CyberCode.ph · Philippines

AI Vendor Due Diligence Checklist Philippines: Privacy, Security, Training Data and Contracts

Last updated September 4, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 4, 2026

Direct Answer

Before adopting an AI vendor, Philippine businesses should review more than price and functionality. The due diligence should cover what data the vendor receives, whether prompts or files are used for model training, retention and deletion, security controls, subprocessors, processing locations, incident notification, service changes, output ownership, confidentiality, audit evidence and exit terms. If personal data is involved, the Data Privacy Act and NPC requirements for controllers and processors also apply.

Key Takeaways

  • Identify exactly what data will enter the AI system and why.
  • Check whether prompts, files or outputs are retained or used to train models.
  • Review subprocessors, hosting locations and cross-border processing.
  • Require appropriate security, breach notification and deletion obligations.
  • Clarify output rights, confidentiality, model changes and termination/export options.

AI Vendor Due Diligence Checklist

1. Data Inputs

  • What categories of personal, confidential or regulated data will be processed?
  • Can the workflow function with redacted or minimized data?
  • Does the vendor clearly distinguish customer data from public or training data?

2. Model Training and Retention

  • Are prompts, uploads or outputs used to improve or train models?
  • Can training use be disabled contractually and technically?
  • What are the default and configurable retention periods?
  • Can data be deleted completely on request or termination?

3. Privacy and Processor Terms

  • Is the vendor acting as a personal information processor for any workflow?
  • Does the agreement define processing instructions, confidentiality, security and deletion?
  • Are subprocessors listed and change notifications provided?

4. Security

  • Review authentication, access controls, encryption, logging and incident response.
  • Ask for relevant assurance reports or certifications where proportionate.
  • Assess AI-specific risks including prompt injection, sensitive information disclosure and excessive agency.

5. Output and Intellectual Property

  • Who owns or may use inputs and outputs?
  • What warranties or disclaimers apply to generated material?
  • Who handles third-party claims involving output?

6. Business Continuity and Exit

  • Can data and records be exported?
  • What happens if the model, pricing, terms or functionality changes?
  • How is data deleted at termination?

Decision Snapshot

If a vendor cannot clearly explain data use, retention, training, security and deletion, do not treat the AI service as a low-risk productivity tool.

Related Cybercode Guides

Official Sources