ScreenJournal

Philippines — Data Privacy Act and RA 4200

Version 2.0 · Effective 5 October 2026

This page explains how ScreenJournal, operated by Cyberinfra Limited (Isle of Man) ("we", "us"), and the employers who use it handle personal data under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173, the "DPA") and its Implementing Rules and Regulations, and how the Anti-Wiretapping Act (Republic Act No. 4200, "RA 4200") bears on audio. It is written for our customers, for the people whose work activity they monitor, and for people who take part in calls with them.

This is a plain-language explainer and is not legal advice. Our Privacy Policy describes in full what we collect and why; this page adds what is specific to Philippine law.

1. Scope

The DPA applies to the processing of personal information of people in the Philippines, including by organisations outside the Philippines that process it in connection with the country. It is administered by the National Privacy Commission (the "NPC"), whose circulars, advisories and advisory opinions explain how it applies. RA 4200 is a separate criminal statute about recording private communications. It applies to audio in addition to the DPA, and compliance with one does not satisfy the other.

2. Who plays which role

  • Your employer is the Personal Information Controller ("PIC") for the monitoring of your work. It decides whether to use ScreenJournal, which features to turn on, what to monitor and why, and what to do with the results. It is accountable to you and to the NPC.
  • Cyberinfra Limited is a Personal Information Processor ("PIP"). We process monitoring data on the employer's behalf, under contract and on its instructions. We do not use monitoring data for our own purposes, and we do not use it to train AI models.
  • We are a PIC only for the data we control directly, such as customer account, billing, sign-in security and website data, as described in our Privacy Policy.

Data Protection Officer. Our Data Protection Officer is a role, not yet a named individual. Until an officer is appointed, the role is reached through support@screenjournal.ai with the subject line "Data protection request". See our Data Protection Contacts page. Your employer, as PIC, needs its own Data Protection Officer.

NPC registration is each customer's own assessment, made on its own headcount, data and processing (see section 7).

3. What the product does

The ScreenJournal desktop app runs on Windows and macOS and is visible in the menu bar or system tray while it runs. While tracking is on it records each connected display as short video segments, by default at one frame per second. The app paints the cursor position and clicks into the recording as markers. Applications and sites on the organisation's exclusion list are not captured. The app also records application names, window titles, browser addresses, and presence and idle signals.

  • Default mode. Screen video is uploaded for analysis and deleted after analysis; any temporary copy is removed by a storage lifecycle rule we configure on the bucket. The desktop app keeps its own copies on the member's device for the period the organisation sets, up to three months.
  • Record + Save (employer-elected). If the organisation enables it, screen video is stored on our servers so managers can play it back.
  • Alert evidence clips (employer-elected). Where the organisation's alert rules call for it, a short clip is kept as evidence for a flagged event.
  • Audio is off by default (see section 9).
  • Connected AI tools. If the organisation connects its own AI tool through our integration feature, that tool can read the organisation's data within the connecting user's permissions.
  • Sign-in region. At desktop sign-in we derive a country or region from the network address, using a local database, and store it on the user record.

At every desktop sign-in the app shows a notice that it may record the screen and, where the organisation turns it on, meeting audio. That acknowledgment is not yet recorded.

4. Lawful basis and proportionality

We summarise the NPC instruments below as we understand them from published summaries, as at October 2026; check the current texts at privacy.gov.ph.

Processing must have a lawful basis and must respect the DPA's principles of transparency, legitimate purpose and proportionality. For ordinary personal information, the bases most relevant to monitoring are the employment contract (section 12(b)) and the employer's legitimate interests (section 12(f)). Screen content can include sensitive personal information, such as health or government identifiers, for which section 13 sets narrower conditions. Choosing and documenting the basis is the employer's decision as PIC.

The NPC's guidance on monitoring is relevant:

  • Advisory Opinion No. 2024-003 considered monitoring software on work devices and said such collection under a company policy may be permissible under section 12(b) or 12(f), provided the method of monitoring relates directly to the legitimate interest pursued.
  • Advisory Opinion No. 2024-005 considered AI that scores and ranks call-centre agents and said automated scoring to evaluate performance can be a legitimate interest, still bound by proportionality and transparency.
  • Advisory Opinion No. 2018-084 described software that records keystrokes or takes random screenshots as excessive and disproportionate.

