This scenario probes your ethical judgment and your willingness to uphold data privacy principles even under pressure from a superior. It's a realistic test because Philippine marketing teams often face informal requests to use contact lists of unclear provenance, which can violate RA 10173.
Show that you would not blindly follow the instruction. Explain that you would first seek clarification on the data source and the consent status. If consent is missing, propose a compliant workaround like a consent-seeking campaign, and educate your supervisor on the risks. Emphasize that protecting the company from legal penalties is part of your role.
Start by acknowledging the instruction without agreeing to it outright, and frame your hesitation as concern for the company rather than defiance. Say plainly that you would ask your supervisor where the list came from and whether each contact has given explicit or implied consent for marketing messages, since RA 10173 requires a lawful basis for processing personal data. If they cannot confirm consent, explain that sending to those addresses risks fines and reputational damage that no campaign is worth. Propose a concrete workaround, such as running a short re-permission email asking recipients to opt in, or using the list only for a low-risk, non-commercial update with an unsubscribe link. Emphasize that you are not refusing the task, you are protecting the team from a DOLE or National Privacy Commission complaint. In a Taglish register, you might say, "Boss, kailangan lang natin i-check kung saan galing 'to, para safe tayo." Offer to help draft a quick consent request or pull the company's privacy policy so the campaign can proceed legally. This shows you are a partner in risk management, not just an order-taker, and it positions you as someone who understands that ethical shortcuts eventually cost more than they save.
A common reaction is to just do it because 'boss ang nag-utos' (the boss ordered it). But saying 'Sige, boss, padala ko na' without vetting the list could expose the company to liability. A better approach is to respectfully ask about the origin of the data and suggest a compliant way to engage the contacts.
Situation
In a previous role as a marketing assistant for a startup, my manager handed me a list of email addresses she had gathered from a networking event, with no record of consent.
Task
I had to responsibly address the request without jeopardizing our company's compliance or alienating potential leads.
Action
I politely asked my supervisor about the source of the contacts and whether they had given explicit permission to receive marketing emails. When she admitted they were just business cards, I explained that under RA 10173 we could not legally add them to our email list without consent. I proposed an alternative: send a one-time, personalized invitation email to each contact (not bulk) introducing ourselves and offering a chance to sign up for our newsletter via a proper opt-in form. She agreed, and we did not use the list for bulk campaigns.
Result
We converted 15% of those contacts into legitimate subscribers, and our company avoided the risk of a data privacy complaint. My supervisor later commended my caution and assigned me to review our entire data collection process.
Questioning a directive when it conflicts with data privacy laws is a responsible professional act, not insubordination.
Write your own answer, then get instant AI feedback graded against:
Get AI feedback on your answer — free.
3 free AI-graded answers + 1 free mock interview, no card needed.
Sign Up FreeAlready have an account? Log in
Sign in to join the conversation.
No answers shared yet — be the first to show how you'd approach this.