CyberCode.ph · Philippines

National Privacy Commission (NPC): Powers, Complaints and Registration

Last updated September 28, 2026 · Practical privacy, cybersecurity and technology-law guidance

Direct answer: The National Privacy Commission (NPC) is the Philippine government body that administers and enforces the Data Privacy Act of 2012 (Republic Act No. 10173). It receives and adjudicates data privacy complaints, investigates on its own initiative, registers data processing systems, receives breach notifications, issues circulars and advisory opinions, and imposes administrative fines. It cannot imprison anyone — criminal penalties under the Act are imposed by the courts, on referral to the Department of Justice.

Quick contacts (from the NPC contact page, checked September 28, 2026)

  • Trunkline: +632 5322 1322
  • Complaints: local 115; mobile 0905 506 1478 (Globe) or 0970 818 0555 (Smart)
  • Breach notification and registration (DBNMS, NPCRS): local 103 or 118; mobile 0910 102 9114 (Smart) or 0975 058 8355 (Globe)
  • Before you file a complaint: write to the organisation first and allow it 15 calendar days to respond. See how to file a data privacy complaint with the NPC.
  • Email addresses: listed per department on the NPC contact page.

For the broader law, rights, complaints and compliance map, use Cybercode’s Data Privacy Philippines hub.

Key Takeaways

  • The NPC is created by Section 7 of RA 10173 and is attached to the Department of Information and Communications Technology (DICT).
  • Before a data subject’s complaint will normally be entertained, the complainant must first have written to the organisation concerned and waited fifteen (15) calendar days for a response. This requirement can be waived in serious cases.
  • The NPC imposes administrative fines — a percentage of annual gross income, capped at ₱5,000,000. The imprisonment and criminal fines in Chapter VIII of the Act are imposed by courts, not by the NPC. These two tracks are routinely confused.
  • Registration of a data processing system is mandatory above defined thresholds (250 employees, or sensitive personal information on 1,000 or more individuals, or high-risk processing), and always for automated decision-making or profiling.
  • Breach notification to the NPC is due within 72 hours and must go through the Data Breach Notification Management System (DBNMS). Submissions made outside the DBNMS are not treated as valid.
  • There is no single statutory deadline for filing an NPC complaint. The Rules adopt the prescriptive periods in Act No. 3326, which vary with the offence.

Jump to a Section

Decision Snapshot

Use this to work out whether the NPC is the right body for your situation, and which route applies.

Your situation Is the NPC the right body? Route
A company mishandled, leaked or refused to correct your personal data Yes Write to the company first, wait 15 calendar days, then file a complaint
Your organisation suffered a personal data breach Yes Notify through the DBNMS within 72 hours, if the three conditions are met
You want to know whether a planned processing activity is lawful Yes Request an advisory opinion
You want someone jailed for a privacy offence Only indirectly The NPC may recommend prosecution to the DOJ; the courts impose imprisonment
You were scammed online and lost money Usually not Report to the PNP Anti-Cybercrime Group or the NBI instead
A lending app is contacting your phone contacts to shame you Yes This is a data privacy matter; complain to the NPC (the SEC also regulates the lender)
You want your data deleted and the company ignored you Yes Exhaust the company’s own channel first, then complain

What the National Privacy Commission Is

The National Privacy Commission is the independent body created by Republic Act No. 10173, the Data Privacy Act of 2012, approved on 15 August 2012. Its job, in the language of the Act, is to administer and implement the law’s provisions, to monitor and ensure compliance with international data protection standards, and to police how personal information is processed in the Philippines.

Two relationships are worth stating plainly, because they are commonly muddled:

  • The NPC is the regulator; RA 10173 is the law. The Act sets the obligations. The NPC interprets, enforces and supplements them through circulars and advisories. Our complete guide to the Data Privacy Act covers the statute itself.
  • The NPC is attached to the DICT, but is not the DICT. Section 9 of the Act attaches the Commission to the Department of Information and Communications Technology for purposes of policy and programme coordination. It remains a distinct body with its own adjudicatory powers.

