CyberCode.ph · Philippines

Data Privacy Rights in the Philippines: What Are Your Rights?

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 2, 2026

Direct Answer: Under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), individuals whose personal data is processed have enforceable rights over that information. These include the rights to be informed, access personal data, object to certain processing, correct inaccurate information, seek erasure or blocking in qualifying circumstances, obtain certain data in a portable format, seek damages, and file a complaint with the National Privacy Commission (NPC).

These rights are important but not absolute. Their application can depend on why the information is being processed, the legal basis relied upon, and specific exceptions recognized by law.

Primary authority: National Privacy Commission — Data Subject Rights.

Key Takeaways

  • The Data Privacy Act gives individuals meaningful rights over personal information relating to them.
  • You generally have a right to know what information is collected, why it is processed, how it is used, who receives it, and how long it will be kept.
  • You may request access to personal data an organization holds about you.
  • Incorrect or inaccurate information may be corrected.
  • You may object to certain processing, but an objection does not automatically require an organization to stop processing if another lawful ground applies.
  • Personal data may sometimes be erased, blocked, removed, or destroyed when qualifying legal grounds exist.
  • Certain electronically processed data may be subject to data portability rights.
  • A person whose privacy rights have been violated may file a complaint with the National Privacy Commission.
  • Data subjects may also seek indemnification for damages resulting from certain unlawful or unauthorized uses of personal information.

Jump to a Section

  1. What is a data subject?
  2. What are your data privacy rights?
  3. Right to be informed
  4. Right to access
  5. Right to object
  6. Right to correction
  7. Right to erasure or blocking
  8. Right to data portability
  9. Right to damages
  10. Right to file a complaint
  11. How to exercise your rights
  12. What evidence should you preserve?
  13. FAQs

Decision Snapshot

Question Practical Answer
Can you ask what personal information a company has about you? Yes.
Can you ask why it is being processed? Yes.
Can you request correction of inaccurate information? Yes.
Can you object to processing? Yes, but lawful exceptions may allow continued processing.
Can you demand deletion in every situation? No. Erasure or blocking depends on qualifying circumstances.
Can you request your data in a reusable electronic format? Sometimes. Data portability applies under specific conditions.
Can you complain to the NPC? Yes.
Can you claim damages after a privacy violation? Potentially, yes.

What Is a Data Subject?

A data subject is an individual whose personal information is processed. You may be a data subject when a bank maintains your account details, an employer holds your employee records, an online store stores your name and delivery address, a hospital maintains health information about you, or an app collects information associated with your account.

To understand what information qualifies as protected data, see What Is Personal Information Under the Philippine Data Privacy Act? and What Is Sensitive Personal Information Under RA 10173?.

What Are Your Data Privacy Rights in the Philippines?

Republic Act No. 10173 and its Implementing Rules and Regulations establish several rights that allow data subjects to understand, influence, and challenge how their personal data is processed.

The National Privacy Commission identifies the principal data subject rights as the right to be informed, right to access, right to object, right to rectify, right to erasure or blocking, right to data portability, right to damages, and right to file a complaint.

These rights work together. Privacy protection is therefore much broader than simply asking whether an organization obtained consent.

1. Right to Be Informed

You have the right to know whether personal data relating to you will be, is being, or has been processed.

This includes meaningful information about the personal data involved, the purpose of processing, the basis of processing when relevant, the scope and method of processing, recipients or classes of recipients, the identity and contact details of the personal information controller or its representative, retention period, and the existence of your rights.

Example

You create an account with an online service. The service should not simply collect your name, telephone number, location, purchase information, and other personal data without giving meaningful information about how that information will be used. A privacy notice is one common way organizations provide this information.

2. Right to Access

You may request reasonable access to personal data that an organization processes about you.

Access can help you determine whether information held about you is accurate and whether it is being processed appropriately. Depending on the circumstances, this may include the contents of the data processed, the source of the information, recipients, how the data was processed, reasons for disclosures, and certain information about automated processing.

Example

Suppose an insurance company rejects an application and you believe incorrect personal information may have contributed to the decision. An access request may help you determine what information the organization actually maintains about you.

The right of access is not necessarily a right to unrestricted access to every internal company record. Other legal rights, confidentiality requirements, and applicable limitations may matter.

3. Right to Object

You may object to the processing of your personal data in circumstances recognized by privacy law.

