Skip to main content

Main Secondary Navigation

  • About Ateneo de Manila
  • Schools
  • Research
  • Global
  • Alumni
  • News
  • Events

Main navigation

  • Learn & Grow
  • Discover & Create
  • Make an Impact
  • Campus & Community
  • Apply
  • Home >
  • News >
  • Are credit card details sensitive personal information?

Are credit card details sensitive personal information?

06 Sep 2021 | Jamael Jacob, Esq

 

Photo from Unsplash

 

Over the course of the week, I was asked these rather curious questions: are credit card details sensitive personal information? If they are, where is it in the Data Privacy Act (DPA) — the country’s data protection law — does it say that?

Before we get around to answering these two, it’s probably best to explain first why it is essential to make a distinction between sensitive personal information and those of the regular variety (i.e., personal information). 

For those still unfamiliar with the DPA, the law defines personal information this way: it is any information from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information. Sometimes, you would have to put it together with other information before their consolidated form actually manages to identify a specific individual.

With that description, the DPA then proceeds to define sensitive personal information as consisting of any of the following: 

  1. Personal information about an individual’s race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;

  2. Personal information about an individual’s health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such person, the disposal of such proceedings, or the sentence of any court in such proceedings;

  3. Personal information issued by government agencies peculiar to an individual which includes, but not limited to, social security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns; and

  4. Personal information specifically established by an executive order or an act of Congress to be kept classified.

Now, why do these definitions matter?

The law treats these two concepts in different ways; that’s why. 

In terms of legal bases, the DPA has one list prepared for personal information, and another that’s meant for sensitive personal information and privileged information. If one looks at the two, it is readily apparent that the law adopts a more permissive stance when it comes to processing personal information. 

While both lists recognize consent as a proper legal bases, those grounds that apply to sensitive personal information tend to be stricter and impose more conditions. So much so that anyone looking to process sensitive personal information almost always end up having to ask for consent, since it is the only viable option for them. 

Another area where the distinction is very important is in the imposable penalties. Except only in two instances, the DPA prescribes heavier penalties when violations of the law involve sensitive personal information. By heavier penalties, we mean longer prison terms and more expensive fines. 

Given these, it’s rather obvious that the distinction does matter — a lot. 

Circling back to credit card information, it is clear from the language of the DPA that there is nothing in it that explicitly mentions this type of data as sensitive personal information. It would then be easy to see how a person can come to the conclusion that it is, in fact, just regular personal information. 

But not so fast. Note that the last part of the definition for sensitive personal information states that any personal information that is specifically established by an executive issuance or law as classified shall also qualify as one. 

That is a crucial detail because, since 2016, we already have Republic Act No. 10870, which is also known as the “Philippine Credit Card Industry Regulation Law”. This piece of legislation expressly provides that, except only in certain circumstances, credit card issuers are duty-bound to keep data on cardholders strictly confidential. More importantly, even recipients of this information are also expected to preserve its confidentiality. It’s not clear, though, if the same set of grounds for permitted disclosures also apply to the latter group. 

What does this mean? It means credit card details may actually qualify as sensitive personal information since there is, in fact, a law that mandates its treatment as strictly confidential information. 

In 2019, the National Privacy Commission (NPC) had the opportunity to elaborate on this subject in one of its policy unit’s opinions. In Privacy Policy Office Advisory Opinion No. 2019-041, a clarification was being requested regarding the implications of RA 10870, in conjunction with the DPA, on credit card fraud investigations. Specifically, the inquiring party was asking if personal information provided to online merchants could be disclosed to credit card issuers as part of said investigations. 

Unfortunately, in discussing the relevant provision of RA 10870, the agency chose to focus on the authority of credit card issuers to make permitted disclosures. It made no categorical statement as regards the classification of credit card information as sensitive personal information. Neither did it directly clarify if recipients of credit card information can also rely on the grounds for permitted disclosures available to credit card issuers. At best, one could probably argue that it may have implied the latter point, considering the question posed by the inquiring party. 

As a consequence, anyone seeking long-term relief from all this ambiguity will probably have to wait further and see if current efforts to amend the DPA actually gain ground and pass the gauntlet of lawmaking. This is because one of the key features of the bill pending at the House of Representatives is its inclusion of individual financial data and other information established by regulations as confidential in the DPA’s definition of sensitive personal information. That particular proposal, if adopted, should put to rest any lingering doubts on this issue. 

