Baliuag University Privacy Policy

Baliuag University Privacy Policy

Baliuag University (“BU” or the “University”) recognizes and upholds the fundamental right of every individual to privacy and is committed to protecting personal information in compliance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, and other applicable issuances of the National Privacy Commission.

As part of its commitment to responsible and transparent data processing, the University adopts this Privacy Policy to guide the collection, use, storage, disclosure, retention, and protection of personal information of its various data subjects. These data subjects include, but are not limited to:

  • Students and applicants for admission;
  • Employees and applicants for employment, including faculty members, staff, contractual, and project-based personnel;
  • Former employees;
  • Alumni;
  • Visitors, guests and event participants;
  • Partner institutions;
  • Service providers; and
  • Other individuals or entities with juridical, contractual, academic, research, extension, or official relations with the University.

 

By submitting personal information to the University, accomplishing forms, accessing University systems, participating in university activities, or signing any applicable consent or data privacy forms, the data subject acknowledges that they have read, understood, and agreed to the terms of this Privacy Policy and consent to the processing of their personal information in accordance with applicable laws and University policies. For students who are minors, such consent may be given or assisted by their parent or legal guardian, where applicable.

This Privacy Policy shall be read together with all existing University rules, regulations, contracts, manuals, and policies that are not inconsistent with its provisions. Should any provision of this Privacy Policy be declared invalid or unenforceable by a competent authority or court, the remaining provisions shall continue to remain valid and enforceable.

The University reserves the right to review, amend, update, or modify this Privacy Policy from time to time to ensure compliance with applicable laws, regulatory requirements, operational changes, and institutional developments. Any revisions or updates shall take effect immediately upon publication through the University’s official website, portals, or other authorized communication channels.

1. What Personal Information Does the University Collect?

BU collects, processes, stores, and maintains personal information necessary for the performance of its academic, administrative, research, employment, contractual, security, and other legitimate institutional functions. The University may collect personal information before, during, and after an individual’s relationship with the University.

The personal information collected may include, but is not limited to:

  • Full name, age, date of birth, sex, civil status, nationality, and photograph;
  • Residential and mailing address;
  • Email address, telephone number, and other contact details;
  • Family background and emergency contact information;
  • Educational background, academic records, scholastic performance, certifications, licensure information, and disciplinary records;
  • Employment records, professional qualifications, work experience, payroll and benefits information, and performance evaluations;
  • Medical, health, wellness, and other sensitive personal information that may be necessary for lawful and legitimate purposes;
  • Information related to curricular, co-curricular, and extra-curricular activities, including student organization membership, leadership positions, competitions, outreach programs, internships, exchange programs, research activities, and seminars;
  • Information generated through the use of university facilities, systems, platforms, websites, learning management systems, libraries, and security systems, including closed-circuit television (CCTV) recordings and access logs; and
  • Other information necessary for the fulfillment of the University’s legal obligations, contractual commitments, institutional functions, and legitimate interests.

 

In certain circumstances, the University may also obtain personal information from third parties such as parents or guardians, previous schools, employers, government agencies, medical professionals, references, partner institutions, or other lawful sources. Such information shall be evaluated to determine whether its collection and processing are lawful, fair, and necessary. When retained, the information shall be afforded the same level of protection as personal information directly provided to the University. If the information is found to be unnecessary or improperly obtained, it shall be securely disposed of or deleted in accordance with applicable laws, regulations, and University policies.

2. How Does the University Collect Personal Information?

BU collects personal information through lawful, fair, and transparent means necessary for the fulfillment of its academic, administrative, operational, research, employment, security, and other legitimate institutional purposes.

