Philippine Business & Compliance

What is Data Privacy Act of 2012?

Short answer

The Data Privacy Act of 2012 (Republic Act 10173) is the Philippine law governing how organisations collect, store, use and share personal information. It applies to businesses of almost any size, gives individuals defined rights over their own data, and created the National Privacy Commission to administer and enforce it.

Also called: DPA, RA 10173, Philippine data privacy law

The law distinguishes a personal information controller, which decides why and how data is processed, from a personal information processor, which handles data on a controller’s instructions. A business running a website that collects enquiries, accounts or payment details is usually the controller, and the obligations that follow sit with it even when an outside vendor built the system: a lawful basis for processing, a privacy notice a visitor can actually find, reasonable security measures, and a route for people to access or correct their records.

Sensitive personal information, a defined category covering health, race, religion and government-issued identifiers, carries stricter conditions than ordinary personal data. Organisations processing personal data are expected to designate a Data Protection Officer, and depending on the volume and nature of that processing, to register their data processing systems with the Commission. Breach reporting duties run to both the Commission and the people affected. Whether and how each of these applies depends on the organisation — this is general information rather than legal advice.

Common questions

Does the Data Privacy Act apply to a small business website?

Generally yes. The law turns on whether personal information is processed, not on company size, so a contact form, a newsletter list or a customer account brings a site within scope. Some obligations, such as registering data processing systems with the National Privacy Commission, depend on the volume and type of data involved. This is general information, not legal advice.

Do we need a privacy policy on our website?

A privacy notice is the standard way of meeting the duty to tell people what is collected, why, who it is shared with, how long it is kept, and how they can exercise their rights. The point is that it describes what the site actually does. A generic template that does not match your systems does not meet the requirement.

Where this comes up in our work

Related terms

National Privacy Commission (NPC)

The National Privacy Commission is the Philippine government body created by the Data Privacy Act of 2012 to administer and enforce it.

E-Commerce Act (RA 8792)

The Electronic Commerce Act of 2000 (Republic Act 8792) is the Philippine law that gives electronic documents, data messages and electronic signatures the same legal recognition as their paper equivalents.

Business Process Outsourcing (BPO)

Business process outsourcing is the practice of contracting a business function, such as customer support, finance and accounting, back-office administration or IT services, to an external provider rather than staffing it internally.

Custom Software vs Off-the-Shelf Software

Custom software is built for one organisation’s specific process; off-the-shelf software is a finished product many organisations subscribe to, such as Shopify or QuickBooks.

Reading definitions because you are scoping a project? Skip ahead and just ask.