CyberCode.ph · Philippines

Cybersecurity in the Philippines: Legal Duties and Practical Baseline

Last updated September 28, 2026 · Practical privacy, cybersecurity and technology-law guidance

Direct answer: There is no single Philippine statute called a cybersecurity law. Your cybersecurity duties come from four places at once: the Data Privacy Act, which requires “reasonable and appropriate organizational, physical, and technical security measures” for personal data; the Cybercrime Prevention Act, which makes attacking a computer system a crime; your sector regulator, which may impose far stricter rules and much shorter reporting clocks than privacy law does; and your own contracts. Everything else is good practice, not legal obligation.

For practical response, vendor, account, website and business-security routes, use Cybercode’s Cybersecurity Philippines hub.

Key Takeaways

  • No omnibus cybersecurity statute exists. Philippine cybersecurity obligations are assembled from privacy law, criminal law, sector regulation and contract. Anyone who tells you “the cybersecurity law requires X” is almost certainly describing the Data Privacy Act or a sector circular.
  • The Data Privacy Act duty is a standard, not a checklist. Rule VI, Section 25 of the Implementing Rules requires “reasonable and appropriate organizational, physical, and technical security measures.” Sections 26 to 28 then break that into specific, enumerated items — and Section 29 says the adequacy of your measures is judged against the risk, the size of your organisation and current best practice.
  • Cybersecurity is defined in Philippine law — in the Cybercrime Prevention Act. Section 3(k) of Republic Act No. 10175 defines it as the “collection of tools, policies, risk management approaches, actions, training, best practices, assurance and technologies” that protect the cyber environment and its assets.
  • Banks and other BSP-supervised institutions run on a two-hour clock, not a 72-hour one. Section 148 of the Manual of Regulations for Banks requires notification to the Bangko Sentral ng Pilipinas within two (2) hours of discovering a reportable major cyber-related incident, with a follow-up report within 24 hours. Privacy law’s 72-hour breach clock runs separately and in parallel.
  • Being the victim does not remove your obligations. An attack that succeeds against you can still leave you exposed to a National Privacy Commission finding that your security measures were inadequate. The two questions — who attacked you, and whether you were adequately protected — are decided separately.
  • The minimum practical baseline is short. Multi-factor authentication, patched software, tested backups, restricted administrator access, trained staff and a written incident contact list will address most of what actually goes wrong in Philippine SMEs.
  • Security controls are risk reduction, not prevention. No control on this page stops an attack from ever succeeding. What good controls change is how likely a compromise is, how far it spreads, and how quickly you can prove what happened.

Jump to a Section

Decision Snapshot

Question Practical answer
Is there a single Philippine cybersecurity law? No. Duties come from privacy law, criminal law, sector regulation and contract.
Does the Data Privacy Act apply even if we are not a tech company? Yes, if you process personal data. The security duty attaches to the data, not the industry.
Is ISO 27001 legally required? No. It is a recognised way to evidence adequacy, not a Philippine legal requirement.
Do we have to report every security incident to the NPC? No. Notification is mandatory only when all three statutory elements are present — see the clocks section.
Does a bank report a cyber incident on the same timeline as a privacy breach? No. BSP-supervised institutions have two hours. The 72-hour privacy clock runs separately.
Can we be liable even though we were the victim of a crime? Yes. Criminal liability of the attacker and regulatory liability for inadequate security are separate questions.
Does encryption satisfy the law by itself? No. It is one enumerated technical measure among several.
Is a written policy enough? No. The rules require measures that are implemented, monitored, tested and reviewed — not only documented.

Is There a Cybersecurity Law in the Philippines?

No, not in the sense most people mean. The Philippines has no single omnibus cybersecurity statute that sets out mandatory security controls for organisations generally, the way some jurisdictions have. What exists instead is a set of overlapping obligations, each with its own scope, its own regulator and its own deadlines.

