SSS MANDATE
The Social Security System (SSS) recognizes the fundamental right of data subject to privacy and is committed to safeguarding personal data entrusted to us. In fulfilling our mandate under the Social Security Act of 2018 (RA 11199), we process personal data in accordance with the Data Privacy Act of 2012 (RA 10173), its Implementing Rules and Regulations, and issuances of the National Privacy Commission (NPC).
This Notice explains in detail how SSS collects, uses, stores, shares, and protects personal data. By availing of our services, accessing our systems, or submitting personal data, you acknowledge that you have read and understood this Notice.
Personal Data Collected
- Full name;
- Date and place of birth, date of marriage/death;
- Gender, age, civil status, religion, citizenship/nationality, health data;
- Address (E-mail, office, local and foreign residential);
- Contact numbers (work, home and mobile);
- Curriculum vitae (employment);
- Agency name and address; Position or designation; employment history;
- Government-issued ID;
- Mother’s maiden name (account opening requirement);
- Signature;
- Photo;
- Biometrics such as fingerprints;
- Video footage or recordings through Closed-circuit television (CCTV), video-conferencing platforms, and other online applications
Primary Use of Data
- Membership registration and maintenance
- Contribution collection and monitoring
- Benefits administration (sickness, maternity, disability, retirement, funeral, death and unemployment)
- Loan processing and repayment \
- Employer coverage and compliance
- Online services (e.g., My.SSS portal, mobile applications)
Secondary Use
- Compliance with RA11199 and other laws
Manner of Storage of Personal Data
Personal data is stored by the SSS in a secure manner, whether in electronic or physical form, through the implementation of appropriate administrative, technical, and physical safeguards, such as access controls, encryption, Data Loss Prevention (DLP), secure storage facilities, CCTV, and other monitoring mechanisms. Such storage practices ensure the confidentiality, integrity, and availability of personal data, and in accordance with established data retention and secure disposal policies, as well as applicable laws and regulations.
Disclosure and Sharing of Personal Data
Personal data under the custody and control of the SSS shall be treated as confidential and shall not be disclosed or shared with any third party except under the following circumstances:
- with the prior consent or authority of the data subject
- when disclosure is authorized or required by the Constitution, law, or regulation, including the lawful performance of the SSS’ mandate
- when required by a lawful order of a court, tribunal, or quasi-judicial body, including a subpoena duces tecum and/or ad testificandum
- when disclosure is made pursuant to a valid data-sharing arrangement.
Data Retention and Disposition
The SSS keeps and disposes personal information in physical and electronic format in accordance with the RA 11199, COA Guidelines, National Archives of the Philippines (NAP) general records disposition schedule and SSS Records Disposition Schedule (RDS) approved by NAP.
Personal data are not retained for a period longer than necessary to achieve the purpose for which it was collected.
Risk and Data Protection
Risks involved during processing: phishing, malware infection, insider threat, identity theft, data breach, unauthorized collection, use, disclosure, or access to personal data.
SSS implements appropriate controls and security measures to safeguard and protect personal data such as:
- Access Control
- Infrastructure Hardening
- Secure Web Transactions
- DLP and Encryption
- Vulnerability Assessment and Secure Socket Layer (SSL)
- Continuous Security Monitoring and security/privacy awareness training
Adequate policies are in place to ensure appropriate security incident management in line with existing NPC policies, circulars, and other issuances.
Methods utilized for automated access
- Data Mapping
- Consent Management
- Subject Rights Management (DSARs)
- Assessments such as PIA
- DLP
- Data De-identification Techniques
Contact Information
DPO dataprotectionofficers@sss.gov.ph and dpcsecretariat@sss.gov.ph
Rights of Data Subjects
- Be informed
- Access their personal data
- Object to processing
- Correct inaccurate data
- Erase or block data, when applicable
- Data portability
- Right to damages
- Lodge complaints with the NPC
Exercise of Data Subject Rights
To exercise their rights, data subjects may submit a written request through the branch or usssaptayo@sss.gov.ph email address, or by contacting the Data Protection Officer (DPO) at dataprotectionofficers@sss.gov.ph.
Requests shall clearly indicate the specific right being invoked and must be accompanied by sufficient information and supporting documentation to reasonably establish the identity of the data subject or their authorized representative.
Complaints may be filed directly with the NPC.