ScreenJournal does not log keystrokes. While tracking is on, it records the screen continuously as short video segments (section 3). As we understand the NPC's guidance, a monitoring method must relate directly to the legitimate interest pursued and must not be excessive for the employer's declared purpose. Assessing and documenting that proportionality for its own deployment is the employer's duty as PIC; the exclusion list, and leaving Record + Save and audio off, narrow what is captured. Consent given as a condition of employment may not be freely given, so employers should not rely on it alone. This is not legal advice.

5. AI systems and NPC Advisory 2024-04

NPC Advisory No. 2024-04 (19 December 2024), as summarised, explains how the DPA applies to AI systems that process personal data. As we understand it, it applies to both PICs and PIPs and expects transparency about the AI's nature, purpose and risks, a privacy impact assessment, meaningful human intervention, and a way for people to question and contest automated outputs. Here is what the service does:

The service draws five kinds of automated inference about the people it monitors:

  1. an activity score from 1 to 5 for each recorded segment of screen activity;
  2. a productivity percentage, measured against the working day;
  3. a position in a weekly ranking of the organisation's members;
  4. flags that activity may be simulated, for example by a mouse-jiggling device;
  5. matches against alert rules written by the organisation.

Segment scores and descriptions are produced by a Google Gemini model accessed through Google Vertex AI, and alert evaluations by a Google Gemini model accessed through Google's Gemini API, from screen content and activity signals such as presence and idle time. The productivity percentage and the weekly ranking are calculated from those scores. Simulated-activity flags come from the same model reviewing the segment's screen recording, on which the desktop app marks the cursor position and clicks; fixed checks in our code then discount the device's own idle periods and apply minimum thresholds before a flag is set. These outputs are probabilistic. They can be wrong, and they describe what was on screen, not the quality or value of anyone's work.

ScreenJournal makes no employment decision. Any decision about a person, whether on pay, performance, discipline or anything else, is made by your employer's managers, who are responsible for it.

The following human-review surfaces exist today:

  • the Review page, where managers can examine flagged segments, and the alerts inbox, where a manager approves or rejects a member's explanation;
  • corrections, where the organisation's administrators change a segment's score;
  • Add a reason, where a member, or a manager on the member's timeline, explains a paused, offline or away stretch (when the organisation's policy allows manual entries);
  • the member's own Activity timeline, which shows their segments, descriptions and scores.

If you disagree with a score, flag or ranking, ask your employer first. Your employer can correct the record or redact a time range. If your employer does not respond, contact support@screenjournal.ai.

A flag that activity may be simulated is an indicator that calls for human judgement. It is never proof of misconduct, and it should not be relied on without a person reviewing the underlying activity.

What we provide. These pages and our Privacy Policy describe the AI in the service; the human-review surfaces listed above let managers check and correct outputs; and a person who disagrees can contest an output through their employer and, failing that, through support@screenjournal.ai. We will give a customer the processing facts it needs for its own assessment.

What the customer must do. Carry out a privacy impact assessment for its own deployment; ensure a qualified person reviews outputs before relying on them for any decision about someone; tell its people how the AI is used; and run a grievance channel through which they can challenge a score, flag or ranking.

6. Your rights

Sections 16 to 18 of the DPA give data subjects the right:

  • to be informed that their personal information is being processed, and how;
  • to object to processing, including profiling;
  • to access their personal information and how it has been processed;
  • to rectification of inaccurate or incomplete data;
  • to erasure or blocking, where the DPA allows;
  • to damages for harm caused by inaccurate, unlawfully obtained or unauthorised use of their data;
  • to data portability, a copy in a commonly used electronic format;
  • to complain to the NPC (privacy.gov.ph); and
  • for heirs and assigns to exercise these rights after the data subject's death or incapacity.

Your employer is the PIC, so raise requests about monitoring data with your employer first. If you write to us, we pass the request to your employer and help it respond.

How requests are fulfilled today. We honour access, correction, erasure and portability requests manually, on a verified request; there is no self-service export. Where your employer has enabled it, you can redact a time range from your own timeline; a redaction removes the activity data for that range, including any Record + Save video. Alert evidence clips are not removed by a member's redaction request. An objection to monitoring or profiling is decided by your employer, which controls whether and how you are monitored.

7. NPC registration

NPC Circular No. 2022-04, effective 11 January 2023 as summarised, superseded Circular No. 17-01. As we understand it, it makes registration of data processing systems mandatory for a PIC or PIP that:

  • employs 250 or more people;
  • processes sensitive personal information of 1,000 or more individuals; or
  • processes personal information in a way likely to pose a risk to the rights and freedoms of data subjects.

