Cross-Border Data Transfer
Data Privacy Act of 2012 — accountability for cross-border transfers
Philippines · September 8, 2012 (Act); NPC Advisory No. 2024-01 from May 2024
Like Canada and Australia, the Philippines uses accountability rather than prohibition. s. 21 makes the personal information controller responsible for personal information under its control or custody, including information transferred to a third party for processing whether domestically or internationally, and requires contractual or other reasonable means to provide a COMPARABLE level of protection while the third party processes it. There is no adequacy list and no filing. The practical route is the one the NPC supplied in Advisory No. 2024-01, which published Model Contractual Clauses that controllers and processors may build into their agreements — voluntary templates rather than a mandated instrument, but the clearest available evidence of comparable protection. Note the Philippines also distinguishes data sharing from outsourcing, each with its own agreement requirements under the Act's implementing rules.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.