Law note · Philippines

Data Privacy Act of 2012, cross-border transfer accountability

cite Republic Act No. 10173 (2012), Section 21 stage IN FORCE in force since 2012-08-15 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring the personal information of an individual in the Philippines, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside the country remains accountable for that data and must use contractual or other reasonable means to secure a level of protection comparable to the Act.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_voice
  • processes_biometrics

What we found

Section 21's Principle of Accountability makes a personal information controller responsible for personal information under its control or custody, including data transferred to a third party for processing domestically or internationally, and requires the controller to use contractual or other reasonable means to provide a comparable level of protection while the data is processed abroad.

This is an accountability-based transfer regime rather than an adequacy list or a localization mandate; no data-localization requirement was found.

← Back to the example  ·  Lint your app →