The University generally collects personal information through various methods, including but not limited to:

  • Accomplished application forms, registration forms, contracts, surveys, and other official documents;
  • Face-to-face meetings, interviews, consultations, seminars, and university activities;
  • Telephone calls, emails, written correspondence, and other communication channels;
  • Online portals, websites, learning management systems, online educational platforms, mobile applications including admissions and marketing platforms, Google forms, online registration systems, multimedia submissions, and official social media engagement channels managed or authorized by the University.
  • Submission of documentary requirements, photographs, video recordings, audio recordings, digital files, and biometric information where permitted by law;
  • Security and monitoring systems, including CCTV cameras, visitor management systems, and access control mechanisms; and
  • Information obtained from third parties such as parents or guardians, previous schools, employers, government agencies, partner institutions, third party service providers, references, and lawful public sources, subject to applicable laws and regulations.

 

The University recognizes that the transmission and processing of information through the internet and electronic platforms involve certain inherent risks. Data subjects are encouraged to exercise caution and responsibility when providing or sharing personal information through email, websites, online services, educational platforms, social media platforms, chat systems, discussion boards, or similar digital environments.

When individuals access or use the University’s websites, online systems, learning platforms, or digital services, the University and its authorized third-party service providers may automatically collect certain technical and usage information generated by browsers, devices, or systems. Such information may include internet protocol (IP) addresses, browser type, device information, access logs, cookies, session information, and usage activity for security, analytics, system administration, and service improvement purposes.

Data subjects are responsible for maintaining the confidentiality and security of their usernames, passwords, authentication credentials, and other account-related information. The University likewise encourages all individuals to avoid unnecessarily disclosing personal or sensitive personal information through public or unsecured online channels.

3. Who May Access and Use Personal Information?

Personal information collected by BU may be accessed, processed, and used only by authorized university personnel, offices, departments, and duly authorized third parties who have a legitimate and lawful purpose in relation to the performance of their official, contractual, academic, administrative, operational, research, security, or legal functions.

Access to personal information shall be limited only to individuals who require such information in the fulfillment of their duties and responsibilities, and who are bound by obligations of confidentiality, data privacy, and information security.

Depending on the nature of the relationship with the University, personal information may be accessed and used by authorized personnel involved in:

  • Admission, enrollment, academic instruction, assessment, and student services;
  • Human resource management, recruitment, payroll administration, and employee relations;
  • Admission and Marketing Services personnel responsible for institutional communication, admissions promotion, public relations, multimedia production, and digital engagement activities.
  • Research, extension, community engagement, and institutional development activities;
  • Alumni relations, career services, and University events or programs;
  • Finance, accounting, procurement, legal, compliance, and audit functions;
  • Information technology, system administration, records management, and security operations; and
  • Other legitimate institutional functions consistent with applicable laws, regulations, and university policies.

 

The University may likewise share or disclose personal information to government agencies, accrediting bodies, partner institutions, service providers, contractors, or other third parties when such disclosure is authorized by law, necessary for the performance of contractual or institutional obligations, required for public authority functions, or made with the consent of the data subject, where applicable.

All persons and entities authorized to access personal information are expected to maintain the confidentiality, integrity, availability, and security of such information and to process the same only in accordance with the Data Privacy Act of 2012 and related University policies.

4. How Does the University Use Personal Information?

BU processes and uses personal information of its various data subjects to effectively carry out its academic, administrative, operational, research, employment, security, and other legitimate institutional functions consistent with the Data Privacy Act of 2012 and other applicable laws and regulations.

Personal information may be processed for purposes that include, but are not limited to, the following:

