Quick answer
An employer may request limited bank, tax, or medical information when it has a specific lawful and job-related reason, such as enrolling an employee in payroll, complying with withholding-tax rules, administering benefits, assessing fitness for a safety-sensitive role, or obeying a subpoena or public-health requirement.
That does not give the employer a blanket right to see complete bank statements, full income-tax returns, medical charts, diagnoses, prescriptions, or unrelated transaction histories. Each request must have a lawful basis, serve a declared legitimate purpose, and be proportionate—meaning adequate, relevant, necessary, and not excessive.
The legality depends on:
- What exact information is requested;
- Why it is needed;
- Whether a law, employment obligation, or valid consent authorizes the processing;
- Whether a less intrusive document would accomplish the same purpose;
- Who will receive the information, how long it will be retained, and how it will be secured; and
- What employment consequence is threatened if the employee refuses.
A request is not automatically lawful merely because it appears in an application form, handbook, employment contract, privacy notice, or broadly worded “consent” form.
The governing privacy rules
Under the Data Privacy Act of 2012, an employer that decides why and how employee information is collected is generally a personal information controller. Collection, viewing, copying, storing, sharing, and deleting records are all forms of “processing.”
Three principles apply throughout the information’s life cycle:
- Transparency. The employee should be told what will be collected, why, how it will be used, who will receive it, how long it will be retained, and how data-subject rights may be exercised.
- Legitimate purpose. The purpose must be lawful, specific, and compatible with the employer’s functions.
- Proportionality. The employer should collect only what is necessary. If a certificate, redacted page, or confirmation can answer the question, demanding the complete underlying record may be excessive.
For ordinary personal information, lawful bases can include an employment contract, compliance with a legal obligation, legitimate interests that do not override the employee’s rights, or valid consent.
The rules are stricter for sensitive personal information. Health information, medical records, tax returns, and government-issued identifiers such as a TIN fall within that category. Processing is generally prohibited unless a specific exception in Section 13 of the Data Privacy Act applies—for example, specific consent, an authorizing law or regulation with safeguards, protection of life and health, medical treatment by an appropriate provider, or the establishment or defense of legal claims.
Financial account information is personal information and may create serious identity-fraud risks. It is not automatically classified as sensitive personal information merely because it concerns money, but its security and potential impact demand strong safeguards.
Consent is not a cure-all
Consent under the Data Privacy Act must be freely given, specific, informed, and evidenced in writing, electronically, or by recorded means.
The NPC’s 2023 Guidelines on Consent state that consent is not freely given where there is pressure, intimidation, a possibility of adverse consequences for refusing, or another inability to exercise free will. Vague or blanket consent is invalid, and unrelated purposes should not be bundled into one all-or-nothing choice.
This matters in employment because an applicant or employee may reasonably fear losing a job, promotion, or benefit. The NPC’s Advisory Opinion No. 2019-034 on employment consent explains that employers should identify the correct lawful basis instead of using consent indiscriminately.
If processing is truly necessary to perform the employment contract or comply with tax or labor law, the employer may not need consent—but it must still explain the processing and keep it proportionate. Conversely, if consent is the only lawful basis, the employee must have a genuine choice. A signature does not validate an excessive or misleading request.
Bank information: what is usually justified?
Payroll details
An employer may ordinarily need limited information to pay wages through a bank or payroll facility, such as:
- Account holder’s name;
- Account number;
- Bank or payroll-provider name;
- Proof that the account belongs to the employee; and
- Other fields genuinely required by the payroll provider.
That does not normally require the employer to see the employee’s account balance, purchases, transfers, loan payments, remittances, or complete transaction history.
If proof of ownership is needed, ask whether a bank certificate, first page of a statement with unrelated entries redacted, voided deposit slip, or screenshot showing only the account name and number will suffice.
Never provide an ATM PIN, online-banking password, one-time password, card verification value, recovery code, or unrestricted access to an account. An employer has no ordinary payroll reason to ask for these credentials.
Statements for reimbursement or investigation
A specific transaction may sometimes be relevant to an expense claim, fraud investigation, conflict-of-interest inquiry, or legal dispute. Even then, the request should normally be confined to the relevant transaction and period. The employer should explain why a receipt, payment confirmation, sworn statement, or redacted extract would not be enough.
A fiduciary or financially sensitive position may justify closer screening than an unrelated role, but “financial integrity” is not a universal license to obtain every applicant’s complete banking history. The employer must still demonstrate necessity and proportionality.
Can the employer obtain records directly from the bank?
Philippine bank-deposit secrecy laws generally prevent a bank from disclosing or allowing inquiry into deposits unless the depositor gives valid written permission or a statutory exception applies. Exceptions include certain court proceedings, anti-money-laundering inquiries, tax-enforcement measures, garnishment, anti-fraud investigations, and other situations defined by law.
