Philippines Data Privacy Act (RA 10173)
The Data Privacy Act of 2012 (Republic Act No. 10173) is the Philippines' comprehensive data protection law. It protects individual personal information in information and communications systems in the government and private sector. Administered by the National Privacy Commission (NPC), it establishes rights of data subjects, obligations of personal information controllers and processors, and penalties for violations.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (14)
Awareness
| Code | Title |
|---|---|
| PH-DPA-13 | Employee Privacy Training |
Controller/Processor Obligations and Enforcement
Security requirements, DPO, NPC enforcement
| Code | Title |
|---|---|
| PH-DPA-OB-01 | Security Measures |
| PH-DPA-OB-02 | Data Protection Officer |
| PH-DPA-OB-03 | Breach Notification |
| PH-DPA-OB-04 | NPC Registration and Compliance |
| PH-DPA-OB-05 | Penalties for Violations |
Data Lifecycle
| Code | Title |
|---|---|
| PH-DPA-10 | Retention and Disposal |
Data Processing Principles and Requirements
General principles and lawful processing criteria
| Code | Title |
|---|---|
| PH-DPA-PR-01 | General Data Privacy Principles |
| PH-DPA-PR-02 | Criteria for Lawful Processing |
| PH-DPA-PR-03 | Sensitive Personal Information |
| PH-DPA-PR-04 | Privileged Information |
Data Subject Rights
| Code | Title |
|---|---|
| PH-DPA-05 | Lawful Basis and Consent Management |
| PH-DPA-06 | Data Subject Rights Fulfilment |
| PH-DPA-11 | Privacy Notices and Transparency |
| PH-DPA-14 | Direct Marketing and Cookies |
Data Transfers
| Code | Title |
|---|---|
| PH-DPA-09 | Cross-Border Transfer Controls |
Governance
| Code | Title |
|---|---|
| PH-DPA-01 | Appointment of Data Protection Officer (DPO) |
| PH-DPA-04 | Privacy Management Programme (PMP) |
| PH-DPA-17 | Accountability and Records of Processing |
Incident Management
| Code | Title |
|---|---|
| PH-DPA-08 | Personal Data Breach Notification |
Information Security
| Code | Title |
|---|---|
| PH-DPA-07 | Security of Personal Data |
| PH-DPA-16 | Logs and Monitoring |
Regulatory Compliance
| Code | Title |
|---|---|
| PH-DPA-02 | Registration of Data Processing Systems with NPC |
Rights of Data Subjects
Individual rights under the Data Privacy Act
| Code | Title |
|---|---|
| PH-DPA-RS-01 | Right to Be Informed |
| PH-DPA-RS-02 | Right to Access |
| PH-DPA-RS-03 | Right to Rectification and Erasure |
| PH-DPA-RS-04 | Right to Damages and Data Portability |
Risk Management
| Code | Title |
|---|---|
| PH-DPA-03 | Privacy Impact Assessment (PIA) |
Special Categories
| Code | Title |
|---|---|
| PH-DPA-15 | Children's Personal Data |
Third Party Management
| Code | Title |
|---|---|
| PH-DPA-12 | Vendor and Processor Management |
Your Compliance Coverage
If you comply with Philippines Data Privacy Act (RA 10173), you already cover:
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
50%
15 controls mapped
Compare →Azure Security Benchmark
47%
14 controls mapped
Compare →EU Digital Markets Act
47%
14 controls mapped
Compare →+ 572 more: NIST SP 800-122 (43%), FAA Cybersecurity Framework for Aviation (43%)
See all 575 mapped frameworks ↓Maps to 575 other frameworks
Frequently Asked Questions
What is Philippines Data Privacy Act (RA 10173)?
Philippines Data Privacy Act (RA 10173) is a compliance framework from Philippines with 14 domains and 30 controls. The Data Privacy Act of 2012 (Republic Act No. 10173) is the Philippines' comprehensive data protection law. It protects individual personal information in information and communications systems in the government and private sector. Administered by the National Privacy Commission (NPC), it establishes rights of data subjects, obligations of personal information controllers and processors, and penalties for violations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Philippines Data Privacy Act (RA 10173) have?
Philippines Data Privacy Act (RA 10173) has 30 controls organised across 14 domains. The largest domains are Controller/Processor Obligations and Enforcement (5 controls), Data Processing Principles and Requirements (4 controls), Data Subject Rights (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Philippines Data Privacy Act (RA 10173) map to?
Philippines Data Privacy Act (RA 10173) maps to 575 other compliance frameworks. The top mapping partners are CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 (50% coverage), Azure Security Benchmark (47% coverage), EU Digital Markets Act (47% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Philippines Data Privacy Act (RA 10173) compliance?
Start your Philippines Data Privacy Act (RA 10173) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Philippines Data Privacy Act (RA 10173) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required