Last materially reviewed: September 23, 2026
Direct Answer
To comply with Republic Act No. 10173, or the Data Privacy Act of 2012, a Philippine business must do more than publish a privacy policy or register with the National Privacy Commission. It must build an operating system for personal data: assign accountability, identify what data it processes, document a lawful and legitimate purpose, collect only what is proportionate, inform people clearly, protect the data with risk-based safeguards, control vendors, honor data-subject rights, and prepare for security incidents and breach reporting.
The exact controls depend on the data, systems, people, risks, and role of the organization. A small online shop and a healthcare platform do not need identical programs. Both, however, should be able to prove what they process, why they process it, who can access it, how long it is kept, how it is protected, and what happens when something goes wrong. The controlling starting points are RA 10173, its Implementing Rules and Regulations, and current National Privacy Commission issuances.
Evidence-and-Action Panel
Keep this evidence: DPO designation, personal-data inventory, processing register, privacy impact assessments, lawful-basis decisions, privacy notices, consent records where consent is used, vendor contracts, access reviews, training records, retention and deletion logs, incident assessments, breach reports, and proof of remediation.
Do these five things first:
- Name the person accountable for privacy and security.
- Map personal data in your five highest-risk systems.
- Check the purpose, lawful basis, notice, retention period, access, and vendor for each system.
- Close obvious exposures such as shared passwords, public folders, former-employee access, and unencrypted exports.
- Test who receives an incident report and who decides whether the NPC and affected people must be notified.
What Does RA 10173 Compliance Require?
Compliance has five connected layers: governance, lawful processing, transparency and individual rights, security, and proof. A weakness in one layer can undermine the others. Strong encryption does not legalize unnecessary collection, while a polished privacy notice does not cure weak access controls.
| Compliance layer | Business control | Evidence to retain |
|---|---|---|
| Accountability | DPO or accountable privacy lead, management oversight, assigned owners | Appointment document, responsibilities, reports, meeting records |
| Lawful and proportionate processing | Defined purpose, valid lawful basis, data minimization, retention limits | Processing inventory, lawful-basis record, retention schedule |
| Transparency and rights | Clear notices and a workable request channel | Notice versions, request log, identity-verification procedure, responses |
| Security | Organizational, physical, and technical safeguards matched to risk | Risk assessments, access reviews, logs, training, tests, remediation |
| Incident readiness | Detection, escalation, containment, assessment, notification, recovery | Incident register, decision record, reports, post-incident review |
Step 1: Confirm Your Role and Scope
Start by deciding whether the organization is a personal information controller, a personal information processor, or both in different activities. A controller decides why and how personal data is processed. A processor handles data on a controller’s instructions. A payroll company may be a processor for client employee records but a controller for its own workers and customers. See CyberCode’s guide to personal information controllers and processors.
Next, list the people whose data you handle: customers, employees, applicants, contractors, website visitors, suppliers, patients, students, users, and anyone captured by CCTV or recorded support calls. Include paper files, spreadsheets, messaging apps, cloud drives, backups, analytics, AI tools, and data held by vendors. If you are still deciding whether the Act applies to the organization, begin with which businesses must comply with the Philippine Data Privacy Act.
Step 2: Assign Accountability and Appoint a DPO
RA 10173 requires a personal information controller to designate one or more individuals accountable for compliance. NPC guidance also describes appointing a Data Protection Officer as a legal requirement for controllers and processors. The DPO does not have to perform every task personally, but the organization needs a named, supported person who can coordinate risk assessments, notices, rights requests, training, vendor reviews, incidents, and regulator communications.
- Give the DPO access to senior management and adequate time, authority, and resources.
- Define who owns privacy decisions in HR, marketing, operations, product, IT, and security.
- Publish a reliable privacy contact channel and plan for absences or staff turnover.
- Manage conflicts of interest. The person reviewing compliance should be able to challenge risky processing.
Official reference: NPC guidance on appointing a DPO.
