This knowledge question gauges your basic literacy in the primary data privacy regulation affecting marketing in the Philippines. While this is a theme-based question, any Digital Marketing Associate should be aware of RA 10173 to avoid legal risks and to handle customer data responsibly.
Briefly explain that RA 10173 sets rules for collecting, using, and storing personal data, with key principles of transparency, legitimate purpose, and proportionality. Highlight its specific impact on email marketing: explicit opt-in consent is required, not implied; data subjects can withdraw consent anytime; and you must not use data for unrelated purposes. Show that you know non-compliance can lead to penalties.
Start by showing that you understand the law as a practical framework, not just a compliance checkbox. Say plainly that the Data Privacy Act of 2012, or RA 10173, governs how you collect, use, and store personal information, and that for email marketing the central rule is consent. Explain that consent must be explicit and freely given, meaning you cannot rely on pre-ticked boxes or buried clauses in a privacy policy. You should describe how you would apply this in daily tasks: obtaining opt-in at the point of collection, stating clearly that the data will be used for marketing, and giving subscribers a straightforward way to withdraw consent, such as an unsubscribe link that actually works. Mention that you would also limit collection to what is necessary for the campaign, avoid using the list for unrelated purposes, and store data securely, perhaps with access restricted to authorized team members. If you can, note that in a BPO or agency setting, you would coordinate with the legal or data protection officer to ensure your processes align with DOLE and NPC guidance, especially when handling client data across borders. Close by acknowledging that penalties for non-compliance can be significant, so treating data privacy as part of your workflow, not an afterthought, is essential.
A candidate might say 'Basta may privacy policy sa website, sapat na' (As long as there's a privacy policy on the website, that's enough). But having a policy is not enough; you must actively obtain consent before processing data for marketing. Explain that RA 10173 requires that consent be given prior to or at the point of collection, and it must be specific to the purpose of marketing.
Situation
During my college internship at a digital marketing agency, our team lead gave a briefing on Philippine data privacy laws before we started handling client email databases.
Task
I needed to understand and apply the key principles of RA 10173 to my daily tasks, such as segmenting email lists and importing contacts from trade show leads.
Action
I studied the law's core requirements: personal data must be collected for a specific and legitimate purpose, data subjects must be informed and give consent, and they have the right to access and correct their data. I learned that for email marketing, explicit consent is mandatory, not implied. I also discovered that buying email lists without proof of lawful consent is non-compliant. I began flagging leads that lacked clear opt-in records and suggested we send re-permission campaigns before adding them to our regular newsletter.
Result
My proactive approach reduced the number of questionable contacts in our database by 40% and helped the agency avoid potential complaints to the National Privacy Commission from a client whose data handling practices were previously lax.
Understanding the law's principles empowers you to make ethical and compliant decisions daily, not just when a crisis hits.
Write your own answer, then get instant AI feedback graded against:
Get AI feedback on your answer — free.
3 free AI-graded answers + 1 free mock interview, no card needed.
Sign Up FreeAlready have an account? Log in
Sign in to join the conversation.
No answers shared yet — be the first to show how you'd approach this.