Back to Frameworks

Philippines Data Privacy Act

Philippines
vRA 10173 (2012); IRR of 24 August 2016
6 domains
30 controls

The Philippines Data Privacy Act of 2012, Republic Act No. 10173, with the National Privacy Commission's Implementing Rules and Regulations of 2016: processing on the principles of transparency, legitimate purpose and proportionality with six lawful criteria and a prohibition on sensitive and privileged information subject to six exceptions; the rights to be informed, to access, to rectification, to erasure or blocking, to damages, to portability and, under the IRR, to object; reasonable and appropriate organizational, physical and technical security measures with four statutory minimums, confidentiality of personnel, and notification of the Commission and data subjects of breaches likely to cause serious harm within 72 hours; accountability for transfers by contractual or other means and a designated accountable individual; security clearances, off-site access limits and encryption for sensitive personal information in government; and, under the IRR, records of processing, data sharing agreements, outsourcing contract terms, registration of processing systems (250 staff or 1,000 sensitive records), notification of solely automated decisions and an annual breach summary. Eight criminal offences with imprisonment and fines, enforced by the National Privacy Commission.

Verified

Philippines Data Privacy Act is a compliance framework from Philippines with 6 domains and 30 controls. The largest domains are Chapter IV: Rights of the data subject – Philippines Data Privacy Act (8 controls), Chapter V: Security of personal information – Philippines Data Privacy Act (8 controls), Chapter III: Processing of personal information – Philippines Data Privacy Act (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Chapter III: Processing of personal information – Philippines Data Privacy Act

5 controls
Controls in the Chapter III: Processing of personal information – Philippines Data Privacy Act domain of Philippines Data Privacy Act — 5 controls
CodeTitle
philippines-data-privacy-act::11General data privacy principles: transparency, legitimate purpose, proportionality
philippines-data-privacy-act::12Criteria for lawful processing of personal information
philippines-data-privacy-act::13Sensitive personal information and privileged information
philippines-data-privacy-act::R.19IRR section 19: consent, collection, data quality, retention and secure disposal
philippines-data-privacy-act::R.20IRR section 20: data sharing and data sharing agreements

Chapter IV: Rights of the data subject – Philippines Data Privacy Act

8 controls
Controls in the Chapter IV: Rights of the data subject – Philippines Data Privacy Act domain of Philippines Data Privacy Act — 8 controls
CodeTitle
philippines-data-privacy-act::16(a)-(b)Right to be informed and the information to be furnished before processing
philippines-data-privacy-act::16(c)Right to reasonable access
philippines-data-privacy-act::16(d)Right to dispute inaccuracy and have it corrected
philippines-data-privacy-act::16(e)Right to suspend, withdraw, block, remove or destroy personal information
philippines-data-privacy-act::16(f)Right to be indemnified for damages
philippines-data-privacy-act::17Transmissibility of the data subject's rights
philippines-data-privacy-act::18Right to data portability
philippines-data-privacy-act::R.34IRR section 34(b): right to object

Chapter V: Security of personal information – Philippines Data Privacy Act

8 controls
Controls in the Chapter V: Security of personal information – Philippines Data Privacy Act domain of Philippines Data Privacy Act — 8 controls
CodeTitle
philippines-data-privacy-act::20(a)-(c)Reasonable and appropriate organizational, physical and technical security measures
philippines-data-privacy-act::20(d)Security measures by third-party processors
philippines-data-privacy-act::20(e)Confidentiality of personnel processing personal information
philippines-data-privacy-act::20(f)Notification of the Commission and affected data subjects of a personal data breach
philippines-data-privacy-act::R.26IRR section 26: organizational security measures
philippines-data-privacy-act::R.27IRR section 27: physical security measures
philippines-data-privacy-act::R.28IRR section 28: technical security measures
philippines-data-privacy-act::R.41IRR section 41: breach report to the Commission, documentation of all incidents and the annual summary

Chapter VI: Accountability for transfer of personal information and subcontracting – Philippines Data Privacy Act

4 controls
Controls in the Chapter VI: Accountability for transfer of personal information and subcontracting – Philippines Data Privacy Act domain of Philippines Data Privacy Act — 4 controls
CodeTitle
philippines-data-privacy-act::14Subcontract of personal information
philippines-data-privacy-act::21(a)Accountability for transferred personal information: comparable protection
philippines-data-privacy-act::21(b)Designated individual accountable for compliance (Data Protection Officer)
philippines-data-privacy-act::R.44IRR section 44: contents of agreements for outsourcing to a personal information processor

Chapter VII: Security of sensitive personal information in government – Philippines Data Privacy Act

3 controls
Controls in the Chapter VII: Security of sensitive personal information in government – Philippines Data Privacy Act domain of Philippines Data Privacy Act — 3 controls
CodeTitle
philippines-data-privacy-act::22Responsibility of heads of government agencies for sensitive personal information
philippines-data-privacy-act::23Access by agency personnel to sensitive personal information: on-site, online and off-site
philippines-data-privacy-act::24Applicability to government contractors

IRR Rule XI: Registration and compliance requirements – Philippines Data Privacy Act

2 controls
Controls in the IRR Rule XI: Registration and compliance requirements – Philippines Data Privacy Act domain of Philippines Data Privacy Act — 2 controls
CodeTitle
philippines-data-privacy-act::R.47IRR section 47: registration of personal data processing systems
philippines-data-privacy-act::R.48IRR section 48: notification of automated processing operations and decisions based solely on them

What is Philippines Data Privacy Act and who does it apply to?

Philippines Data Privacy Act is a compliance framework from Philippines with 6 domains and 30 controls. The Philippines Data Privacy Act of 2012, Republic Act No. 10173, with the National Privacy Commission's Implementing Rules and Regulations of 2016: processing on the principles of transparency, legitimate purpose and proportionality with six lawful criteria and a prohibition on sensitive and privileged information subject to six exceptions; the rights to be informed, to access, to rectification, to erasure or blocking, to damages, to portability and, under the IRR, to object; reasonable and appropriate organizational, physical and technical security measures with four statutory minimums, confidentiality of personnel, and notification of the Commission and data subjects of breaches likely to cause serious harm within 72 hours; accountability for transfers by contractual or other means and a designated accountable individual; security clearances, off-site access limits and encryption for sensitive personal information in government; and, under the IRR, records of processing, data sharing agreements, outsourcing contract terms, registration of processing systems (250 staff or 1,000 sensitive records), notification of solely automated decisions and an annual breach summary. Eight criminal offences with imprisonment and fines, enforced by the National Privacy Commission. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Philippines Data Privacy Act actually require?

Philippines Data Privacy Act has 30 controls organised across 6 domains. The largest domains are Chapter IV: Rights of the data subject – Philippines Data Privacy Act (8 controls), Chapter V: Security of personal information – Philippines Data Privacy Act (8 controls), Chapter III: Processing of personal information – Philippines Data Privacy Act (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Philippines Data Privacy Act do I already cover?

Philippines Data Privacy Act does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement Philippines Data Privacy Act?

Start your Philippines Data Privacy Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Philippines Data Privacy Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required