CyberCode.ph · Philippines

Penalties for Violating the Data Privacy Act in the Philippines

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 2, 2026

Direct Answer: Violating the Philippine Data Privacy Act can lead to criminal penalties, administrative fines, and potentially other legal consequences depending on the offense. Republic Act No. 10173 sets specific imprisonment terms and monetary fines for acts such as unauthorized processing, negligent access, improper disposal, processing for unauthorized purposes, intentional breaches, concealment of certain security breaches, malicious disclosure, and unauthorized disclosure. Separately, the National Privacy Commission (NPC) may impose administrative fines under NPC Circular No. 2022-01.

Primary authority: Republic Act No. 10173 — Data Privacy Act of 2012; see also NPC Circular No. 2022-01 on administrative fines.

Key Takeaways

  • There is no single universal fine for violating the Data Privacy Act.
  • Different offenses under RA 10173 carry different imprisonment and fine ranges.
  • Offenses involving sensitive personal information often carry heavier penalties than offenses involving ordinary personal information.
  • A combination or series of prohibited acts can lead to penalties of 3 to 6 years imprisonment and ₱1 million to ₱5 million in fines (RA 10173).
  • The NPC may also impose administrative fines on Personal Information Controllers and Personal Information Processors.
  • For a single act resulting in one or multiple administrative infractions, NPC Circular No. 2022-01 states that the total imposable administrative fine shall not exceed ₱5 million.
  • Responsible corporate officers may face criminal liability when they participated in, or through gross negligence allowed, the offense.

Jump to a Section

Decision Snapshot

Question Practical Answer
Can a Data Privacy Act violation lead to imprisonment? Yes. Specific criminal offenses under RA 10173 carry imprisonment.
Can fines reach millions of pesos? Yes. Depending on the offense, statutory criminal fines can reach several million pesos.
Are sensitive-data offenses treated more seriously? Often, yes. Several statutory penalty ranges are higher.
Can the NPC impose fines even outside criminal prosecution? Yes. NPC Circular No. 2022-01 establishes administrative fines.
Can a company officer be personally liable? Potentially, yes. RA 10173 addresses responsible officers who participate in or grossly negligently allow an offense.
Does every privacy mistake automatically mean jail? No. The particular statutory offense, facts, intent or negligence, and applicable proceedings matter.

Quick Table: Criminal Penalties Under RA 10173

Offense Imprisonment Fine
Unauthorized processing — personal information 1 to 3 years ₱500,000 to ₱2,000,000
Unauthorized processing — sensitive personal information 3 to 6 years ₱500,000 to ₱4,000,000
Negligent access — personal information 1 to 3 years ₱500,000 to ₱2,000,000
Negligent access — sensitive personal information 3 to 6 years ₱500,000 to ₱4,000,000
Improper disposal — personal information 6 months to 2 years ₱100,000 to ₱500,000
Improper disposal — sensitive personal information 1 to 3 years ₱100,000 to ₱1,000,000
Processing for unauthorized purpose — personal information 1 year 6 months to 5 years ₱500,000 to ₱1,000,000
Processing for unauthorized purpose — sensitive personal information 2 to 7 years ₱500,000 to ₱2,000,000
Unauthorized access or intentional breach 1 to 3 years ₱500,000 to ₱2,000,000
Concealment of qualifying security breach 1 year 6 months to 5 years ₱500,000 to ₱1,000,000
Malicious disclosure 1 year 6 months to 5 years ₱500,000 to ₱1,000,000
Unauthorized disclosure — personal information 1 to 3 years ₱500,000 to ₱1,000,000
Unauthorized disclosure — sensitive personal information 3 to 5 years ₱500,000 to ₱2,000,000
Combination or series of acts under Sections 25–32 3 to 6 years ₱1,000,000 to ₱5,000,000

These are statutory ranges. The actual consequence in a real case depends on the offense charged, evidence, applicable defenses, and the outcome of the relevant proceedings.

1. Unauthorized Processing of Personal Information

Processing personal information without consent or another lawful authorization can be a criminal offense under Section 25 of RA 10173.

For ordinary personal information, the statutory penalty is 1 to 3 years imprisonment and a fine of ₱500,000 to ₱2 million.

For sensitive personal information, the range increases to 3 to 6 years imprisonment and ₱500,000 to ₱4 million.

This does not mean that every instance where consent is absent is automatically criminal. Consent is not the only lawful basis for processing. The question is whether the processing was authorized under RA 10173 or another applicable law.

2. Accessing Personal Information Due to Negligence

Section 26 penalizes situations where, because of negligence, unauthorized access to personal information is provided.