Step 3: Build a Personal-Data Inventory
A useful inventory follows the data from collection to deletion. Do not stop at a list of databases. For every material process, record the data subjects, data categories, source, purpose, lawful basis, system, users with access, recipients, vendor, storage location, cross-border transfer, retention period, deletion method, and applicable notice.
For an online seller, the map may include storefront accounts, order records, courier handoffs, payment references, customer-support chats, marketing audiences, fraud screening, and accounting records. For a technology team, it may include production databases, logs, crash reports, analytics, test environments, support tools, model prompts, code repositories, and backups.
Step 4: Document Purpose, Lawful Basis, and Proportionality
Every processing activity should have a specific legitimate purpose and a lawful basis. Consent is one possible basis, but it is not the only one. Depending on the data and circumstances, processing may instead be necessary for a contract, legal obligation, vital interests, public authority, or a legitimate interest subject to statutory conditions. Sensitive personal information has stricter rules and should not be treated like ordinary contact data.
Apply proportionality by asking whether the purpose can be achieved with less data, fewer people having access, shorter retention, or a less intrusive method. A business asking for a government ID merely to join a basic newsletter would have difficulty explaining why that collection is necessary. A payroll team may need government identifiers, but access should be limited and retention should follow a documented legal and business need.
| Question | Weak answer | Better documented answer |
|---|---|---|
| Why do we collect it? | “For business purposes” | A specific operational or legal purpose tied to the transaction |
| What allows us to process it? | “The user gave us data” | An identified lawful basis and the facts supporting it |
| How much do we collect? | Everything the form can capture | Only fields necessary for the defined purpose |
| How long do we keep it? | Indefinitely | A stated period or defensible event-based rule |
Step 5: Give Clear Privacy Notices and Manage Consent Correctly
Tell people, in clear and accessible language, what data is collected, why it is used, the basis and scope of processing, who receives it, how long it is kept, what rights they have, and how to contact the organization. Place the notice where the decision happens: application form, checkout, employee onboarding, CCTV entrance, account registration, or product feature. A buried website policy may not provide meaningful notice for a separate employee or offline process.
When consent is the chosen basis, it must be valid for the actual purpose. Avoid bundled permissions, pre-checked boxes, or treating silence as agreement. Keep proof of what a person saw and agreed to, including the version and date. Withdrawal must be possible when the processing depends on consent. For a fuller checklist, see privacy notice requirements for Philippine businesses.
Step 6: Conduct Privacy Impact Assessments
A Privacy Impact Assessment evaluates how a system, project, process, or technology affects privacy and what controls are needed. Conduct one before launching or materially changing high-risk processing, not after the system is already live. Revisit it when the purpose, data, vendor, access model, automation, AI use, or threat environment changes.
- Describe the processing and business objective.
- Test necessity, lawful basis, transparency, and proportionality.
- Identify risks to people, not only risks to the company.
- Select controls, owners, deadlines, and any residual-risk decision.
- Record approval and review triggers.
Official reference: the NPC’s explanation of a privacy risk or impact assessment.
Step 7: Create a Privacy Management Program
Turn the legal rules into written, assigned procedures. The NPC’s compliance framework includes a Privacy Management Program and Privacy Manual covering how the organization handles data from collection through destruction. The documents should reflect what the business actually does; copied policies that no one follows can create false confidence and poor evidence.
- Data collection, use, sharing, access, correction, retention, and deletion
- Employee confidentiality, acceptable use, remote work, and account offboarding
- Vendor selection, contracting, monitoring, and termination
- Privacy-by-design review for new projects, campaigns, integrations, and AI tools
- Data-subject requests, complaints, security incidents, and breach escalation
- Training, audits, exceptions, corrective actions, and management reporting
Official reference: the NPC’s guidance on creating a Privacy Management Program and Privacy Manual.
