EnglishTL
Philippines flag

Philippines

Philippines Data Privacy Act of 2012 (RA 10173): Complete Guide (2026)

By Recording Law Editorial TeamReviewed August 20, 202621 min read
Philippines Data Privacy Act of 2012 (RA 10173): Complete Guide (2026)

Frequently Asked Questions

Does the Philippine Data Privacy Act apply to foreign companies?

Yes. The DPA has extraterritorial application. It applies to any organization that processes personal data of individuals in the Philippines, uses equipment located in the Philippines for processing, or maintains an office, branch, or agency in the country. A foreign company with servers, cloud infrastructure, or employees in the Philippines that handles personal data falls within the scope of the DPA even if its headquarters are elsewhere.

What are the administrative fines for data privacy violations in the Philippines?

Under NPC Circular 2022-01, administrative fines range from 0.5% to 3% of annual gross income for grave violations such as processing violations affecting 1,000 or more people, and from 0.25% to 2% for major violations such as security measure failures. Registration and notification failures attract fines of PHP 50,000 to PHP 200,000. Non-compliance with NPC orders draws PHP 20,000 to PHP 50,000 per incident. The total imposable fine for a single act is capped at PHP 5 million.

What is the penalty for failing to report a data breach within 72 hours?

Concealment of a security breach that requires notification is a criminal offense under Section 30 of the DPA: 1 year 6 months to 5 years imprisonment plus a fine of PHP 500,000 to PHP 1,000,000. The NPC can also impose administrative fines under NPC Circular 2022-01 and issue compliance orders, cease and desist orders, or a temporary or permanent processing ban.

Does a small business need to comply with the Data Privacy Act?

Yes. The DPA applies to all natural and juridical persons involved in processing personal information, regardless of size. Mandatory NPC registration applies specifically to organizations employing 250 or more people or processing sensitive personal information of 1,000 or more individuals. Even small businesses that regularly process personal data must appoint a Data Protection Officer, implement appropriate security measures, and honor data subject rights.

Can a data subject in the Philippines request deletion of their personal data?

Yes. Under the Right to Erasure or Blocking in Chapter IV of the DPA, data subjects may demand the blocking, removal, or destruction of their personal data when it is incomplete, outdated, false, unlawfully obtained, being used for unauthorized purposes, or no longer necessary for the original collection purpose. Controllers must act on valid erasure requests promptly and at no cost to the data subject.

How does the Philippines handle cross-border data transfers?

The Philippines maintains no whitelist of approved countries for data transfers. Transfers are assessed case by case. Organizations must conduct a Data Privacy Impact Assessment before transferring data abroad, put in place model contractual clauses or equivalent legal safeguards, and register their data processing systems with the NPC if they process 1,000 or more records. The transferring organization retains full accountability for ensuring the receiving party provides adequate protection.

Is consent obtained through financial incentives valid under Philippine law?

Not reliably. The NPC's October 2025 cease and desist order against Tools for Humanity (World App) established that consent obtained through financial incentives cannot be considered freely given. The DPA requires consent to be freely given, specific, and informed. Where consent is induced by payment or significant benefits, the NPC will scrutinize whether the data subject had a genuine free choice. Organizations relying on consent as a lawful basis should carefully audit whether any form of inducement is present.

Do AI systems need to comply with the Philippine Data Privacy Act?

Yes. NPC Advisory 2024-04, issued December 2024, applies the DPA to AI systems at every stage of their lifecycle including development, training, testing, and deployment. Personal information controllers using AI must provide transparent disclosures to data subjects about AI-based processing, conduct privacy impact assessments before deployment, implement privacy-by-design measures, and ensure AI-generated decisions affecting individuals are explainable.

Updates

Corrected the Tools for Humanity/World App cease and desist order date throughout the article (previously stated as September 2025 / September 23, 2025; confirmed primary-source date is October 8, 2025, per privacy.gov.ph). Clarified the intro paragraph's administrative fines summary to state the full grave (0.5-3%) and major (0.25-2%) percentage ranges and the PHP 5,000,000 aggregate cap, rather than implying 3% is the absolute ceiling. Added a brief section on NPC Circular 2024-02 (CCTV Systems). Added contextual links to the Data Protection Officer Requirements and [GDPR](/world-laws/world-data-privacy-laws) vs. CCPA guides.

Corrected Section 25(b) SPI criminal penalty range in the penalties table: imprisonment is 3-6 years (not 2-7) and fine is PHP 500K-4M (not 500K-2M), per RA 10173 Section 25 as published on lawphil.net.

Major expansion and update: added constitutional basis section, NPC Circular 2022-01 administrative fines detail with graduated-fine table, 2024-2026 NPC developments (Advisory 2024-04 on AI, Circular 2025-01 on body-worn cameras, Advisory 2026-01 on data scraping, Tools for Humanity cease and desist order), expanded cross-border transfers, criminal penalties table, updated compliance checklist, and new FAQ entries on AI and incentivized consent.

Initial publication.

Sources and References

  1. Republic Act No. 10173 -- Data Privacy Act of 2012 (Full Text)(privacy.gov.ph).gov
  2. 1987 Constitution of the Republic of the Philippines -- Article III, Bill of Rights(officialgazette.gov.ph).gov
  3. Implementing Rules and Regulations of RA 10173 (Original, 2016)(officialgazette.gov.ph).gov
  4. Implementing Rules and Regulations of RA 10173 (As Amended, 2023)(privacy.gov.ph).gov
  5. National Privacy Commission -- Powers and Functions(privacy.gov.ph).gov
  6. NPC Circular 2022-01 -- Guidelines on Administrative Fines (August 8, 2022)(privacy.gov.ph).gov
  7. NPC Circular 2022-04 -- Registration of DPO and Data Processing Systems(privacy.gov.ph).gov
  8. NPC Circular 16-03 -- Personal Data Breach Management(privacy.gov.ph).gov
  9. NPC Circular 2023-07 -- Guidelines on Legitimate Interest (December 2023)(privacy.gov.ph).gov
  10. National Privacy Commission -- Appointing a Data Protection Officer(privacy.gov.ph).gov
  11. National Privacy Commission -- Enforcement Decisions(privacy.gov.ph).gov
  12. NPC -- Cease and Desist Order Against Tools for Humanity (World App, September 2025)(privacy.gov.ph).gov
  13. NPC Circular 2025-01 -- Guidelines on Processing Personal Data Collected Using Body-Worn Cameras(privacy.gov.ph).gov
  14. NPC Advisory 2024-04 -- Guidelines on AI Systems Processing Personal Data (December 2024)(privacy.gov.ph).gov
  15. Republic Act No. 10173 -- LawPhil Full Text(lawphil.net)
  16. DLA Piper -- Data Protection Laws of the World: Philippines(dlapiperdataprotection.com)
  17. Baker McKenzie -- Philippines: Regulators, Enforcement Priorities and Penalties(resourcehub.bakermckenzie.com)
  18. National Privacy Commission -- Advisories and Circulars (Index)(privacy.gov.ph).gov
Share: