The Philippine DPA is a decade older than most Asian privacy laws and structurally harsher than nearly all of them: it is a criminal statute first, with imprisonment attached to eight defined offenses, and an administrative regime bolted on in 2022 that scales fines to gross income. The National Privacy Commission pairs that severity with unusually operational expectations, registered DPOs, registered processing systems, annual incident reports, so Philippine compliance is more procedural than principle-recitation.
| Regulation | Data Privacy Act of 2012 (RA 10173) + IRR |
|---|---|
| Max penalty | 3% of gross income per infraction (admin); 6 years + PHP 5M (criminal) |
| Enforcing authority | National Privacy Commission |
| Official text | RA 10173 (LawPhil) |
The duty stack
Lawful processing. Consent or another section 12 criterion for personal information; for sensitive personal information (health, government IDs, race, religion, sexual life, offenses) section 13 narrows to consent, law, life-and-health protection, public organizations’ member data, medical treatment, and legal claims. Legitimate interests exists for ordinary data but not as a sensitive-data route.
Governance. DPO appointment and NPC registration; privacy management program; privacy impact assessments per NPC guidance; security measures spanning organizational, physical, and technical controls (the IRR enumerates them, including encryption expectations for data in transit and at rest); and processor contracts with subcontracting controls.
Data subject rights. Information, access, correction, erasure or blocking, objection, damages, and portability, the DPA anticipated GDPR’s menu by four years. Rights are enforceable through NPC complaints, and indemnity claims ride the statute directly.
Incidents. The 72-hour dual notification for qualifying breaches, plus the annual security-incident report aggregating everything else. Concealing breaches involving sensitive data is itself a crime, a provision worth internalizing in incident-response governance.
Enforcement reality
The NPC has ordered processing suspensions and referred cases for prosecution, publicly named non-compliant entities, and applied the 2022 fine schedule to breaches and lending-app abuses (the sector behind its most aggressive enforcement, including app takedowns for debt-shaming practices). The 2018 Wendy’s Philippines and COMELEC (“Comeleak”, 55 million voters’ data, 2016) cases remain the reference investigations, the latter producing criminal referral of the responsible official. Treat the registration and DPO requirements as table stakes: they are the first checks in any NPC inquiry.
Regional context sits in the Asia-Pacific comparison pages, and the APEC CBPR guide covers the certification scheme the Philippines participates in. Baseline your Philippine-facing collection with a free scan.