In NPC Advisory Opinion No. 2025-015, the NPC advised that the PhilSys QR code constitutes personal and sensitive personal information. The PhilSys QR code enables access to or verification of information linked to government-issued identifiers, which are expressly classified as sensitive personal information under Section 3(l) of the Data Privacy Act (DPA). Accordingly, the QR code and any data derived from it are subject to the stricter requirements for processing sensitive personal information.
The opinion also noted that a bank may lawfully allow a third-party KYC provider to access and process the PhilSys QR code on the basis of Sections 12 and 13 of the DPA, particularly compliance with legal obligations under the Anti-Money Laundering Act and BSP regulations, and for sensitive personal information, processing provided for by existing laws and regulations. Since the third-party provider acts as a personal information processor, it may only process the personal data only upon the bank’s documented instructions.




