RA 10173 Compliance: Data Privacy Act
How DentalView helps your clinic comply with the Philippine Data Privacy Act of 2012 (RA 10173) and NPC guidelines.
What the Law Actually Asks of You
The Data Privacy Act of 2012 (RA 10173) makes your clinic a personal information controller for patient data — and dental records are sensitive personal information, which raises the bar. In practice the law asks five things: collect consent, limit access to what each person needs, be able to show who accessed what, honor deletion, and handle breaches responsibly. Here is how each maps to something concrete in DentalView — and what remains yours to do.
Consent (Sections 12–13)
Processing sensitive personal information needs consent, and consent you can prove. Both registration paths capture it — the front-desk form's pre-ticked consent checkboxes (treatment records, SMS notifications, data processing) and the QR self-intake flow, which adds the patient's finger-drawn signature. Everything lands in the profile's Data Consent card with status, method, date, and IP address.

Withdrawal is honored mechanically, too: a patient who replies STOP to any SMS is blocked from all future messages automatically, and the opt-out is logged with its source.
Proportional Access (Section 11)
The law expects access limited to legitimate purpose. DentalView's role system is that principle running as software: Front Desk sees no financial data, assistants see queue-level information, students in teaching clinics see only their assigned patients — enforced server-side, adjustable per role in Settings > Roles. Deactivating a staff member removes their access instantly, which is the enforcement moment that matters most in practice.
Accountability (Section 21)
When the National Privacy Commission asks "who accessed this record?", the Audit Log is your answer: every create, read, update, delete, and export of patient data, recorded with actor, timestamp, device, and IP, filterable per patient, and not editable from the app by anyone. Accountability without logs is a promise; with them it's a report you can print.
Retention and Erasure (Section 11c)
Data kept only as long as necessary, and erasure honored: archived patients anonymize automatically after 30 days — identity removed permanently, de-identified clinical statistics retained. The predictable schedule is the compliance feature: you can tell a patient exactly when they will be forgotten, and the system keeps that promise without anyone remembering to.
What Stays on Your Plate
The software covers mechanics; four obligations remain human:
- NPC registration — clinics processing sensitive personal information at scale may need to register with the National Privacy Commission and designate a Data Protection Officer (in a small practice, typically the owner-dentist). Check the current thresholds on the NPC's site.
- Breach response — RA 10173 expects notification of qualifying breaches within 72 hours. Know the rule before you need it.
- Staff discipline — individual logins, no password sharing, lock screens. The audit log identifies people, not shared accounts.
- Physical paper — the law covers the folder on the desk as much as the database; your paper handling should match your digital hygiene.
Saying It to Patients
When a patient asks about their data, the honest script writes itself: consent captured and shown on request; access limited by role and logged; deletion honored on a 30-day anonymization schedule; payments tokenized so the clinic never holds card numbers. Most practices can't say those four sentences truthfully. Yours can.
Was this article helpful?
Need more help? Contact our support team