The BSP primer on bank-deposit secrecy explains the current framework, including exceptions under later legislation. An ordinary employer request is not, by itself, authority for a bank to disclose an employee’s deposits.
Bank-secrecy law and data-privacy law address different questions. Bank secrecy principally restricts inquiry into or disclosure by the financial institution. If the employee personally supplies a statement, the employer’s collection and use must still comply with the Data Privacy Act.
Before signing a bank waiver, check the named bank and recipient, specific account, fields covered, purpose, period, expiration date, and whether onward disclosure is allowed. Avoid open-ended authority covering “all accounts, records, transactions, and related information.”
Tax records: what the employer may properly need
Employers have legal duties to register employees where applicable, withhold compensation taxes, prepare returns and alphalists, and issue tax certificates. Appropriate requests may include:
- The employee’s TIN and relevant registration information;
- A properly required BIR registration form;
- Information necessary to calculate withholding; and
- BIR Form No. 2316 from a previous employer when there are successive employments during the same taxable year.
Under BIR Revenue Regulations No. 11-2018, an employee with successive employers during the taxable year must furnish the new employer an extra certified copy of the previous employer’s BIR Form No. 2316. This enables correct withholding and year-end adjustment.
The same regulations require an employer to give the employee BIR Form No. 2316 by January 31 of the following calendar year, or, if employment ends earlier, on the date of the final compensation payment.
These requirements do not automatically entitle an employer to the employee’s complete annual income-tax return, schedules, business records, spouse’s income, unrelated investment income, or earlier years’ filings. A request for a full ITR needs a separate, fact-specific justification. Ask why Form 2316, a BIR certificate, or a redacted extract is insufficient.
Tax-return information held by the BIR is confidential. Section 270 of the National Internal Revenue Code restricts BIR personnel from divulging taxpayer information except as authorized by law. The BIR Data Privacy Manual likewise requires tax information to be secured and processed according to transparency, legitimate purpose, and proportionality. An employer cannot simply ask the BIR to release a worker’s return.
Medical information: fitness is not the same as a complete medical history
Medical information is sensitive personal information. A legitimate need to know whether an employee is fit for particular work does not always justify access to the employee’s diagnosis, treatment notes, laboratory history, prescriptions, genetic information, reproductive history, or unrelated conditions.
In many situations, a narrower document should be considered, such as:
- A fit-to-work certificate;
- A statement of functional limitations;
- Recommended restrictions or accommodations;
- Expected duration of restrictions;
- Confirmation that required testing was completed; or
- A medical certificate supporting leave, without an unnecessary detailed diagnosis.
The occupational-health provider should disclose only what the employer is lawfully entitled to receive. The medical-treatment exception under the Data Privacy Act allows appropriate providers to process information for treatment; it does not automatically authorize the transfer of the patient’s entire chart to HR or management.
Applicants and employees with disabilities
The Magna Carta for Disabled Persons prohibits employment discrimination against a qualified person with a disability unless a challenged standard is job-related and consistent with business necessity.
For a disabled applicant, Section 33 permits a medical examination after an offer of employment when all entering employees are subjected to the examination regardless of disability. Information about medical condition or history must be kept on separate forms and in separate confidential medical files. Managers should receive only necessary restrictions and accommodation information; first-aid or safety personnel may receive appropriate emergency information.
HIV information
The Philippine HIV and AIDS Policy Act makes HIV testing voluntary and confidential except for limited statutory cases. Using HIV testing as an employment prerequisite is a form of compulsory testing. Rejecting an applicant, terminating employment, or imposing other employment disadvantages based wholly or partly on actual, perceived, or suspected HIV status is prohibited.
HIV information may not ordinarily be disclosed without written consent. The law provides narrow exceptions, including specific public-health reporting, treatment-related sharing, and tightly controlled court subpoenas.
Mental-health records
The Mental Health Act protects the confidentiality of information, communications, and records relating to a service user’s mental health or treatment. Disclosure to third parties generally requires written consent unless a statutory exception applies. The law also protects service users from discrimination and denial of reasonable accommodation.
Drug testing and workplace safety
A narrow statutory exception exists for workplace drug testing. Section 36 of the Comprehensive Dangerous Drugs Act permits random testing of officers and employees under company work rules for reducing workplace risk. The Supreme Court upheld that limited framework in Social Justice Society v. Dangerous Drugs Board because it includes safeguards such as random selection, accredited testing, screening and confirmatory tests, confidentiality, and need-to-know access.
That ruling does not authorize employers to demand unrelated medical records or conduct unlimited, targeted searches disguised as random testing.
