Last materially reviewed: September 3, 2026
Direct Answer
Philippine privacy compliance is governed not only by Republic Act No. 10173 but also by its Implementing Rules and Regulations, National Privacy Commission circulars, rules of procedure, breach-notification rules and later regulator guidance. This database is designed as a practical index to those layers.
Core Privacy Authorities
| Authority | What it covers |
|---|---|
| Republic Act No. 10173 | Data Privacy Act of 2012; rights, obligations, lawful processing and penalties |
| Implementing Rules and Regulations | Operational rules for implementing the Data Privacy Act |
| NPC Rules of Procedure | How complaints and cases are filed and handled before the Commission |
| NPC breach-notification issuances | Security incident management, mandatory breach notification and reporting |
| NPC circulars and advisories | Sector-specific, procedural and emerging privacy guidance |
Key Topics to Track
- data-subject rights;
- personal information controller and processor duties;
- privacy impact assessments;
- data protection officers;
- security measures;
- data sharing and outsourcing;
- personal data breach notification;
- complaints and administrative fines;
- AI, biometrics and new processing technologies.
Use the Current NPC Source
Because NPC guidance changes over time, businesses should verify the current circular or advisory before relying on an older compliance summary. Cybercode will keep this page as a living index.
Related Guides
- Data Privacy Compliance Checklist
- Data Breach Notification Philippines
- Data Privacy Complaint Checklist