  • Evaluating and processing applications for admission, employment, scholarships, grants, research participation, and other University programs or services;
  • Facilitating enrollment, registration, hiring, accreditation, appointments, and other institutional transactions;
  • Establishing, maintaining, updating, and securing academic, employment, alumni, financial, health, administrative, and other official records;
  • Managing and evaluating academic performance, class participation, attendance, research outputs, co-curricular and extra-curricular involvement, employee performance, and institutional activities;
  • Administering learning management systems, information technology resources, online educational platforms, and other digital services;
  • Providing student support, employee support, health, counseling, library, sports, transportation, campus mobility, safety, security, and other related services;
  • Facilitating internships, exchange programs, on-the-job training, community engagement, research collaborations, and partnerships with external organizations or institutions;
  • Conducting investigations, disciplinary proceedings, grievance handling, compliance monitoring, risk management, and security operations;
  • Preparing statistical reports, institutional research, analytics, accreditation requirements, audits, and government compliance reports;
  • Maintaining directories, alumni relations, career placement services, and communication networks;
  • Disseminating official announcements, advisories, emergency notifications, and other institutional communications;
  • Producing publications, promotional materials, marketing campaigns, and documentation of university events and activities, subject to applicable laws and policies;
  • Soliciting participation in surveys, research studies, assessments, and non-commercial institutional initiatives;
  • Carrying out the day-to-day administration and operations of the University; and
  • Fulfilling contractual obligations, protecting lawful interests, and complying with legal, regulatory, and public authority requirements.

 

The University processes personal information only to the extent necessary and proportionate to the declared and legitimate purposes for which such information was collected. Reasonable organizational, physical, and technical safeguards are implemented to ensure the confidentiality, integrity, availability, and security of personal information under its custody.

In certain instances, failure or refusal to provide the required personal information may affect the University’s ability to process applications, provide requested services, continue enrollment or employment, facilitate participation in specific programs or activities, or fulfill legal and contractual obligations.

4.A. Admission and Marketing Services Office (AMSO) and Institutional Marketing Activities

The Admission and Marketing Services Office (“AMSO”) of BU is authorized to collect, process, use, store, reproduce, publish, and disseminate personal information for legitimate institutional marketing, admissions promotion, public relations, student engagement, branding, and communication purposes consistent with the University’s educational mission and institutional interests.

Personal Information Processed by AMSO

Personal information that may be processed by AMSO may include:

  • full name;
  • course, program, year level, position, or organizational affiliation;
  • photographs, digital images, video recordings, and audio recordings;
  • testimonials, interviews, achievements, and participation records;
  • event attendance and activity documentation;
  • submitted materials through online forms and digital platforms; and
  • other information voluntarily provided or lawfully collected in connection with University marketing, communication, promotional, recruitment, or documentation activities.

Platforms and Channels for Processing and Publication

AMSO may collect, process, store, and publish personal information through official University communication and technology platforms, including but not limited to:

  • the official BU website;
  • Learning Management Systems (LMS);
  • online admissions and registration platforms;
  • Google Forms and other cloud-based or web-based data collection tools authorized by the University;
  • official University social media accounts and online communities;
  • digital learning and collaboration platforms;
  • institutional publications, newsletters, brochures, promotional materials, and reports; and
  • multimedia presentations, livestreams, recordings, and other audio-visual communication materials.

Purpose of Processing

Personal information processed by AMSO may be used for purposes including but not limited to:

  • admissions promotion and student recruitment;
  • dissemination of official announcements and institutional information;
  • promotion of academic programs, University services, achievements, and events;
  • documentation and archival of University activities;
  • publication of institutional accomplishments, recognitions, and success stories;
  • production of promotional, informational, and educational materials;
  • strengthening alumni, stakeholder, and community engagement; and
  • other lawful and legitimate institutional communication and marketing activities.

Consent and Notice

Where required by law or University policy, AMSO shall obtain the consent of the data subject prior to the collection or publication of personal information, photographs, audio recordings, or video recordings. For minors or dependent students, consent may be obtained from parents or legal guardians in accordance with applicable laws and regulations.

Participation in public University events, programs, ceremonies, and activities where photography, video recording, or media documentation is reasonably expected may constitute acknowledgment that the University may process and publish related images, recordings, or documentation for legitimate institutional purposes, subject to applicable laws and reasonable privacy safeguards.

Third-Party Platforms and Online Services

The University recognizes that official content may be published or processed through third-party platforms such as social media networks, cloud-based services, learning management systems, and online collaboration tools. While the University implements reasonable safeguards and exercises due diligence in the selection and use of such platforms, the University cannot fully control the further sharing, reposting, or redistribution of publicly available content by third parties once published online.