That matters practically. A Philippine company looking for “the cybersecurity law” will not find one, conclude nothing applies to it, and be wrong. The duties are real; they are just distributed. The question to ask is not “does the cybersecurity law cover us” but “which of the four sources below reaches our organisation, and what does each one require.”

The nearest thing to a statutory definition sits inside criminal law. Section 3(k) of Republic Act No. 10175, the Cybercrime Prevention Act of 2012, defines cybersecurity as the “collection of tools, policies, risk management approaches, actions, training, best practices, assurance and technologies that can be used to protect the cyber environment and organization and user’s assets.” That is a description of a discipline, not a compliance obligation — but it is the definition Philippine law actually uses.

The Four Sources of a Philippine Cybersecurity Duty

Source What it does Who it reaches Enforced by
Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules Requires reasonable and appropriate organizational, physical and technical security measures for personal data; sets a 72-hour breach notification clock Any organisation that processes personal data, including foreign entities with a defined Philippine link National Privacy Commission
Republic Act No. 10175 (Cybercrime Prevention Act of 2012) Criminalises attacks on computer systems and data; provides preservation, disclosure and warrant machinery Everyone — it defines offences, not compliance duties DOJ Office of Cybercrime, NBI, PNP Anti-Cybercrime Group
Sector regulation — e.g. Section 148 of the Manual of Regulations for Banks Imposes specific IT risk management systems, governance and short incident-reporting deadlines Regulated entities only — banks, other BSP-supervised institutions, and the equivalents in other sectors Bangko Sentral ng Pilipinas and other sector regulators
Contract Imposes whatever the parties agreed — security schedules, audit rights, breach-notice periods often far shorter than the law’s Whoever signed The counterparty, through the contract

Most Philippine organisations are reached by at least the first two. Any organisation handling personal data on behalf of a client is usually reached by the fourth as well, and the contractual deadline is frequently the tightest one in the stack.

What the Data Privacy Act Actually Requires

This is the obligation that reaches the widest set of Philippine organisations, so it is worth reading precisely rather than in paraphrase. The general duty is in Rule VI, Section 25 of the Implementing Rules and Regulations of Republic Act No. 10173: personal information controllers and personal information processors “shall implement reasonable and appropriate organizational, physical, and technical security measures for the protection of personal data.”

Three words in that sentence do most of the work. Reasonable and appropriate mean the standard is relative, not absolute — which Section 29 then makes explicit. And the split into organizational, physical and technical is not decorative: Sections 26, 27 and 28 each enumerate specific items, and an organisation that has invested heavily in one column while ignoring another has not met the standard.

Organizational measures — Rule VI, Section 26

Item What it requires
(a) Compliance officers Designate an individual or individuals to function as data protection officer or compliance officer, “accountable for ensuring compliance with applicable laws and regulations for the protection of data privacy and security”
(b) Data protection policies Implement organizational, physical and technical measures having regard to the nature, scope, context and purposes of the processing
(c) Records of processing activities Maintain documentation of processing systems, duties and responsibilities, purposes, categories of data, data flow, security measures and contact details
(d) Management of human resources Select and supervise employees handling personal data, with confidentiality obligations that survive the end of employment
(e) Processing of personal data Procedures for collection, access management, data subject rights and retention schedules
(f) Contracts with processors Ensure by contract that processors implement the required security measures

Physical measures — Rule VI, Section 27

Item What it requires
(a) Access control Policies and procedures to “monitor and limit access to and activities in the room, workstation or facility,” including guidelines on electronic media
(b) Office design Design that provides privacy for processing, taking account of the environment and accessibility
(c) Duties and schedules Clear duties, responsibilities and schedules so that only authorised individuals occupy work stations
(d) Media handling Policies on the transfer, removal, disposal and re-use of electronic media
(e) Protection against loss Procedures preventing mechanical destruction of files, and rooms secured against natural disasters and external threats

Section 27 is the column Philippine organisations most often skip, because “cybersecurity” sounds like it lives entirely in software. It does not. A well-patched network in an office where anyone can walk to an unlocked workstation, or where old hard drives go out with the rubbish, does not meet the standard.

