Skip to content
Jo, home

Data privacy

Is my data safe with AI? What Philippine businesses should ask

Photo of Jo

Jo Founder, MarketDragon

This article gives you five questions to ask anyone who wants to put AI to work on your business data, and the answers I give to my own clients. You will learn what the Data Privacy Act means for you, why an NDA comes before anything else, and how "least access" works in practice.

I am not a lawyer, and this is not legal advice. For your own case, ask a lawyer.

Claude and Claude Code are Anthropic's products. I am an independent consultant and I am not affiliated with Anthropic.

The honest answer

Data is as safe as the rules around it. AI is a tool. What decides the risk is who can see the data, what the tool is allowed to do, and whether a person checks the important steps.

So "is AI safe?" is the wrong question. A better one is: "What can this setup see, what can it do, and who approves it?" The five questions below cover that.

Question 1: Which law applies to us?

In the Philippines, the main law is the Data Privacy Act of 2012 (Republic Act 10173). It covers how personal information is collected, used, stored and shared. If your business handles names, contact details, patient records, employee files or customer orders, it likely matters to you.

I follow it in my work. What it requires of your specific business depends on your situation, so confirm the details with a lawyer.

Question 2: Will you sign an NDA first?

A non-disclosure agreement (NDA) should come before anyone looks at your data. Not after, and not "when we get to it."

When I work with a business, I sign an NDA before I see your data. The discovery week, the setup and everything after it happen under that agreement. If a consultant or a vendor will not sign one, treat that as a warning.

Question 3: How much access does the AI get?

This is the one that matters most day to day. I use the rule of least access: the AI gets only what it needs for the task, and nothing more.

Think of a sales sheet. A system like that can have four kinds of access:

  • Read: look at the data.
  • Write: change the data.
  • Send: email or message someone.
  • Delete: remove data.

I start with read-only. If a task really needs more, I add one permission at a time, and only for that task. A report builder does not need to delete anything. A reply drafter does not need to send anything.

If something goes wrong, least access limits how far it can go.

Question 4: Who approves what gets sent, paid or deleted?

My rule is: the AI drafts, and a person approves.

Anything that sends, pays or deletes waits for a person. The AI can prepare a customer reply, but your staff read it and press send. It can prepare an invoice entry, but a person confirms before money moves. It can suggest a clean-up, but a person decides what is deleted.

Every setup also lists what the AI may and may not touch. That list is written down, so you can read it, and so can your team.

Question 5: Where does the work happen, and who owns it?

Ask where the AI runs, what leaves your computers, and who owns what is built. In my setups, I work on your computers, test on a copy of your data rather than the live files, and you own everything I build. At the end there is a full handover, so you do not depend on me to keep it running.

A short example: a logistics office

This is an illustration, not a client story.

Imagine a small logistics office in Davao. Staff keep delivery records and customer contact details in spreadsheets. They want daily delivery summaries and drafted replies to "where is my parcel?" messages.

A careful setup would look like this:

  1. An NDA is signed before anyone opens the spreadsheets.
  2. Claude Code starts with read-only access to only the delivery sheet, not the whole drive.
  3. It builds the daily summary on a copy of the data first, so the live file is never at risk during testing.
  4. It drafts the replies, and a staff member reads and sends each one.
  5. Nothing is sent, paid or deleted without a person.

The office gets the time back. The control stays with the staff.

Red flags to watch for

When you talk to any AI consultant or vendor, be careful if they:

  • Ask for full access to everything "to make it easier."
  • Will not sign an NDA before seeing your data.
  • Cannot explain, in plain words, what the AI is allowed and not allowed to touch.
  • Promise that nothing can ever go wrong.
  • Let the AI send messages or move money with no person in between.

A good provider can answer your five questions without hiding behind technical words.

What to do next

  1. List the data your business holds: customers, patients, staff, suppliers.
  2. Mark which of it is personal information. Ask a lawyer how the Data Privacy Act applies to you.
  3. Decide the first task you would hand to AI, and the smallest access it would need.

If you want to see how this works on your own tasks, read What Claude Code can do for a small business in the Philippines. To see what a setup covers from start to handover, read What a Claude Code setup includes.

When you are ready, apply for a discovery week. It starts with a short call, and the NDA comes before I see anything.

Free checklist: 5 repeat tasks your business can automate.

Enter your email and I will send it to you.