Safeguards and Responsible Use

AMSO and all authorized University personnel involved in marketing and communication activities shall ensure that:

  • personal information is processed lawfully, fairly, and transparently;
  • only appropriate and relevant information is published;
  • sensitive personal information is not disclosed without lawful basis or explicit consent where required;
  • reasonable organizational, physical, and technical safeguards are implemented; and
  • the dignity, privacy, safety, and rights of data subjects are respected at all times.

4.B. Human Resources Management and Employment-Related Processing

BU through its Human Resources Office (“HR”), authorized officers, and designated personnel, collects, processes, stores, uses, shares, and retains personal information, sensitive personal information, and privileged information necessary for lawful and legitimate employment-related, administrative, operational, and institutional purposes.

This applies to various employment-related data subjects, including:

  • applicants for employment;
  • newly hired employees;
  • regular employees;
  • probationary employees;
  • faculty members;
  • administrative staff;
  • contractual, project-based, part-time, and temporary personnel;
  • interns, trainees, and consultants; and
  • former or separated employees.

Types of Information Processed

The University may process personal information and sensitive personal information including, but not limited to:

  • full name, age, sex, civil status, nationality, and date of birth;
  • residential and contact information;
  • educational background, transcripts, certifications, licenses, and eligibility records;
  • employment history, work experience, references, and professional qualifications;
  • government-issued identification numbers and records;
  • payroll, compensation, benefits, taxation, and banking information;
  • attendance, leave, performance evaluation, training, promotion, disciplinary, and administrative records;
  • medical, health, wellness, disability, and insurance-related information;
  • biometric data, photographs, CCTV recordings, audio and video recordings;
  • emergency contact and dependent information;
  • background verification and character reference information; and
  • other information necessary for recruitment, employment administration, legal compliance, safety, security, and institutional operations.

The University may likewise process privileged or confidential information where authorized or required by law, contractual obligations, or legitimate institutional interests, subject to applicable confidentiality and security safeguards.

Purpose of Processing

Personal information may be processed for purposes including but not limited to:

  • evaluation and processing of employment applications;
  • recruitment, screening, interviews, examinations, and background verification;
  • hiring, onboarding, appointment, deployment, and employment administration;
  • payroll processing, compensation, benefits administration, and taxation;
  • attendance monitoring, scheduling, and workforce management;
  • performance evaluation, promotion, training, professional development, and career advancement;
  • administration of employee relations, disciplinary proceedings, grievance handling, and investigations;
  • health, safety, wellness, insurance, and occupational compliance programs;
  • maintenance of employment records and institutional directories;
  • communication of official announcements, advisories, and University-related activities;
  • compliance with labor laws, government regulations, accreditation requirements, and legal obligations;
  • implementation of security, access control, and information technology measures;
  • institutional planning, reporting, analytics, and research; and
  • other lawful and legitimate purposes related to employment and University operations.

Collection Methods and Platforms

The University may collect employment-related personal information through:

  • application forms and employment documents;
  • interviews, examinations, and recruitment activities;
  • online recruitment systems and employment portals;
  • email communications and digital submissions;
  • Human Resource Information Systems (HRIS);
  • Learning Management Systems (LMS) for Teaching Personnel;
  • Google Forms and authorized online forms;
  • biometric and attendance systems;
  • CCTV and security monitoring systems;
  • internal communication and collaboration platforms; and
  • third-party references, government agencies, educational institutions, and lawful external sources.

Sharing and Disclosure of Employment Information

Personal information may be disclosed to authorized persons or entities including:

  • government agencies and regulatory authorities;
  • payroll providers, insurance companies, healthcare providers, and financial institutions;
  • accreditation bodies and partner institutions;
  • external auditors, legal counsel, and service providers;
  • information technology and cloud service providers;
  • authorized University officials and departments; and
  • other parties authorized by law, contract, or the consent of the data subject.