Technical measures — Rule VI, Section 28

Item What it requires
(a) Security policy A security policy with respect to the processing of personal data
(b) Network safeguards Safeguards to protect the computer network “against accidental, unlawful or unauthorized usage,” interference and unauthorised access
(c) Systems assurance The ability to ensure the “confidentiality, integrity, availability, and resilience of their processing systems and services”
(d) Monitoring Regular monitoring for security breaches, identification of vulnerabilities, and preventive action
(e) Restoration The ability to restore availability and access to personal data in a timely manner after an incident
(f) Testing A process for regularly testing, assessing and evaluating the effectiveness of security measures
(g) Encryption and authentication “Encryption of personal data during storage and while in transit, authentication process, and other technical security measures”

Two of these deserve emphasis because they are obligations to do something repeatedly, not to own something. Item (e) means backups that have actually been restored from, not backups that exist. Item (f) means testing on a schedule — an organisation that has never once tested its controls cannot honestly claim to have evaluated their effectiveness.

How adequacy is judged — Rule VI, Section 29

Section 29 is the provision that answers “how much security is enough.” The Commission considers the nature of the personal data requiring protection, the risks posed by the processing, the size of the organisation and the complexity of its operations, current data privacy best practices, and the cost of implementing the security measures. Measures are also “subject to regular review and updating.”

The practical effect is that a five-person consultancy and a national retailer are not held to the same controls — but both are held to controls proportionate to what they hold. A small organisation processing sensitive personal information about thousands of people does not get a small-organisation discount on the risk side of that equation. Running a privacy impact assessment is the standard way to document where your organisation sits on each of those factors.

For the full treatment of the Data Privacy Act — its lawful bases, data subject rights, registration and penalties — see the complete guide to Republic Act No. 10173, and the National Privacy Commission guide for how the regulator itself operates. If your interest is specifically the corporate compliance programme rather than the field as a whole, cybersecurity compliance for Philippine companies covers the documentation and evidence side in more detail.

What the Cybercrime Prevention Act Makes Criminal

Republic Act No. 10175, approved on 12 September 2012, does something different from the Data Privacy Act. It does not tell you how to secure your systems. It tells you what other people may not lawfully do to them — which matters when you are deciding whether an incident is a crime you can report.

Section 4(a) sets out the offences against the confidentiality, integrity and availability of computer data and systems:

Offence What it covers
4(a)(1) Illegal access “The access to the whole or any part of a computer system without right”
4(a)(2) Illegal interception Interception, by technical means and without right, of non-public transmissions of computer data
4(a)(3) Data interference Intentional or reckless alteration, damaging, deletion or deterioration of computer data or electronic documents without right
4(a)(4) System interference Intentional or reckless hindering of the functioning of a computer or network, including through the transmission of viruses
4(a)(5) Misuse of devices Producing, selling, distributing or possessing devices, passwords or access codes for the purpose of committing the above offences
4(a)(6) Cyber-squatting Acquiring a domain name in bad faith where it is similar to an existing registered trademark or another person’s name

Three further provisions change the picture materially. Section 5 reaches aiding, abetting and attempt. Section 6 provides that crimes already defined in the Revised Penal Code and special laws, if committed by, through and with the use of information and communications technologies, are covered by the Act, “Provided, That the penalty to be imposed shall be one (1) degree higher.” And Section 7 makes prosecution under the Act without prejudice to liability under other laws.

On penalties, Section 8 imposes for Section 4(a) and 4(b) offences prisión mayor or a fine of at least ₱200,000 up to an amount commensurate to the damage incurred, or both. Misuse of devices under Section 4(a)(5) carries a fine of not more than ₱500,000. Offences against critical infrastructure carry reclusión temporal or a fine of at least ₱500,000.

One practical provision is worth knowing before you need it. Section 13 requires service providers to preserve the integrity of traffic data and subscriber information for a minimum of six months from the date of the transaction, and content data for six months from receipt of a law enforcement order, extendable once for a further six months. That six-month window is the real-world limit on how long you can wait before reporting an incident and expecting the records to still exist. The full offence-by-offence treatment is in the complete guide to RA 10175.

