Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
What it requires →
Section 20(f) requires a personal information controller to promptly notify the National Privacy Commission and affected data subjects when sensitive personal information, or other information that may enable identity fraud, is reasonably believed to have been acquired by an unauthorized person, where the controller or the Commission believes the acquisition is likely to give rise to a real risk of serious harm.
The Act itself sets no fixed numeric deadline; a fixed 72-hour operational deadline is commonly cited as set by a subordinate NPC Circular, which was not read this pass.
Comprehensive regime
What it requires →
The Data Privacy Act of 2012 (Republic Act No. 10173) uses a criteria-based consent model under Section 12 for ordinary personal information, with a stricter standard under Section 13 for sensitive personal information, and adopts personal information controller and personal information processor terminology, a controller and processor style split. The National Privacy Commission (NPC) enforces the Act.
The Official Gazette's own page presented a Cloudflare CAPTCHA that crawler infrastructure correctly stopped on rather than solving, and the NPC's own PDF mirror extracted as a PDF.js viewer render rather than document text; the substantive text for this document was instead read from the NPC's own HTML reproduction of the Act at privacy.gov.ph, with the Official Gazette recorded here as the more authoritative citation.
Cross border transfer
What it requires →
Section 21's Principle of Accountability makes a personal information controller responsible for personal information under its control or custody, including data transferred to a third party for processing domestically or internationally, and requires the controller to use contractual or other reasonable means to provide a comparable level of protection while the data is processed abroad.
This is an accountability-based transfer regime rather than an adequacy list or a localization mandate; no data-localization requirement was found.
Data subject rights
What it requires →
Section 16 grants a data subject rights including to be informed, to object, to access, to rectification or correction, to erasure or blocking, and to damages for inaccurate, unlawfully obtained, or unauthorized use of personal information, alongside the right to file a complaint before the Commission. Section 17 makes these rights transmissible to lawful heirs after the data subject's death or incapacity.
Section 18 grants a right to data portability, obtaining personal data in an electronic or structured, commonly used format that allows further use by the data subject; this right was already present in the original 2012 Act, unlike some regimes that added it only by later amendment.
Enforcement supervision
What it requires →
The National Privacy Commission is the supervisory authority, with Chapter VIII (Sections 25-36) setting criminal penalties, including imprisonment and fines, for unauthorized processing, negligent access, improper disposal, unauthorized purposes, unauthorized access due to negligence, malicious disclosure, unauthorized disclosure, and combinations of these acts, scaling with whether sensitive personal information is involved.
Section 37 provides that restitution for any aggrieved party is governed by the general Civil Code, a private civil remedy but one routed through general civil law rather than a freestanding, Data Privacy Act-specific statutory cause of action with its own procedural rules.