Skip to content
PPAI-ETMSDeveloper Portal

Template pending LTFRB Legal review

This page is a draft template prepared to align PPAI-ETMS with the Data Privacy Act of 2012 (Republic Act No. 10173) and issuances of the National Privacy Commission (NPC). It has not been reviewed or approved by LTFRB Legal or LTFRB's Data Protection Officer, and must not be treated as a final, publishable privacy notice until they sign off and the placeholders below are filled in.

Privacy notice

Last reviewed: [LTFRB Legal to date-stamp on approval]

1. Who this notice covers

This notice describes how the Land Transportation Franchising and Regulatory Board (LTFRB) processes personal data within PPAI-ETMS (the Passenger Personal Accident Insurance Electronic Transmission and Monitoring System), covering:

2. What data is collected

PPAI-ETMS receives and stores, per transmitted certificate:

3. Purpose and legal basis

Personal data is processed to carry out LTFRB's regulatory mandate: registering and verifying Passenger Personal Accident Insurance coverage for public utility and for-hire vehicles, monitoring compliance, investigating flagged or disputed coverage, and producing regulatory reports. Processing is grounded in RA 10173 §12 (data subject consent obtained by the insurer at policy issuance; and processing necessary to comply with a legal obligation to which LTFRB is subject) and §13 for any sensitive personal information incidentally collected. [LTFRB Legal to confirm the precise legal-basis citations for each processing activity.]

4. Data sharing

Operator and vehicle data transmitted by an insurer is visible to: LTFRB staff (per role-based access), the transmitting organization, the issuing insurer, and — where applicable — the pool lead insurer or assigned management company. Operator personally identifiable information is masked by default in the LTFRB Admin portal and requires an explicit, reason-logged "Reveal" action to view in full; every reveal is written to the audit log. PPAI-ETMS does not sell, rent, or share personal data with any party outside this regulatory chain, except where required by law or a valid legal order. [LTFRB Legal to confirm any additional sharing arrangements, e.g. with LTO.]

5. Retention

Certificates, their version history, amendments, cancellations and audit log entries are retained indefinitely as the official electronic record of PPAI coverage — records are never deleted, only superseded or marked cancelled, consistent with LTFRB's regulatory record-keeping obligations. Database backups are retained per the disaster-recovery policy (see docs/deployment/disaster-recovery.md). [LTFRB Legal/Records Management to confirm the applicable retention schedule under the National Archives of the Philippines Act, if any.]

6. Security measures

Consistent with the design specification (§2.8, §4), PPAI-ETMS applies:

7. Data subject rights

Under RA 10173, data subjects may exercise the right to:

Because PPAI-ETMS is a business-to-government registry (operators do not hold accounts in it directly), operator data subjects should first raise requests with the insurer that transmitted their certificate; the insurer coordinates with LTFRB as needed. [LTFRB Legal to confirm the exact intake process and turnaround time for data subject requests.]

8. Contact

Questions about this notice or requests to exercise data subject rights may be directed to:

LTFRB Data Protection Officer
[Office address, email and phone to be published by LTFRB]

9. Changes to this notice

This notice will be updated as PPAI-ETMS evolves. Material changes will be dated and (where required) communicated to registered insurer organizations.