Sector Rules: The BSP Two-Hour Clock

If your organisation is supervised by a sector regulator, that regulator’s rules will usually be stricter and faster than general privacy law. The clearest Philippine example is banking.

Section 148 of the Manual of Regulations for Banks sets out the Bangko Sentral ng Pilipinas requirements on information technology risk management. It requires BSP-supervised financial institutions to maintain an IT risk management system built on four components: IT governance; risk identification and assessment; implementation of IT controls; and risk measurement and monitoring. The board is “ultimately responsible for understanding the IT risks confronted by a BSFI and ensuring that they are properly managed,” while senior management is “accountable for designing and implementing the ITRMS approved by the board.”

The provision that most often surprises people is the reporting deadline. Section 148 requires notification to the Bangko Sentral within two (2) hours of discovering a reportable major cyber-related incident or disruption, with a follow-up report within twenty-four (24) hours describing the nature of the incident, how it was detected, its impact and the response taken.

Regime Trigger Deadline Notify whom
Data Privacy Act, IRR Rule IX Sec. 38 Personal data breach meeting all three statutory elements 72 hours from knowledge or reasonable belief National Privacy Commission and affected data subjects
MORB Section 148 Reportable major cyber-related incident or disruption 2 hours from discovery, follow-up within 24 hours Bangko Sentral ng Pilipinas
Contractual security schedules Whatever the contract defines as an incident Frequently 24 hours or less The counterparty

These clocks are cumulative, not alternative. A bank that suffers a compromise affecting customer personal data is on the two-hour BSP clock and the 72-hour NPC clock and whatever its outsourcing contracts require, all from the same moment. Building the incident plan around only the longest of them is the most common structural mistake in Philippine incident response. The incident response plan guide and the first-72-hours checklist both assume this multi-clock reality.

Other sectors have their own layers. Organisations in regulated financial services beyond banking, in health, and in government each face additional issuance-level requirements that a general page cannot responsibly summarise. The rule of thumb is simple: if a regulator licenses you, assume it also has an opinion about your IT controls, and go and read its issuances rather than relying on privacy law alone.

The National Policy Layer: DICT, the NCSP and the CICC

Above the enforceable duties sits a layer of national policy and institutional machinery. It rarely creates direct obligations for a private company, but it explains who does what when something large goes wrong.

The Department of Information and Communications Technology (DICT) is the executive department responsible for information and communications technology policy, including cybersecurity policy. Its enabling statute is Republic Act No. 10844, covered separately in the DICT Act guide.

The National Cybersecurity Plan 2023–2028 is the government’s stated roadmap, adopted by Executive Order No. 58. The Presidential Communications Office describes it as “the whole-of-nation roadmap for the integrated development and strategic direction of the country’s cybersecurity,” directing all national government agencies, instrumentalities and local government units to “support and cooperate towards the successful implementation of the NCSP 2023-2028,” with the DICT monitoring progress and providing technical assistance. The Plan is a policy instrument: it sets direction for government, and does not by itself impose security controls on private organisations.

The Cybercrime Investigation and Coordinating Center (CICC) was created by Section 24 of RA 10175 as an inter-agency body under the Office of the President, with the composition set out in Section 25. Its role is coordination and policy for cybercrime response rather than day-to-day complaint handling, which in practice runs through the NBI and the PNP Anti-Cybercrime Group.