As summarised, the Circular also says that a data processing system involving automated decision-making or profiling must be registered in all instances. ScreenJournal's scoring, weekly rankings and simulated-activity flags are profiling in that sense, so a deployment likely brings a customer within mandatory registration regardless of its size; confirm with the NPC or counsel.

Registration is the customer's duty as PIC. We cannot decide it or register on a customer's behalf.

8. Breach notification

Under NPC Circular No. 16-03, as we understand it from published summaries, a personal data breach must be notified to the NPC within 72 hours of knowledge or reasonable belief that it occurred, and to affected data subjects within the same period, where it involves sensitive personal information or information that could enable identity fraud and there is a real risk of serious harm. The PIC is responsible for those notifications.

Our part as PIP: we notify the affected customer without undue delay after confirming a breach, and give it the facts it needs for its own notifications. We do this manually; there is no automated notification. Our Security page describes our measures and what is not yet built.

9. Audio and RA 4200

RA 4200 makes it a crime to record a private communication without the authority of all parties to it, and to possess, replay or share such a recording. Consent under the DPA does not cure an RA 4200 problem. The people at risk are usually not the monitored employee but the other participants on a call.

How audio works in ScreenJournal:

  • Audio is off by default. An administrator must turn it on for the organisation, and is shown an organisation-level warning about recording laws when doing so.
  • There is no per-call announcement gate. Nothing in the product announces a recording to the other people on a call or stops capture until they agree.
  • When audio is on, the app records whenever a listed meeting or calling application uses the microphone. It records all participants, including people outside the organisation such as customers, and where listen capture is enabled it records whole meetings or webinars.
  • Transcripts attribute each passage to the "member" (the monitored user) or to the "other party". The transcription model also separates the voices it hears and may label a passage with a name spoken in the conversation; that label is stored with the transcript, and the Audio page shows only the member's name or "Other party". We do not match voices against voiceprints or identify anyone biometrically.
  • The member sees "Recording from" and the application's name while audio is recording.

Telling other participants and obtaining the authority RA 4200 requires is the responsibility of the organisation that turned audio on. We recommend Philippine customers keep audio off until they have confirmed their RA 4200 position with counsel.

10. If you took part in a call

If you spoke with someone whose organisation uses ScreenJournal with audio on, your voice and words may have been recorded and transcribed, labelled as "other party". That organisation controls the recording; ask it first about what it holds and why. If you cannot reach it, or want a recording corrected or deleted, write to support@screenjournal.ai and we will pass the request to the organisation and help it respond. See our notice for people recorded on calls and webinars.

11. Cross-border transfers and retention

The service is hosted in Germany. Activity time-series data is stored in India, in Amazon Web Services' Mumbai region. Some data is transferred onward to the vendors listed on our Subprocessors page, including AI processing through Google Vertex AI and Google's Gemini API. These transfers take place under each vendor's standard terms. Under the DPA, the PIC remains accountable for personal information it has transferred to a third party, including abroad; we support our customers in meeting that accountability.

Data is retained for the term of your employer's subscription unless it is deleted earlier on a verified request or by your employer. Where Record + Save is enabled, stored screen video is kept for up to three months by policy. Automated expiry is not yet built; deletion is carried out by our operational procedure.

Our Retention & Deletion Protocol sets out how long each kind of data is kept.

Data Protection Officer (role): support@screenjournal.ai, subject "Data protection request". Post: Cyberinfra Limited, 50 Athol Street, Douglas, Isle of Man IM1 1JB. You can complain to the National Privacy Commission at privacy.gov.ph.

We list every change on the Legal page with its effective date and, where practicable, post material changes before they take effect.

Related: Privacy Policy, Subprocessors, Security, Retention & Deletion Protocol, Data Protection Contacts, Vulnerability Disclosure Policy, Cookie Policy and Terms of Use.

This page is for information and is not legal advice. Employers remain responsible, as PIC, for the lawfulness of their own monitoring, for RA 4200 compliance on any recorded call and for their own NPC registration.

Changes and previous versions

  • 5 October 2026v2.0: current stack; NPC Advisory 2024-04 on AI systems; registration limbs corrected; call-participant section; audio posture.

Questions about this document: support@screenjournal.ai. Canonical URL: /legal/philippines-dpa.