The Telecommuting Act: Remote Work Has Its Own Statute Here
Remote work in the Philippine private sector is governed by the Telecommuting Act (Republic Act No. 11165) and the implementing rules issued by DOLE. It applies to employees who perform work away from the employer's regular workplace using telecommunications and computer technology — whether you call it remote, work from home or hybrid.
Three things need to be settled up front:
- A telecommuter is still an employee. This matters most. Companies sometimes treat the move to remote as an opportunity to switch people onto service contracts and drop social contributions and statutory benefits. Whether an employment relationship exists is decided on substance — who engaged the worker, who pays, who can dismiss, and above all who exercises control over how the work is done. If you still set schedules, issue instructions and appraise performance, it is employment, and relabelling the contract tends to be read as circumvention.
- It must be voluntary and mutually agreed. The statute frames telecommuting as an arrangement the employer and employee agree on, not a condition the employer imposes and not a route for quietly demoting someone.
- You need a written programme, and it must be reported. Employers adopting telecommuting should have a written policy and report the arrangement to DOLE as required. Like the compressed work week, doing everything except the filing leaves you exposed at inspection.
One frequent confusion worth clearing: telecommuting, part-time work, contracting and platform engagement are different legal arrangements. Do not mix them in one document. If you want the same employee working from a different place, write a telecommuting arrangement. If you want no employment relationship at all, that is a separate exercise with a very different risk profile.
The Core Rule: No Less Favourable Than a Comparable On-Site Employee
The pivot of the Telecommuting Act is fair treatment: an employee who telecommutes must receive treatment no less favourable than comparable employees performing the same or similar work at the employer's premises. This is not aspirational language — the implementing rules break it into a checklist you can audit against, typically covering:
- Pay: the same rate for the same work; the salary cannot be trimmed because the person works from home;
- Hours and overtime: normal hours, overtime premium, night differential, rest day and regular holiday rules all continue to apply;
- Rest and leave: statutory leave and the special-purpose leaves apply equally;
- Statutory contributions: SSS, PhilHealth and Pag-IBIG registration and remittance carry on unchanged;
- Training and career development: equal access to training and to promotion consideration, rather than being quietly passed over for not being in the office;
- Freedom of association and collective bargaining: telecommuters may join a union and take part in bargaining;
- Workload and performance standards: comparable to on-site peers, not inflated because the work is remote;
- Occupational safety and health: the duty of care does not evaporate because the employee is elsewhere.
In practice the flashpoint is allowances. Companies moving to remote often cut transport and meal allowances on the spot. Distinguish two situations. Where those allowances were genuinely attendance-linked reimbursements that stop when attendance stops, that generally holds. Where they were paid as a fixed part of remuneration regardless of attendance, they may already be a vested benefit, and unilateral removal runs into the non-diminution principle. What decides it is how you actually paid them, not how you now describe them.
The right sequence is to document each allowance — its nature, its conditions and how it may be varied — have employees acknowledge that in writing, and only then discuss changes. This is general guidance, not legal advice; consult a licensed Philippine lawyer on your specific case.
Voluntary, Written, and Explicit About Costs
A workable telecommuting policy or agreement should at minimum cover:
- Scope and eligibility: which roles qualify, on what conditions (performance, employment status, nature of the work), and the approval route;
- Work location: name the employee's designated work location and require notice of any change. It looks like housekeeping, but it underpins injury assessment, data security and cross-border exposure alike;
- Working hours and contactable hours: see the next section;
- Deliverables and how performance is measured: the recurring remote dispute is how the employer knows work is happening; defining outputs beats installing surveillance;
- Equipment, connectivity and consumables: the big one, covered below;
- Data security and confidentiality obligations;
- Health, safety and incident reporting;
- Variation and termination, including the employee's route to return to on-site work and the circumstances in which the company may end the arrangement.
On costs: the law does not itemise who pays for what, but it does require the policy to state how costs are allocated — who supplies equipment, how connectivity and electricity are handled, who covers consumables and repairs, whether employee-owned equipment attracts a subsidy. Two hard limits apply. First, cost-shifting must not push actual take-home remuneration below the applicable statutory wage floor. Second, company equipment needs an issue-and-return schedule so exit clearance is straightforward — and losses cannot simply be deducted from wages, because wage deductions are tightly restricted; the route is written acknowledgement and a lawful recovery process.
If employees use their own devices, add two items: separation of company and personal data (dedicated accounts, containerisation, and advance notice of what any remote wipe would cover), and a clear statement of the nature of any device subsidy — compensatory or benefit — because that will determine whether you can adjust it later.
