Comprehensive Privacy Law
Data Privacy Act of 2012
Philippines · September 8, 2012 (Act); IRR effective September 9, 2016
Verify detailsSection 6 gives the Act unusually explicit extraterritorial reach for its vintage: it applies to acts done or practices engaged in outside the Philippines where the entity has a link to the Philippines and processes personal information about Philippine citizens or residents — with 'link' illustrated by having a Philippine office, branch or agency, being a Philippine-incorporated entity, or using equipment located in the Philippines. Section 4 exempts, among other things, information about government officials in their official capacity, journalistic/artistic/literary purposes, research, and certain regulatory and foreign-jurisdiction processing. The National Privacy Commission requires registration of data processing systems by qualifying controllers, appointment of a Data Protection Officer, breach notification within 72 hours, and privacy impact assessments; criminal penalties attach to several violations, which is a meaningfully different risk profile from purely administrative regimes.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.