The Implementing Rules and Regulations specifically address objections involving matters such as direct marketing, automated processing, and profiling. However, objecting does not automatically make all further processing unlawful. An organization may have another legal basis that allows or requires processing to continue.

Example: Marketing Messages

You gave an online retailer your email address to complete an order. That does not necessarily give the retailer unlimited authority to use your information indefinitely for every unrelated purpose. If your information is being used for direct marketing, your right to object may become particularly relevant.

4. Right to Rectification or Correction

You have the right to challenge inaccurate or erroneous personal data and seek its correction.

Incorrect personal information can cause real consequences. Examples include a wrong birth date, address, account status, employment record, transaction detail, contact information, or identification record.

When exercising this right, identify the inaccurate information clearly and, where appropriate, provide documentation supporting the requested correction.

5. Right to Erasure or Blocking

Philippine privacy law provides a right to seek suspension, withdrawal, blocking, removal, or destruction of personal information under qualifying circumstances.

This does not create an unlimited right to force every organization to delete every record on demand. Circumstances that may support erasure or blocking include personal information that is incomplete, outdated, false, unlawfully obtained, used for unauthorized purposes, no longer necessary for the purposes for which it was collected, or otherwise processed unlawfully under applicable rules.

Can You Ask a Company to Delete Your Data?

Yes, you can make the request. Whether the company must comply depends on the circumstances.

An organization may legitimately need to retain information because of statutory recordkeeping requirements, contractual obligations, tax or accounting requirements, pending disputes, regulatory requirements, fraud prevention, establishment or defense of legal claims, or another lawful basis.

This is why “withdraw consent” and “delete all my data” are not always legally identical.

6. Right to Data Portability

In qualifying circumstances, you may obtain a copy of electronically processed personal data in an electronic or structured format that allows further use.

Section 18 of the Data Privacy Act recognizes data portability where personal information is processed electronically and in a structured and commonly used format. The right is particularly relevant to certain automated processing situations involving consent, contract, or commercial purposes.

It does not necessarily mean every document ever created about you must be converted into a downloadable format.

7. Right to Damages

A data subject may be entitled to indemnification for damages resulting from certain improper uses of personal data.

Section 16 of RA 10173 recognizes indemnification for damage caused by inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal information. Whether compensation is actually recoverable in a particular dispute depends on the evidence, circumstances, and applicable proceedings.

A privacy violation does not automatically establish a particular amount of damages.

8. Right to File a Complaint

If you believe your personal information has been misused or your data privacy rights have been violated, you may file a complaint with the National Privacy Commission.

The NPC provides complaint information and forms on its official website. Because procedural requirements and submission methods can change, check the NPC’s current complaint guidance before filing.

Are Your Data Privacy Rights Absolute?

No. Data subject rights are important, but they are not unlimited.

RA 10173 recognizes limitations in specific circumstances, including certain processing solely for scientific and statistical research and information gathered for investigations relating to criminal, administrative, or tax liabilities. Other situations may also involve competing legal duties or lawful bases.

Therefore, a company responding that it cannot delete a record because a law requires retention is not automatically violating your rights. The important questions are what information is involved, why it is being processed, what legal basis applies, whether continued processing is necessary, and whether a valid exception or legal obligation exists.

Does a Company Always Need Your Consent?

No. Consent is not the only possible lawful basis for processing personal information.

For ordinary personal information, Philippine privacy law recognizes other possible grounds, including circumstances involving contracts, legal obligations, vitally important interests, public authority, and legitimate interests, subject to the requirements of the Act.

For the broader legal framework, see Data Privacy Act of 2012 Philippines: Complete Guide to RA 10173.

How Do You Exercise Your Data Privacy Rights?

A practical first step is usually to contact the organization responsible for processing the information. Look for its privacy notice, privacy policy, Data Protection Officer, privacy contact, customer-support channel, or formal data-subject-request procedure.

Then identify exactly which right you are exercising. For example, you might request access to personal data, correction of inaccurate information, cessation of direct marketing, or erasure of data that you believe is no longer lawfully needed.

Specific requests are usually easier to evaluate than a general statement such as “delete everything you know about me.”

What Information Should You Include in a Privacy Request?

  1. Your name and sufficient information to identify the relevant account or record.
  2. The organization or service involved.
  3. The particular personal information concerned.
  4. The privacy right you are attempting to exercise.
  5. A clear description of what you want the organization to do.
  6. Relevant dates.
  7. Supporting documentation where necessary.
  8. A reasonable method for the organization to respond.