Recording Hours, and Where Always-Available Stops Being Acceptable
Remote work does not switch off the hours rules. Overtime premium, night differential, rest day and holiday rules continue; the only real question is how you record. The durable approach layers three sources: system login and activity logs, delivery records in the task management tool, and employee self-declaration confirmed by a supervisor. Cross-checked, they hold up far better than any single mechanism.
Extended hours should require prior approval, with the policy stating that hours may not be extended without it. But note the other side: hours worked include work the employer suffered or permitted. You did not authorise it, yet you knew someone was answering messages every evening and handling clients at weekends, and you never intervened — that time can still be counted. So the intervening has to be documented: where someone consistently overruns, send a written reminder, adjust the workload, follow up. A friendly note in a group chat is not a record.
On always-on expectations: the Philippines currently has no generally applicable right-to-disconnect statute (bills have been filed; do not treat them as law). That absence is not a licence to demand round-the-clock availability, because the on-call analysis applies to remote work too. An employee who must be reachable at any moment and cannot effectively use the time for personal purposes has a real argument that the time counts; time actually spent responding certainly does.
The pragmatic drafting is a defined core contactable window, an express statement that immediate response is not expected outside it, and a clear escalation path for genuine emergencies — who may trigger it, through which channel, how it is logged and compensated afterwards. Getting that on paper protects operations and removes the vague always-on state that generates claims.
Be careful with monitoring. Screenshots, keystroke logging and webcam checks are processing of personal data: they need a lawful basis, prior notice, and must be necessary and proportionate. Beyond privacy exposure, heavy surveillance can be argued as an unreasonable working condition. Where output can be measured, measure output instead.
Data Security and Injuries at Home: the Two Hard Parts
Responsibility for data does not move to the employee's living room. The company remains the controller and remains accountable for the processing, under the Data Privacy Act and the National Privacy Commission (NPC). What that means operationally: least-privilege access, device encryption and management, access to systems through controlled channels, rules on home networks and shared devices, physical protection of screens and paper, employee training and written undertakings, and a working breach escalation and notification process. Outsourcing and shared service operations carry a further layer of client contractual obligations, usually stricter than the statutory baseline — align the two.
Injuries at home are the other hard part. First, terminology: the ECC here is the Employees' Compensation Commission, which oversees work injury and occupational disease compensation. It is an entirely different thing from the exit clearance certificate that the Bureau of Immigration issues to departing foreign nationals, which shares the same acronym. Do not conflate them.
Assessment at home turns on two elements: whether the incident arose in the course of performing duties, and whether it is causally connected to the work. A fall during agreed working hours in the designated work area while doing something work-related is a very different case from a fall while doing household chores off-hours. Three measures reduce the uncertainty:
- state the designated work area and working hours in the agreement;
- require prompt incident reporting, keep a record, and follow the SSS and employees' compensation filing routes as prescribed;
- issue a simple home workstation safety self-assessment (electrical, seating, lighting, walkways) and keep the employee's confirmation.
Do not settle quietly instead of filing. Paying someone to keep an incident off the books creates two problems here: the employee can still pursue the statutory benefit later while you hold no filing record, and if contributions were missed, the portion the system was meant to bear may end up on the employer.
Injuries at home and data leaks still land on the company? → remote work policy and compliance review
Can I Use a Remote Worker in the Philippines on Our EHR or Client System?
Yes — a remote worker based in the Philippines can be given access to a US EHR, a CRM or any other client system, and nothing in Philippine law forbids it. What the arrangement needs is a contract chain that makes a named party accountable for the data, plus access controls that survive an audit.
Three rulebooks apply at the same time, and companies usually check only one of them:
- Your own sector rules, at your end. For US healthcare, HIPAA does not itself ban offshore access to protected health information, but the entity handling it is a business associate and needs a signed Business Associate Agreement. What actually blocks these arrangements is usually one layer down: payer contracts, state Medicaid programmes and government contracts often carry their own onshore-only clauses. Read the agreements you have already signed before you scope the role.
- Philippine data privacy law, at their end. The Data Privacy Act of 2012 (Republic Act 10173) covers personal data processed in the Philippines even when every data subject sits overseas. In practice that means a named Data Protection Officer, a written security policy, breach notification to the National Privacy Commission, and NPC registration once the thresholds are met. If you engage a Philippine company — an employer of record, a BPO or an outsourcing provider — it is the personal information processor and you are the controller. Put that split in writing rather than assuming it.
