Policy approved as of November 2019.
Page updated as of November 9, 2020.
MERALCO cares for your personal data and takes your privacy seriously. We, in MERALCO, are committed to ensuring that your personal data is protected from collection to disposal.
This serves as our notice to all our data subjects of our privacy procedures and practices which we ensure to be consistent with the data privacy principles of transparency, legitimate purpose and proportionality.
In this Policy, the term “We” or “Us” refers to MERALCO, which under the DPA, is your Personal Information Controller (PIC) with respect to the personal data specified below.
WHAT WE COLLECT
We collect your personal data in the course of, or incidental to the conduct of, our business with you. These data include any other information you voluntarily provide for any legitimate purpose declared at point of collection as well as those we collect from publicly available sources, and from third parties and from other sources where the disclosure was subject of a separate consent or was otherwise lawfully permitted. The following are examples of these personal data.
- From prospective and existing customers, including customers with terminated services:
- Information you provide to us when you apply for service, such as your name, address (i.e. postal address, geolocation), phone number, email address, Tax Identification Number (TIN), evidence of authority to occupy (e.g., contract of lease, Transfer Certificate of Title, Special Power of Attorney (SPA), Undertaking / Authorization from owner of the premises) and, if applicable, details of your authorized representative and other documentary requirements;
- Information you provide in relation to the conduct of our business such as regarding retail electricity supply or embedded generation;
- Billing and payment information used to process payment for your electric consumption and other liabilities, such as your banking (for auto debit arrangement) and credit card (for auto charge arrangement) information. However, details of the payment instrument (like prepaid card, debit card, credit card) used to pay your bills via the Meralco Customer Portal are captured and processed by the payment gateway service provider;
- Information to determine eligibility to participate in certain energy programs or services, such as peak-off-peak rates (POP), net metering, Interruptible Load Program (ILP), demand side management (DSM), etc.;
- Information you provide us when you visit or use our website, mobile applications or other communication channels, such as when you wish to contact us to lodge your concerns, to register at our customer portal, or to avail of our online application, outage notifications, and billing and/or payment services, including information generated through such activities;
- Information you give us when you communicate with MERALCO and/or any of our representatives (e.g., Call Center Representatives, Relationship Managers, etc.), such as with respect to inquiries and complaint details on the quality and reliability of electric service;
- Responses you or your representative provide when you participate in our customer surveys, promos, and loyalty programs;
- Information you provide for verification purposes (e.g., to facilitate refunds), such as photocopy of a valid / government-issued identification card.
- Meralco-related information that you post in your social media accounts, such as your posts in Twitter, Facebook, Youtube, etc. that talk about your experience in transacting with Meralco and/or any of our representatives.
- From prospective, active, and separated employees, as well as on-the-job trainees:
- Information you submit when you apply at MERALCO for work or training, including what is contained in your resume or curriculum vitae and application form (e.g., work references);
- Information we collect during the processing of your application, such as testing results, employment offer, results of character investigation, and pre-employment medical assessment;
- Information we collect and maintain during your employment, such as your personal information, addresses, education records, professional licenses and permits; payroll information, including but not limited to government mandated and third party remittances like SSS, Philhealth, and Pag-ibig membership and contributions, taxes, bank account information; wages; entitlements and benefits; medical and dental care records; emergency contact information; training and certifications; performance evaluation; sanctions; and employment changes / work history;
- Information you provide about your dependents/beneficiaries for purposes of but not limited to administration of health maintenance plan, insurance claims, or profiling;
- Information we retain after your separation from service, such as but not limited to pension information, retiree eligibilities and other benefits, bank account information, addresses, beneficiaries, and emergency contact information.
- From vendors, suppliers or contractors, and consultants:
- Information you submit to MERALCO in your application for accreditation, use of supply chain application system, and/or processing of payments, such as your name, tax identification number, address, contact details, educational attainment, work experience and banking information;
- Information we collect and maintain about you and your employees in relation to the preparation, execution, or fulfilment of your contract with us;
- Information that your employees submit to have access to, or perform your services or deliver your products within, the premises of the Company.
- From shareholders:
- Information you submit to us when you become a shareholder of or while being a shareholder of MERALCO like your name, address, contact details, marital status, government issued identification, and if applicable, details of your authorized representative and heir/s;
- Information provided to us by your broker or by the Company’s stock transfer agent.
- From guests / visitors:
- Information we collect when you enter our premises such as your name, address, vehicle type and plate number or conduction sticker number, and identification card details;
- Information captured by our close circuit television (CCTV) installed in our premises including entrance and exit points.
- From other pertinent third parties:
- Information we collect from third parties by virtue of a legal claim or demand, such as claims filed by or against third parties, claims in relation to damage to company property, or in connection with our services, programs and events such as Corporate Social Responsibility Programs, Luminaries, Makabansa Basketball League, and other company events;
- Information we collect from our business partners pursuant to a potential or existing transaction;
- Information provided to us by government agencies, regulators or public officers and employees in the performance of their lawfully mandated duties;
- In general, information collected or provided relating to our business, including those intended for market research and data analytics.
