The employer needs to confirm you understand the legal and procedural safeguards around employee records. Mishandling a 201 file or medical record can lead to DOLE complaints, privacy violations, and loss of employee trust.
Reference the company's confidentiality policy, the Data Privacy Act, and standard HR practices such as locked storage, restricted access, and logging. Emphasize that you would always verify the requester's authority and purpose before releasing any information.
Start by grounding your answer in the Data Privacy Act of 2012 as your primary legal framework, since it directly governs the collection, storage, and sharing of personal information like medical records and salary details. Say plainly that you would treat every 201 file as sensitive personal data, which means you only access it when a legitimate business need exists, and you never discuss its contents casually even with colleagues. Explain that you would follow the company's own confidentiality policy on top of the law, which typically means physical files stay in locked cabinets with a sign-out log, and digital copies are password-protected with access limited to authorized HR staff only. When someone requests information, clarify that you would verify their identity, confirm their role, and check whether the purpose aligns with company policy or a legal obligation like a DOLE inspection or a court subpoena. Mention that you would document every release, noting who received what and why, and that you would escalate any ambiguous request to your HR manager rather than deciding on your own. Finally, acknowledge the practical reality of the Philippine BPO and corporate setting, where shift handovers and shared workspaces are common, so you would always lock your workstation and never leave files unattended, keeping the same discipline whether you are in the office or working remotely.
Some candidates say 'Basta huwag lang ipakita sa ibang department, okay na' without mentioning any policy or law. Instead, cite the company's data privacy policy and the Data Privacy Act of 2012, and explain that access must be logged, limited, and based on legitimate business need.
Situation
During my HR internship, I was asked to organize the 201 files of over 200 employees and had to understand exactly which documents could be accessed by whom.
Task
I had to correctly identify the confidentiality rules and apply them to my daily tasks, including file storage and access logging.
Action
I reviewed the company's data privacy policy and learned that 201 files must be kept in locked cabinets with limited access, and that only authorized HR staff may view them. I implemented a sign-out log for any file retrieval and ensured that medical records were stored separately from general personnel files. I also attended a briefing on the Data Privacy Act of 2012, which clarified that personal and sensitive information must be processed with consent and only for legitimate purposes.
Result
My file organization passed an internal audit with no findings, and my supervisor complimented the clear access log. I became the go-to person for file retrieval because I always followed the proper procedure.
Knowing the specific rules for handling employee records turns compliance from theory into daily practice.
Write your own answer, then get instant AI feedback graded against:
Get AI feedback on your answer — free.
3 free AI-graded answers + 1 free mock interview, no card needed.
Sign Up FreeAlready have an account? Log in
Sign in to join the conversation.
No answers shared yet — be the first to show how you'd approach this.