CyberCode.ph · Philippines

Automated Decision-Making and Profiling Philippines: Data Privacy Rules for AI Decisions

Last updated September 4, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 4, 2026

Direct Answer

Philippine data privacy rules specifically recognize automated decision-making and profiling. Where automated processing becomes the sole basis for decisions that significantly affect a data subject, additional transparency, registration and accountability requirements can apply. AI systems used for employee scoring, credit, eligibility, fraud detection, customer segmentation or other consequential decisions should be reviewed under the Data Privacy Act, its IRR, NPC Circular No. 17-01 and NPC Advisory No. 2024-04.

Key Takeaways

  • NPC Circular No. 17-01 defines automated decision-making as wholly or partially automated processing that serves as the sole basis for decisions that significantly affect a data subject.
  • Profiling includes automated processing used to evaluate or predict aspects of a person.
  • Data subjects have a right to be informed about automated decision-making and profiling.
  • Meaningful human review can reduce legal and operational risk where decisions have significant consequences.
  • Businesses should document the purpose, data, logic, safeguards, review process and appeal/escalation path.

What Counts as Automated Decision-Making?

The NPC definition covers automated processing that serves as the sole basis for a decision with significant effects on a person. Examples may include systems that automatically reject an applicant, suspend an account, assign a credit outcome, determine eligibility, trigger disciplinary consequences or otherwise materially affect a person’s rights or opportunities.

What Is Profiling?

Profiling is automated processing used to evaluate, analyze or predict aspects of an individual, such as behavior, economic situation, performance, preferences, location or reliability. Not all profiling is prohibited, but it can create higher privacy risk and requires transparency, lawful processing and appropriate safeguards.

Transparency Requirements

The NPC states that data subjects should be told when automated decision-making or profiling exists. Relevant information may include the purpose, processing method, categories of data, recipients, retention, and meaningful information about the logic involved and the significance and expected consequences of the processing.

Registration and Notification

NPC Circular No. 17-01 states that data processing systems involving automated decision-making must be registered with the Commission. Organizations should also check later NPC registration issuances and current registration rules before relying on older thresholds or procedures.

Human Review and Contestability

Even where a system is technically automated, businesses should consider meaningful human review for decisions with significant effects. The reviewer should have authority to reassess the result, access relevant facts, recognize model limitations and reverse or escalate the outcome when appropriate.

Decision Snapshot

If an AI or algorithm can materially affect someone’s job, money, access, eligibility or rights without meaningful human review, treat it as a high-risk privacy and governance use case.

Related Cybercode Guides

Official Sources