For ordinary personal information, the penalty is 1 to 3 years imprisonment plus ₱500,000 to ₱2 million.

For sensitive personal information, the range is 3 to 6 years imprisonment plus ₱500,000 to ₱4 million.

This is particularly important for businesses because a privacy problem does not need to result from deliberate theft. Weak access controls, careless credential handling, or negligent system administration can create serious legal exposure depending on the facts.

3. Improper Disposal of Personal Information

Section 27 addresses knowingly or negligently discarding or abandoning personal information in a publicly accessible area or placing it in a container for trash collection in the manner described by the law.

For ordinary personal information, the penalty is 6 months to 2 years imprisonment and ₱100,000 to ₱500,000.

For sensitive personal information, the penalty is 1 to 3 years imprisonment and ₱100,000 to ₱1 million.

Examples of risky conduct can include throwing unshredded customer files, employee records, medical records, identification copies, or account documents into ordinary public trash where they may be accessed.

4. Processing for Unauthorized Purposes

Section 28 applies where personal information is processed for a purpose that is not authorized by the data subject or otherwise permitted by the Data Privacy Act or existing law.

For ordinary personal information, the statutory range is 1 year and 6 months to 5 years imprisonment and a fine of ₱500,000 to ₱1 million.

For sensitive personal information, the range is 2 to 7 years imprisonment and ₱500,000 to ₱2 million.

A company that collected data for one legitimate purpose should not assume that it may automatically repurpose that information for an unrelated use.

5. Unauthorized Access or Intentional Breach

Section 29 penalizes knowingly and unlawfully breaking into a system where personal or sensitive personal information is stored, including conduct that violates data confidentiality and security.

The statutory penalty is 1 to 3 years imprisonment and a fine of ₱500,000 to ₱2 million.

Depending on the facts, the same incident may also raise issues under the Cybercrime Prevention Act or other laws.

6. Concealment of Certain Security Breaches

Section 30 penalizes a person who knows of a security breach and knows of an obligation to notify the National Privacy Commission under the applicable provision, but intentionally or by omission conceals the breach.

The statutory penalty is 1 year and 6 months to 5 years imprisonment and a fine of ₱500,000 to ₱1 million.

This is not the same as every late or disputed breach notification. The statutory offense has specific elements, including knowledge of the breach and the notification obligation.

7. Malicious Disclosure

Section 31 applies to a Personal Information Controller, Personal Information Processor, or their officials, employees, or agents who, with malice or in bad faith, disclose unwarranted or false information relating to personal or sensitive personal information obtained by them.

The penalty is 1 year and 6 months to 5 years imprisonment and ₱500,000 to ₱1 million.

8. Unauthorized Disclosure

Section 32 separately penalizes disclosure to a third party without the data subject’s consent in the circumstances covered by that section.

For ordinary personal information, the statutory range is 1 to 3 years imprisonment and ₱500,000 to ₱1 million.

For sensitive personal information, the range is 3 to 5 years imprisonment and ₱500,000 to ₱2 million.

Whether a disclosure is actually unauthorized still requires examination of the applicable lawful basis, statutory authority, and surrounding facts.

9. Combination or Series of Privacy Offenses

Section 33 provides a separate penalty where there is a combination or series of acts defined in Sections 25 to 32.

The statutory penalty is 3 to 6 years imprisonment and a fine of ₱1 million to ₱5 million.

This provision matters in complex incidents where conduct may involve multiple stages—for example, unlawful collection followed by unauthorized use and disclosure.

NPC Administrative Fines

Criminal penalties are not the only possible consequence. NPC Circular No. 2022-01 establishes an administrative-fine framework for Personal Information Controllers and Personal Information Processors that violate RA 10173, its Implementing Rules and Regulations, or applicable NPC issuances.

Grave Infractions

NPC Circular No. 2022-01 provides for administrative fines of 0.5% to 3% of the annual gross income of the immediately preceding year for specified grave infractions. These include certain violations of general privacy principles or data-subject rights affecting more than 1,000 data subjects, as well as repetition of the same infraction covered by the Circular.

Major Infractions

Specified major infractions may result in administrative fines of 0.25% to 2% of annual gross income of the immediately preceding year.

Examples listed by the Circular include certain violations affecting 1,000 or fewer data subjects, failure to implement reasonable and appropriate security measures, failure to ensure appropriate security by third-party processors, and certain failures to notify the NPC and affected data subjects of a personal data breach.

Maximum Administrative Fine for a Single Act

NPC Circular No. 2022-01 states that the total imposable administrative fine for a single act of a PIC or PIP, whether resulting in single or multiple infractions, shall not exceed ₱5 million.

