All resources
Playbook 10 min read

The Philippines Data Privacy Act (RA 10173): a compliance playbook

C1The Compliance One team27 August 2026

The Philippines' Data Privacy Act of 2012 (Republic Act No. 10173) is not a certification you earn — it's a law you comply with, enforced by the National Privacy Commission (NPC) and detailed in its Implementing Rules and Regulations. It matters more than many teams assume: offences carry imprisonment and fines up to PHP 5 million, penalties fall on responsible officers personally, and the NPC actively investigates complaints and issues compliance orders.

Who's in scope

The DPA covers any organisation that processes the personal data of people in the Philippines — local businesses, the country's huge BPO and outsourcing sector, and non-Philippine companies with a Philippine link. Data processing systems that meet NPC thresholds (for example, 250+ employees, or processing sensitive personal information of 1,000+ individuals) must also register with the NPC.

The NPC Five Pillars — the order that works

The NPC frames compliance as five pillars, and they double as a build sequence:

  • 1. Commit to comply — appoint a Data Protection Officer (DPO) and register with the NPC. Everything else reports up to this role.
  • 2. Know your risk — conduct a Privacy Impact Assessment (PIA) for your key processing, so you build only what your risk demands.
  • 3. Be accountable — create a Privacy Management Program and a Privacy Manual that embed privacy into day-to-day operations.
  • 4. Demonstrate compliance — implement the organizational, physical and technical security measures, uphold data-subject rights, and govern data sharing and outsourcing.
  • 5. Be prepared for breach — stand up a breach-response procedure that can notify the NPC and affected individuals within 72 hours of knowing about a notifiable breach.

The 72-hour clock

The breach-notification rule is the one that catches teams out. Once you know, or reasonably believe, that a notifiable personal-data breach has occurred, you have 72 hours to notify the NPC and the affected data subjects, with prescribed contents and a follow-up breach report. That's not a lot of time to assess scope, contain, and communicate — which is exactly why the procedure has to exist before you need it, not after.

How Compliance One helps

Compliance One ships the full DPA and NPC IRR control library (Rules IV–XII) organised on the Five Pillars, enabled by default, with a promote-to-Statement-of-Applicability model for the parts that only apply to some organisations (for example, the government-sector rules). Every mandatory document is pre-filled — DPO designation, PIA, Privacy Management Program, Privacy Manual, privacy notice, security policy, breach-response procedure, data-sharing and outsourcing agreements, and the NPC registration pack.

Because the DPA is a close cousin of Singapore's PDPA and DPTM, and cross-maps to ISO 27001 and SOC 2 Privacy, a regional programme shares most of its evidence — capture it once, satisfy the Philippines, Singapore and your international frameworks together. And the platform tracks the 72-hour breach clock and the NPC registration thresholds so nothing slips.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.