Step 8: Implement Organizational, Physical, and Technical Security
RA 10173 requires reasonable and appropriate safeguards. “Reasonable” is not a license to do the minimum; controls must match the nature of the data, the risks, the size and complexity of operations, current capabilities, and the cost of implementation. NPC Circular No. 2023-06 provides current minimum security guidance for government and private-sector processing.
| Control area | Practical examples |
|---|---|
| Organizational | Policies, training, background-appropriate access, risk reviews, vendor controls, incident roles, change management |
| Physical | Locked records, visitor controls, secure disposal, device protection, restricted server or file rooms |
| Technical | Unique accounts, multi-factor authentication, least privilege, encryption where appropriate, patching, endpoint protection, logs, tested backups, secure configuration |
| Lifecycle | Privacy-by-design, test-data controls, retention automation, deletion verification, account offboarding |
Start with the controls that reduce likely and severe harm. Remove shared administrator accounts, require MFA for email and cloud tools, disable access immediately when staff leave, encrypt portable devices and sensitive exports where appropriate, restrict production data in test systems, monitor unusual access, and restore-test backups. CyberCode’s Philippine cybersecurity baseline explains the broader legal and practical security duties.
Step 9: Control Vendors, SaaS Tools, and Data Sharing
Using a cloud service, agency, payroll provider, courier, analytics tool, or AI platform does not remove the organization’s responsibility. Before sharing data, document the role of each party, instructions, purpose, permitted use, confidentiality, security, subcontractors, location, incident notification, assistance with rights requests, deletion or return, audit evidence, and exit arrangements.
Review whether the vendor uses data for its own purposes, including product improvement or model training. Do not upload customer, employee, or client data to a generative-AI tool merely because it is convenient. See the guides on vendor and SaaS security due diligence and customer data uploaded to ChatGPT.
Step 10: Make Data-Subject Rights Work in Practice
Create a request process that staff can recognize and escalate. A person should not need to know a legal phrase before the business treats a message as a possible privacy request. The process should cover intake, identity verification, logging, search, review of exceptions, response, correction or deletion where applicable, and secure delivery.
- Publish a monitored privacy contact address.
- Verify identity without collecting excessive new data.
- Search all relevant systems and responsible vendors.
- Keep a decision record, especially when a request is limited or denied.
- Use request trends to fix recurring data-quality or transparency problems.
Step 11: Check NPC Registration and Exemption Requirements
NPC registration is a separate compliance task, not the whole program. Under NPC Circular No. 2022-04, mandatory registration can apply based on workforce size, the number of individuals whose sensitive personal information is processed, or processing likely to pose a risk to data subjects’ rights and freedoms. Organizations that claim exemption should follow the current NPC declaration and undertaking process rather than simply assuming that “small business” means no filing.
Use the NPC’s current registration instructions and exemption guidance. Check fees, validity, renewal, update, and display requirements at the time of filing because administrative procedures can change.
Important: an NPC Certificate or Seal of Registration proves registration; it does not verify every statement filed or certify full privacy compliance. The underlying policies, controls, and evidence still matter.
Step 12: Prepare for Incidents and Breach Reporting
Build a response plan before an incident. Staff must know how to report a lost device, misdirected email, exposed database, compromised account, malicious insider, ransomware event, or vendor notification. The response team should preserve evidence, contain the incident, identify the affected systems and data, assess harm, document the notification decision, communicate accurately, and correct the root cause.
Not every security incident automatically triggers the same notification duty. Apply the legal criteria to the facts and keep the assessment. When mandatory notification is required, the rules can require notification to the NPC and affected data subjects within 72 hours from knowledge or reasonable belief that a qualifying breach occurred, subject to the governing rules. Use the current NPC reporting channel and instructions. CyberCode’s dedicated guide explains when a Philippine data breach must be reported.
The NPC also requires an Annual Security Incident Report covering security incidents and personal data breaches for the calendar year, including incidents not subject to mandatory notification. Verify the current filing window and procedure on the NPC’s breach reporting page.