The actual administrative fine depends on the classification of the infraction and the factors specified by the NPC.

Can Failure to Report a Data Breach Result in a Fine?

Yes, when notification is required and the applicable conditions are met. The NPC’s current breach-reporting guidance states that a failure to notify the NPC and affected data subjects as required under Section 20(f), when not punishable as concealment under Section 30, can be administratively liable for a fine equivalent to 0.25% to 2% of the annual gross income of the immediately preceding year.

This is why organizations should have a documented breach-assessment and notification process rather than deciding informally whether an incident is serious enough to report.

Can Company Officers Be Personally Liable?

Potentially, yes. Section 34 of RA 10173 provides that when an offender is a corporation, partnership, or other juridical person, the criminal penalty is imposed on responsible officers who participated in the crime or, through gross negligence, allowed its commission.

This means corporate structure does not automatically shield every decision-maker from personal criminal exposure.

Can Foreigners Be Deported After a Conviction?

RA 10173 provides that if an offender is an alien, the person may be deported after serving the imposed sentence, without further proceedings, subject to the wording and application of the statute.

Can Public Officials Face Additional Consequences?

The Data Privacy Act also contains provisions addressing offenses committed by public officers or employees. Depending on the offense and circumstances, additional consequences involving disqualification from public office may apply.

Do Administrative Fines Replace Criminal Penalties?

No. Administrative and criminal consequences arise under different enforcement mechanisms. An administrative fine does not automatically mean a criminal offense has been established, and criminal liability requires the applicable legal elements and proceedings.

A single incident can also create other exposure, such as contractual claims, employment consequences, regulatory orders, or civil claims, depending on the facts.

Does Every Data Breach Mean Someone Will Be Fined?

No. A data breach and a proven violation are not automatically the same thing.

An investigation may consider factors such as the safeguards in place, how the incident happened, the type of information involved, how quickly the organization responded, whether notification obligations applied, and whether the organization complied with applicable privacy requirements.

For the broader violation analysis, see What Counts as a Data Privacy Violation in the Philippines?

What Should a Business Do After a Potential Violation?

  1. Contain the incident. Stop ongoing unauthorized access, disclosure, or processing where possible.
  2. Preserve evidence. Keep logs, emails, system records, notices, audit trails, screenshots, and incident timelines.
  3. Identify the data involved. Determine whether ordinary personal information or sensitive personal information was affected.
  4. Determine the roles involved. Identify the PIC and any PIP.
  5. Assess notification requirements. Review current NPC breach-notification rules.
  6. Document decisions. Record why the organization took—or did not take—specific actions.
  7. Correct the root cause. Fix security, access-control, policy, retention, training, or vendor-management failures.

What Should an Individual Do If Their Data Was Misused?

Preserve evidence before deleting messages, posts, emails, or account records. Consider contacting the organization or its Data Protection Officer and clearly identify the information and conduct involved.

You may also have relevant data privacy rights under RA 10173, including the right to file a complaint with the National Privacy Commission in qualifying circumstances.

Frequently Asked Questions

What is the maximum criminal fine under the Data Privacy Act?

For a combination or series of acts under Sections 25 to 32, Section 33 provides a fine of up to ₱5 million, together with imprisonment of 3 to 6 years. Individual offenses have their own ranges.

Can someone go to jail for violating RA 10173?

Yes. Sections 25 to 33 establish imprisonment for specific criminal offenses.

What is the penalty for unauthorized processing of personal information?

For ordinary personal information, Section 25 provides 1 to 3 years imprisonment and a fine of ₱500,000 to ₱2 million. The statutory range is higher for sensitive personal information.

What is the penalty for leaking sensitive personal information?

The applicable offense must first be identified. For unauthorized disclosure under Section 32(b), the statutory range is 3 to 5 years imprisonment and ₱500,000 to ₱2 million.

Can the National Privacy Commission fine a company?

Yes. NPC Circular No. 2022-01 establishes administrative fines applicable to covered PICs and PIPs.

Can an employee be personally liable for a privacy violation?

Potentially. Several criminal provisions expressly refer to officials, employees, or agents, while the exact liability depends on the conduct and statutory offense.

Is failure to notify the NPC about a breach punishable?

Potentially, yes. Depending on the circumstances, it may create administrative liability, and intentional concealment of a qualifying security breach can fall under Section 30.

Are administrative fines based on company revenue?

For grave and major infractions under NPC Circular No. 2022-01, the fine ranges are expressed as percentages of the annual gross income of the immediately preceding year, subject to the Circular’s rules and limits.

Official Sources

Related Cybercode Guides

Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.