CyberCode.ph · Philippines

AI and Data Privacy Philippines: Personal Data Rules for AI Systems and Generative AI

Last updated September 4, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 4, 2026

Direct Answer

AI systems that process personal data in the Philippines are subject to the Data Privacy Act, its Implementing Rules and Regulations, and relevant National Privacy Commission issuances. Businesses should identify the personal data involved, establish a lawful basis, explain the processing clearly, limit collection and use to what is necessary, secure the data, govern vendors, and preserve data-subject rights. NPC Advisory No. 2024-04 specifically explains how these obligations apply to AI systems processing personal data.

Key Takeaways

  • Using AI does not remove ordinary Data Privacy Act obligations.
  • Do not upload personal or sensitive personal information to an AI tool merely because the tool is convenient.
  • Transparency must cover the purpose, method, recipients, retention and meaningful information about automated processing where applicable.
  • Privacy impact assessment is especially important for new or higher-risk AI processing.
  • Third-party AI vendors may act as personal information processors and need appropriate contractual and security controls.

When Does AI Become a Data Privacy Issue?

Privacy obligations arise when an AI workflow collects, receives, stores, analyzes, generates, infers, scores, predicts or otherwise processes information that identifies or can reasonably identify an individual. This may include customer records, employee information, support transcripts, biometric data, health data, financial information, location data and prompts containing personal details.

Lawful Basis and Purpose

The organization should identify the lawful basis before processing personal data and make sure the AI use is compatible with a specified and legitimate purpose. Consent is not the only possible basis, but businesses should not assume legitimate interest or contract automatically applies. The appropriate basis depends on the specific facts and processing activity.

Transparency and Data-Subject Rights

The NPC states that data subjects have a right to be informed about processing, including automated decision-making and profiling. Privacy notices should explain the categories of data, purposes, basis, processing method, recipients, retention, controller identity and relevant rights. Where automated access or decisions are involved, the notice may also need meaningful information about the logic, significance and envisaged consequences.

Data Minimization and Prompt Hygiene

Employees should avoid including unnecessary personal or confidential data in prompts. Organizations can reduce risk by using approved enterprise tools, redacting identifiers, limiting retention, separating testing from production data and blocking unapproved uploads where feasible.

AI Vendors and Processors

When a vendor processes personal data on behalf of a business, the relationship should be governed by appropriate agreements and due diligence. Review retention, model training, subprocessors, location of processing, security, deletion, breach handling and audit or assurance information.

Privacy Impact Assessment

The NPC describes a Privacy Impact Assessment as a process for identifying privacy risks and treating them early in an initiative. AI uses involving sensitive data, large-scale profiling, employee monitoring, automated decisions or novel technologies should be assessed before deployment rather than after problems arise.

Decision Snapshot

If an AI system receives personal data, inferential data or identifiable employee/customer information, treat the workflow as a regulated data-processing activity and apply privacy controls from design through deletion.

Related Cybercode Guides

Official Sources