GET CabreraLaw

Legal

Data Privacy Notice

Effective 16 August 2026 · Last updated 16 August 2026

Our commitment to your privacy

GET Cabrera Law is committed to protecting the personal data entrusted to us.

Confidentiality has always been the foundation of legal practice. Data protection is how that duty is kept in a digital environment, and we treat it as a professional obligation rather than a compliance formality. The care we bring to a client’s most sensitive matters is the same care we bring to the information you share when you visit this site or make contact with us.

Advising regulated organizations on their own data protection obligations is part of what this firm does. We hold ourselves to the standard we recommend to them.

This notice explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the rights you can exercise over it. It is written to comply with Republic Act No. 10173 (the Data Privacy Act of 2012), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC).

For purposes of the Data Privacy Act, GET Cabrera Law is the personal information controller for the personal data described below.

Who this notice covers

This notice applies to:

  • Visitors to getcabreralaw.com — including anyone who submits the contact form, registers for service notifications, or books a consultation through our scheduling link.
  • Prospective clients — anyone who contacts us to discuss a possible engagement, whether or not an engagement follows.
  • Clients and their personnel — organizations we act for, and the officers, directors, employees, and representatives whose data reaches us in the course of a matter.
  • Counterparties and third parties — individuals whose personal data appears in documents, records, or communications we receive while handling a matter.
  • Principals and witnesses in electronic notarization — once our commission as an Electronic Notary Public is issued.

It does not cover the privacy practices of other websites we link to, or of platforms our clients use independently of us.

What we collect

From website visitors

  • Contact form. Full name, email address, phone number (optional), area of interest (optional), and the content of your message.
  • Notification list. If you ask to be notified when our electronic notarization service becomes available, we collect the details you provide through that form.
  • Consultation scheduling. If you book through our scheduling link, the booking platform collects your name, email address, and the information you enter when booking, and shares it with us.
  • Technical data. Our hosting provider generates standard server logs — IP address, browser type, pages requested, timestamps — as an ordinary function of serving the site. We use these only to keep the site available and secure. We do not operate advertising trackers or sell traffic data.

From prospective clients

Before we can discuss a matter substantively, we run a conflicts check. That requires the names of the parties, the identity of any adverse or related party, and enough of the subject matter to determine whether we can act. We collect this whether or not you engage us, because we need a record of what we cleared.

From clients and in the course of matters

The scope depends on the matter. It commonly includes contact and identification details, corporate records, employment and personnel records, contracts and correspondence, regulatory filings and submissions, financial and billing information, and case or dispute records.

Sensitive personal information. Some matters unavoidably involve sensitive personal information as the Data Privacy Act defines it — for example, health information in a product recall or adverse event file, government-issued identification numbers in a corporate or notarial record, or information about proceedings and offenses in a dispute. We collect this only where the matter genuinely requires it, and we apply the additional controls described below.

From electronic notarization (once commissioned)

We are pursuing commissioning as an Electronic Notary Public under the Supreme Court’s Rules on Electronic Notarization (A.M. No. 24-10-14-SC). We are not yet commissioned and are not yet offering the service. When the service goes live, notarization will involve:

  • Identity verification — competent evidence of identity, processed through the electronic identity-verification and multi-factor authentication features of an accredited Electronic Notarization Facility.
  • Audio-visual recording of remote notarization sessions, where the Rules require it.
  • Geolocation confirmation of the parties, as the Rules require for remote sessions.
  • Entries in the Electronic Notarial Book, including the details of the notarial act, the identities and addresses of the parties, the evidence of identity relied on, and the fees charged.

These records are governed by the Rules on Electronic Notarization. They are maintained within the accredited Facility, transmitted to the Supreme Court’s central notarial database as the Rules direct, and turned over to the Supreme Court on the expiry, resignation, or revocation of the commission. We cannot delete or withhold them at a party’s request, because they are court records.

