WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Asia-Pacific

Philippines Privacy & Data Protection Laws

Every regime below can apply to a business handling Philippines residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

September 8, 2012 (Act); IRR effective September 9, 2016
Data Privacy Act of 2012
Philippines DPA
Verify details

Section 6 gives the Act unusually explicit extraterritorial reach for its vintage: it applies to acts done or practices engaged in outside the Philippines where the entity has a link to the Philippines and processes personal information about Philippine citizens or residents — with 'link' illustrated by having a Philippine office, branch or agency, being a Philippine-incorporated entity, or using equipment located in the Philippines. Section 4 exempts, among other things, information about government officials in their official capacity, journalistic/artistic/literary purposes, research, and certain regulatory and foreign-jurisdiction processing. The National Privacy Commission requires registration of data processing systems by qualifying controllers, appointment of a Data Protection Officer, breach notification within 72 hours, and privacy impact assessments; criminal penalties attach to several violations, which is a meaningfully different risk profile from purely administrative regimes.

Republic Act No. 10173, ss. 4, 6 (scope and extraterritorial application); IRR (2016)Read regulation →

Cross-Border Data Transfer · 1

September 8, 2012 (Act); NPC Advisory No. 2024-01 from May 2024
Data Privacy Act of 2012 — accountability for cross-border transfers
PH DPA s. 21

Like Canada and Australia, the Philippines uses accountability rather than prohibition. s. 21 makes the personal information controller responsible for personal information under its control or custody, including information transferred to a third party for processing whether domestically or internationally, and requires contractual or other reasonable means to provide a COMPARABLE level of protection while the third party processes it. There is no adequacy list and no filing. The practical route is the one the NPC supplied in Advisory No. 2024-01, which published Model Contractual Clauses that controllers and processors may build into their agreements — voluntary templates rather than a mandated instrument, but the clearest available evidence of comparable protection. Note the Philippines also distinguishes data sharing from outsourcing, each with its own agreement requirements under the Act's implementing rules.

Republic Act No. 10173, s. 21 (Principle of Accountability); NPC Advisory No. 2024-01 on Contractual Clauses for Cross-Border Transfers (issued May 30, 2024)Read regulation →

Data Security & Breach Notification · 1

September 8, 2012 (Act); NPC Circular 16-03 issued December 15, 2016
Data Privacy Act of 2012 — personal data breach notification
PH DPA s. 20(f)

The statutory trigger is narrow and specific: notification is owed where sensitive personal information, or information that could enable identity fraud, is reasonably believed to have been acquired by an unauthorized person AND the acquisition is likely to give rise to a real risk of serious harm. Where it applies, NPC Circular 16-03 gives 72 hours from knowledge or reasonable belief to notify BOTH the National Privacy Commission and the affected data subjects — the Philippines does not split the two onto different clocks or different thresholds the way the GDPR does. Delay is permitted only to determine scope, prevent further disclosure, or restore system integrity, and is not permitted at all where at least 100 data subjects are affected or where disclosing the sensitive personal information will harm the data subject.

Republic Act No. 10173, s. 20(f); NPC Circular 16-03 on Personal Data Breach ManagementRead regulation →

Other Asia-Pacific jurisdictions