Data Privacy Act of 2012 (Philippines)

Asia-PacificPrivacy2012
ByDecipherU Editorial

The Philippines Data Privacy Act (Republic Act No. 10173) is one of the earliest broad data protection laws in Southeast Asia. It established the National Privacy Commission (NPC) as the regulatory authority, codified data subject rights, mandated data protection officers for certain organizations, and imposed breach notification requirements. The law applies to any entity processing personal information of Filipino citizens regardless of location.

Quick Reference

EnactedAugust 15, 2012; Implementing Rules and Regulations effective September 2016
Enforcement BodyNational Privacy Commission (NPC)
PenaltiesFines from PHP 500,000 to PHP 5 million (approximately $9,000 to $90,000); imprisonment from 1 to 6 years; penalties double for certain offenses involving sensitive personal information
Applicable ToNatural and juridical persons processing personal information in the Philippines or of Philippine citizens and residents; entities outside the Philippines processing data of Filipino subjects

Key Requirements

Section 11 (General Data Privacy Principles)

Personal information must be collected for specified legitimate purposes, processed fairly and lawfully, and be accurate, relevant, and not excessive

Section 20 (Breach Notification)

Personal information controllers must notify the NPC and affected data subjects within 72 hours upon knowledge of or reasonable belief that a personal data breach has occurred

NPC Circular 2016-03 (Data Protection Officers)

All personal information controllers and processors must designate a Data Protection Officer to monitor compliance and serve as the contact for data subjects and the NPC

How Does Philippines DPA Affect Cybersecurity Careers?

The Philippines is a major hub for business process outsourcing (BPO), including many cybersecurity-related services. Privacy professionals at BPO companies must ensure client data is protected under the DPA. The NPC's active enforcement posture (hundreds of cases investigated annually) makes compliance roles essential. The law's extraterritorial reach means global companies serving Filipino customers must comply.

Cybersecurity Roles That Work With Philippines DPA

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of Philippines DPA at the official source: https://www.privacy.gov.ph/data-privacy-act/

Frequently Asked Questions

The Philippines Data Privacy Act (Republic Act No. 10173) is one of the earliest broad data protection laws in Southeast Asia. It established the National Privacy Commission (NPC) as the regulatory authority, codified data subject rights, mandated data protection officers for certain organizations, and imposed breach notification requirements. The law applies to any entity processing personal information of Filipino citizens regardless of location.

The Philippines is a major hub for business process outsourcing (BPO), including many cybersecurity-related services. Privacy professionals at BPO companies must ensure client data is protected under the DPA. The NPC's active enforcement posture (hundreds of cases investigated annually) makes compliance roles essential. The law's extraterritorial reach means global companies serving Filipino customers must comply.

Fines from PHP 500,000 to PHP 5 million (approximately $9,000 to $90,000); imprisonment from 1 to 6 years; penalties double for certain offenses involving sensitive personal information

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?