Philippines Data Privacy Act (RA 10173)
The Data Privacy Act of 2012 (Republic Act No. 10173) is the Philippines' comprehensive data protection law. It protects individual personal information in information and communications systems in the government and private sector. Administered by the National Privacy Commission (NPC), it establishes rights of data subjects, obligations of personal information controllers and processors, and penalties for violations.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Controller/Processor Obligations and Enforcement
Security requirements, DPO, NPC enforcement
| Code | Title |
|---|---|
| PH-DPA-OB-01 | Security Measures |
| PH-DPA-OB-02 | Data Protection Officer |
| PH-DPA-OB-03 | Breach Notification |
| PH-DPA-OB-04 | NPC Registration and Compliance |
| PH-DPA-OB-05 | Penalties for Violations |
Data Processing Principles and Requirements
General principles and lawful processing criteria
| Code | Title |
|---|---|
| PH-DPA-PR-01 | General Data Privacy Principles |
| PH-DPA-PR-02 | Criteria for Lawful Processing |
| PH-DPA-PR-03 | Sensitive Personal Information |
| PH-DPA-PR-04 | Privileged Information |
Rights of Data Subjects
Individual rights under the Data Privacy Act
| Code | Title |
|---|---|
| PH-DPA-RS-01 | Right to Be Informed |
| PH-DPA-RS-02 | Right to Access |
| PH-DPA-RS-03 | Right to Rectification and Erasure |
| PH-DPA-RS-04 | Right to Damages and Data Portability |
Maps to 539 other frameworks
Frequently Asked Questions
What is Philippines Data Privacy Act (RA 10173)?
Philippines Data Privacy Act (RA 10173) is a compliance framework from Philippines with 3 domains and 13 controls. The Data Privacy Act of 2012 (Republic Act No. 10173) is the Philippines' comprehensive data protection law. It protects individual personal information in information and communications systems in the government and private sector. Administered by the National Privacy Commission (NPC), it establishes rights of data subjects, obligations of personal information controllers and processors, and penalties for violations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Philippines Data Privacy Act (RA 10173) have?
Philippines Data Privacy Act (RA 10173) has 13 controls organised across 3 domains. The largest domains are Controller/Processor Obligations and Enforcement (5 controls), Data Processing Principles and Requirements (4 controls), Rights of Data Subjects (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Philippines Data Privacy Act (RA 10173) map to?
Philippines Data Privacy Act (RA 10173) maps to 539 other compliance frameworks. The top mapping partners are EU Digital Markets Act (54% coverage), NIST Privacy Framework 1.0 (54% coverage), Australia Consumer Data Right — Banking (CDR) (54% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Philippines Data Privacy Act (RA 10173) compliance?
Start your Philippines Data Privacy Act (RA 10173) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Philippines Data Privacy Act (RA 10173) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 13 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required