Last materially reviewed: September 3, 2026
Direct Answer
There is no single Philippine law that acts as a universal cybersecurity checklist for every private company. Cybersecurity obligations instead come from the laws, regulations, contracts and sector rules that apply to the organization. For many companies that process personal data, the Data Privacy Act is central because it requires reasonable and appropriate organizational, physical and technical security measures. Regulated industries may have additional requirements from their own regulators.
Key Takeaways
- Cybersecurity compliance is risk-based and depends on the business, data and sector.
- The Data Privacy Act requires reasonable and appropriate security measures for personal data.
- Companies should maintain policies, access controls, monitoring, vulnerability management and incident procedures.
- Third-party processors and vendors must be considered in the security program.
- Evidence of implementation matters as much as written policies.
Data Privacy Act security obligations
Section 20 of Republic Act No. 10173 requires personal information controllers to implement reasonable and appropriate organizational, physical and technical measures against accidental or unlawful destruction, alteration, disclosure and other unlawful processing. The appropriate level of security depends on the nature of the data, processing risks, organization size and complexity, current best practices and implementation cost.
Organizational controls
Organizations should assign accountability, maintain data-protection and information-security policies, train employees, define access rules, document incident response and review controls periodically. Policies should match real operations rather than existing only for audits.
Technical controls
NPC rules identify safeguards including network protection, authentication, encryption where appropriate, monitoring for breaches, vulnerability identification, resilience, recovery capability and regular testing of security measures.
Physical controls
Businesses should also protect workstations, facilities, portable media and equipment that contain or access personal data. Security is not limited to cloud and network controls.
Vendor and processor responsibilities
When a business uses third parties to process personal data, it should select providers that offer sufficient guarantees and use appropriate contractual arrangements. Use the Vendor and SaaS Security Checklist as an operational review.
Incident and breach procedures
Companies need a process to identify, contain and respond to security incidents and to assess whether a personal-data breach requires notification. See Cybersecurity Incident Response Plan and Data Breach Notification Philippines.
Evidence of compliance
Keep evidence such as access-review records, training completion, risk assessments, security-policy approvals, vendor reviews, backup tests, incident logs, vulnerability remediation and change records. A written policy with no implementation evidence provides weak assurance.
Sector-specific requirements
Banks, payment providers, telecommunications companies, critical infrastructure operators and other regulated organizations may be subject to more specific cybersecurity rules. Businesses should identify their regulator and industry requirements rather than relying on a generic checklist.
Baseline compliance checklist
- Named security/privacy accountability
- Information-security policies
- User access and offboarding process
- MFA for critical systems
- Patch and vulnerability process
- Backups and tested recovery
- Logging and monitoring
- Employee training
- Vendor security review
- Incident and breach procedures
- Periodic control review
FAQs
Is ISO 27001 legally required for all Philippine companies?
No. It may be useful or contractually required in some contexts, but there is no blanket rule requiring every Philippine company to be ISO 27001 certified.
Does the Data Privacy Act apply to cybersecurity?
Yes, when personal data is involved. The law expressly requires reasonable and appropriate security measures.
Is a cybersecurity policy enough for compliance?
No. Organizations should be able to show implementation, monitoring, review and response capability.
Related Cybercode Guides
- Cybersecurity Checklist for Philippine Businesses
- What to Do After a Business Cyberattack
- Vendor and SaaS Security Checklist
- Data Privacy Compliance Checklist
