Law note · Philippines

Data Privacy Act of 2012, comprehensive regime and lawful processing criteria

cite Republic Act No. 10173 (2012), Sections 3, 12, 13 stage IN FORCE in force since 2012-08-15 kind Comprehensive regime binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that processes the personal information of an individual in the Philippines must satisfy one of the Act's lawful-processing criteria, with a stricter, separate standard for sensitive personal information, even though the Act's own sensitive-category list does not name biometric data specifically; a faceprint or voiceprint is still personal information subject to the Act's general processing criteria.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

What we found

The Data Privacy Act of 2012 (Republic Act No. 10173) uses a criteria-based consent model under Section 12 for ordinary personal information, with a stricter standard under Section 13 for sensitive personal information, and adopts personal information controller and personal information processor terminology, a controller and processor style split. The National Privacy Commission (NPC) enforces the Act.

The Official Gazette's own page presented a Cloudflare CAPTCHA that crawler infrastructure correctly stopped on rather than solving, and the NPC's own PDF mirror extracted as a PDF.js viewer render rather than document text; the substantive text for this document was instead read from the NPC's own HTML reproduction of the Act at privacy.gov.ph, with the Official Gazette recorded here as the more authoritative citation.

Primary source

Official Gazette citation
substantive text read from the National Privacy Commission's official HTML reproduction (privacy.gov.ph/data-privacy-act)

← Back to the example  ·  Lint your app →