Philippines Data Privacy Act
Philippines Data Privacy Act of 2012 (RA 10173) + IRR 2016 + NPC circulars.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
Breach
| Code | Title |
|---|---|
| NPC-16-03-BMT | Breach Management Team and Procedures |
| NPC-16-03-BREACH | Personal Data Breach Notification |
Cross-border Transfers
| Code | Title |
|---|---|
| RA10173-S21 | Principle of Accountability for Cross-Border Transfers |
DPIA
| Code | Title |
|---|---|
| NPC-18-02-PIA | Privacy Impact Assessment |
Data Subject Rights
| Code | Title |
|---|---|
| NPC-18-01-RIGHTS | Exercise of Data Subject Rights Procedure |
| RA10173-S16-A | Right to be Informed |
| RA10173-S16-B | Right to Access |
| RA10173-S16-C | Right to Object |
| RA10173-S16-D | Right to Erasure or Blocking |
| RA10173-S16-E | Right to Damages |
| RA10173-S18 | Right to Data Portability |
| RA10173-S19 | Non-Applicability and Filing of Complaints |
Enforcement
| Code | Title |
|---|---|
| RA10173-S22-25 | Penalties: Unauthorized Processing and Access |
| RA10173-S34-LARGE | Large-Scale or Sensitive Information Aggravated Penalties |
Exemptions
| Code | Title |
|---|---|
| NPC-RESEARCH | Research Exemption Conditions |
Governance
| Code | Title |
|---|---|
| IRR-S26-PRIVACY-MANUAL | Privacy Management Program and Manual |
| NPC-16-01-DPO | Mandatory Designation of Data Protection Officer |
HR
| Code | Title |
|---|---|
| NPC-EMPLOYEE | Employee Personal Data Processing |
Lawful Basis
| Code | Title |
|---|---|
| RA10173-S12 | Criteria for Lawful Processing of Personal Information |
| RA10173-S13 | Sensitive Personal Information and Privileged Information |
Marketing
| Code | Title |
|---|---|
| NPC-DIRECT-MARKETING | Direct Marketing Restrictions |
Online
| Code | Title |
|---|---|
| NPC-COOKIES | Cookies and Online Tracking |
Principles
| Code | Title |
|---|---|
| RA10173-S11 | General Data Privacy Principles |
Registration
| Code | Title |
|---|---|
| NPC-17-01-DPS | Registration of Data Processing Systems with NPC |
Regulator
| Code | Title |
|---|---|
| RA10173-S7-NPC | National Privacy Commission Authority |
Retention
| Code | Title |
|---|---|
| IRR-S37-RETENTION | Data Retention and Disposal |
Sector Specific
| Code | Title |
|---|---|
| NPC-BPO-SECTOR | BPO and KPO Sector Compliance |
| NPC-GOV-AGENCIES | Government Agencies Specific Obligations |
| NPC-HEALTH-SECTOR | Health Sector Personal Data Protections |
Security
| Code | Title |
|---|---|
| IRR-S38-ACCESS-LOGS | Access and Activity Logging |
| RA10173-S20-A | Security of Personal Information: Organizational Measures |
| RA10173-S20-B | Security of Personal Information: Physical Measures |
| RA10173-S20-C | Security of Personal Information: Technical Measures |
Special Categories
| Code | Title |
|---|---|
| IRR-S25-CHILDREN | Processing of Personal Information of Minors |
Third Parties
| Code | Title |
|---|---|
| IRR-S26-PROCESSORS | Personal Information Processors Contracts |
| NPC-OUTSOURCING | Outsourcing and Subcontracting Agreements |
Frequently Asked Questions
What is Philippines Data Privacy Act?
Philippines Data Privacy Act is a compliance framework from Philippines with 19 domains and 36 controls. Philippines Data Privacy Act of 2012 (RA 10173) + IRR 2016 + NPC circulars. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Philippines Data Privacy Act have?
Philippines Data Privacy Act has 36 controls organised across 19 domains. The largest domains are Data Subject Rights (8 controls), Security (4 controls), Sector Specific (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Philippines Data Privacy Act map to?
Philippines Data Privacy Act does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with Philippines Data Privacy Act compliance?
Start your Philippines Data Privacy Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Philippines Data Privacy Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 36 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required