Last materially reviewed: September 6, 2026
Direct Answer
Republic Act No. 12234, the Konektadong Pinoy Act, is now in force and has implementing rules. The law creates a broader open-access framework for Philippine data transmission, requires Data Transmission Industry Participants (DTIPs) to register with the National Telecommunications Commission, promotes infrastructure sharing and competition, and imposes cybersecurity and performance obligations. The law lapsed into law on August 24, 2025, and its IRR was issued on November 5, 2025.
For businesses, the practical question is whether an activity makes the company a DTIP or otherwise places it inside the Act’s registration, authorization, access, spectrum, infrastructure-sharing or cybersecurity framework. For consumers, the intended effect is more competition, wider coverage and more affordable and reliable connectivity, although outcomes depend on implementation by DICT, NTC, PCC and market participants.
For a recent example of NTC enforcement on mobile broadband quality, see the NTC’s ₱100,000 daily penalty orders against DITO, Globe and Smart.
Primary authorities: Republic Act No. 12234 and Implementing Rules and Regulations of RA 12234.
Key Takeaways
- The Act is already law. It lapsed into law on August 24, 2025.
- The IRR is also in effect. It was issued on November 5, 2025.
- DTIPs must register with the NTC. Some activities, such as operating an international gateway facility or core/backbone network, require additional authorization.
- Open access and infrastructure sharing are central. The framework is intended to lower barriers and improve competition.
- Cybersecurity is a statutory obligation. DTIPs must adopt national and global best practices and standards and are subject to cybersecurity performance requirements.
- Registration does not erase every other rule. Spectrum, competition, foreign investment, consumer, privacy and other laws may still apply.
What Changed Under the Konektadong Pinoy Act?
The Konektadong Pinoy Act establishes a comprehensive data-transmission framework rather than treating connectivity only through older telecommunications assumptions. Its policy goals include narrowing the digital divide, encouraging investment, supporting open access, improving competition, promoting infrastructure sharing and making data-transmission services more affordable and reliable.
The Act also assigns specific implementation roles to DICT, NTC and the Philippine Competition Commission, among other agencies.
Decision Snapshot
| Question | Current answer | Practical implication |
|---|---|---|
| Is RA 12234 already law? | Yes | Businesses should assess current compliance, not treat it as a proposal |
| Does it have an IRR? | Yes, issued November 5, 2025 | Operational requirements must be read from both the Act and IRR |
| Must DTIPs register? | Yes, with the NTC | Determine whether the business falls within the DTIP definition |
| Are all data-transmission activities treated the same? | No | Core/backbone and international gateway activities can require additional authorization |
| Does the Act create cybersecurity duties? | Yes | Security standards, audit and certification planning matter |
| Does it replace privacy or cybercrime law? | No | RA 10173, RA 10175 and other laws continue to operate |
Who Is a Data Transmission Industry Participant?
The Act and IRR use the term Data Transmission Industry Participant (DTIP) for entities participating in covered segments of the data-transmission network. A business should not decide coverage based only on whether it calls itself a telco, ISP, infrastructure company, satellite provider, network operator or digital platform.
The practical compliance step is to compare the actual service, network segment, facilities and role against the statutory and IRR definitions. If the activity falls within the covered framework, NTC registration or authorization requirements may apply.
What Registration Is Required?
Section 8 of RA 12234 provides that DTIPs are required to register with the NTC. The NTC is directed to maintain a speedy administrative process and apply eligibility criteria aligned with DICT policy.
The IRR further distinguishes between types of participation. Qualified entities may receive a certificate of registration for last-mile or middle-mile participation, while an entity seeking to operate an international gateway facility or core/backbone network requires authorization after review of its route or rollout plan and manner of construction.
Does Registration Mean No Other Approval Is Needed?
No. The Act changes the participation framework but does not create blanket deregulation. A business may still need to comply with requirements involving spectrum, facilities, foreign investment, public-service rules, competition, permits, data privacy, cybersecurity, local government approvals or sector-specific obligations.
Businesses should map the exact activity rather than assume that one NTC registration resolves every legal requirement.
What Does Open Access Mean?
The Act adopts an open-access policy designed to make relevant digital infrastructure and services available on fair, reasonable and non-discriminatory terms where the law and implementing mechanisms require access. The objective is to reduce barriers to entry and avoid unnecessary duplication of costly infrastructure.
The IRR contemplates access lists, reference access offers and terms dealing with interconnection, infrastructure sharing, traffic, cybersecurity, financial terms, technical commitments, confidentiality, liability and disputes.