Why we process your data, and on what legal basis

What we doWhyLawful basis under the Data Privacy Act
Respond to enquiries and consultation requestsTo answer you and assess whether we can helpConsent; steps taken at your request prior to entering a contract (Sec. 12)
Run conflicts checksTo determine whether we are professionally able to actLegitimate interests; compliance with our obligations under the Code of Professional Responsibility and Accountability (Sec. 12)
Provide legal servicesTo perform the engagementPerformance of a contract (Sec. 12); establishment, exercise, or defense of legal claims, and provision of legal services (Sec. 13)
Handle sensitive personal information in a matterBecause the matter requires itNecessary for the protection of lawful rights and interests in court proceedings, or the establishment, exercise, or defense of legal claims, or provision of legal services (Sec. 13)
Bill, collect, and keep accounting recordsTo be paid, and to satisfy tax and audit requirementsLegal obligation; legitimate interests (Sec. 12)
Perform notarial actsTo discharge the functions of a commissioned notaryLegal obligation under the Rules on Electronic Notarization (Sec. 12); provided by existing law (Sec. 13)
Maintain site availability and securityTo keep the site working and defendedLegitimate interests (Sec. 12)
Send service updates you asked forBecause you askedConsent (Sec. 12)

We do not use your data for automated decision-making or profiling.

Who we share it with

We disclose personal data only where there is a reason to, and only to the extent the reason requires:

  • Service providers acting on our instructions — website hosting, email and productivity services, form and scheduling tools, document management, and, once commissioned, the accredited Electronic Notarization Facility. These are personal information processors and are bound to process data only as we direct.
  • Courts, tribunals, arbitral bodies, and government agencies — where a matter, a filing, or a lawful order requires it. This includes the Supreme Court’s central notarial database for electronic notarial records.
  • Counterparties and their counsel — to the extent the conduct of the matter requires disclosure, and subject to our duty of confidentiality.
  • Co-counsel, local counsel, or experts — engaged on a matter with the client’s knowledge.
  • Professional advisers and auditors — where necessary, and under confidentiality.

We do not sell personal data. We do not share it for anyone else’s marketing.

Sharing is always subject to the lawyer’s duty of confidentiality under Canon III, Section 27 of the Code of Professional Responsibility and Accountability, which requires a lawyer to maintain the confidences of the client and to respect data privacy laws, and which continues after the engagement ends. Where the duty of confidentiality is stricter than the Data Privacy Act, the stricter duty governs.

Where your data goes

Some of the platforms we use — email, document storage, scheduling, form collection — process data on servers outside the Philippines. Where that happens, we remain accountable for the data under Section 21 of the Data Privacy Act, and we select providers that offer contractual and technical protections consistent with the Act.

If a matter requires a transfer that falls outside our ordinary arrangements, we will tell the client before we make it.

How long we keep it

CategoryRetention
Enquiries that do not become engagementsUp to two years, so we can trace conflicts and prior contacts, then deleted
Conflicts-check recordsRetained for the life of the practice, in minimal form — names and the fact of the check
Client files and matter recordsAt least ten years from the close of the matter, consistent with prescriptive periods and professional record-keeping practice, unless the client directs otherwise in writing or a longer period applies
Billing and accounting recordsTen years, consistent with tax and audit requirements
Electronic notarial recordsAs prescribed by the Rules on Electronic Notarization, including transmission to and custody by the Supreme Court
Notification-list contactsUntil you unsubscribe, or until the notification purpose is spent
Server logsShort-term, as set by our hosting provider, for security and diagnostics

When a retention period ends, we securely delete or anonymize the data, unless a legal hold, pending proceeding, or regulatory requirement obliges us to keep it.

How we protect it

We maintain organizational, physical, and technical security measures appropriate to the confidential and sensitive nature of the material we hold, as Sections 20 to 24 of the Data Privacy Act require:

  • Access to matter files is restricted to those who require it for the matter.
  • Devices and accounts are protected by encryption and multi-factor authentication.
  • Data in transit is encrypted; email carrying sensitive material is encrypted or password-protected as the circumstances warrant.
  • Service providers are selected for their security posture and bound by confidentiality and data-processing terms.
  • Everyone who works on our matters — personnel, contractors, and co-counsel — is bound in writing to confidentiality.
  • Records that have reached the end of their retention period are securely disposed of.
  • Our security measures are reviewed and updated as our systems, our practice, and the threat environment change.

