Property Data Privacy Compliance for Philippine Businesses
A brokerage buys a list of licensed brokers scraped from a public register and starts a campaign. The information was publicly available, which the brokerage treats as settling the question. It does not. Publicly available is not the same as available for marketing, and in a professional community this small, cold outreach becomes a reputation problem before it becomes a legal one.
Real estate runs on personal information. Buyer identification documents, financial capacity, family circumstances, tenant records, building access logs, and CCTV footage are all personal data, and the Data Privacy Act of 2012, Republic Act No. 10173, applies to all of it. This article sets out what the law requires of property businesses, where the exposure concentrates, and what a workable compliance position looks like.

What the Law Covers
The Data Privacy Act governs the processing of personal information by both private and public entities, and it is administered by the National Privacy Commission.
Personal information is any information from which an individual's identity is apparent or can reasonably be ascertained.
Sensitive personal information is a narrower category attracting stricter treatment, including information about an individual's health, education, genetic or sexual life, offenses, government-issued identifiers such as social security numbers, and other categories the law specifies. Government identification documents collected during property transactions frequently fall into this category.
Processing covers essentially anything done with the data: collection, recording, storage, use, consolidation, disclosure, and disposal.
The obligations attach to the personal information controller, meaning the entity that decides how and why data is processed. A brokerage, a developer, a property manager, and a platform are each controllers of the data they decide to collect.
Where Property Businesses Collect Personal Data
Buyer and tenant onboarding. Identification documents, tax identification numbers, proof of income, employment details, and bank information.
Financing applications, which involve some of the most sensitive information a person holds and which frequently pass through a broker's hands en route to a lender.
Building access and security systems. Access logs, visitor records, CCTV footage, and increasingly biometric access.
Tenant records held by property managers, including contact details, occupancy information, and payment history.
Marketing databases, including enquiry records, website analytics, and any list acquired from a third party.
Employee and agent records held by the business itself.
Platform and portal data, where identity verification is part of the service.
The Core Obligations
Establish a lawful basis for processing. Consent is one basis and not the only one. Contract necessity, legal obligation, and legitimate interests are others, and relying on consent where another basis fits better creates a fragile position, because consent can be withdrawn.
Collect only what you need. Proportionality is a principle rather than a suggestion. A brokerage collecting a client's complete financial history when it needs a budget range is over-collecting.
Be transparent. Data subjects are entitled to know what is being collected, why, who it will be shared with, and how long it will be kept. A privacy notice at the point of collection is the practical mechanism.
Keep it secure, through organizational, physical, and technical measures proportionate to the risk. A file of client identification documents in an unlocked cabinet or an unsecured shared drive is a failure of this obligation.
Retain only as long as necessary, then dispose securely. Indefinite retention is a common failure in property businesses, where transaction files accumulate for years after any purpose has expired.
Honor data subject rights, including the rights to be informed, to access, to object, to erasure or blocking, to damages, to data portability, and to rectification.
Register with the National Privacy Commission and appoint a Data Protection Officer where the business meets the applicable thresholds, and maintain records of processing activities.
Report qualifying breaches to the Commission and to affected data subjects within the prescribed period.
The Marketing Exposure
This is where property businesses most commonly get into difficulty, and it is entirely avoidable.
Publicly available is not marketable. A professional register exists so that the public can verify licensure. That is the purpose for which the information was published, and using it to build a marketing list is processing for a different purpose.
Purchased and scraped lists carry the seller's problems. If the original collection had no lawful basis, using the list does not cure it, and the buyer becomes a controller of data it cannot account for.
Referral programs involve disclosing someone's contact details to a third party, which requires a basis. A referrer passing a friend's number to a broker is a disclosure, and the friend has rights in it.
Group chats and shared listings frequently circulate client details without anyone considering the position. A buyer's requirement forwarded through four Viber groups is personal information disclosed to parties the buyer never agreed to.
The practical rule: if you cannot state the lawful basis for holding a contact record, do not market to it.