WHAT WE DO WITH THE INFORMATION WE GATHER
We store, process, and/or analyze the personal data collected for some legitimate purpose, related or incidental to the conduct of our business, including maintaining safety and security within the Company premises. Specifically, we may store, process, and/or analyze your personal data for the following and any other legitimate purposes:
- For our customers
- To perform our contractual and legal obligations to you We process your personal data to evaluate your eligibility for electric and other related services, to provide you quality, reliable and regular supply of electricity, to continuously improve our business and operations as well as our products and services;
- To enhance your customer experience. We process your personal data to respond to your inquiry, concern, or complaint; to provide you information about our programs, service offerings, and any other programs or promos that may be of interest to you; to send you messages related to your services including outage notifications, updates, alerts, and other information that you request; to understand your needs and preferences by analyzing your use of our products and services, your participation in our surveys and research activities, and your browsing behavior in our mobile applications and websites; to address root causes of common concerns by analyzing Meralco-related information that you post in your social media accounts, so we can serve you better.
- To manage your account with us.We process your data to administer and update your customer data, to compute your electric consumption and facilitate your payment or claims, including acceptance of bill payments according to your enrolled payment mode (e.g., automatic debit from your bank account), and to verify your identity when you access your account through the various customer engagement channels (e.g., e-mail, website, mobile application, via phone call, walk-in) and/or your eligibility to our programs, or entitlement to refunds and other claims
The information collected from social media will not be used against you or to hold you in a negative light, except if the social media activity promotes fraud or any illegal act that can hurt others.
- For our applicants, active and separated employees, as well as on-the-job trainees
- To handle your application for employment or training.We process your personal data to evaluate your eligibility for employment or training, including the verification of your qualifications, employment history, and character references (background checking);
- To manage our employer-employee or training relationship.We process your data to maintain your employment, on-the-job training and/or personal records, including your contact information, for operational or administrative efficiency. Specifically for employees, we collect, store, and process your data to administer your pay, statutory and salary deductions, entitlements, and benefits, and those of your dependents or beneficiaries, to conduct your performance reviews and grant rewards, to establish appropriate training and/or developmental interventions including your membership with professional or industry organizations, to monitor your work performance and use of company resources, and to conduct internal investigation and/or administer disciplinary action and sanction as necessary.
- To address or enforce legal claims or obligations arising from employment contract or training relationship.We process your data to comply with applicable statutory and regulatory requirements and submissions, including the processing of your work or labor-related claims (e.g. worker compensation, insurance claims, etc.). Your personal data may also be processed to enforce our claims or defend our rights in any proceeding arising from our relationship.
- To improve your welfare, safety, and security.We process your data to develop your health and wellness programs, including provision of your medical benefits, to conduct employee engagement activities, and to facilitate and maintain safety and security in the workplace and in all business operations. We also facilitate the payment of your donation to foundations or charitable institutions through deduction from your payroll account, and implement corporate social responsibility and other Company programs or events.
- To maintain our post-employment relationship.We process your data to administer your pension, retiree eligibilities and other benefits.
- For our vendors, suppliers or contractors, and consultants
- To establish our business relationship or consultancy engagement. We process your personal data to evaluate your application for accreditation or as basis for our engagement.
- To conduct business with you. We process your data to enforce our legal and contractual obligations including evaluating or auditing the provision of goods and/or services you provide, and facilitating the payment of your invoices in various payment methods (i.e., Fund Transfer, Corporate Check, Outsourced Check); informing you of our requirements, programs, or advisories; and responding to your questions, comments, and feedback by letter, e-mail, telephone, or other media for internal administrative purposes, such as auditing, data analysis, and database records management. Your data may also be processed to comply with statutory, legal, and regulatory requirements related to our business.
- To maintain your account with us and establish potential business relationship with our Subsidiaries and Affiliates. We maintain and update your vendor account information and establish details of your authorized contact persons for the goods and/or services you provide. We may also process your data for procurement synergy initiatives, including referring you as a potential vendor to our subsidiaries and affiliates.
- For our shareholders
- To manage investor relations. We process your personal data to maintain your account and our relationship, to administer the shareholder register, to facilitate payment of your dividend or any other amounts related to your shareholdings, to coordinate with your broker or our stock transfer agent for your concerns, and to comply with legal or disclosure requirements.
- To improve our stakeholder engagement. We process your data to facilitate communications with you, including responding to your queries and requests, sending notices of general meetings, annual reports, and shareholder circulars to you, registering shareholders at general meetings and shareholders’ events including without limitation to verification of your identity and/or your proxy.
- For our visitors / guests and abovementioned data subjects entering our Company premises or using our facilities or resources.
- To monitor and/or control your entrance to, or exit from, and activities within, our premises. We process your personal data to facilitate your ingress to and egress from our premises, offices, and facilities, including your vehicles or materials, such as verification of your identity and recording the purpose of your visit. We also monitor your location and activities inside the company premises, including ingress and egress of equipment, vehicle, and materials;
- To enforce safety and security measures and procedures. This includes conducting investigations and imposing sanctions in case of violations of Company policies and security and safety procedures or commission of crimes.