Infrastructure Sharing and Co-Location
Infrastructure sharing is a core part of the law’s strategy. Sharing ducts, towers, facilities, network elements and other relevant infrastructure can reduce deployment costs and accelerate coverage, particularly in underserved areas.
For operators, this creates both opportunity and compliance work: access arrangements should be reviewed for pricing, technical standards, service levels, confidentiality, cybersecurity, liability and competition concerns.
What Cybersecurity Duties Apply?
RA 12234 expressly requires DTIPs to adopt and comply with national and global best practices and standards on cybersecurity. The Act also provides for cybersecurity performance audit by the DICT Cybersecurity Bureau.
Under Section 9 of the Act, DTIPs must secure cybersecurity certification from a third-party organization within two years from registration, based on prevailing ISO information-security-management standards or other minimum security standards identified by DICT.
This means cybersecurity is not merely a voluntary best practice for covered DTIPs. It is part of the statutory compliance architecture.
What Does the Law Say About Spectrum?
The Act creates a Spectrum Management Policy Framework intended to promote fair competition, efficient use and adaptation to technology changes. It requires review of spectrum allocations and assignments and provides mechanisms involving valuation, assignment, joint use, recall and transparency.
Businesses that need spectrum resources should not assume ordinary DTIP registration alone is enough. Spectrum use remains subject to NTC authorization and the applicable framework.
How Does the Act Affect Businesses?
The most direct effects are on entities that build, own, lease, operate or seek access to data-transmission infrastructure. Possible business implications include:
- new or changed NTC registration and authorization pathways;
- opportunities for new entrants and community-based networks;
- access to infrastructure and interconnection arrangements;
- cybersecurity audit and certification planning;
- new performance standards;
- spectrum-policy changes;
- pricing and transparency obligations; and
- competition scrutiny for entities with significant market power.
How Does the Act Affect Consumers?
The law’s policy objective is to support broader, more affordable and more reliable connectivity through competition, investment, infrastructure sharing and open access. Consumers may benefit if those mechanisms lead to more providers, better coverage, lower deployment costs and stronger service-performance standards.
However, the Act does not guarantee an immediate price reduction or service improvement for every customer. Real-world results depend on agency implementation, market entry, infrastructure investment and compliance by industry participants.
What Existing Laws Still Apply?
RA 12234 sits alongside other Philippine technology laws. Depending on the activity, relevant frameworks can include:
- Data Privacy Act of 2012 for personal-data processing;
- Cybercrime Prevention Act for cybercrime offenses and investigations;
- Electronic Commerce Act for electronic transactions;
- Internet Transactions Act for covered online transactions and platforms; and
- competition, foreign-investment, public-service, consumer and local permitting rules where applicable.
Business Compliance Checklist
- Identify whether the company is a DTIP under the Act and IRR.
- Map the network segment and service being provided.
- Determine whether NTC registration or additional authorization is required.
- Identify any spectrum requirement.
- Review infrastructure-sharing and access obligations.
- Assess cybersecurity audit and certification requirements.
- Review performance, reporting and transparency obligations.
- Check foreign-investment and competition implications.
- Map privacy and cybercrime obligations separately.
- Monitor DICT and NTC implementing issuances for operational changes.
Frequently Asked Questions
Did President Marcos sign the Konektadong Pinoy Act?
The Act lapsed into law on August 24, 2025 without the President’s signature under the constitutional process stated in the official law text.
Is the IRR already available?
Yes. The implementing rules were issued on November 5, 2025 and should be read together with the statute.
Does every internet-related company automatically become a DTIP?
No. Coverage depends on the statutory definitions and the company’s actual role in data transmission. Businesses should analyze their activity rather than rely on labels.
Does the Act remove all franchise, permit or regulatory requirements?
No. The Act creates its own registration and authorization framework for covered DTIPs, but other legal and regulatory requirements can still apply depending on the activity.
Is cybersecurity certification mandatory?
For covered DTIPs, the Act requires cybersecurity certification within two years from registration based on applicable standards identified in the law and DICT framework.
Related Cybercode Guides
- Technology Law Philippines
- Philippine Technology Laws Database
- Cybersecurity Compliance for Philippine Companies
- Electronic Commerce Act Philippines
- Internet Transactions Act Philippines
Official Sources
- Republic Act No. 12234 — Konektadong Pinoy Act
- Implementing Rules and Regulations of RA 12234
- Presidential Communications Office — IRR announcement
Disclaimer
Important: This article provides general educational information about Philippine law, regulation, cybersecurity, technology, or business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, agency procedures, technical standards, platform rules, and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when your rights, deadlines, money, safety, or legal exposure may be affected.