Building Access, CCTV and Smart Systems
Property managers and building owners process substantial personal information and frequently have no compliance position on it.
CCTV requires notice. Signage informing people that the area is under surveillance is the minimum, alongside a defined retention period and controlled access to the footage.
Access logs and visitor records identify individuals and their movements, which makes retention period and access control genuine questions rather than administrative ones.
Biometric access data is sensitive personal information and attracts stricter treatment. A building deploying fingerprint or facial recognition should have taken advice before doing so.
Occupancy analytics differ by design. Counting people anonymously is a different exercise from identifying and tracking individuals, and systems marketed as smart building technology sometimes do the second while being described as the first.
Tenant employees are data subjects. A landlord introducing individual-level monitoring affects people who have no relationship with the landlord at all, and that belongs in the lease and in the tenant conversation rather than being implemented unilaterally.
Third Parties and Cross-Border Transfers
A controller remains responsible for data it passes to processors. Customer relationship management systems, marketing platforms, cloud storage, and outsourced administration are all processors.
Contract with them properly. The arrangement should specify what the processor may do, the security measures required, breach notification obligations, and what happens to the data when the relationship ends.
Cross-border transfer requires attention. Where a platform stores data outside the Philippines, the controller remains accountable, and the transfer needs a basis and appropriate safeguards.
Generative artificial intelligence tools deserve specific caution. Pasting a client's identification document or financial details into a general-purpose tool is a disclosure to a third party. Establish where the data goes, whether it is retained, and whether it is used for training, before doing it rather than afterward.
A Workable Compliance Position
- Map what you actually hold. Most property businesses have never listed their personal data holdings, and the exercise usually reveals more than expected.
- Establish and document the lawful basis for each category of processing.
- Publish a privacy notice and present it at the point of collection rather than burying it.
- Set retention periods and enforce them. Transaction files, enquiry records, CCTV footage, and access logs should each have a defined life.
- Secure the storage. Access controls, encryption where appropriate, and a clear position on who in the business can see what.
- Appoint a Data Protection Officer and register with the National Privacy Commission where the thresholds apply.
- Contract properly with processors, including platforms and outsourced providers.
- Train the people handling data, particularly agents and salespersons who collect identification documents routinely.
- Have a breach response plan before you need one, since the reporting period is short.
Common Failures in Property Businesses
The same gaps appear repeatedly and none of them is difficult to close once identified.
Identification documents held indefinitely. Copies of passports, drivers licenses, and tax identification numbers accumulate in transaction files and shared drives with no retention limit and no access control.
Client data in personal devices and personal accounts. An agent holding client information in a personal messaging app or an unmanaged email account puts it outside any organizational control the business can demonstrate.
No privacy notice at collection. Data is collected at the first meeting and the notice, if it exists, appears in a contract signed weeks later.
Sharing between agents without basis. A client requirement circulated among colleagues, or between brokerages, is a disclosure that the client has rights in.
CCTV without signage or retention policy, which is among the most visible failures and the easiest to correct.
No breach plan. The reporting period is short, and a business improvising a response while the clock runs will handle it badly.
Why This Is Commercially Relevant
The compliance argument is real and the commercial argument is stronger.
The number one blocker in Philippine property is fear of being deceived. A buyer handing over identification documents, payslips, and bank details is extending trust at exactly the point where they are most anxious. A business that can explain what it does with that information is answering the objection rather than adding to it.
Verification requires collecting sensitive data, and platforms and brokerages asking for government identification and liveness checks are asking for more, not less. The credibility of that request depends entirely on the answer to what happens to it afterward.
In a small professional community, a data incident travels quickly, and reputational cost in this market exceeds regulatory cost in most realistic scenarios.
Property businesses collect some of the most sensitive information their clients hold, and being able to explain what happens to it is part of earning the transaction. You can explore verified property listings across the Philippines at The Grid Property Ventures, the Philippines' smartest real estate platform.