Philippine SME and Technology-Team Examples
| Scenario | Main risk | First controls |
|---|---|---|
| Online shop using social media, a storefront, courier, and payment provider | Customer data copied across chats and spreadsheets with unclear retention | Map handoffs, restrict exports, publish checkout notice, set deletion rules, contract and review providers |
| Small employer using cloud HR and payroll tools | Government IDs, health data, bank details, and disciplinary records broadly accessible | Role-based access, separate sensitive files, vendor terms, offboarding, retention and secure deletion |
| SaaS startup logging user activity | Production data and logs reused in testing, analytics, or AI without clear purpose | PIA, data minimization, test-data controls, log retention, vendor review, documented lawful basis |
| BPO or agency handling client databases | Instructions, controller-processor roles, and incident duties are unclear | Written instructions, least privilege, monitoring, subcontractor controls, rapid client notification |
A 30-Day Compliance Build for a Small Business
| Period | Priority outcome |
|---|---|
| Days 1–7 | Assign the DPO or accountable lead; map critical systems; close urgent access and sharing weaknesses |
| Days 8–14 | Document purposes and lawful bases; identify high-risk processing; update key notices and forms |
| Days 15–21 | Complete priority PIAs; review vendors; approve retention, rights-request, and incident procedures |
| Days 22–30 | Train staff; test a rights request and breach scenario; confirm registration or exemption steps; report gaps to management |
This is a risk-based implementation sequence, not a statutory grace period. If the organization already processes personal data, legal duties already apply. High-risk exposures or an active incident should be addressed immediately.
Common Compliance Mistakes
- Treating consent as the answer to everything. Consent does not cure an unnecessary, excessive, insecure, or misleading process.
- Copying a privacy policy. A notice must match actual systems, purposes, recipients, retention, and rights channels.
- Focusing only on the website. HR files, messaging apps, paper forms, CCTV, exports, test systems, and backups may hold greater risk.
- Assuming the vendor owns the problem. Outsourcing processing does not outsource accountability.
- Collecting data “just in case.” Undefined future use conflicts with purpose limitation and proportionality.
- Keeping data forever. Indefinite retention expands exposure and becomes harder to justify.
- Buying security tools without governance. Tools cannot fix unclear ownership, excessive access, or a missing incident process.
Frequently Asked Questions
Does RA 10173 apply to a small business?
It can. Business size does not create a blanket exemption from the Data Privacy Act. Registration obligations may use thresholds and risk criteria, but the core processing, transparency, security, accountability, and rights duties can still apply to a smaller organization handling personal data.
Is consent always required to process personal data?
No. Consent is one lawful basis, but RA 10173 recognizes other bases subject to their conditions. The correct question is which lawful basis fits the specific purpose and data. Do not request consent when the business will proceed regardless of the answer or when another basis is the real justification.
Does an NPC registration certificate prove full compliance?
No. NPC Circular No. 2022-04 states that the certificate is proof of registration, not verification of its contents. Registration should therefore be treated as one administrative requirement within a broader compliance program.
Does every personal data breach have to be reported within 72 hours?
No. The mandatory notification criteria must be assessed against the incident. However, every incident should be escalated promptly, documented, contained, and evaluated. Qualifying breaches can trigger the 72-hour rule, while other incidents may still belong in the Annual Security Incident Report.
Is a public privacy policy enough?
No. A policy is only one transparency control. Compliance also requires lawful and proportionate processing, accountability, security, rights handling, vendor governance, retention, incident readiness, and evidence that these controls operate.
How often should the compliance program be reviewed?
Review it whenever material processing, technology, vendors, risks, or rules change, and use a regular scheduled review to catch drift. There is no single universal review interval that replaces event-driven reassessment. High-risk or fast-changing environments need more frequent testing.
Official Sources
- Republic Act No. 10173 — Data Privacy Act of 2012
- Implementing Rules and Regulations of RA 10173
- NPC Five Pillars of Compliance — Privacy Management Program
- NPC Circular No. 2023-06 Security FAQ
- NPC Circular No. 2022-04 on registration
- NPC breach reporting guidance
This guide provides general legal information, not legal advice. The correct compliance design depends on the organization, processing activity, contracts, sector rules, risks, and current NPC issuances.

