Baliuag University Privacy Policy
Baliuag University (“BU” or the “University”) recognizes and upholds the fundamental right of every individual to privacy and is committed to protecting personal information in compliance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, and other applicable issuances of the National Privacy Commission.
As part of its commitment to responsible and transparent data processing, the University adopts this Privacy Policy to guide the collection, use, storage, disclosure, retention, and protection of personal information of its various data subjects. These data subjects include, but are not limited to:
By submitting personal information to the University, accomplishing forms, accessing University systems, participating in university activities, or signing any applicable consent or data privacy forms, the data subject acknowledges that they have read, understood, and agreed to the terms of this Privacy Policy and consent to the processing of their personal information in accordance with applicable laws and University policies. For students who are minors, such consent may be given or assisted by their parent or legal guardian, where applicable.
This Privacy Policy shall be read together with all existing University rules, regulations, contracts, manuals, and policies that are not inconsistent with its provisions. Should any provision of this Privacy Policy be declared invalid or unenforceable by a competent authority or court, the remaining provisions shall continue to remain valid and enforceable.
The University reserves the right to review, amend, update, or modify this Privacy Policy from time to time to ensure compliance with applicable laws, regulatory requirements, operational changes, and institutional developments. Any revisions or updates shall take effect immediately upon publication through the University’s official website, portals, or other authorized communication channels.
1. What Personal Information Does the University Collect?
BU collects, processes, stores, and maintains personal information necessary for the performance of its academic, administrative, research, employment, contractual, security, and other legitimate institutional functions. The University may collect personal information before, during, and after an individual’s relationship with the University.
The personal information collected may include, but is not limited to:
In certain circumstances, the University may also obtain personal information from third parties such as parents or guardians, previous schools, employers, government agencies, medical professionals, references, partner institutions, or other lawful sources. Such information shall be evaluated to determine whether its collection and processing are lawful, fair, and necessary. When retained, the information shall be afforded the same level of protection as personal information directly provided to the University. If the information is found to be unnecessary or improperly obtained, it shall be securely disposed of or deleted in accordance with applicable laws, regulations, and University policies.
2. How Does the University Collect Personal Information?
BU collects personal information through lawful, fair, and transparent means necessary for the fulfillment of its academic, administrative, operational, research, employment, security, and other legitimate institutional purposes.
The University generally collects personal information through various methods, including but not limited to:
The University recognizes that the transmission and processing of information through the internet and electronic platforms involve certain inherent risks. Data subjects are encouraged to exercise caution and responsibility when providing or sharing personal information through email, websites, online services, educational platforms, social media platforms, chat systems, discussion boards, or similar digital environments.
When individuals access or use the University’s websites, online systems, learning platforms, or digital services, the University and its authorized third-party service providers may automatically collect certain technical and usage information generated by browsers, devices, or systems. Such information may include internet protocol (IP) addresses, browser type, device information, access logs, cookies, session information, and usage activity for security, analytics, system administration, and service improvement purposes.
Data subjects are responsible for maintaining the confidentiality and security of their usernames, passwords, authentication credentials, and other account-related information. The University likewise encourages all individuals to avoid unnecessarily disclosing personal or sensitive personal information through public or unsecured online channels.
3. Who May Access and Use Personal Information?
Personal information collected by BU may be accessed, processed, and used only by authorized university personnel, offices, departments, and duly authorized third parties who have a legitimate and lawful purpose in relation to the performance of their official, contractual, academic, administrative, operational, research, security, or legal functions.
Access to personal information shall be limited only to individuals who require such information in the fulfillment of their duties and responsibilities, and who are bound by obligations of confidentiality, data privacy, and information security.
Depending on the nature of the relationship with the University, personal information may be accessed and used by authorized personnel involved in:
The University may likewise share or disclose personal information to government agencies, accrediting bodies, partner institutions, service providers, contractors, or other third parties when such disclosure is authorized by law, necessary for the performance of contractual or institutional obligations, required for public authority functions, or made with the consent of the data subject, where applicable.
All persons and entities authorized to access personal information are expected to maintain the confidentiality, integrity, availability, and security of such information and to process the same only in accordance with the Data Privacy Act of 2012 and related University policies.
