Philippines
ComprehensiveData Privacy Act of 2012 (RA 10173)
Authority: National Privacy Commission (NPC) | Enforcement: Active | Enacted: September 2012
Overview
The Philippines was an early adopter of comprehensive data protection in ASEAN. The NPC is an active regulator with enforcement powers. The law applies to all processing of personal information by government and private sector.
14-Topic Coverage
Data Protection Authority
Fully AddressedNPC has investigation, enforcement, advisory, and public education functions.
Consent Requirements
Fully AddressedConsent or other legitimate criteria required. Consent must be freely given, specific, and informed.
Data Subject Rights
Fully AddressedRights to be informed, access, object, erasure, rectification, portability, and damages.
Cross-Border Transfer
Fully AddressedNPC approval or adequate protection in recipient country required.
Breach Notification
Fully AddressedMust notify NPC and affected data subjects within 72 hours.
DPO Requirements
Fully AddressedDPO mandatory for all personal information controllers and processors.
Children's Data
Partially AddressedParental consent required for children. No specific age threshold in law.
Penalties & Enforcement
Fully AddressedFines from PHP 500K to PHP 5 million. Imprisonment from 1 to 6 years. Active enforcement.
Sector-Specific Rules
Fully AddressedBSP circulars for banking, DOH regulations for health, NTC telecom rules.
Cookie/Tracking
Not AddressedNo specific cookie regulation.
AI & Automated Decisions
Not AddressedNo specific provisions. General rights may apply to automated processing.
Data Localisation
Not AddressedNo general localisation requirement.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Fully AddressedDPA applies to government. Privileged information and exemptions defined.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Philippines's regulations.
Book a Consultation