The University shall ensure that disclosures are limited to legitimate and lawful purposes and are subject to appropriate confidentiality and security measures.

5. To Whom May the University Disclose Personal Information?

BU may disclose or share personal information, including sensitive personal information, to authorized individuals, offices, organizations, or entities when such disclosure is necessary, lawful, and consistent with the legitimate purposes for which the information was collected, as well as in compliance with the Data Privacy Act of 2012 and other applicable laws and regulations.

Depending on the nature of the relationship with the University, personal information of students, applicants, employees, faculty members, staff, alumni, visitors, contractors, service providers, and other persons or entities with juridical or official relations with the University may be disclosed to:

  • Authorized university officials and departments;
  • Government agencies, regulatory bodies, accrediting institutions, and public authorities when required or authorized by law, regulation, legal process, or official directive;
  • Educational institutions, partner universities, training institutions, and research organizations for academic collaborations, exchange programs, internships, certifications, articulation agreements, or related institutional activities;
  • Medical professionals, healthcare providers, counselors, psychologists, insurers, and emergency responders for health, wellness, safety, insurance, or emergency-related purposes;
  • Third-party service providers, suppliers, contractors, consultants, auditors, legal advisers, and other entities engaged by the University to support its academic, administrative, operational, technological, security, financial, or institutional functions;
  • Parents, legal guardians, next of kin, authorized representatives, or lawful heirs, when appropriate and permitted by law;
  • Alumni associations, foundations, partner organizations, sponsors, and fundraising or development entities affiliated with or supporting the University;
  • Providers of information technology services, cloud storage, communication platforms, learning management systems, and other digital or electronic systems utilized by the University;
  • Organizers, coordinators, and partners involved in university-sponsored programs, events, competitions, outreach activities, and research initiatives;
  • Social Media platforms, digital communication providers, livestreaming services, and multimedia distribution platforms utilized for official University communication and marketing purposes;
  • Financial institutions, payment processors, scholarship providers, and entities involved in grants, sponsorships, payroll, or financial assistance programs; and
  • Other persons or entities to whom the data subject has given consent or where disclosure is otherwise authorized or permitted under applicable laws and regulations.

 

In certain cases, the University may transfer or disclose personal information to recipients located outside the Philippines, such as for international academic partnerships, exchange programs, cloud-based services, research collaborations, certifications, or other legitimate institutional purposes. Where cross-border transfer of personal information is necessary, the University shall take reasonable steps to ensure that appropriate safeguards, security measures, and data protection standards are implemented consistent with applicable data privacy laws and regulations.

The University likewise endeavors to ensure that third parties who receive or process personal information on its behalf observe confidentiality obligations and implement adequate organizational, physical, and technical measures to protect personal information against unauthorized access, disclosure, misuse, alteration, loss, or destruction.

5.A. Data Sharing

For purposes of administrative, operational, legal, academic, security, and institutional purposes,the University may enter into Data Sharing Agreements (“DSAs”), Data Processing Agreements (“DPAs”), service agreements, or similar contractual arrangements with authorized third parties, service providers, partner institutions, and government agencies that require access to or processing of personal information for legitimate and lawful purposes.

Personal information may be shared or disclosed, where necessary and proportionate, with:

·         government agencies and regulatory authorities such as the Social Security System (SSS), Philippine Health Insurance Corporation (PhilHealth), Home Development Mutual Fund (Pag-IBIG Fund), Bureau of Internal Revenue (BIR), Department of Labor and Employment (DOLE), Department of Education (DepEd), Commission on Higher Education (CHED), and other public authorities;

·         payroll processors, banks, healthcare providers, insurance providers, and employee benefits administrators;

·         accreditation bodies, auditors, legal counsel, consultants, and compliance officers;

·         information technology providers, cloud service providers, Human Resource Information Systems (HRIS), Learning Management Systems (LMS), email and collaboration platforms, and authorized digital service providers;

·         partner institutions, training providers, research collaborators, and external organizations involved in official University programs and activities; and

·         other entities authorized by law, contract, or with the consent of the data subject.