Who Regulates What

Body Role in cybersecurity What you go to it for
National Privacy Commission (NPC) Administers and enforces RA 10173, including the security-measures duty and breach notification Breach notification, complaints about inadequate security affecting personal data, registration
Department of Information and Communications Technology (DICT) National ICT and cybersecurity policy; implementation of the National Cybersecurity Plan Policy direction, national programmes, government-sector coordination
Cybercrime Investigation and Coordinating Center (CICC) Inter-agency coordination and policy on cybercrime under RA 10175 Coordination of the national cybercrime response
DOJ Office of Cybercrime Central authority on cybercrime matters; prosecution Prosecution, international cooperation, preservation and disclosure requests
NBI Cybercrime Division Investigation Filing a cybercrime complaint for investigation
PNP Anti-Cybercrime Group Investigation and enforcement Filing a cybercrime complaint; urgent incidents
Bangko Sentral ng Pilipinas (BSP) IT risk management and incident reporting for supervised financial institutions Two-hour incident reporting; supervisory expectations on controls

The government cybersecurity agencies directory and the cybercrime reporting directory hold the current contact routes.

The Practical Baseline: Essential, Recommended, Advanced

Nothing in Philippine law prescribes a specific list of controls. What follows is a practical baseline drawn from the enumerated measures in Rule VI of the Data Privacy Act IRR and from recognised technical frameworks. It is not a legal safe harbour. It is what, in practice, addresses most of what actually goes wrong.

Essential — do these first

  1. Turn on multi-factor authentication everywhere it is available, starting with email, banking, cloud consoles and anything with administrator rights. Credential theft is the entry point for most business compromises. See the MFA guide.
  2. Use a password manager and stop reusing passwords. Reuse turns one breach anywhere into a breach everywhere. See the password security guide.
  3. Keep operating systems, browsers and business software updated. Automatic updates, on, by default.
  4. Back up, and restore from the backup at least once. Rule VI, Section 28(e) requires the ability to restore availability in a timely manner — an untested backup does not demonstrate that. See backup and recovery.
  5. Restrict administrator access. Day-to-day work should not happen on an administrator account, and departing staff should lose access the day they leave.
  6. Train staff on phishing and payment fraud, and make it safe to report a mistake quickly. See employee cybersecurity training.
  7. Write down who to call. A one-page contact list — internal escalation, your DPO, your IT provider, your bank, your lawyer — is worth more at 2am than a 40-page policy.

Recommended

  • A written security policy and an employee cybersecurity policy, as Section 28(a) contemplates.
  • Records of processing activities, as Section 26(c) requires — this is also the fastest way to answer “what was affected” during an incident.
  • Logging and regular review, supporting the monitoring duty in Section 28(d).
  • Encryption of personal data at rest and in transit, per Section 28(g).
  • Vendor due diligence before signing, per Section 26(f). See the vendor and SaaS security checklist.
  • A tested incident response plan with named roles.
  • Hardening for the systems you actually expose — see the website security checklist and cloud security for SMEs.

Advanced

  • Independent testing — vulnerability assessment or penetration testing on a defined scope and schedule, supporting Section 28(f).
  • Formal certification such as ISO/IEC 27001, where clients or regulators expect it. Useful as evidence of adequacy; not a Philippine legal requirement.
  • Centralised log management and alerting.
  • Governance of AI tools in the business, which introduces its own exposure — see AI security risks for Philippine businesses.

The full control-by-control version of the essential and recommended tiers is in the cybersecurity checklist for Philippine businesses.

Mapping the Baseline to NIST CSF 2.0

Philippine law does not require any particular framework. But regulators, auditors and enterprise clients increasingly ask organisations to describe their controls in a recognised vocabulary, and the most widely used one is the NIST Cybersecurity Framework (CSF) 2.0, published by the United States National Institute of Standards and Technology as NIST CSWP 29 on 26 February 2024. It is a voluntary framework from a foreign standards body; it has no binding force in the Philippines. It is useful here because it gives a clean structure for showing that your measures are complete.

