Regulation Finder/Philippines

Philippines

Comprehensive

Data Privacy Act of 2012 (RA 10173)

Authority: National Privacy Commission (NPC) | Enforcement: Active | Enacted: September 2012

Overview

The Philippines was an early adopter of comprehensive data protection in ASEAN. The NPC is an active regulator with enforcement powers. The law applies to all processing of personal information by government and private sector.

14-Topic Coverage

Data Protection Authority

Fully Addressed

NPC has investigation, enforcement, advisory, and public education functions.

Data Subject Rights

Fully Addressed

Rights to be informed, access, object, erasure, rectification, portability, and damages.

Cross-Border Transfer

Fully Addressed

NPC approval or adequate protection in recipient country required.

Breach Notification

Fully Addressed

Must notify NPC and affected data subjects within 72 hours.

DPO Requirements

Fully Addressed

DPO mandatory for all personal information controllers and processors.

Children's Data

Partially Addressed

Parental consent required for children. No specific age threshold in law.

Penalties & Enforcement

Fully Addressed

Fines from PHP 500K to PHP 5 million. Imprisonment from 1 to 6 years. Active enforcement.

Sector-Specific Rules

Fully Addressed

BSP circulars for banking, DOH regulations for health, NTC telecom rules.

AI & Automated Decisions

Not Addressed

No specific provisions. General rights may apply to automated processing.

Data Localisation

Not Addressed

No general localisation requirement.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Fully Addressed

DPA applies to government. Privileged information and exemptions defined.