Philippines Data Privacy Act
The Philippines Data Privacy Act of 2012, Republic Act No. 10173, with the National Privacy Commission's Implementing Rules and Regulations of 2016: processing on the principles of transparency, legitimate purpose and proportionality with six lawful criteria and a prohibition on sensitive and privileged information subject to six exceptions; the rights to be informed, to access, to rectification, to erasure or blocking, to damages, to portability and, under the IRR, to object; reasonable and appropriate organizational, physical and technical security measures with four statutory minimums, confidentiality of personnel, and notification of the Commission and data subjects of breaches likely to cause serious harm within 72 hours; accountability for transfers by contractual or other means and a designated accountable individual; security clearances, off-site access limits and encryption for sensitive personal information in government; and, under the IRR, records of processing, data sharing agreements, outsourcing contract terms, registration of processing systems (250 staff or 1,000 sensitive records), notification of solely automated decisions and an annual breach summary. Eight criminal offences with imprisonment and fines, enforced by the National Privacy Commission.
Philippines Data Privacy Act is a compliance framework from Philippines with 6 domains and 30 controls. The largest domains are Chapter IV: Rights of the data subject – Philippines Data Privacy Act (8 controls), Chapter V: Security of personal information – Philippines Data Privacy Act (8 controls), Chapter III: Processing of personal information – Philippines Data Privacy Act (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Chapter III: Processing of personal information – Philippines Data Privacy Act
| Code | Title |
|---|---|
| philippines-data-privacy-act::11 | General data privacy principles: transparency, legitimate purpose, proportionality |
| philippines-data-privacy-act::12 | Criteria for lawful processing of personal information |
| philippines-data-privacy-act::13 | Sensitive personal information and privileged information |
| philippines-data-privacy-act::R.19 | IRR section 19: consent, collection, data quality, retention and secure disposal |
| philippines-data-privacy-act::R.20 | IRR section 20: data sharing and data sharing agreements |
Chapter IV: Rights of the data subject – Philippines Data Privacy Act
| Code | Title |
|---|---|
| philippines-data-privacy-act::16(a)-(b) | Right to be informed and the information to be furnished before processing |
| philippines-data-privacy-act::16(c) | Right to reasonable access |
| philippines-data-privacy-act::16(d) | Right to dispute inaccuracy and have it corrected |
| philippines-data-privacy-act::16(e) | Right to suspend, withdraw, block, remove or destroy personal information |
| philippines-data-privacy-act::16(f) | Right to be indemnified for damages |
| philippines-data-privacy-act::17 | Transmissibility of the data subject's rights |
| philippines-data-privacy-act::18 | Right to data portability |
| philippines-data-privacy-act::R.34 | IRR section 34(b): right to object |
Chapter V: Security of personal information – Philippines Data Privacy Act
| Code | Title |
|---|---|
| philippines-data-privacy-act::20(a)-(c) | Reasonable and appropriate organizational, physical and technical security measures |
| philippines-data-privacy-act::20(d) | Security measures by third-party processors |
| philippines-data-privacy-act::20(e) | Confidentiality of personnel processing personal information |
| philippines-data-privacy-act::20(f) | Notification of the Commission and affected data subjects of a personal data breach |
| philippines-data-privacy-act::R.26 | IRR section 26: organizational security measures |
| philippines-data-privacy-act::R.27 | IRR section 27: physical security measures |
| philippines-data-privacy-act::R.28 | IRR section 28: technical security measures |
| philippines-data-privacy-act::R.41 | IRR section 41: breach report to the Commission, documentation of all incidents and the annual summary |
Chapter VI: Accountability for transfer of personal information and subcontracting – Philippines Data Privacy Act
| Code | Title |
|---|---|
| philippines-data-privacy-act::14 | Subcontract of personal information |
| philippines-data-privacy-act::21(a) | Accountability for transferred personal information: comparable protection |
| philippines-data-privacy-act::21(b) | Designated individual accountable for compliance (Data Protection Officer) |
| philippines-data-privacy-act::R.44 | IRR section 44: contents of agreements for outsourcing to a personal information processor |
Chapter VII: Security of sensitive personal information in government – Philippines Data Privacy Act
| Code | Title |
|---|---|
| philippines-data-privacy-act::22 | Responsibility of heads of government agencies for sensitive personal information |
| philippines-data-privacy-act::23 | Access by agency personnel to sensitive personal information: on-site, online and off-site |
| philippines-data-privacy-act::24 | Applicability to government contractors |
IRR Rule XI: Registration and compliance requirements – Philippines Data Privacy Act
| Code | Title |
|---|---|
| philippines-data-privacy-act::R.47 | IRR section 47: registration of personal data processing systems |
| philippines-data-privacy-act::R.48 | IRR section 48: notification of automated processing operations and decisions based solely on them |
What is Philippines Data Privacy Act and who does it apply to?
Philippines Data Privacy Act is a compliance framework from Philippines with 6 domains and 30 controls. The Philippines Data Privacy Act of 2012, Republic Act No. 10173, with the National Privacy Commission's Implementing Rules and Regulations of 2016: processing on the principles of transparency, legitimate purpose and proportionality with six lawful criteria and a prohibition on sensitive and privileged information subject to six exceptions; the rights to be informed, to access, to rectification, to erasure or blocking, to damages, to portability and, under the IRR, to object; reasonable and appropriate organizational, physical and technical security measures with four statutory minimums, confidentiality of personnel, and notification of the Commission and data subjects of breaches likely to cause serious harm within 72 hours; accountability for transfers by contractual or other means and a designated accountable individual; security clearances, off-site access limits and encryption for sensitive personal information in government; and, under the IRR, records of processing, data sharing agreements, outsourcing contract terms, registration of processing systems (250 staff or 1,000 sensitive records), notification of solely automated decisions and an annual breach summary. Eight criminal offences with imprisonment and fines, enforced by the National Privacy Commission. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Philippines Data Privacy Act actually require?
Philippines Data Privacy Act has 30 controls organised across 6 domains. The largest domains are Chapter IV: Rights of the data subject – Philippines Data Privacy Act (8 controls), Chapter V: Security of personal information – Philippines Data Privacy Act (8 controls), Chapter III: Processing of personal information – Philippines Data Privacy Act (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Philippines Data Privacy Act do I already cover?
Philippines Data Privacy Act does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement Philippines Data Privacy Act?
Start your Philippines Data Privacy Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Philippines Data Privacy Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required