4. How Does the University Use Personal Information?
BU processes and uses personal information of its various data subjects to effectively carry out its academic, administrative, operational, research, employment, security, and other legitimate institutional functions consistent with the Data Privacy Act of 2012 and other applicable laws and regulations.
Personal information may be processed for purposes that include, but are not limited to, the following:
The University processes personal information only to the extent necessary and proportionate to the declared and legitimate purposes for which such information was collected. Reasonable organizational, physical, and technical safeguards are implemented to ensure the confidentiality, integrity, availability, and security of personal information under its custody.
In certain instances, failure or refusal to provide the required personal information may affect the University’s ability to process applications, provide requested services, continue enrollment or employment, facilitate participation in specific programs or activities, or fulfill legal and contractual obligations.
The Admission and Marketing Services Office (“AMSO”) of BU is authorized to collect, process, use, store, reproduce, publish, and disseminate personal information for legitimate institutional marketing, admissions promotion, public relations, student engagement, branding, and communication purposes consistent with the University’s educational mission and institutional interests.
Personal information that may be processed by AMSO may include:
AMSO may collect, process, store, and publish personal information through official University communication and technology platforms, including but not limited to:
Personal information processed by AMSO may be used for purposes including but not limited to:
Where required by law or University policy, AMSO shall obtain the consent of the data subject prior to the collection or publication of personal information, photographs, audio recordings, or video recordings. For minors or dependent students, consent may be obtained from parents or legal guardians in accordance with applicable laws and regulations.
Participation in public University events, programs, ceremonies, and activities where photography, video recording, or media documentation is reasonably expected may constitute acknowledgment that the University may process and publish related images, recordings, or documentation for legitimate institutional purposes, subject to applicable laws and reasonable privacy safeguards.
The University recognizes that official content may be published or processed through third-party platforms such as social media networks, cloud-based services, learning management systems, and online collaboration tools. While the University implements reasonable safeguards and exercises due diligence in the selection and use of such platforms, the University cannot fully control the further sharing, reposting, or redistribution of publicly available content by third parties once published online.
AMSO and all authorized University personnel involved in marketing and communication activities shall ensure that:
4.B. Human Resources Management and Employment-Related Processing
BU through its Human Resources Office (“HR”), authorized officers, and designated personnel, collects, processes, stores, uses, shares, and retains personal information, sensitive personal information, and privileged information necessary for lawful and legitimate employment-related, administrative, operational, and institutional purposes.
This applies to various employment-related data subjects, including:
Types of Information Processed
The University may process personal information and sensitive personal information including, but not limited to:
The University may likewise process privileged or confidential information where authorized or required by law, contractual obligations, or legitimate institutional interests, subject to applicable confidentiality and security safeguards.
Purpose of Processing
Personal information may be processed for purposes including but not limited to:
Collection Methods and Platforms
The University may collect employment-related personal information through:
Sharing and Disclosure of Employment Information
Personal information may be disclosed to authorized persons or entities including:
The University shall ensure that disclosures are limited to legitimate and lawful purposes and are subject to appropriate confidentiality and security measures.
5. To Whom May the University Disclose Personal Information?
BU may disclose or share personal information, including sensitive personal information, to authorized individuals, offices, organizations, or entities when such disclosure is necessary, lawful, and consistent with the legitimate purposes for which the information was collected, as well as in compliance with the Data Privacy Act of 2012 and other applicable laws and regulations.
Depending on the nature of the relationship with the University, personal information of students, applicants, employees, faculty members, staff, alumni, visitors, contractors, service providers, and other persons or entities with juridical or official relations with the University may be disclosed to:
In certain cases, the University may transfer or disclose personal information to recipients located outside the Philippines, such as for international academic partnerships, exchange programs, cloud-based services, research collaborations, certifications, or other legitimate institutional purposes. Where cross-border transfer of personal information is necessary, the University shall take reasonable steps to ensure that appropriate safeguards, security measures, and data protection standards are implemented consistent with applicable data privacy laws and regulations.
