Philippine Identification System (PhilSys)
Detects Philippine Identification System (PhilSys) patterns. This pattern is based on a Microsoft Purview built-in sensitive information type. Users already running Purview may prefer to enable the built-in SIT directly, or use this version as a starting point for customisation.
- Type
- regex
- Engine
- universal
- Confidence
- high
- Confidence justification
- High confidence: pattern has strong structural constraints (specific format, prefix, or character class restrictions) that significantly reduce false positive rates. Context label evidence plus explicit template/example exclusion improves precision for high-risk identifiers. Added context gating and exclusion rules improve precision and reduce incidental matches.
- Detection quality
- Verified
- Jurisdictions
- ph
- Regulations
- Data Privacy Act of 2012 (Philippines)
- Frameworks
- ISO 27001, ISO 27701
- Data categories
- pii, government-id
- Scope
- narrow
- Risk rating
- 9
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Compatible, Netskope: Compatible
Pattern
\b\d{4}[- ]?\d{4}[- ]?\d{4}\b
Corroborative evidence keywords
PhilSys, PSN, national ID, Philippine identification, ID number, identification, ID card, license, permit, registration, certificate, data record, database record, record set, data extract, data export, database table, spreadsheet, data registry, registry entry (+14 more)
Proximity: 300 characters
Should match
1234-5678-9012— PhilSys 12-digit number (4-4-4 grouping)9876 5432 1098— PhilSys with space separators123456789012— PhilSys without separators
Should not match
1234-567890-2— Too few digits in middle group1234-5678901-23— Too many digits in last groupsample template placeholder number 123456789— Template/sample context should be excluded even when numeric-like values appeartemplate example placeholder record identifier— Template/sample context should be excluded even when anchor words are present
Known false positives
- The specific dash-separated format (XXXX-XXXXXXX-X) significantly reduces false positives. Mitigation: The structured format provides strong inherent validation. Keyword context further improves accuracy.
- In multiple languages, similar terminology used in formal or administrative contexts (education, professional documentation) that does not constitute sensitive data collection. Mitigation: Layer with additional contextual signals such as structured identifiers, form fields, or database column headers to distinguish sensitive records from general references.