CSF 2.0 Function NIST’s description Where the Philippine duty sits
GOVERN “The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.” IRR Sec. 26(a) compliance officer; Sec. 26(b) data protection policies; MORB 148 board and senior management responsibilities
IDENTIFY “The organization’s current cybersecurity risks are understood.” IRR Sec. 26(c) records of processing activities; privacy impact assessment; MORB 148 risk identification and assessment
PROTECT “Safeguards to manage the organization’s cybersecurity risks are used.” IRR Secs. 27 (physical) and 28(a), (b), (g) (technical)
DETECT “Possible cybersecurity attacks and compromises are found and analyzed.” IRR Sec. 28(d) regular monitoring for security breaches
RESPOND “Actions regarding a detected cybersecurity incident are taken.” IRR Rule IX breach management and notification; MORB 148 incident reporting
RECOVER “Assets and operations affected by a cybersecurity incident are restored.” IRR Sec. 28(e) ability to restore availability and access in a timely manner

Read across that table and the practical point becomes visible: the Philippine enumerated measures map onto all six functions, but they are thinnest on DETECT. Section 28(d) is a single line. Organisations that satisfy the letter of Rule VI can still have almost no ability to notice an intrusion in progress — which is why so many Philippine breaches are discovered by a customer, a bank or an attacker’s ransom note rather than by the organisation itself.

When Something Goes Wrong: The Clocks That Start Running

Not every security incident is a personal data breach, and not every personal data breach must be notified. Under the National Privacy Commission’s published breach reporting guidance, notification to the Commission and to affected data subjects is mandatory only when all three of the following are present:

  1. The personal data involved is sensitive personal information, or information that may be used to enable identity fraud;
  2. There is reason to believe the information may have been acquired by an unauthorised person; and
  3. The breach is likely to give rise to a real risk of serious harm to the affected data subject.

Where those elements are present, IRR Rule IX, Section 38 sets the deadline at seventy-two (72) hours upon knowledge of, or reasonable belief that, a personal data breach has occurred. Section 39 sets out what the notification must contain: the nature of the breach, the personal data possibly involved, the measures taken to address it, the contact details of the controller, and the assistance provided to those affected. Section 40 allows notification to be delayed “only to the extent necessary to determine the scope of the breach, to prevent further disclosures” — it is a narrow carve-out for scoping, not a general extension.

One procedural point catches organisations out every year. The NPC states that it accepts breach notification forms through the Data Breach Notification Management System only, and that any form submitted outside the DBNMS is not considered valid. An email to the Commission is not a notification.

The NPC’s guidance also sets the window for the Annual Security Incident Report at 1 January to 31 March.

The step-by-step version is in when the NPC must be notified, the data breach response checklist, and what a company should do after a personal data breach. For an attack that has not yet been assessed as a personal data breach, start with what to do after a business cyberattack.

What to Preserve

Whether you end up in a regulatory process, a criminal complaint or a contractual dispute, the same material matters — and it is usually destroyed in the first hour by well-meaning people trying to fix things. Do not wipe and rebuild the affected machine until someone has decided whether an image is needed.

  • System, application, authentication and firewall logs, exported before rotation deletes them
  • The full email including headers, not a forwarded copy or a screenshot of the body
  • Ransom notes, attacker messages and payment demands, in original form
  • Transaction records and reference numbers for any money that moved
  • An incident timeline: who noticed what, at what time, and what was done — written contemporaneously
  • A record of what personal data was in the affected system, which is where records of processing activities earn their keep
  • Copies of the relevant policies, contracts and vendor agreements as they stood on the day

Do not alter, crop, re-save or annotate original files. The electronic evidence checklist covers preservation properly, and remember Section 13 of RA 10175: the service-provider records that may corroborate your account have a six-month floor, not an indefinite life.

Practical Scenarios

A 12-person Manila agency has a client list stolen from a shared drive

The agency is a personal information controller for the contact details it holds. The security duty in Rule VI applies to it at its own scale — Section 29 takes account of the size of the organisation and the complexity of its operations, so it is not expected to run a security operations centre. It is expected to have had access controls, some monitoring, and a way to restore. Whether it must notify the NPC depends on the three-element test: business contact details alone may not meet the identity-fraud or serious-harm limbs, while a file also containing government ID scans very likely would.