Illness is not an automatic ground for dismissal
Article 299 of the Labor Code, formerly Article 284, permits termination because of disease only under defined conditions and with separation pay. The implementing rules require certification by a competent public-health authority that the disease cannot be cured within six months even with proper treatment. If it can be cured within that period, the employee should generally be placed on leave and reinstated upon recovery.
The Supreme Court applied these safeguards in ATCI Overseas Corporation v. Court of Appeals. A diagnosis, clinic note, or employer-selected doctor’s unsupported conclusion does not by itself satisfy every requirement for a lawful disease-based termination.
A practical way to respond
Do not ignore the request or refuse impulsively. Respond in writing and ask:
- What exact fields or pages are required?
- What specific purpose will they serve?
- What law, regulation, contract provision, or other lawful basis authorizes the collection?
- Why would a certificate, redacted copy, or verification not be sufficient?
- Who will have access, including clinics, payroll processors, background-check providers, affiliates, or overseas offices?
- How long will the data be retained, and how will it be securely destroyed?
- What is the consequence of declining, and which policy authorizes that consequence?
- Who is the employer’s Data Protection Officer, and what secure submission channel should be used?
Where appropriate, offer a less intrusive alternative. Redact irrelevant transactions, family details, account balances, diagnoses, identifiers, and records outside the relevant period—but do not alter a document that must legally be submitted complete. Clearly label redactions and ask the recipient to confirm that the narrowed document is acceptable.
Use a secure company portal or an official DPO/HR channel. If email is unavoidable, consider an encrypted or password-protected file and send the password separately. Watermark copies with the employer’s name, purpose, and date when this will not invalidate the document.
Evidence to preserve
Keep copies of:
- The original request, including its date and deadline;
- The privacy notice, consent form, policy, handbook provision, and explanation supplied;
- Your written questions, objections, and proposed alternatives;
- The exact version of every document you submitted;
- Proof of delivery and names of recipients;
- Messages threatening rejection, discipline, demotion, termination, or loss of benefits;
- Any bank, BIR, clinic, laboratory, or hospital notice showing that information was released;
- Screenshots, access logs, emails, and witness details concerning unauthorized sharing; and
- Any warning, suspension, termination notice, performance action, or request to resign.
Do not secretly obtain records by accessing another person’s account or restricted system. Preserve evidence lawfully and keep unedited originals.
Your rights after disclosure
Under the Data Privacy Act, an employee may request reasonable information about:
- The personal data being processed;
- Its sources;
- The recipients;
- The manner and purpose of processing;
- The date of access or modification;
- Automated decision-making that significantly affects the employee; and
- The identity and contact information of the controller.
The employee may also seek correction of inaccurate data and, when legally available, object to processing or request blocking, removal, or destruction of data that was unlawfully obtained, used for an unauthorized purpose, or retained after it ceased to be necessary. Erasure is not absolute: tax, labor, accounting, litigation, and regulatory requirements may justify continued retention.
NPC Advisory Opinion No. 2018-042 recognizes an employee’s right to access personal employment data, including copies of annual physical-examination results, subject to lawful limitations and appropriate procedures.
If the employer or another institution refuses to correct the problem
Data-privacy complaint
First notify the employer, clinic, bank, or other controller in writing, preferably through its DPO, and request specific corrective action.
Under the 2021 NPC Rules of Procedure, a complaint ordinarily will not be given due course unless the complainant shows that the respondent was informed in writing and failed to take timely or appropriate action, or gave no response within 15 calendar days of receiving that notice. The NPC may waive exhaustion for good cause or a serious, patently illegal, or potentially irreparable violation.
A formal NPC complaint must generally be written, signed, verified, supported by evidence and correspondence, and accompanied by a certification against forum shopping. Current forms and instructions are available on the NPC complaint page.
Employment dispute or retaliation
If the request leads to threatened or actual suspension, dismissal, discrimination, withheld wages, or forced resignation, a worker may file a Request for Assistance through DOLE’s Assistance for Request Management System or approach a DOLE, NLRC, or NCMB office for the Single Entry Approach process.
Privacy and labor remedies can overlap. An NPC complaint addresses unlawful data processing; a labor case addresses the employment action. One does not automatically replace the other.
Unauthorized bank disclosure
Complain first through the bank’s Financial Consumer Protection Assistance Mechanism. If unresolved, the matter may be escalated through the BSP Consumer Assistance Mechanism, including the BSP Online Buddy or the current complaint form and channels stated there.
