← Back to Home News · PH

Philippines' National ID eVerify: Relying-Party Onboarding, eKYC Tiers, and Data Limits

Make RegTech.com preferred on Google
Philippines' National ID eVerify: Relying-Party Onboarding, eKYC Tiers, and Data Limits
The Philippines has opened its National ID register to banks, employers, schools and government agencies through the National ID eVerify authentication service.
AI Summary
  • The PSA and DICT have opened the National ID register to banks, employers, schools and agencies through the National ID Authentication Service.
  • The government has published what it returns, a two-tier basic and eKYC split, and what it takes to connect: a Letter of Intent, a swimlane business process map, a VAPT certificate, and a Subscription Contract signed by both sides' data protection officers.
  • The Philippine Statistics Authority (PSA) and the Department of Information and Communications Technology (DICT) launched the Digital National ID alongside two authentication services, National ID eVerify and National ID Check, and published the terms under which banks, employers, schools, and agencies may connect.
  • That rulebook is the substantive part: it sets out what the state will and will not return, what an integrator must prove before going live, and where accountability sits once it does.

The Philippine Statistics Authority (PSA) and the Department of Information and Communications Technology (DICT) launched the Digital National ID alongside two authentication services, National ID eVerify and National ID Check, and published the terms under which banks, employers, schools, and agencies may connect. That rulebook is the substantive part: it sets out what the state will and will not return, what an integrator must prove before going live, and where accountability sits once it does.

The PSA announced the launch on 10 June 2024 in release 2024-184. Registration had passed 87 million people at that point, and the agency said every one of them could now pull up the card in digital form and clear an identity check through the two new services.

"With these developments, every registered Filipino now has improved access to a reliable and secure proof of identity that can be easily authenticated on their devices. This will facilitate the faster distribution and wider utilization of the National ID, with relying parties finding it easier to onboard to the National ID system," by Claire Dennis S. Mapa of the Philippine Statistics Authority

DICT emphasised what the change does to everyday government transactions.

"This modern identification system will streamline transactions, improve service delivery, and ultimately make doing business easier for everyone," by Ivan E. Uy of the Department of Information and Communications Technology

What the service actually returns

The authentication layer is the National ID Authentication Service (NIDAS), which the government describes as consent-based and real-time, checking an individual against the National ID registry through secure API transactions. It runs in two tiers. 

Tier 1, basic authentication, returns a "Verified" or "Not Verified" result together with the registered full name. Tier 2, electronic know-your-customer, returns verified demographic data and the portrait photograph captured during National ID registration, and may be used to pre-fill the relying party's own application forms. After a successful call at either tier, the system generates a backend token, which the relying party may store as a unique reference and reuse across other onboarded systems, cutting repeat processing of personal identity data.

Alongside it sits National ID Check, which confirms whether any format of the National ID, including the digital one, is authentic by scanning its QR code. The PSA describes the Digital National ID itself as valid proof of both identification and age, reachable at national-id.gov.ph or through the eGovPH app after demographic input and facial verification.

Who may connect, and who may not

Eligible relying parties range from national agencies, local government units, state corporations, and state universities to financial institutions, employers, schools, and private companies with a legitimate verification requirement, subject to regulatory review, use-case validation, and security standards. One category is excluded outright. Technology solution providers and software vendors cannot register as relying parties on their own. They may act as solution partners supplying the integration work, but legal accountability for data privacy and security compliance stays with the relying party, which shifts the regulatory burden to the vendor's customer rather than the vendor.

Three phases before anything reaches production

Onboarding is staged. Regulatory onboarding comes first: documents submitted through the eVerify portal for compliance evaluation, one Letter of Intent per organisation with any additional systems listed in an annex, and a Business Process Map. The map is not a formality. It must show the data capture points, the user consent flow, and when and how authentication is triggered, preferably as a swimlane diagram with a narrative, and it must cover the workflow for failed attempts as well as successful ones.

Technical onboarding follows approval: a temporary API key valid for thirty calendar days to build and test against a designated environment, then a technical clearance covering a system demonstration and the applicable security assessments. Deployment is governed by a Subscription Contract granting API access for one or three years depending on sector, followed by a Certificate to Go Live. Application review alone typically takes seven to ten working days, and the government's own estimate for the full path to go-live runs from several weeks to a few months.

The conditions attached to access

The API is reachable only over HTTPS; each relying party gets a unique Client ID, Client Secret and access token, and calls are accepted only from whitelisted IP addresses. Before public deployment, the integrated system must pass a Vulnerability Assessment and Penetration Testing exercise, run either in-house or by a third party of the relying party's choosing, with only the certification of completion submitted to the PSA.

On privacy, the framework is consent-first: explicit consent for every authentication transaction, only the minimum data necessary returned, and logging for auditability. The National ID system does not store authentication responses. Data exchange is unidirectional and transaction-based, and the PSA does not collect or store data about a relying party's own customers through the integration. Relying parties may retain only what their agreement expressly authorises, and they may not retain National ID data without authorisation. The binding instrument is the Subscription Contract, signed by the head of agency and the data protection officer of both the PSA and the relying party. That second signature matters: a named DPO's sign-off is a condition of access, not an internal courtesy.

Service levels, and what it costs

In its relying-party FAQ, eVerify publishes the service level: a minimum 99.5 per cent monthly availability across a 24-hour, seven-day window, capacity for up to 1,000 authentication transactions per minute per system, and responses typically returned in one to five seconds. Support runs 7am to 6pm on working days, with standard queries answered within 24 hours. Government relying parties pay nothing, perpetually. Private sector relying parties also pay nothing at present, though the government reserves the right to introduce what it calls a minimal fee in future, subject to prior notice.

The age-assurance question

One listed use case carries wider significance than its placement suggests. Among the benefits eVerify sets out for employers and companies is streamlined age verification, restricting access to age-gated content or services using National ID-based checks. That is the government's own description of what the rail is for, and it arrives while regulators elsewhere are attaching a price to the alleged mishandling of children's data, as TikTok found in its $400 million US settlement. Whether consumer platforms adopt a state age-assurance rail is unsettled; that the rail exists, on published terms, at no cost to connect, is not.

Why it matters for compliance teams

A state-run authentication service changes the economics of onboarding: a bank resolving identity against the source register in one to five seconds, at no charge, with a reusable token, works from a different cost base than one paying per check to a commercial provider. The tradeoff is dependency, since the government sets uptime, tiering and pricing, and the published documents make clear that the pricing can change.

Then there is mandate. PhilSys was created under the Philippine Identification System Act (Republic Act 11055) as a foundational identity system, and transactions over it remain subject to the Data Privacy Act (Republic Act 10173). The onboarding regime reads as an attempt to hold that line through process: consent per transaction, minimum disclosure, no response storage, a DPO signature and a VAPT certificate before go-live. Across a region where digital economy policy is moving quickly, and identity is the control point anti-scam legislation keeps reaching for, it is a concrete reference for verifying a person while the data stays put, written into a contract rather than a press release.

Read the government's own material: the National ID eVerify service page, its relying-party FAQ, and the PSA's launch release 2024-184.

Link copied to clipboard
AI Bot
AI Bot
Hi! I'm the RegTech.com assistant. How can I help you today?
Ask me anything — top trending news, latest regulatory changes in the EU, or simply search for topics.