WorldPrivacyAtlas
Laws by country

Comprehensive Privacy Law

Data Privacy Act of 2012

Philippines DPA

Philippines · September 8, 2012 (Act); IRR effective September 9, 2016

Verify details

Section 6 gives the Act unusually explicit extraterritorial reach for its vintage: it applies to acts done or practices engaged in outside the Philippines where the entity has a link to the Philippines and processes personal information about Philippine citizens or residents — with 'link' illustrated by having a Philippine office, branch or agency, being a Philippine-incorporated entity, or using equipment located in the Philippines. Section 4 exempts, among other things, information about government officials in their official capacity, journalistic/artistic/literary purposes, research, and certain regulatory and foreign-jurisdiction processing. The National Privacy Commission requires registration of data processing systems by qualifying controllers, appointment of a Data Protection Officer, breach notification within 72 hours, and privacy impact assessments; criminal penalties attach to several violations, which is a meaningfully different risk profile from purely administrative regimes.

Republic Act No. 10173, ss. 4, 6 (scope and extraterritorial application); IRR (2016)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.