The University ensures that all data sharing and processing activities are governed by appropriate confidentiality obligations, security safeguards, contractual controls, and data protection measures to protect personal information against unauthorized access, disclosure, misuse, alteration, loss, or destruction, in accordance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission.

The University shall process and share personal information only for declared, specified, and legitimate purposes consistent with the principles of transparency, legitimate purpose, and proportionality under applicable data privacy laws and regulations.

6. How Long Does the University Retain Personal Information?

BU retains personal information only for as long as necessary to fulfill the purposes for which such information was collected and processed, including the performance of academic, administrative, operational, employment, research, security, legal, regulatory, and historical functions of the University.

Personal information relating to students, applicants, employees, faculty members, staff, contractual and project-based personnel, alumni, visitors, partner institutions, service providers, and other persons or entities with official or juridical relations with the University may be retained in accordance with applicable laws, government regulations, contractual obligations, institutional policies, records management standards, and legitimate University interests.

Certain records and documents may be retained for extended periods or indefinitely for legitimate academic, archival, historical, statistical, research, accreditation, alumni, or institutional purposes, subject to the implementation of appropriate safeguards and security measures.

Employment-related records shall be retained only for as long as necessary for lawful employment, operational, administrative, legal, tax, audit, historical, archival, or institutional purposes, in accordance with applicable laws, regulations, and records retention policies.

Where retention periods are prescribed by law, regulation, or official policy, the University shall securely dispose of, anonymize, archive, or delete personal information after the applicable retention period has expired and when such information is no longer necessary for lawful or legitimate purposes. Disposal or destruction of records shall be conducted in a manner that protects the confidentiality and privacy of the data subject and prevents unauthorized access, use, disclosure, or recovery of personal information.

7. How Does the University Protect and Secure Personal Information?

BU is committed to protecting the privacy, confidentiality, integrity, and security of personal information under its custody and control. The University implements reasonable and appropriate organizational, physical, and technical measures to safeguard personal information against unauthorized access, disclosure, misuse, alteration, destruction, loss, or any other unlawful processing, in accordance with the Data Privacy Act of 2012 and other applicable laws, regulations, and institutional policies.

All University personnel, including officials, faculty members, staff, contractual and project-based personnel, interns, consultants, and authorized third parties, are required to observe confidentiality obligations and uphold the privacy rights of students, applicants, employees, alumni, visitors, service providers, and other data subjects whose personal information is processed by the University. Access to personal information is restricted only to authorized individuals who require such access in the performance of their legitimate duties and responsibilities.

The University adopts and maintains appropriate security measures which may include, but are not limited to:

  • Secure storage and controlled access to physical records and documents;
  • Password protection, user authentication, and role-based access controls for electronic systems and databases;
  • Encryption, firewalls, antivirus software, monitoring systems, and other cybersecurity measures for digital information and networks;
  • Data privacy and information security policies, protocols, and training programs for university personnel;
  • Security monitoring systems, including closed-circuit television (CCTV and access control mechanisms where appropriate;
  • Procedures for secure transmission, retention, backup, recovery, disposal, and destruction of records and data; and
  • Regular assessment, review, and enhancement of security practices and data protection measures.

 

While the University continuously strives to maintain adequate safeguards to protect personal information, no method of transmission, storage, or electronic processing can be guaranteed to be completely secure. As such, data subjects are likewise encouraged to exercise reasonable care in protecting their personal information, account credentials, passwords, and devices when accessing University systems, online platforms, and digital services.

8. How Does the University Handle Data Breaches and Security Incidents?

BU recognizes the importance of promptly addressing data security incidents and personal data breaches to protect the rights and interests of its data subjects. The University is committed to complying with the requirements of the Data Privacy Act of 2012, its implementing rules and regulations, and applicable issuances of the National Privacy Commission concerning personal data breach management and notification.

