CyberCode.ph · Philippines

Data Subject Rights in the Philippines: What to Do First, What to Ask and Where to Report

Last updated October 7, 2026 · Practical privacy, cybersecurity and technology-law guidance

Philippines • Updated October 2026 • Practical guide to the Data Privacy Act of 2012

When a company holds your name, phone number, health record, location history or account details, you are a data subject under the Data Privacy Act of 2012 (RA 10173). You have rights to know how your data is used, inspect it, correct errors, object in appropriate cases, request erasure or blocking in appropriate cases, obtain portable data when the conditions are met, complain, and seek damages when warranted. The legal basis is Sections 16 to 18 of the Act: Section 16 lists the core rights (to be informed, to access, to correct, to have data blocked, removed or destroyed in stated cases, and to be indemnified for damages); Section 17 lets lawful heirs and assigns invoke those rights after the data subject dies or becomes incapacitated; and Section 18 adds data portability (RA 10173, National Privacy Commission). The National Privacy Commission (NPC) rights guide describes these protections.

Start here: Preserve evidence and secure any compromised account. Then send a specific written request to the organization that decides why and how your data is processed—the personal information controller (PIC)—usually through its privacy notice or data protection officer (DPO). A personal information processor (PIP) processes data on the PIC’s instructions, such as an outsourced service provider. The PIC should tell you who handles requests even when a vendor operates the system. If the matter is unresolved or serious, use the NPC’s formal complaint route. Do the written request first: under the NPC’s Rules of Procedure, a complaint is generally given due course only if you informed the PIC in writing and it did not act appropriately, or did not respond within 15 calendar days (details below). A privacy complaint is distinct from a fraud or physical-safety report.

For the broader overview of all eight rights, see CyberCode’s Data Privacy Rights in the Philippines. This guide focuses on choosing the first action and reporting route for a specific problem.

The benefits: what exercising your rights can change

Right or action Practical benefit Example
Be informed and get access Learn what an organization holds, why, where it came from, who received it and how long it plans to keep it. You ask a shopping app whether it shared your phone number with marketing partners.
Object to certain processing Stop or challenge processing based on consent or legitimate interest, including direct marketing or profiling, subject to another lawful basis. You opt out of promotional profiling while keeping a necessary service account.
Correct inaccurate data Prevent mistakes from following you through a service or decision. A lender has the wrong contact number or a clinic has a mistaken birth date.
Seek erasure or blocking Limit continued use of data that is no longer needed or was unlawfully obtained or used, when legal conditions are met. You ask a former service to remove unnecessary ID images after the purpose has ended.
Request portability Obtain qualifying data in a commonly used structured format for your own use or transfer, where processing is based on consent or contract and electronically structured. You request an eligible transaction history as CSV for a move to another service.
Complain and seek appropriate remedies Create a record and ask the regulator to examine a suspected rights violation; damages may be available when supported by evidence and law. A company ignores repeated correction requests and its inaccurate record causes documented harm.

Limits matter. These rights give you reasonable control, not an automatic veto over every lawful use. Consent is not the only possible legal basis. A deletion request may be refused in whole or part where data is still needed for a legal obligation, a claim, or another lawful purpose. Portability applies only under its stated conditions: the NPC says processing must be based on consent or contract and done electronically in a structured, commonly used format, and it covers data you provided or that was observed through your use of the service. NPC: objection · erasure · portability · access.

Data privacy action matrix: what happens, what to do first, and where to report

What happened First action What to ask or do next Reporting route if unresolved or serious
A company collected your details but gives no clear privacy notice. Save the sign-up screen, form and current notice. Ask the PIC/DPO what data is collected, purpose and legal basis, recipients, retention period and how to exercise your rights. NPC formal complaint guidance for a suspected privacy violation.
You do not know what data it holds or shared. Identify the account and the exact categories or dates you need. Send an access request to the PIC/DPO for a copy or details of your data, sources, purpose, recipients and retention. Use CyberCode’s access-request guide and letter template. NPC if a rights request is improperly denied or ignored; retain the request and reply.
A record about you is wrong. Keep a copy of the incorrect record and reliable proof of the correct information. Request rectification and ask whether recipients of the wrong record can be informed. Some civil-registry or other official corrections require their own legal process. NPC for a privacy-rights dispute; use the responsible government procedure where correction requires an official order.
You receive unwanted marketing or discover profiling. Save a sample message and its unsubscribe or preference screen. Object or withdraw consent, identifying the marketing or profiling activity. Ask the PIC to explain any other lawful basis it relies on to continue. NPC if the company continues processing without a valid basis or does not address the objection.
A former app still keeps or exposes your ID or private details. Save the listing, publication, URL or account screen before anything changes. Ask for erasure or blocking, describe why retention or use is no longer necessary or unlawful, and seek confirmation of action. Use CyberCode’s deletion request template. NPC if improperly refused; a platform or search service may have a separate removal route for public content.
You want to move your data to another service. Confirm the relevant data is yours and was supplied or observed through use of the service. Ask the PIC for qualifying electronically processed data in a common structured format or for a permitted transfer. NPC if a qualifying portability request is wrongly refused.
Your data appears in a breach or a scammer is using it. Secure the account, change affected passwords, enable MFA, alert a bank or wallet immediately if money is at risk, and save the message or transaction details. Ask the PIC what data was involved, what containment it performed and what protective steps you should take. See CyberCode’s data-breach guide. NPC for privacy issues; report financial fraud to the payment provider and appropriate law-enforcement or cybercrime channel as well. Do not wait for a formal privacy complaint to secure funds.
A person’s data was misused and you are acting for them. Preserve proof of the relationship and authority, without exposing more data. A parent or legal guardian may act for a minor. Other representatives should check the NPC rules on authorization, including special power of attorney where required. Follow NPC complaint instructions with the required authority and evidence.