- For other pertinent third parties
- To file and/or prosecute a legal claim or defend the Company, its officers, employees, and representatives against a demand;
- To pursue a potential or existing transaction;
- To comply with our legal, regulatory, or contractual obligations;
- To assist public authorities in their government programs and initiatives;
- In general, to facilitate the performance of our services, provide you information about our products, services, programs, or promos that may be of interest to you, implement our programs or events like Corporate Social Responsibility Programs, Luminaries, Makabansa Basketball League, and other company events, or conduct our business operations.
We restrict the disclosure, including cross-border transfer, and processing of your personal data to our employees, trainees, authorized representatives, consultants, contractors, business partners, and government entities, on a need to know basis to carry out their responsibilities in relation to the conduct of our business.
- Employees, Authorized Representatives, Trainees, and Consultants
We ensure that our employees and trainees commit to observe the privacy policies of the Company. We require our Authorized Representatives and Consultants to sign a Non-Disclosure Agreement (NDA), to ensure that they process your data confidentially in a manner consistent with the purpose of their employment or engagement.
- Contractors, and Business Partners, including Auditors
We require our contractors, subsidiaries, and business partners, through a Data Processing Outsourcing and/or Non-Disclosure Agreement (NDA), to secure and keep your data confidential. We take your privacy seriously so punitive or legal action will be initiated in case of proven misdeed. Moreover, we do not allow our contractors, subsidiaries, and business partners to disclose or share your data to others, or to use it for their own purposes, without your consent.
- Government entities
Your information may also be disclosed to government entities pursuant to and in compliance with applicable laws and regulations, subpoena or court order.
Unless you provide specific consent or except in instances allowed under the Data Privacy Act, we will not:
- Share your personal data with our business partners and other third parties for their own commercial purpose or benefit;
- Use your personal data to enable third-party targeted advertisements which are not related to our business.
In case data sharing, including cross-border transfer, is allowed, we shall ensure the protection of your data through appropriate Data Sharing Agreements and commit to give you prior notice to any such transfer and processing of your data.
We are committed to ensure the integrity, confidentiality, availability, and security of your information. We implement reasonable organizational, physical, and technical security measures in collecting, processing, transmitting, storing, and disposing your personal data such as using secure servers, firewalls and security controls and ensuring regular conduct of audit and testing of our security protocols.
For an enhanced online experience, our services are available through compatible devices, such as laptops, PCs, tablets, and mobile phones. For your added security, we recommend that you install anti-virus software on any such device before accessing the internet.
You are responsible for the security of your information once it reaches you or your representative in any medium, including but not limited to written correspondences, bills, emails, system applications, and on-line accounts. You should take appropriate measures to ensure that any medium or device you use to monitor or manage your account is secure and not accessible to anyone without permission.
A cookie is a small file, which asks permission to be placed on your computer's hard drive. Once you agree, the file is added, and the cookie helps analyze web traffic or lets you know when you visit a site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
We use traffic log cookies to identify which pages are being used. This helps us analyze web page traffic data to improve our website and enhance your browsing experience. A cookie does not give us access to your computer or any information about you, other than the data you choose to share with us.
We receive and store certain types of information (such as the amount of time you spend on the site and the number of views you made on each page, the IP address of your device, and the browser and operating system that you are using) when you interact with our website, mobile website, emails, and online advertising, to monitor proper functionality, determine areas for continuous improvement and to support website requirements. This information is gathered automatically, temporarily stored in log files, and removed from the system at a certain point.
LINKS TO OTHER WEBSITES
Your personal information may be collected by our secured logging processes in case of logical and physical access to our systems and/or premises. When necessary, personal information may be retrieved for auditing and security purposes.
PERSONAL DATA RETENTION AND DISPOSAL
We keep your personal data only for as long as necessary:
- for the fulfillment of the declared, specified, and legitimate purposes provided above, or when the processing relevant to the purpose has been completed or terminated;
- for the establishment, exercise, or defense of legal claims; or
- for other business purposes, that are consistent with standards established or approved by regulatory agencies governing MERALCO
Thereafter, your personal data shall be disposed of or discarded in a secure manner that would prevent further processing, unauthorized access, or disclosure to any other party or the public.
CONTROLLING YOUR PERSONAL INFORMATION
You may request for a copy of your personal information in our possession, or have it corrected if you believe that it is inaccurate or incomplete.
If you wish to request for a copy of your personal data, or have it corrected or deleted, or to exercise your rights as data subjects, please reach out to us through our contact information found below. We will promptly respond to your request.
William S. Pamintuan
Chief Legal Counsel, Head, Legal and Corporate Governance, Compliance Officer and
Chief Data Protection Officer
Tel. No.: 8631-2222
Office: Lopez Building, Meralco Center, Ortigas Avenue, Brgy. Ugong, Pasig City, 1600
CHANGES TO POLICY
CHANGE CONTROL PROCESS
- changes to the DPA and its IRR
- new issuances from the NPC
- changes to the Company’s data processing activities
- others that may impact this Policy