When stockholders demand to inspect corporate records containing personal data, companies and their boards must navigate the interplay among three competing considerations: the right to corporate transparency under the Revised Corporation Code (RCC), their fiduciary duties necessitating good corporate governance, and the duty to protect personal or sensitive personal information under the Data Privacy Act of 2012 (DPA).
Corporate records may contain confidential operational and financial information as well as personal data, including compensation arrangements, tax information and employee records.
The National Privacy Commission (NPC), in Advisory Opinion (AO) Nos. 2026-005 and 2026-007, both dated 25 August 2026, recently clarified how corporations and their boards should balance their fiduciary duties and their obligations under the RCC and DPA.
Harmonization of the stockholder inspection rights under the RCC and data privacy protection under the DPA
In NPC AO No. 2026-005, the request covered records concerning the compensation and benefits of the company’s seven most highly compensated directors or officers, including compensation policies and approvals, benchmarking data, job descriptions and relevant board or committee minutes.
NPC AO No. 2026-007 involved records concerning retirement and other employee benefits, as well as records relating to the top seven most highly compensated directors or officers.
Section 73 of the RCC recognizes the right of stockholders to inspect corporate records and obtain copies or excerpts, subject to applicable confidentiality rules, including the DPA.
The threshold question, however, remains whether the stockholder is entitled to inspect the requested records under Section 73 of the RCC. The DPA neither enlarges nor diminishes that statutory inspection right. Once the company determines that an inspection demand is valid under the RCC, it must separately determine the lawful and proportionate manner in which records containing personal data may be disclosed.
The NPC explained that “the [Data Privacy Act (DPA)] neither creates a blanket prohibition against stockholder inspection nor independently authorizes access to corporate records x x x the applicable lawful-processing standard depends on the nature of the data involved. Personal information may be processed only if the processing is not otherwise prohibited by law and at least one of the criteria under Section 12 of the DPA applies.”
The NPC has also “recognized that the DPA cannot be invoked to curtail existing stockholder inspection rights when the inspection complies with prevailing laws and regulations, and that a corporation may limit the scope of inspection or redact information that is not relevant to the request.”
Accordingly, where a corporation determines that an inspection demand is valid under the RCC, the resulting processing of personal data must still comply with the principles of transparency, legitimate purpose and proportionality under the DPA.
With respect to the compensation records, the NPC explained that “[c]ompensation and benefits information linked to identifiable directors or officers is personal information. It is not, by that fact alone, sensitive personal information. Whether a record contains sensitive personal information or privileged information depends on its actual contents”.
For sensitive personal information and privileged information, the NPC opined that Section 73 of the RCC may serve as the existing law contemplated by Sections 12(c) and 13(b) of the DPA. Significantly, however, the existence of a lawful basis does not by itself determine the extent of personal data that may be disclosed. The corporation must therefore consider not only whether disclosure is legally permissible, but also how much personal data must actually be disclosed to satisfy the legitimate purpose of the inspection.
Disclosure of benchmarking or comparative analysis and board minutes
The NPC also addressed requests for benchmarking or comparative compensation information.
It opined that the disclosure of benchmarking or comparative analysis may proceed under the DPA where the company has first determined under applicable law that the material may or must be disclosed, the processing is supported by a lawful basis, and the personal data disclosed is necessary and proportionate to the stated stockholder purpose.
Company-level data, compensation ranges, methodology, and aggregated results should be used where they are sufficient for that purpose.
Names, position-specific identifiers, individualized compensation, and other personal data of comparator-company officers should not form part of the disclosure when they are unnecessary for the stated purpose and may instead be redacted or otherwise excluded from the personal data disclosed.
The NPC also emphasized that pseudonymization alone does not remove the information from the DPA when the individuals remain identifiable.
The NPC further opined that the company “may disclose personal data in the portions of committee or board minutes that are responsive to the request. It may provide excerpts and redact nonresponsive portions and personal data that is not necessary for the stated purpose. Names, positions, votes, or other identifiers may be retained when necessary to understand the corporate action, quorum, approval, or accountability.”
Disclosure of identity and tax-related data
The corporation should likewise determine whether the identity of an individual is genuinely necessary to address the purpose identified by the requesting stockholder.
