Template pending LTFRB Legal review
Privacy notice
Last reviewed: [LTFRB Legal to date-stamp on approval]
1. Who this notice covers
This notice describes how the Land Transportation Franchising and Regulatory Board (LTFRB) processes personal data within PPAI-ETMS (the Passenger Personal Accident Insurance Electronic Transmission and Monitoring System), covering:
- Vehicle operators whose Passenger Personal Accident Insurance (PPAI) certificates are transmitted to LTFRB by accredited insurers, pools and management companies via the machine API.
- Users of the LTFRB Admin portal (LTFRB personnel only — insurers have no web portal or human logins; they integrate solely via machine API credentials issued by LTFRB).
- Technical contacts registered against machine API clients.
2. What data is collected
PPAI-ETMS receives and stores, per transmitted certificate:
- Operator data: name, business name, Tax Identification Number (TIN), address, contact email and phone, case/CPC/franchise numbers.
- Vehicle data: plate number, MV file number, engine number, chassis number, VIN, make/model/series, year, type, denomination, passenger capacity, region/province/route.
- Policy and certificate data: policy number, coverage type, premium amount, official receipt number, certificate of cover (COC) number, effective/expiration dates.
- LTFRB Admin account data: name, email, role, and multi-factor authentication enrollment status for LTFRB users (passwords are never stored in plain text; TOTP secrets and other sensitive fields are encrypted at rest).
- System & audit data: IP addresses of API clients (for allowlisting and abuse detection) and login/audit trail entries.
3. Purpose and legal basis
Personal data is processed to carry out LTFRB's regulatory mandate: registering and verifying Passenger Personal Accident Insurance coverage for public utility and for-hire vehicles, monitoring compliance, investigating flagged or disputed coverage, and producing regulatory reports. Processing is grounded in RA 10173 §12 (data subject consent obtained by the insurer at policy issuance; and processing necessary to comply with a legal obligation to which LTFRB is subject) and §13 for any sensitive personal information incidentally collected. [LTFRB Legal to confirm the precise legal-basis citations for each processing activity.]
4. Data sharing
Operator and vehicle data transmitted by an insurer is visible to: LTFRB staff (per role-based access), the transmitting organization, the issuing insurer, and — where applicable — the pool lead insurer or assigned management company. Operator personally identifiable information is masked by default in the LTFRB Admin portal and requires an explicit, reason-logged "Reveal" action to view in full; every reveal is written to the audit log. PPAI-ETMS does not sell, rent, or share personal data with any party outside this regulatory chain, except where required by law or a valid legal order. [LTFRB Legal to confirm any additional sharing arrangements, e.g. with LTO.]
5. Retention
Certificates, their version history, amendments, cancellations and audit log entries are retained indefinitely as the official electronic record of PPAI coverage — records are never deleted, only superseded or marked cancelled, consistent with LTFRB's regulatory record-keeping obligations. Database backups are retained per the disaster-recovery policy (see docs/deployment/disaster-recovery.md). [LTFRB Legal/Records Management to confirm the applicable retention schedule under the National Archives of the Philippines Act, if any.]
6. Security measures
Consistent with the design specification (§2.8, §4), PPAI-ETMS applies:
- Encryption in transit (TLS 1.2+ at the load balancer) and at rest (KMS-encrypted database and object storage; sensitive fields such as TIN additionally encrypted at the application layer).
- Argon2id password hashing and mandatory TOTP multi-factor authentication for all human users.
- Role-based access control, masked PII by default with logged reveal actions, and an append-only, hash-chained audit log covering reads and writes alike.
- Machine-to-machine authentication via OAuth2 client credentials, HMAC-signed requests, IP allowlisting and per-client rate limiting.
- Network controls (VPC segmentation, a Web Application Firewall, security groups) and continuous vulnerability scanning in production.
7. Data subject rights
Under RA 10173, data subjects may exercise the right to:
- Be informed that their personal data is being processed;
- Access their personal data held in the system;
- Object to processing, and request correction of inaccurate data;
- Request erasure or blocking, subject to LTFRB's legal and regulatory retention obligations described above;
- Lodge a complaint with the National Privacy Commission.
Because PPAI-ETMS is a business-to-government registry (operators do not hold accounts in it directly), operator data subjects should first raise requests with the insurer that transmitted their certificate; the insurer coordinates with LTFRB as needed. [LTFRB Legal to confirm the exact intake process and turnaround time for data subject requests.]
8. Contact
Questions about this notice or requests to exercise data subject rights may be directed to:
LTFRB Data Protection Officer
[Office address, email and phone to be published by LTFRB]
9. Changes to this notice
This notice will be updated as PPAI-ETMS evolves. Material changes will be dated and (where required) communicated to registered insurer organizations.