The University likewise endeavors to ensure that third parties who receive or process personal information on its behalf observe confidentiality obligations and implement adequate organizational, physical, and technical measures to protect personal information against unauthorized access, disclosure, misuse, alteration, loss, or destruction.
5.A. Data Sharing
For purposes of administrative, operational, legal, academic, security, and institutional purposes,the University may enter into Data Sharing Agreements (“DSAs”), Data Processing Agreements (“DPAs”), service agreements, or similar contractual arrangements with authorized third parties, service providers, partner institutions, and government agencies that require access to or processing of personal information for legitimate and lawful purposes.
Personal information may be shared or disclosed, where necessary and proportionate, with:
· government agencies and regulatory authorities such as the Social Security System (SSS), Philippine Health Insurance Corporation (PhilHealth), Home Development Mutual Fund (Pag-IBIG Fund), Bureau of Internal Revenue (BIR), Department of Labor and Employment (DOLE), Department of Education (DepEd), Commission on Higher Education (CHED), and other public authorities;
· payroll processors, banks, healthcare providers, insurance providers, and employee benefits administrators;
· accreditation bodies, auditors, legal counsel, consultants, and compliance officers;
· information technology providers, cloud service providers, Human Resource Information Systems (HRIS), Learning Management Systems (LMS), email and collaboration platforms, and authorized digital service providers;
· partner institutions, training providers, research collaborators, and external organizations involved in official University programs and activities; and
· other entities authorized by law, contract, or with the consent of the data subject.
The University ensures that all data sharing and processing activities are governed by appropriate confidentiality obligations, security safeguards, contractual controls, and data protection measures to protect personal information against unauthorized access, disclosure, misuse, alteration, loss, or destruction, in accordance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission.
The University shall process and share personal information only for declared, specified, and legitimate purposes consistent with the principles of transparency, legitimate purpose, and proportionality under applicable data privacy laws and regulations.
6. How Long Does the University Retain Personal Information?
BU retains personal information only for as long as necessary to fulfill the purposes for which such information was collected and processed, including the performance of academic, administrative, operational, employment, research, security, legal, regulatory, and historical functions of the University.
Personal information relating to students, applicants, employees, faculty members, staff, contractual and project-based personnel, alumni, visitors, partner institutions, service providers, and other persons or entities with official or juridical relations with the University may be retained in accordance with applicable laws, government regulations, contractual obligations, institutional policies, records management standards, and legitimate University interests.
Certain records and documents may be retained for extended periods or indefinitely for legitimate academic, archival, historical, statistical, research, accreditation, alumni, or institutional purposes, subject to the implementation of appropriate safeguards and security measures.
Employment-related records shall be retained only for as long as necessary for lawful employment, operational, administrative, legal, tax, audit, historical, archival, or institutional purposes, in accordance with applicable laws, regulations, and records retention policies.
Where retention periods are prescribed by law, regulation, or official policy, the University shall securely dispose of, anonymize, archive, or delete personal information after the applicable retention period has expired and when such information is no longer necessary for lawful or legitimate purposes. Disposal or destruction of records shall be conducted in a manner that protects the confidentiality and privacy of the data subject and prevents unauthorized access, use, disclosure, or recovery of personal information.
7. How Does the University Protect and Secure Personal Information?
BU is committed to protecting the privacy, confidentiality, integrity, and security of personal information under its custody and control. The University implements reasonable and appropriate organizational, physical, and technical measures to safeguard personal information against unauthorized access, disclosure, misuse, alteration, destruction, loss, or any other unlawful processing, in accordance with the Data Privacy Act of 2012 and other applicable laws, regulations, and institutional policies.
All University personnel, including officials, faculty members, staff, contractual and project-based personnel, interns, consultants, and authorized third parties, are required to observe confidentiality obligations and uphold the privacy rights of students, applicants, employees, alumni, visitors, service providers, and other data subjects whose personal information is processed by the University. Access to personal information is restricted only to authorized individuals who require such access in the performance of their legitimate duties and responsibilities.
The University adopts and maintains appropriate security measures which may include, but are not limited to:
While the University continuously strives to maintain adequate safeguards to protect personal information, no method of transmission, storage, or electronic processing can be guaranteed to be completely secure. As such, data subjects are likewise encouraged to exercise reasonable care in protecting their personal information, account credentials, passwords, and devices when accessing University systems, online platforms, and digital services.