- Philippine labour law, for the person. Whoever is the employer on paper, the work is performed in the Philippines, so Philippine employment rules govern the relationship and the Telecommuting Act applies to the home-based setup. That is what makes the choice between your own entity, an EOR and an independent contractor a compliance decision rather than an administrative one — see the comparison of HR outsourcing models.
The controls that decide whether this passes a client audit:
- No local copies. Access through a hosted desktop or a locked-down browser session that blocks download, print, screenshot and clipboard, so the record never lands on a home machine.
- Named accounts, least privilege. One login per person, scoped to the modules the role actually touches, revoked the day the person leaves — no shared team accounts.
- Logs you can produce. Retain access logs for the period your own sector requires, not the period a vendor defaults to.
- A data clause in the telecommuting agreement. The Telecommuting Act already requires you to spell out how the employee protects company and client data at home; use that clause to cover the physical side too — a room that can be closed, no shared household devices, headsets for calls involving personal data.
- A named escalation path. Write the DPO and the breach-notification route into the contract, because the notification clocks in the Philippines and the ones at your end run in parallel, not in sequence.
Where this genuinely does not work: when your own client or payer contract prohibits offshore access outright. No amount of Philippine-side compliance repairs that clause — renegotiate it, or keep that workload onshore.
When the Employee Is Abroad: Assess Cross-Border Remote Work Case by Case
The last section is the one most often waved through and the most costly: the employee is physically outside the Philippines while continuing to work for the Philippine company. Perhaps a local employee relocated, a foreign national went home, or you want head-office colleagues carried on the Philippine payroll. HR often approves it with a shrug because remote is remote. Signing it opens four risk lines at once:
- Personal income tax. Taxing rights depend on residence status and where the income is sourced; the employee may face filing obligations in two places, and the company's Philippine withholding treatment has to be re-examined. Cross-border cases vary enormously and need to be checked on the facts.
- Corporate tax exposure. An employee working from another country over a sustained period can create a permanent establishment there, dragging the company into local corporate tax and filing duties. This one is most often missed and most expensive.
- Social contributions. Whether SSS, PhilHealth and Pag-IBIG coverage continues, and whether the host country imposes its own mandatory scheme, has to be confirmed item by item rather than assumed.
- Host-country labour law and work authorisation. Mandatory employment protections where the work is actually performed may apply, and a governing-law clause pointing at Philippine law will not necessarily displace them. More immediately, immigration: working in a country generally engages that country's work authorisation rules, and sustained remote work on a visitor status is a clearly high-risk position.
So cross-border remote work is a case-by-case exercise: get the tax and legal assessment first, decide on the structure (continue the employment, use a local entity, use an employer of record, or decline), and record the outcome in a tailored side agreement rather than the standard telecommuting policy.
One more point: discipline and dismissal rules are identical for remote staff. Grounds split into just cause (employee fault, as a rule no separation pay) and authorized cause (business grounds, separation pay due), with different procedures that must not be mixed. Just cause requires the full twin-notice rule — a first notice stating the specific charge and its factual basis with a reasonable period to answer, a genuine opportunity to be heard, then a second notice setting out the findings and decision. The burden of proof rests with the employer, so evidence is created in advance. Where the cause is valid but the procedure defective, reinstatement is generally not ordered but nominal damages are owed. Remote settings add a service problem: alongside electronic delivery, send to the address on the personnel file and keep proof of dispatch, and minute any hearing held by video with signed confirmation.
If your remote arrangement is still an internal memo, turn it into a proper programme before the next review cycle: a written policy, individually signed agreements, fixed positions on cost and working time, and the DOLE filing done. Have the Yixing visa and HR team review your remote work setup for compliance and we will work through it against the rules in force for your region and industry. This article is general guidance, not legal advice; consult a licensed Philippine lawyer on your specific case.
Frequently Asked Questions
Can we pay remote employees less than office-based staff?
Who pays for internet, electricity and equipment?
Can we require remote staff to be available at all times?
Is an injury at home treated as a work injury?
Do we have to report a telecommuting programme to DOLE?
What is the risk if an employee works remotely from another country?
Can I use a remote worker in the Philippines on our EHR system?
Let’s talk through your situation — free
Every company is different. Leave your details and a Chinese-speaking advisor will get back within 1 business day with practical, industry-specific guidance and a transparent quote.
Get help with Visa & HR → Free consultation
