Philippine Business & Compliance

What is National Privacy Commission?

Short answer

The National Privacy Commission is the Philippine government body created by the Data Privacy Act of 2012 to administer and enforce it. It issues implementing rules, circulars and advisory opinions, registers data processing systems and Data Protection Officers, investigates complaints from individuals, and can order organisations to change how they handle personal data.

Also called: NPC, Philippine data protection authority

Most of the operational detail sits in the Commission’s issuances rather than in the statute itself. Its circulars and advisory opinions set out what registration involves, what a Data Protection Officer is expected to do, how breaches are reported, and how the law’s principles apply to specific situations, from CCTV in a shop to the handling of job applicants’ records.

For a business the practical read is that the Commission is both the rule-maker and the first place a dissatisfied customer or employee can take a complaint about personal data. Its published advisory opinions are useful reading precisely because they answer narrow, real questions — but each responds to the facts put to the Commission, so they are guidance rather than a ruling on your own situation.

Where this comes up in our work

Related terms

Data Privacy Act of 2012 (RA 10173)

The Data Privacy Act of 2012 (Republic Act 10173) is the Philippine law governing how organisations collect, store, use and share personal information.

E-Commerce Act (RA 8792)

The Electronic Commerce Act of 2000 (Republic Act 8792) is the Philippine law that gives electronic documents, data messages and electronic signatures the same legal recognition as their paper equivalents.

Consumer Act of the Philippines (RA 7394)

The Consumer Act of the Philippines (Republic Act 7394) is the country’s principal consumer protection law.

Reading definitions because you are scoping a project? Skip ahead and just ask.