Any actual, suspected, or potential data security incident or personal data breach that comes to the attention of the University shall be properly documented, investigated, assessed, and managed in accordance with established University policies, procedures, and applicable laws and regulations.

The University shall take all necessary, appropriate, and reasonable measures to contain, mitigate, and address the effects of any data security incident or personal data breach. Such measures may include restricting unauthorized access, securing affected systems, conducting investigations, restoring system integrity, strengthening security controls, and implementing corrective and preventive actions to minimize the risk of recurrence.

Where required by law or when there are reasonable grounds to believe that a personal data breach is likely to affect the rights, freedoms, or interests of data subjects, the University shall notify the appropriate regulatory authorities and the affected individuals within the periods and in the manner prescribed by applicable laws and regulations.

Notifications, when necessary, shall be made through appropriate and available communication channels and may include information regarding the nature of the incident, the personal information involved, measures undertaken by the University, and recommended actions that affected individuals may take to protect themselves.

The University likewise encourages all data subjects to immediately report any suspected unauthorized access, misuse, loss, or disclosure of personal information involving University systems, records, or services to the appropriate University office or designated Data Protection Officer.

9. What Are the Rights of Data Subjects Regarding their Personal Information?

Under the Data Privacy Act of 2012, all data subjects of BU are granted specific rights in relation to the personal information processed by the University.

Data subjects have the right to be informed about how their personal information is collected and processed, to access the personal data held by the University, and to request correction or rectification of any inaccurate, outdated, or incomplete information. They also have the right to object to the processing of their personal data, to withdraw consent where applicable, and to request the suspension, blocking, removal, or destruction of their personal information, subject to lawful grounds and applicable regulations.

The University recognizes the role of parents or legal guardians in the exercise of data privacy rights for students, particularly in basic education levels. As such, requests for consent, notices, and related communications concerning a student’s personal information are generally addressed to parents or guardians, and consent given by them is deemed as consent on behalf of the student. However, for higher education students who are of legal age, or in circumstances where appropriate, the University may allow students to independently exercise their data privacy rights, including giving or withholding consent and managing access to their personal information.

Requests for access, correction, or other rights may be made by submitting a formal written request to the appropriate University office, such as the concerned department head, College Dean, or University Registrar. The University may require the requesting party to verify their identity and provide sufficient details regarding the information being requested to ensure proper handling and protection of personal data.

The University may charge reasonable fees to cover administrative costs such as verifying identity, locating, retrieving, reviewing, and reproducing requested records, where applicable and permitted by law.

Access to personal information may be denied or restricted in certain circumstances, including but not limited to situations where disclosure would:

  • violate the privacy rights of other individuals;
  • compromise security, safety, or the University’s duty of care;
  • conflict with legal, regulatory, or contractual obligations; or
  • fall under exemptions provided under applicable data privacy laws.

 

In cases where access is denied, the University shall inform the requesting party in writing of the reasons for such denial, in accordance with applicable laws, rules, and regulations.

10. Inquiries and Concerns

For any questions, clarifications, or further information regarding how Baliuag University (“BU” or the “University”) collects, processes, stores, discloses, or protects personal information of all its data subjects,  data subjects may contact the University’s designated Data Protection Officer.

 
   

Data Protection Officer
Atty. Susan B. Jacinto
Legal Counsel / Data Protection Officer
Email:
[email protected]
Office Address: 1069 Gil Carlos Street, Baliwag, Bulacan


Any concerns, inquiries, or complaints regarding possible violations of the Data Privacy Act of 2012 or the University’s Privacy Policy may be addressed to:

 

The University shall promptly review, investigate, and evaluate all received concerns or complaints in accordance with applicable laws, regulations, and internal policies. A response or formal decision shall be communicated to the concerned data subject within a reasonable period, depending on the nature and complexity of the inquiry or complaint.

Revised July 2026