Back to Frameworks

Philippines Data Privacy Act

Philippines
19 domains
36 controls

Philippines Data Privacy Act of 2012 (RA 10173) + IRR 2016 + NPC circulars.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (19)

Breach

2 controls
Controls in the Breach domain of Philippines Data Privacy Act2 controls
CodeTitle
NPC-16-03-BMTBreach Management Team and Procedures
NPC-16-03-BREACHPersonal Data Breach Notification

Cross-border Transfers

1 controls
Controls in the Cross-border Transfers domain of Philippines Data Privacy Act1 controls
CodeTitle
RA10173-S21Principle of Accountability for Cross-Border Transfers

DPIA

1 controls
Controls in the DPIA domain of Philippines Data Privacy Act1 controls
CodeTitle
NPC-18-02-PIAPrivacy Impact Assessment

Data Subject Rights

8 controls
Controls in the Data Subject Rights domain of Philippines Data Privacy Act8 controls
CodeTitle
NPC-18-01-RIGHTSExercise of Data Subject Rights Procedure
RA10173-S16-ARight to be Informed
RA10173-S16-BRight to Access
RA10173-S16-CRight to Object
RA10173-S16-DRight to Erasure or Blocking
RA10173-S16-ERight to Damages
RA10173-S18Right to Data Portability
RA10173-S19Non-Applicability and Filing of Complaints

Enforcement

2 controls
Controls in the Enforcement domain of Philippines Data Privacy Act2 controls
CodeTitle
RA10173-S22-25Penalties: Unauthorized Processing and Access
RA10173-S34-LARGELarge-Scale or Sensitive Information Aggravated Penalties

Exemptions

1 controls
Controls in the Exemptions domain of Philippines Data Privacy Act1 controls
CodeTitle
NPC-RESEARCHResearch Exemption Conditions

Governance

2 controls
Controls in the Governance domain of Philippines Data Privacy Act2 controls
CodeTitle
IRR-S26-PRIVACY-MANUALPrivacy Management Program and Manual
NPC-16-01-DPOMandatory Designation of Data Protection Officer

HR

1 controls
Controls in the HR domain of Philippines Data Privacy Act1 controls
CodeTitle
NPC-EMPLOYEEEmployee Personal Data Processing

Lawful Basis

2 controls
Controls in the Lawful Basis domain of Philippines Data Privacy Act2 controls
CodeTitle
RA10173-S12Criteria for Lawful Processing of Personal Information
RA10173-S13Sensitive Personal Information and Privileged Information

Marketing

1 controls
Controls in the Marketing domain of Philippines Data Privacy Act1 controls
CodeTitle
NPC-DIRECT-MARKETINGDirect Marketing Restrictions

Online

1 controls
Controls in the Online domain of Philippines Data Privacy Act1 controls
CodeTitle
NPC-COOKIESCookies and Online Tracking

Principles

1 controls
Controls in the Principles domain of Philippines Data Privacy Act1 controls
CodeTitle
RA10173-S11General Data Privacy Principles

Registration

1 controls
Controls in the Registration domain of Philippines Data Privacy Act1 controls
CodeTitle
NPC-17-01-DPSRegistration of Data Processing Systems with NPC

Regulator

1 controls
Controls in the Regulator domain of Philippines Data Privacy Act1 controls
CodeTitle
RA10173-S7-NPCNational Privacy Commission Authority

Retention

1 controls
Controls in the Retention domain of Philippines Data Privacy Act1 controls
CodeTitle
IRR-S37-RETENTIONData Retention and Disposal

Sector Specific

3 controls
Controls in the Sector Specific domain of Philippines Data Privacy Act3 controls
CodeTitle
NPC-BPO-SECTORBPO and KPO Sector Compliance
NPC-GOV-AGENCIESGovernment Agencies Specific Obligations
NPC-HEALTH-SECTORHealth Sector Personal Data Protections

Security

4 controls
Controls in the Security domain of Philippines Data Privacy Act4 controls
CodeTitle
IRR-S38-ACCESS-LOGSAccess and Activity Logging
RA10173-S20-ASecurity of Personal Information: Organizational Measures
RA10173-S20-BSecurity of Personal Information: Physical Measures
RA10173-S20-CSecurity of Personal Information: Technical Measures

Special Categories

1 controls
Controls in the Special Categories domain of Philippines Data Privacy Act1 controls
CodeTitle
IRR-S25-CHILDRENProcessing of Personal Information of Minors

Third Parties

2 controls
Controls in the Third Parties domain of Philippines Data Privacy Act2 controls
CodeTitle
IRR-S26-PROCESSORSPersonal Information Processors Contracts
NPC-OUTSOURCINGOutsourcing and Subcontracting Agreements

Frequently Asked Questions

What is Philippines Data Privacy Act?

Philippines Data Privacy Act is a compliance framework from Philippines with 19 domains and 36 controls. Philippines Data Privacy Act of 2012 (RA 10173) + IRR 2016 + NPC circulars. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Philippines Data Privacy Act have?

Philippines Data Privacy Act has 36 controls organised across 19 domains. The largest domains are Data Subject Rights (8 controls), Security (4 controls), Sector Specific (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Philippines Data Privacy Act map to?

Philippines Data Privacy Act does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Philippines Data Privacy Act compliance?

Start your Philippines Data Privacy Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Philippines Data Privacy Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 36 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required