The NPC lists eight rights: be informed, access, object, rectify, erasure or blocking, portability, file a complaint, and damages. Its guide also explains representation for minors, legal assignees and heirs, and limitations for certain research and investigations. The matrix is a starting point, not a promise that every request must be granted in full. NPC rights overview.

How to make a request the organization can act on

  1. Find the controller and privacy contact. Use the organization’s privacy notice, official website or account support page. Verify the destination independently; do not send a scan of your ID to an address from a suspicious message.
  2. Name the right and the data. For example: “I request access to the phone number and location data linked to my account, the purposes and recipients, and the retention periods.” A narrow request is easier to investigate.
  3. Give safe proof of identity. Ask what minimum verification is needed and send it through a secure official channel. Do not share passwords or one-time codes.
  4. Keep a paper trail. Save the request, delivery confirmation, ticket number, replies and supporting evidence. If the company refuses, ask for the reason and the lawful basis it relies on.
  5. Escalate based on the actual harm. If data is being actively exposed, request containment immediately. If an account or wallet is compromised, secure it and notify the provider first. For a continuing privacy violation or unresolved request, prepare a formal NPC complaint.

Sample request: “I am the data subject for account [reference]. Please confirm whether you process [specific data], the purpose, legal basis, recipients and retention period. I request [access/correction/objection/erasure/portability] because [brief facts]. Please acknowledge this request, tell me how to verify my identity securely, and provide a written response.”

Who receives a report, and how?

Destination Use it for What to prepare
The PIC/DPO first A rights request, correction, objection, removal request, or explanation of processing. Account reference, dates, the specific data and remedy, screenshots and a safe reply address.
NPC: file a complaint A suspected violation of data subject rights or personal-data breach affecting you. The NPC describes a filled and notarized complaint-assisted form or verified complaint, evidence and witness affidavit, submitted in person, by registered mail or courier, or by an electronic method the Commission authorizes. Check the current instructions before sending; a general inquiry email is not automatically a properly filed formal complaint.
Bank, wallet or platform plus cybercrime authorities Theft, account takeover, extortion, impersonation or a live scam alongside data misuse. Freeze or secure the account first. Keep transaction references, recipient details, URLs, messages and a timeline; use the provider’s official fraud channel and the relevant police or cybercrime route. A complaint to NPC does not replace urgent fraud reporting.

The NPC complaint page says its investigators have 30 calendar days from receipt to give due course or dismiss a complaint without prejudice; it describes final resolution as a longer process. That is a procedural estimate, not a deadline to wait before protecting an account or stopping a scam. CyberCode has a separate step-by-step NPC complaint guide for the filing details.

Before you file with the NPC: the written-request rule and timing

Write to the PIC first, then wait 15 calendar days. Rule II, Section 2 of the NPC’s 2021 Rules of Procedure (NPC Circular No. 2021-01, as amended by NPC Circular No. 2024-01) says no complaint will be given due course unless you show that (1) you informed the PIC, PIP or concerned entity in writing of the privacy violation or breach, and (2) it did not take timely or appropriate action, or did not respond within 15 calendar days of receiving your letter. The NPC may waive this for good cause shown, or where the complaint involves a serious violation or breach (2021 Rules of Procedure, as amended).

Under Rule IV, Section 1, an investigating officer may dismiss a complaint without prejudice if, among other grounds, it is insufficient in form, the complainant did not give the respondent a chance to address it without justification, or there is not enough information to support the allegations. A dismissal without prejudice can be cured and refiled, but it costs time.

Step What to do Keep as proof
1. Written request to the PIC Send a dated letter or email to the DPO naming the right, the data and the remedy you want. Copy of the request and delivery or read confirmation.
2. Wait 15 calendar days Count from the PIC’s receipt. Act sooner only to secure accounts or money, which is not a privacy complaint. Any reply, ticket number or the absence of a reply.
3. Verified complaint to the NPC File a notarized complaints-assisted form or a verified complaint with evidence and any witness affidavits. All correspondence with the PIC; the Rules require the complaint to state it.
4. Track the NPC’s initial action The investigating officer has 30 calendar days from receipt to give due course or dismiss without prejudice. Your filing receipt and case reference.

Is there a deadline to file? The Rules of Procedure do not set a separate filing deadline for complaints. For violations penalized by the Data Privacy Act, Rule I, Section 6 adopts the prescription periods under Act No. 3326. CyberCode did not verify which period applies to any particular violation, so file promptly once the 15-day period has passed, and get legal advice if the events are old. For damages in court, or for a criminal case, a lawyer or the Public Attorney’s Office can advise on the right route.

Why this matters

A data right is useful when it produces a specific outcome: an explanation, a copy, a correction, a lawful stop to marketing, a justified deletion, or a documented complaint. Ask for the remedy that fits the problem, preserve proof, and keep immediate security actions separate from the slower regulatory process. That makes the law practical for an ordinary person and gives responsible organizations a clear request they can answer.

Primary sources: NPC data subject rights; Data Privacy Act of 2012; NPC right to be informed; access; object; rectify; erasure or blocking; portability; complaint instructions; 2021 Rules of Procedure of the NPC, as amended; NPC notice on NPC Circular No. 2024-01.

Sources rechecked as of: 2 October 2026

Disclaimer

This is general information about Philippine privacy rights, not legal advice or a finding that any organization violated the law. The result of a request depends on the facts, the lawful basis for processing and applicable exceptions. Check current NPC instructions and seek qualified advice for a specific dispute.

Related articles

If the data subject is a minor using an app, game or platform, see the children’s personal data guide for age assurance, high-privacy defaults, profiling and parent evidence steps.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.