A rural bank discovers unauthorised access to a customer-facing system at 4pm

Two clocks start at once. The BSP clock under MORB Section 148 gives two hours from discovery for the initial report, with a 24-hour follow-up. If customer personal data was involved, the 72-hour NPC clock also begins from the point of knowledge or reasonable belief. Neither substitutes for the other, and the bank’s incident plan should name a person responsible for each.

A BPO’s client demands notification within 24 hours under its contract

The contract governs between the parties. A 24-hour contractual notice period does not shorten or lengthen the statutory 72-hour period, and complying with one does not discharge the other. As a processor, the BPO also has direct obligations under the IRR, and its client remains a controller with its own. Both parties should have mapped this in the data processing agreement rather than discovering it mid-incident. See cloud computing legal requirements for the contractual layer.

An employee clicks a phishing link and enters their password

Treat it as a live credential compromise: reset the password, revoke active sessions, check for mail-forwarding rules and new MFA devices, and look at what that account could reach. Whether it becomes a reportable breach depends on what was accessible, not on the click itself. The first-hour sequence is in clicked a phishing link in the Philippines, and the payment-fraud variant in business email compromise.

Common Mistakes

  • Assuming no cybersecurity law means no duty. The duty is in privacy law and sector regulation. It is no less enforceable for being distributed.
  • Writing the policy and stopping. Rule VI requires measures that are implemented, monitored, tested and reviewed. A document in a folder evidences intent, not compliance.
  • Planning only around 72 hours. Sector and contractual clocks are often far shorter, and they run from the same moment.
  • Notifying the NPC by email. The Commission’s position is that submissions outside the DBNMS are not valid.
  • Treating backups as done because they exist. Section 28(e) is about the ability to restore. If it has never been tested, it has not been demonstrated.
  • Destroying evidence while remediating. Rebuilding the machine first is the single most common way a Philippine organisation loses its ability to establish what happened.
  • Ignoring the physical column. Section 27 is a full third of the statutory standard and is the one most often left empty.
  • Over-claiming in the aftermath. Saying “no data was compromised” before the scoping is finished creates a second problem on top of the first.

Cybersecurity for Individuals

Most of this page addresses organisations, because that is where the legal duties sit. For an individual, the legal position is simpler — you owe no statutory security duty over your own accounts — but the practical exposure is the same.

  • Enable multi-factor authentication on email first. Email is the recovery route to everything else.
  • Use a password manager. Reuse is the single highest-impact habit to break.
  • Treat urgency as the warning sign. Pressure to act immediately is the common thread in nearly every scam.
  • Verify money requests through a channel you chose, not one the message gave you.
  • Keep your phone number secure — under the SIM Registration Act regime, your number is now bound to your identity. See the SIM Registration Act guide.
  • If money has already moved, contact your bank or e-wallet provider first, then report. Start with where and how to report cybercrime, and online estafa if you were defrauded.

Unfamiliar terms are defined in the Philippine cybersecurity glossary.

Frequently Asked Questions

Is there a cybersecurity law in the Philippines?

There is no single omnibus cybersecurity statute. The enforceable duties come from the Data Privacy Act of 2012 and its Implementing Rules, which require reasonable and appropriate organizational, physical and technical security measures for personal data; from the Cybercrime Prevention Act of 2012, which criminalises attacks on computer systems; from sector regulators such as the Bangko Sentral ng Pilipinas; and from contract.

Does the Data Privacy Act apply to my business if we are not a technology company?

Yes, if you process personal data. The security obligation in Rule VI attaches to the processing of personal data, not to an industry classification. A clinic, a school, a recruitment agency and a neighbourhood store with a customer database are all within scope.

How much security is enough?

Rule VI, Section 29 answers this relatively. The National Privacy Commission considers the nature of the personal data requiring protection, the risks posed by the processing, the size of the organisation and the complexity of its operations, current data privacy best practices, and the cost of implementation. Measures are also subject to regular review and updating. There is no fixed control list that guarantees compliance.

Is ISO 27001 legally required in the Philippines?

