Law / Philippines

Philippines

privacy

The Philippines' comprehensive private-sector data-protection law is the Data Privacy Act of 2012 (Republic Act No. 10173), enforced by the National Privacy Commission (NPC).

Section 3(l)'s enumerated sensitive personal information categories do not name biometric data, and a direct full-text search of the Act for biometric returned zero hits, so a faceprint or voiceprint is regulated under the base Act only as ordinary personal information; two NPC advisories, NPC Advisory No. 2024-04 (on AI systems processing personal data) and NPC Advisory No. 2026-01 (on scraping of publicly available personal data), may extend the Act's reach by regulatory interpretation, but their text was not read this research pass, so their contents are not represented in this document.

Section 21's accountability principle governs cross-border transfer, requiring the controller to use contractual or other reasonable means to secure comparable protection wherever the data goes, with no data-localization mandate found. Section 37 routes an aggrieved data subject's restitution through the general Civil Code rather than a dedicated statutory tort, a lighter mechanism than the purpose-built civil-liability clauses found elsewhere in this research wave.

14 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Data Privacy Act of 2012, breach notification

cite Republic Act No. 10173 (2012), Section 20(f) stage IN FORCE in force since 2012-08-15 binds public and private bodies source National Privacy Commission's official HTML reproduction of the Act
What it requires

Section 20(f) requires a personal information controller to promptly notify the National Privacy Commission and affected data subjects when sensitive personal information, or other information that may enable identity fraud, is reasonably believed to have been acquired by an unauthorized person, where the controller or the Commission believes the acquisition is likely to give rise to a real risk of serious harm.

The Act itself sets no fixed numeric deadline; a fixed 72-hour operational deadline is commonly cited as set by a subordinate NPC Circular, which was not read this pass.

Comprehensive regime

Data Privacy Act of 2012, comprehensive regime and lawful processing criteria

cite Republic Act No. 10173 (2012), Sections 3, 12, 13 stage IN FORCE in force since 2012-08-15 binds public and private bodies source Official Gazette citation
What it requires

The Data Privacy Act of 2012 (Republic Act No. 10173) uses a criteria-based consent model under Section 12 for ordinary personal information, with a stricter standard under Section 13 for sensitive personal information, and adopts personal information controller and personal information processor terminology, a controller and processor style split. The National Privacy Commission (NPC) enforces the Act.

The Official Gazette's own page presented a Cloudflare CAPTCHA that crawler infrastructure correctly stopped on rather than solving, and the NPC's own PDF mirror extracted as a PDF.js viewer render rather than document text; the substantive text for this document was instead read from the NPC's own HTML reproduction of the Act at privacy.gov.ph, with the Official Gazette recorded here as the more authoritative citation.

Cross border transfer

Data Privacy Act of 2012, cross-border transfer accountability

cite Republic Act No. 10173 (2012), Section 21 stage IN FORCE in force since 2012-08-15 binds public and private bodies source National Privacy Commission's official HTML reproduction of the Act
What it requires

Section 21's Principle of Accountability makes a personal information controller responsible for personal information under its control or custody, including data transferred to a third party for processing domestically or internationally, and requires the controller to use contractual or other reasonable means to provide a comparable level of protection while the data is processed abroad.

This is an accountability-based transfer regime rather than an adequacy list or a localization mandate; no data-localization requirement was found.

Data subject rights

Data Privacy Act of 2012, data subject rights

cite Republic Act No. 10173 (2012), Sections 16-18 stage IN FORCE in force since 2012-08-15 binds public and private bodies source National Privacy Commission's official HTML reproduction of the Act
What it requires

Section 16 grants a data subject rights including to be informed, to object, to access, to rectification or correction, to erasure or blocking, and to damages for inaccurate, unlawfully obtained, or unauthorized use of personal information, alongside the right to file a complaint before the Commission. Section 17 makes these rights transmissible to lawful heirs after the data subject's death or incapacity.

Section 18 grants a right to data portability, obtaining personal data in an electronic or structured, commonly used format that allows further use by the data subject; this right was already present in the original 2012 Act, unlike some regimes that added it only by later amendment.

Enforcement supervision

Data Privacy Act of 2012, enforcement and restitution

cite Republic Act No. 10173 (2012), Sections 25-37 stage IN FORCE in force since 2012-08-15 binds public and private bodies source National Privacy Commission's official HTML reproduction of the Act
What it requires

The National Privacy Commission is the supervisory authority, with Chapter VIII (Sections 25-36) setting criminal penalties, including imprisonment and fines, for unauthorized processing, negligent access, improper disposal, unauthorized purposes, unauthorized access due to negligence, malicious disclosure, unauthorized disclosure, and combinations of these acts, scaling with whether sensitive personal information is involved.

Section 37 provides that restitution for any aggrieved party is governed by the general Civil Code, a private civil remedy but one routed through general civil law rather than a freestanding, Data Privacy Act-specific statutory cause of action with its own procedural rules.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.