Law note · Philippines
Data Privacy Act of 2012, comprehensive regime and lawful processing criteria
What it requires
- An app that processes the personal information of an individual in the Philippines must satisfy one of the Act's lawful-processing criteria, with a stricter, separate standard for sensitive personal information, even though the Act's own sensitive-category list does not name biometric data specifically; a faceprint or voiceprint is still personal information subject to the Act's general processing criteria.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
What we found
The Data Privacy Act of 2012 (Republic Act No. 10173) uses a criteria-based consent model under Section 12 for ordinary personal information, with a stricter standard under Section 13 for sensitive personal information, and adopts personal information controller and personal information processor terminology, a controller and processor style split. The National Privacy Commission (NPC) enforces the Act.
The Official Gazette's own page presented a Cloudflare CAPTCHA that crawler infrastructure correctly stopped on rather than solving, and the NPC's own PDF mirror extracted as a PDF.js viewer render rather than document text; the substantive text for this document was instead read from the NPC's own HTML reproduction of the Act at privacy.gov.ph, with the Official Gazette recorded here as the more authoritative citation.
Primary source
Official Gazette citation
substantive text read from the National Privacy Commission's official HTML reproduction (privacy.gov.ph/data-privacy-act)