No. No Philippine statute or NPC issuance requires ISO/IEC 27001 certification for organisations generally. It can be strong evidence that your measures are reasonable and appropriate, and clients or regulators may require it contractually, but it is not itself a legal obligation.

Do we have to report every security incident to the NPC?

No. Under the Commission’s breach reporting guidance, notification is mandatory only when all three elements are present: sensitive personal information or identity-fraud-enabling data is involved; there is reason to believe it may have been acquired by an unauthorised person; and the breach is likely to give rise to a real risk of serious harm. Incidents falling short of that are still recorded and may appear in the annual report.

How long do we have to notify a personal data breach?

Seventy-two hours from knowledge of, or reasonable belief in, the breach, under Rule IX, Section 38 of the IRR. Notification may be delayed only to the extent necessary to determine the scope of the breach and prevent further disclosures. The notification must be submitted through the Data Breach Notification Management System; the NPC’s position is that submissions made outside the DBNMS are not valid.

We are a bank. Is our deadline also 72 hours?

No — you have an additional and much shorter one. Section 148 of the Manual of Regulations for Banks requires notification to the Bangko Sentral within two hours of discovering a reportable major cyber-related incident, with a follow-up report within 24 hours. If personal data is involved, the 72-hour NPC clock runs in parallel. Both apply.

Can our company be liable even though we were the victim of a crime?

Yes. The criminal liability of whoever attacked you and your own regulatory exposure for inadequate security are separate questions decided by separate bodies. Reporting an attack to the NBI or the PNP Anti-Cybercrime Group does not resolve whether your Rule VI measures were reasonable and appropriate.

What are the penalties for a cyberattack under Philippine law?

Under Section 8 of RA 10175, offences under Sections 4(a) and 4(b) are punishable by prisión mayor or a fine of at least ₱200,000 up to an amount commensurate to the damage incurred, or both. Misuse of devices under Section 4(a)(5) carries a fine of not more than ₱500,000, and offences against critical infrastructure carry reclusión temporal or a fine of at least ₱500,000. Separately, Section 6 provides that offences under the Revised Penal Code and special laws committed through information and communications technologies carry a penalty one degree higher.

How long are logs kept by service providers?

Section 13 of RA 10175 requires service providers to preserve the integrity of traffic data and subscriber information for a minimum of six months from the date of the transaction. Content data must be preserved for six months from receipt of a law enforcement order, with a one-time extension of six months. In practice this is the outer limit on how long you can wait before reporting and still expect corroborating records to exist.

Does a cybersecurity policy on its own make us compliant?

No. Section 28(a) of the IRR contemplates a security policy, but Sections 26 to 28 also require designated accountability, records of processing activities, access controls, monitoring, restoration capability and regular testing. A policy that is not implemented, monitored and tested does not satisfy the standard.

Verification Note

This guide was built from primary government and standards sources read directly for this article. Two limitations are worth stating openly rather than papering over.

No case citations. Philippine Supreme Court materials could not be retrieved for this article, so no jurisprudence is cited. Where courts have interpreted any provision described here, that interpretation is not reflected.

A date discrepancy on Executive Order No. 58. Two Philippine government publications give different details for the adoption of the National Cybersecurity Plan 2023–2028: the Presidential Communications Office release refers to signature on 4 April, while the Philippine Information Agency describes it as “Executive Order No. 58, s. 2024,” unveiled in February 2024. Rather than pick one, this page states that EO 58 adopted the Plan, links both releases, and leaves the date unasserted. Readers who need the exact date should consult the Official Gazette text of the order.

The Department of Information and Communications Technology and Cybercrime Investigation and Coordinating Center websites were not reachable when this guide was prepared, so nothing is attributed to them beyond what other government sources state.

Official Sources

Related Cybercode Guides

About This Guide

Author: Cybercode.ph Editorial Team. This page has not been reviewed by a named external legal reviewer; where a point is unsettled or a source could not be verified, the text says so rather than resolving it silently.

Last materially reviewed: 16 September 2026.

Disclaimer: Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.