Organizations may also need to verify that the person making an access or correction request is actually entitled to receive or change the information.

What Evidence Should You Preserve?

If you believe your privacy rights have been violated, preserve relevant evidence before making changes that could destroy it.

Depending on the incident, this may include:

  • screenshots;
  • full emails and email headers;
  • text messages and chat conversations;
  • privacy notices and consent screens;
  • account settings;
  • copies of requests you submitted;
  • responses from the company;
  • transaction records;
  • dates and timestamps;
  • URLs;
  • account notifications;
  • breach notifications; and
  • an incident timeline.

Where possible, preserve original files. Do not unnecessarily crop, alter, overwrite, or delete original evidence.

What If the Company Ignores Your Request?

Keep proof that you submitted the request. If the matter remains unresolved and you believe the Data Privacy Act or your rights have been violated, the National Privacy Commission provides a formal complaint mechanism.

The NPC’s published complaint procedure should be checked before filing because procedural requirements can change.

Can Someone Else Exercise Your Privacy Rights?

In certain circumstances, yes. RA 10173 recognizes transmissibility of certain data subject rights. Lawful heirs or assigns may invoke applicable rights after a data subject’s death or when that person is incapacitated or otherwise incapable of exercising the rights. Parents, guardians, or authorized representatives may also act in qualifying circumstances.

Practical Scenarios

A Company Keeps Sending Marketing Messages

You previously provided your telephone number while purchasing a product and continue receiving marketing messages. Relevant rights: the right to be informed and right to object.

An Online Account Contains the Wrong Personal Information

Your account shows an incorrect birth date or address. Relevant right: rectification. Request correction and provide supporting information if necessary.

A Company Holds Data It No Longer Appears to Need

You closed an account years ago but discover unnecessary profile information remains stored. Relevant right: erasure or blocking may potentially apply. Ask why the information is still being retained and what lawful basis supports continued storage.

You Want to Know What Information a Company Has About You

You suspect an organization has built a detailed profile using information collected over several years. Relevant rights: be informed and access.

Your Personal Information Was Disclosed Without Authorization

A document containing your personal information was publicly posted. Potentially relevant rights: complaint, damages, and possibly erasure or blocking depending on the facts. Preserve the evidence before requesting removal.

Common Mistakes

Assuming Consent Controls Everything

Consent is important, but it is not the only lawful basis recognized by privacy law.

Assuming the Right to Delete Is Unlimited

Organizations may sometimes lawfully retain records despite a deletion request.

Sending a Vague Request

Identify the specific information and right involved.

Deleting Your Own Evidence

Preserve screenshots, messages, emails, and other evidence before accounts or content disappear.

Publicly Posting More Personal Information While Complaining

Avoid unnecessarily publishing IDs, complete addresses, account numbers, or other sensitive information when asking for help online.

Frequently Asked Questions

What are the eight data privacy rights in the Philippines?

The National Privacy Commission identifies the principal rights as the rights to be informed, access, object, rectify, erase or block, data portability, damages, and file a complaint.

Can I ask a company what information it has about me?

Yes. The right of access allows data subjects to seek reasonable access to personal data being processed and related processing information, subject to applicable law and limitations.

Can I demand that a company delete my information?

You can request deletion, blocking, or destruction, but the right is not absolute. The applicable circumstances depend on the lawfulness, necessity, accuracy, and purpose of the processing and other legal requirements.

Can a company process my data without my consent?

Potentially, yes. Consent is not the only lawful basis for processing personal information under the Data Privacy Act.

Can I object to marketing use of my information?

Yes. The implementing rules recognize the right to object in relation to processing including direct marketing.

Can I correct information a company has about me?

Yes. Data subjects have a right to challenge inaccurate or erroneous personal data and request rectification.

Can I get compensation after a privacy violation?

Potentially. The DPA recognizes indemnification for damages resulting from specified improper handling or use of personal information. Whether damages are recoverable depends on the facts and applicable proceedings.

Where do I complain about a data privacy violation?

Complaints involving potential violations of the Data Privacy Act may be filed with the National Privacy Commission, subject to its current procedural requirements.

Are data privacy rights unlimited?

No. The law recognizes limitations and exceptions in specific circumstances.

Official Sources

Related CyberCode Guides

CyberCode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.