For now, we must deal with our own interpretations of the two laws and our unique way of reconciling their relevant provisions. 

Would it be fair to recognize equivalence between strictly confidential information, as described in RA 10870, and classified personal information, as a component of the DPA’s definition of sensitive personal information? I think so. It is the interpretation that offers the better cover for the rights and interests of individuals, and best represents the value proposition of data protection. And isn’t that what the DPA is for?

This article first appeared on Newsbytes.PH on September 3, 2021, 11:41 am

General Interest Administration Administration Cluster
Share:

Recent News

Bending toward justice: A forum on the ICC, the Duterte Case, and victim participation

31 Mar 2026

[Hot Off the Press] Arkipelago

31 Mar 2026

Matthew General clinches gold at Excalibur Fencing Tournament

31 Mar 2026

Silver success for Belarmino at Wilson Epee Invitational

31 Mar 2026

From AGS to ASHS: Ateneo fencers haul 6 medals at 1st Estudio de Espada League

31 Mar 2026

Ethan Santos grabs bronze at Hampton Fencing Club’s 3rd Winter Cup

31 Mar 2026

Blue Eagle blades Santos and General grab gold in Young Musketeers meet

31 Mar 2026

Matthew General secures gold at Coach Benny Fencing Competition

31 Mar 2026

Bending Toward Justice: ALS Forum Examines the ICC, the Duterte Case, and Victim Participation

31 Mar 2026

Protecting Creativity: AIPO and Rizal Library Host Copyright Awareness Session for the Ateneo Community

31 Mar 2026

You may also like these articles

Arkipelago

31 Mar 2026

[Hot Off the Press] Arkipelago

New book from the Ateneo Press Arkipelago provides a fascinating and fantastical twist on Philippine politics and history Our country is an archipelago of stories

Copyright Awareness Session

31 Mar 2026

Protecting Creativity: AIPO and Rizal Library Host Copyright Awareness Session for the Ateneo Community

On March 18, 2026, the Ateneo Intellectual Property Office (AIPO), in collaboration with the Rizal Library, successfully conducted a Copyright Awareness Session held on the

Close up of University seal and logo at Xavier Hall

31 Mar 2026

Holy Week 2026 Holidays (Memo # UHR2526-038)

Memo # UHR2526-038 31 March 2026 TO: All Employees FROM: [Sgd] Maria Victoria T Cortez, PhD Vice President for University Human Resources SUBJECT: Holy Week

ASOG’s Tobacco Control initiatives spotlighted in DOH National Technical Working Group for Tobacco Prevention and Control

31 Mar 2026

ASOG’s Tobacco Control initiatives spotlighted in DOH National Technical Working Group for Tobacco Prevention and Control

On March 10 to 12, 2026, the Ateneo School of Government (ASOG), through its research and public policy unit, the Ateneo Policy Center, participated in

Geloy Concepcion Exhibition 2026

30 Mar 2026

Things You Wanted to Say But Never Did: Geloy Concepcion’s six-year project makes Its exhibition debut at the Ateneo Art Gallery

Geloy Concepcion’s Things You Wanted To Say But Never Did comes to the Ateneo Art Gallery this 18 April 2026. After receiving almost 300,000 messages

Love If I'm Pretty

30 Mar 2026

[Hot Off the Press] Love If I'm Pretty

New YA Release from the Ateneo Press Love If I’m Pretty tackles the nuances of growing up through complex characters and straightforward prose What do

Katipunan Avenue, Loyola Heights, Quezon City 1108, Philippines

info@ateneo.edu

+63 2 8426 6001

Connect With Us
  • Contact Ateneo
  • A to Z Directory
  • Social Media
Information for
  • Current Students
  • Prospective Students
  • International Students
  • Faculty & Staff
  • Alumni
  • Researchers & Visiting Academics
  • Parents
  • Donors & Partners
  • Visitors & Media
  • Careers
Security & Emergency
  • COVID-19
  • Campus Safety
  • Network & Tech
  • Emergency Management
  • Disaster Preparedness
Digital Resources
  • AteneoBlueCloud
  • Archium
  • Rizal Library
  • Ateneo Mail (Staff)
  • Ateneo Student Email
  • Alumni Mail
  • Branding & Trademarks
  • Data Privacy
  • Acceptable Use Policy
  • Report Website Issues
  • Ateneo Network
  • Philippine Jesuits

Copyright © 2022 Ateneo de Manila University. All rights reserved. | info@ateneo.edu | +63 2 8426 6001

Search