8. How Does the University Handle Data Breaches and Security Incidents?
BU recognizes the importance of promptly addressing data security incidents and personal data breaches to protect the rights and interests of its data subjects. The University is committed to complying with the requirements of the Data Privacy Act of 2012, its implementing rules and regulations, and applicable issuances of the National Privacy Commission concerning personal data breach management and notification.
Any actual, suspected, or potential data security incident or personal data breach that comes to the attention of the University shall be properly documented, investigated, assessed, and managed in accordance with established University policies, procedures, and applicable laws and regulations.
The University shall take all necessary, appropriate, and reasonable measures to contain, mitigate, and address the effects of any data security incident or personal data breach. Such measures may include restricting unauthorized access, securing affected systems, conducting investigations, restoring system integrity, strengthening security controls, and implementing corrective and preventive actions to minimize the risk of recurrence.
Where required by law or when there are reasonable grounds to believe that a personal data breach is likely to affect the rights, freedoms, or interests of data subjects, the University shall notify the appropriate regulatory authorities and the affected individuals within the periods and in the manner prescribed by applicable laws and regulations.
Notifications, when necessary, shall be made through appropriate and available communication channels and may include information regarding the nature of the incident, the personal information involved, measures undertaken by the University, and recommended actions that affected individuals may take to protect themselves.
The University likewise encourages all data subjects to immediately report any suspected unauthorized access, misuse, loss, or disclosure of personal information involving University systems, records, or services to the appropriate University office or designated Data Protection Officer.
9. What Are the Rights of Data Subjects Regarding their Personal Information?
Under the Data Privacy Act of 2012, all data subjects of BU are granted specific rights in relation to the personal information processed by the University.
Data subjects have the right to be informed about how their personal information is collected and processed, to access the personal data held by the University, and to request correction or rectification of any inaccurate, outdated, or incomplete information. They also have the right to object to the processing of their personal data, to withdraw consent where applicable, and to request the suspension, blocking, removal, or destruction of their personal information, subject to lawful grounds and applicable regulations.
The University recognizes the role of parents or legal guardians in the exercise of data privacy rights for students, particularly in basic education levels. As such, requests for consent, notices, and related communications concerning a student’s personal information are generally addressed to parents or guardians, and consent given by them is deemed as consent on behalf of the student. However, for higher education students who are of legal age, or in circumstances where appropriate, the University may allow students to independently exercise their data privacy rights, including giving or withholding consent and managing access to their personal information.
Requests for access, correction, or other rights may be made by submitting a formal written request to the appropriate University office, such as the concerned department head, College Dean, or University Registrar. The University may require the requesting party to verify their identity and provide sufficient details regarding the information being requested to ensure proper handling and protection of personal data.
The University may charge reasonable fees to cover administrative costs such as verifying identity, locating, retrieving, reviewing, and reproducing requested records, where applicable and permitted by law.
Access to personal information may be denied or restricted in certain circumstances, including but not limited to situations where disclosure would:
In cases where access is denied, the University shall inform the requesting party in writing of the reasons for such denial, in accordance with applicable laws, rules, and regulations.
10. Inquiries and Concerns
For any questions, clarifications, or further information regarding how Baliuag University (“BU” or the “University”) collects, processes, stores, discloses, or protects personal information of all its data subjects, data subjects may contact the University’s designated Data Protection Officer.
Data Protection Officer
Atty. Susan B. Jacinto
Legal Counsel / Data Protection Officer
Email: [email protected]
Office Address: 1069 Gil Carlos Street, Baliwag, Bulacan
Any concerns, inquiries, or complaints regarding possible violations of the Data Privacy Act of 2012 or the University’s Privacy Policy may be addressed to:
The University shall promptly review, investigate, and evaluate all received concerns or complaints in accordance with applicable laws, regulations, and internal policies. A response or formal decision shall be communicated to the concerned data subject within a reasonable period, depending on the nature and complexity of the inquiry or complaint.
Revised July 2026