No system is perfectly secure, and we do not claim otherwise. What we commit to is diligent protection of what you entrust to us, and prompt, candid handling if an incident ever occurs.

If there is a data breach

If a personal data breach occurs that meets the notification criteria under the Data Privacy Act and NPC issuances, we will notify the National Privacy Commission and the affected data subjects within seventy-two (72) hours of knowledge of, or reasonable belief in, the breach. Our notification will describe the nature of the breach, the personal data likely involved, the measures taken to address it, and the steps you can take to protect yourself.

We maintain a breach response procedure and a record of security incidents, whether or not they are notifiable.

Your rights

Under the Data Privacy Act and its Implementing Rules, you have the right to:

  • Be informed whether your personal data is being, has been, or will be processed, and to receive the details of that processing before it happens.
  • Object to processing, including processing based on consent or legitimate interests, and to withdraw consent you previously gave.
  • Access the personal data we hold about you, its sources, the recipients it has been disclosed to, and the manner of processing.
  • Rectify personal data that is inaccurate or incomplete.
  • Erasure or blocking — to require the suspension, withdrawal, removal, or destruction of your personal data where it is incomplete, outdated, false, unlawfully obtained, used for an unauthorized purpose, or no longer necessary.
  • Damages for inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of your personal data.
  • Data portability — to obtain a copy of personal data you provided electronically in a commonly used, machine-readable format.
  • Lodge a complaint with the National Privacy Commission.

These rights are transmissible to your lawful heirs and assigns.

Limits on these rights

Two limits apply in a legal practice, and we would rather state them plainly than have you discover them in a refusal letter:

  • Privileged material. Where personal data is covered by the lawyer-client privilege or the lawyer’s duty of confidentiality, we may be unable to disclose, correct, or delete it at the request of someone other than the client. The privilege is the client’s, not ours to waive.
  • Records we are required to keep. Court records, electronic notarial records, filings already made, and records subject to a statutory retention period or a legal hold cannot be erased on request.

Where a limit applies, we will tell you which one, and why.

How to exercise them

Write to the Data Protection Officer using the details below. Tell us what you are asking for and give us enough information to identify you and locate your data. We will acknowledge your request and respond within a reasonable period, and in any case within the periods prescribed by the National Privacy Commission. There is no charge for a first request; a repetitive or manifestly excessive request may attract a reasonable administrative fee, which we will quote before doing the work.

Cookies and analytics

This site uses only the cookies necessary to serve pages, keep the site secure, and remember your session. We do not run advertising or cross-site tracking cookies.

Third-party tools embedded in the site — the scheduling link and the notification form — are operated by their providers and may set their own cookies when you use them. Their privacy notices govern that activity.

You can block or delete cookies through your browser settings. Doing so will not stop you from reading the site.

Children

Our services are directed to organizations and their representatives. We do not knowingly collect personal data from minors through this website. If a minor’s personal data reaches us as part of a matter, we handle it as sensitive material and process it only as the matter and the law require.

Registration with the National Privacy Commission

We monitor our registration position against the criteria set by the National Privacy Commission under NPC Circular No. 2022-04 — which turn on headcount, the volume of sensitive personal information processed, the risk a processing system poses to the rights and freedoms of data subjects, and the use of automated decision-making or profiling — and we register our data processing systems where those criteria are met.

Registration is a threshold requirement, not the measure of compliance. Every substantive obligation under the Data Privacy Act — lawful processing, transparency, proportionality, security, breach management, and the rights of data subjects — applies to us in full, and we discharge them in full.

Contact

Direct any question, request, or complaint about personal data to:

The Data Protection Officer
GET Cabrera Law
Email: info@getcabreralaw.com
Telephone: +63 961 952 3927
Web: getcabreralaw.com

If you are not satisfied with our response, you may bring the matter to the National Privacy Commission — privacy.gov.ph, complaints@privacy.gov.ph.

Changes to this notice

We will update this notice when our practices, our tools, or the law changes — including when our commission as an Electronic Notary Public is issued. The revision date appears at the top. Material changes will be flagged on the site, and clients affected by a material change will be told directly.

Nothing in this notice creates a lawyer-client relationship or constitutes legal advice. See our Disclosure page.