When help is urgent
Seek prompt advice from a Philippine lawyer, union representative, DOLE, or the appropriate regulator when:
- A deadline is imminent and refusal may cost you the job;
- You are being required to sign an unrestricted bank or medical waiver;
- HR demands passwords, OTPs, PINs, or direct account access;
- HIV, mental-health, reproductive-health, or other highly sensitive information has been disclosed;
- Records were sent to co-workers, clients, social media, or an unauthorized third party;
- The disclosure creates an immediate risk of fraud, identity theft, blackmail, or physical harm;
- You are suspended, dismissed, demoted, or pressured to resign;
- A subpoena, court order, government investigation, or public-health directive is involved; or
- You are asked to conceal, alter, or falsely certify a record.
Where a personal-data breach involves sensitive information or information usable for identity fraud, unauthorized acquisition, and a likely real risk of serious harm, mandatory breach notification may be required within 72 hours of the controller’s knowledge or reasonable belief. The NPC explains the criteria and current reporting process on its breach-reporting page.
Common mistakes to avoid
- Assuming every HR request is lawful because it is “company policy”;
- Assuming every request is unlawful simply because the information is private;
- Signing a waiver without checking its scope, recipients, duration, and onward-sharing terms;
- Sending an unredacted statement when one transaction would suffice;
- Giving passwords, PINs, OTPs, or recovery codes;
- Altering an official record instead of making disclosed, clearly marked redactions;
- Relying only on a verbal objection and leaving no written record;
- Posting confidential documents or accusations publicly while a dispute is pending;
- Treating a privacy complaint as a substitute for meeting labor-case deadlines; or
- Resigning or signing a quitclaim immediately after a threat without obtaining advice.
Possible liability
An excessive request does not automatically prove a criminal offense. Liability depends on what was collected, the lawful basis, intent or negligence, disclosure, harm, and the responsible person’s participation.
Still, unauthorized processing of sensitive personal information under the Data Privacy Act can carry imprisonment of three to six years and a fine of ₱500,000 to ₱4 million upon conviction. Other offenses—including negligent access, unauthorized-purpose processing, malicious disclosure, and unauthorized disclosure—have their own elements and penalty ranges.
The NPC may also impose administrative fines after notice and hearing. Under NPC Circular No. 2022-01, fines for major or grave infractions are calculated as percentages of annual gross income, while the total administrative fine for a single act resulting in one or more infractions cannot exceed ₱5 million. HIV, mental-health, bank-secrecy, tax-confidentiality, labor, and professional-regulation laws may create separate liability.
FAQ
Can I simply refuse to provide the records?
You may question or object to an excessive request, but refusal is not risk-free where the information is genuinely necessary for payroll, tax compliance, a lawful occupational requirement, or another employment obligation. Ask for the basis and propose a narrower document. Refusal is not automatically insubordination; any employment order and resulting sanction must themselves be lawful, reasonable, job-related, and procedurally fair.
Can my employer ask my bank, the BIR, or my doctor directly?
It may ask, but the institution generally cannot disclose protected information merely because an employer requested it. Disclosure needs valid authority, such as specific consent, an applicable law, or proper compulsory process. A doctor may be authorized to issue a limited fitness certificate without being authorized to release the entire medical chart.
Does a signed consent form make the request lawful?
Not necessarily. Consent must be freely given, specific, informed, and properly evidenced. Processing must remain fair, lawful, and proportionate. A blanket waiver tied to hiring or continued employment may be defective, particularly if refusal brings unrelated adverse consequences.
May an employer see my bank balance?
Usually, a balance is unnecessary for ordinary payroll enrollment. A different answer may apply to a particular investigation, legal proceeding, or narrowly regulated role, but the employer should identify the precise basis and explain why a less intrusive document will not work.
May an employer require my full ITR?
Not as a routine substitute for the tax information normally needed for employment. TIN information and Form 2316 are commonly relevant. A full ITR requires a distinct justification because it may reveal income, deductions, businesses, investments, and family information unrelated to the job.
Must I disclose my diagnosis to obtain medical leave or accommodation?
Not always. A medical certificate describing incapacity, duration, functional limitations, or recommended accommodation may be enough. A more detailed diagnosis may be justified in some cases, but the employer should establish why it is necessary and restrict access to personnel who genuinely need it.
Can I withdraw consent and demand deletion?
Consent may generally be withdrawn without cost. If no other lawful basis remains, processing should stop without undue delay. Withdrawal does not erase lawful past processing, and deletion may be refused where another law requires retention or the records remain necessary for legal claims, tax compliance, or employment administration.
What if I was dismissed after objecting?
Preserve the request, your objection, the termination notice, and all related messages. Do not assume a privacy complaint alone protects labor rights or pauses filing periods. Seek immediate labor advice and consider a DOLE SEnA request while separately evaluating an NPC complaint.
This article provides general Philippine legal information, not legal advice for a specific employment dispute. Outcomes depend on the documents, position, workplace rules, purpose of the request, and actions taken by the parties. Laws, regulations, procedures, and official guidance were checked through 11 August 2026.