In NPC AO No. 2026-007, the NPC opined that the company “may disclose an identity only when it is responsive and necessary to the stated inspection purpose, such as evaluating a specific related-party transaction, conflict-of-interest concern, or corporate governance issue.”
Even where disclosure of an individual’s identity is necessary, the NPC emphasized that the corporation should disclose only the minimum amount of personal data required.
Thus, “[e]ven when an identity must be disclosed, [the company] should disclose only the minimum personal data necessary and withhold unrelated details, including birthdates, home addresses, full tax identification numbers, bank account details, family information, and other data that do not materially assist the inspection.”
As the personal information controller, the company bears responsibility for determining which details may be disclosed in relation to the stockholders’ stated purpose. The company is required to consider the general data privacy principles and the rights of affected data subjects.
Moreover, tax-related personal data may be disclosed only “when an applicable lawful basis exists—for sensitive personal information such as tax returns, an exception under Section 13—and only to the minimum extent necessary.”
For records relating to natural persons, the NPC advised companies to “prefer certifications, summaries, redacted copies, masked tax identification numbers, or confirmation that withholding and remittance obligations were performed, when these alternatives sufficiently address the purpose.”
The NPC warned against disclosing a full and unredacted tax return merely because it was requested or because a confidentiality undertaking was executed.
Anonymization, pseudonymization, redaction, and confidentiality undertakings
The NPC identified several measures corporations may employ to reconcile a valid stockholder inspection request with their data privacy obligations. These include “anonymization, pseudonymization, selective redaction, disclosure by excerpt, and access controls to limit the processing to personal data necessary for the lawful purpose.”
The NPC also advised that “[i]n determining the appropriate measures, the company should consider the nature of the personal data, the risks represented by the processing, the size and complexity of its operations, current data privacy best practices, and the cost of implementation.”
A confidentiality and non-disclosure undertaking may serve as an organizational safeguard, but the NPC opined that it is “not sufficient, by itself, to establish compliance with the DPA for complete, unlimited, and unconditional inspection.”
The company should combine it with reasonable access limits, supervised inspection, restrictions on copying and onward disclosure, inspection logs, secure handling, and appropriate organizational, physical, and technical measures.
Actionable Takeaways
To stay compliant with both the RCC and DPA, corporations faced with a stockholder inspection request should implement a structured review process:
• Determine the Right to Inspect. Assess whether the request satisfies Section 73 of the RCC and other applicable corporate-law requirements before addressing the manner of disclosure.
• Identify the Data Involved. Determine whether the responsive records contain personal information, sensitive personal information or privileged information.
• Establish the Lawful Basis. Identify the applicable lawful basis for processing under Sections 12 or 13 of the DPA, as appropriate.
• Apply the Necessity & Proportionality Test: Determine what personal data are actually necessary to satisfy the legitimate purpose of the inspection. A lawful basis for processing does not automatically justify disclosure of every piece of personal information contained in the responsive records.
• Minimize Disclosure. Where appropriate, use certifications, summaries, aggregated information, excerpts, masking, selective redaction, pseudonymization or anonymization instead of disclosing complete and unredacted records.
• Control Access. Consider supervised inspection, confidentiality undertakings, copying and onward-disclosure restrictions, inspection logs, secure handling procedures and other organizational, physical and technical safeguards.
• Document Decisions: Maintain clear internal records justifying why certain data points were disclosed, masked, or redacted.
In practice, the strongest response is neither automatic disclosure nor automatic refusal. It is a documented, purpose-driven and proportionate review of the information requested, supported by appropriate redaction, anonymization, access controls and other safeguards.
The NPC’s recent opinions underscore that stockholder inspection rights and data privacy obligations are not mutually exclusive. A valid inspection request does not cease to be valid merely because responsive records contain personal data; conversely, a stockholder’s inspection right does not justify indiscriminate disclosure of every personal detail contained in those records. The corporation must respect the inspection right while limiting the processing and disclosure of personal data to what is lawful, necessary and proportionate.
Accordingly, a stockholder inspection request involving personal data should be treated not merely as a corporate-governance matter, but as a corporate governance and data privacy issue.

For further information, please contact:
Fernand Joseph D. Miranda, Partner, Cruz Marcelo & Tenefrancia
fd.miranda@cruzmarcelo.com




