NPC warns public over ID photography
Balancing verification and privacy as NPC mandates strict compliance with data privacy laws
At A Glance
- The National Privacy Commission (NPC) has issued a public warning to businesses and associations that are taking photos of identification documents without sufficient safeguards or privacy notices.
- The warning cites examples of inappropriate practices, such as hotel receptionists using personal smartphones to photograph guest IDs, car sales agents photocopying potential customers' identification, and residential associations requiring physical ID deposits with sensitive information without proper safeguards.
- The NPC highlighted the significant security risks these activities pose, including data breaches, unauthorized use of personal information, improper disposal of sensitive data, absence of informed consent, and possible discriminatory profiling.
- The Commission has called for explicit consent from individuals before capturing and processing their ID photos and details, and providing a clear, transparent privacy notice detailing the purpose of data processing, security measures, data retention period, and usage limitations.
- Any violation of the Data Privacy Act of 2012 and related regulations in the processing of personal data will be subject to penalties and administrative fines, as per the NPC's reminder.
The National Privacy Commission (NPC) has issued a public warning to businesses and associations involved in the indiscriminate photographing of identification documents without appropriate safeguards or privacy notices in place. This reminder is intended for Personal Information Controllers (PICs) and Personal Information Processors (PIPs) who authorize, permit, or consent to such practices.
Several examples of these practices were highlighted in the announcement. They include hotel receptionists using personal smartphones to photograph guest IDs, car sales agents photocopying potential customers' identification for verification, telecommunications agents requesting ID photos via private communication channels, and residential associations requiring physical ID deposits containing sensitive personal information without proper safeguards.

The Commission emphasized that these activities pose significant security risks, including data breaches, unauthorized use of personal information, improper disposal of sensitive data, absence of informed consent, and possible discriminatory profiling.
As per the Data Privacy Act (DPA) and other applicable laws and regulations, PICs/PIPs must obtain consent from data subjects before collecting and processing their personal data. The Commission stressed the duty of PICs, and their representatives, to uphold the confidentiality and privacy of the personal data they handle.
In order to enforce compliance, the Commission outlined certain mandated practices. These include acquiring explicit consent from individuals before capturing and processing their ID photos and details and providing a clear, transparent privacy notice before obtaining such data.
The notice should detail the purpose of the data processing, implemented security measures, data retention period, and limitations on usage. In addition, the Commission requires entities to establish policies to ensure secure storage and transmission of photographs taken by personal devices and appropriate disposal procedures once the need for the images has passed.
The Commission reiterated that any processing of personal data in violation of the Data Privacy Act of 2012 and related regulations will be subject to penalties and administrative fines. This move is part of a broader effort to safeguard personal data and protect privacy rights across all sectors.