Criminal penalties
Offences carry imprisonment and fines up to PHP 5M, with penalties falling on responsible officers — this is personal, board-level risk, not just a corporate fine.
The Philippines' data-protection law.
The Philippines Data Privacy Act of 2012 (Republic Act No. 10173), enforced by the National Privacy Commission (NPC) and operationalised by its Implementing Rules and Regulations (IRR), is the country's comprehensive data-protection law. It's organised in practice around the NPC's Five Pillars of Accountability and Compliance.
The standard
Philippines Data Privacy Act of 2012 (RA 10173)
Who needs it
Any organisation that processes the personal data of people in the Philippines — local businesses, BPOs and outsourcing providers, and non-Philippine companies with a Philippine link. Data processing systems meeting NPC thresholds must also register with the NPC.
PHP 5M
max fine + imprisonment
The basics
The DPA is a law you comply with, not a certificate you earn. It sets out data-privacy principles, criteria for lawful processing, data-subject rights, security measures (organizational, physical and technical), breach notification, and accountability — for any personal information controller or processor.
The NPC frames compliance as five pillars: appoint a Data Protection Officer (DPO), conduct a Privacy Impact Assessment (PIA), build a Privacy Management Program and Privacy Manual, implement data-protection measures, and be ready for breaches (a 72-hour NPC and data-subject notification regime).
It applies extraterritorially to processing of Philippine citizens' or residents' data with a Philippine link, and carries criminal penalties — imprisonment and fines up to PHP 5M — for offences, with heavier penalties for sensitive personal information and large-scale breaches.
Why it matters
Offences carry imprisonment and fines up to PHP 5M, with penalties falling on responsible officers — this is personal, board-level risk, not just a corporate fine.
The NPC registers data processing systems, investigates complaints, and can issue compliance and cease-and-desist orders. Non-compliance is actively enforced.
For BPOs and data-intensive businesses, demonstrable DPA compliance is a prerequisite for winning and keeping clients.
Appoint a DPO and register with the NPC; conduct Privacy Impact Assessments.
A Privacy Management Program and Privacy Manual embedding privacy into operations.
Organizational, physical and technical security measures; lawful processing; and data-subject rights.
Breach management with 72-hour notification to the NPC and affected data subjects.
The DPA and its IRR require a documented programme most teams have never built: a DPO, PIA, Privacy Management Program, Privacy Manual, security measures across three dimensions, a 72-hour breach procedure, data sharing and outsourcing agreements, and NPC registration. Standing all of that up — and keeping it evidenced — by hand is the hard part.
Do it once, reuse it everywhere. Evidence you collect for Philippines DPAis automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps Philippines DPA to your environment in a 30-minute walkthrough — and how much of it we handle for you.