, no off-site backup, and physical servers in an unsecured office environment. Most reputable cloud payroll providers have: 24/7 security monitoring, automated patch deployment, geographically redundant backups, physical data centre security, and regular third-party security audits.

For the overwhelming majority of Philippine SMEs, a reputable cloud HRIS is more secure than on-premise — not because cloud is inherently safer, but because the cloud provider's security investment far exceeds what an SME can practically maintain internally.

Questions to ask your payroll software vendor

QuestionAcceptable answer
Where is our payroll data stored?Named data centres in the Philippines or a jurisdiction with adequate data protection (e.g. Singapore, Australia)
Who at your company can access our employee payroll data?Named roles only, with documented access controls and audit logging. No open access.
When did you last conduct a penetration test?Within the last 12 months. Ask for a summary report.
What is your breach notification process?Written commitment to notify within 24 hours of discovery
Do you have a Data Processing Agreement template?Yes — they should have one ready. If they don't know what a DPA is, walk away.
What happens to our data if we cancel?Full export in standard format + deletion confirmation within 30 days
Payroll

Payroll data handled with Philippine DPA compliance built in.

KAMI operates with a signed Data Processing Agreement, encrypted data storage, role-based access controls, and complete audit logging. Our security and technical documentation is available at kamiworkforce.com/security.

Book a demoSee KAMI Payroll →

No slides. We'll show you your PH payroll, running on KAMI.

Frequently asked questions

Does the Data Privacy Act apply to small businesses?

Yes. RA 10173 applies to any organisation that processes personal data, regardless of size. The NPC has issued guidance clarifying that small businesses are not exempt — though enforcement has historically focused on larger data breaches.

Can we share employee payroll data with a third-party accounting firm?

Yes — but only under a signed Data Processing Agreement and only to the extent necessary for the accounting purpose. The accounting firm becomes a personal information processor for the data shared with them.

How long must payroll records be kept?

DOLE requires attendance and payroll records for at least 3 years. BIR requires tax-related records including payroll for 10 years. Keep the longer retention period — 10 years — for all payroll records.

What is the NPC's position on cloud storage of HR data?

The NPC permits cloud storage of personal data provided appropriate technical and organisational safeguards are in place. The key requirements are: a signed DPA with the cloud provider, data centre in an adequate jurisdiction, and encryption in transit and at rest.

This guide reflects Philippine law and DOLE/BIR guidelines current as of May 2026. Regulations change — always verify against the latest government issuances, or consult a licensed Philippine labour lawyer for specific situations. Published by KAMI Workforce.

The KAMI guarantee

If we don’t deliver, you don’t pay.
Simple.

We’ll refund every peso if we fail to deliver any promise made — no questions asked. That’s how confident we are.

Book a demoSee pricing