Structure and leadership

The Commission is headed by a Privacy Commissioner, who also acts as Chairman and holds the rank and benefits of a Secretary. Two Deputy Privacy Commissioners — one for Data Processing Systems, one for Policies and Planning — hold the rank of Undersecretary. All three are appointed by the President for three-year terms, renewable once. The Act requires the Privacy Commissioner to be at least thirty-five years old, of good moral character and unquestionable integrity, and a recognised expert in information technology and data privacy.

As published on the NPC’s own website at the time of review, the Commission is headed by Privacy Commissioner and Chairman Atty. Johann Carlos S. Barcena, with Deputy Privacy Commissioners Atty. Jose Amelito S. Belarmino II and Atty. Juan Paolo F. Fajardo.

Section 8 of the Act imposes a confidentiality duty on the Commission itself: it must ensure at all times the confidentiality of any personal information that comes to its knowledge and possession. That matters when you file — the evidence you submit is handled under the same law you are invoking.

What the NPC Can Actually Do

Section 7 of RA 10173 lists the Commission’s functions. Rather than reproduce all seventeen paragraphs, here is what they amount to in practice, grouped by what a reader is likely to need.

Power What it means in practice Source
Ensure compliance by personal information controllers The general supervisory mandate behind everything else Sec. 7(a)
Receive complaints, investigate, mediate and adjudicate The NPC decides cases; it is not merely an advisory office Sec. 7(b)
Issue cease and desist orders; ban processing temporarily or permanently The sharpest tool it holds — it can stop a business activity outright Sec. 7(c)
Compel entities and government agencies to comply with its orders Orders are binding, not advisory Sec. 7(d)
Monitor government agency compliance with security measures Public sector systems are squarely within scope Sec. 7(e)
Recommend prosecution to the Department of Justice The bridge from administrative to criminal liability Sec. 7(i)
Review, approve or modify privacy codes Industry-level self-regulation runs through the NPC Sec. 7(j)
Comment on the privacy implications of proposed legislation A policy voice, exercised through position papers Sec. 7(l)–(m)
Coordinate with foreign regulators; negotiate cross-border arrangements Relevant to BPO and multinational processing Sec. 7(n)–(q)

What the NPC cannot do

This is the half that is usually missing from competing explanations, and it changes what a complainant should expect:

  • It cannot imprison anyone. Imprisonment under Chapter VIII of the Act follows a criminal conviction in court. The NPC’s role is to recommend prosecution to the DOJ under Section 7(i).
  • It does not award general damages the way a court does. Civil indemnity for a privacy violation is pursued in court; Section 37 leaves restitution to the New Civil Code.
  • It is not a general consumer complaints desk. If your grievance is about a defective product, a refund, or a scam that did not involve the mishandling of your personal data, the DTI, the SEC, the BSP or the police are the right forum.
  • It cannot act on a complaint you have not properly framed. The Rules allow outright dismissal on formal grounds, discussed below.

Who the NPC Regulates

The Act applies to personal information controllers (PICs) and personal information processors (PIPs) — broadly, organisations that decide how and why personal data is processed, and those that process it on their behalf. The distinction determines who carries which duty, and we cover it in detail in our guide on personal information controller vs processor.

In scope are private companies of every size, government agencies, schools, hospitals, banks, lending companies, BPOs, online platforms and, in defined circumstances, foreign entities processing the personal data of people in the Philippines. Out of scope, in general, are purely personal or household activities.

What counts as regulated data matters as much as who holds it. Ordinary personal information and sensitive personal information attract different thresholds throughout the Act — different penalties, different registration triggers, different breach consequences.

Filing a Complaint With the NPC

Who may file: under Rule II, Section 1 of the 2021 Rules of Procedure (NPC Circular No. 2021-01), data subjects who are the subject of a privacy violation or personal data breach may file complaints for violations of the Data Privacy Act.

The step most complainants miss: exhaustion

Rule II, Section 2 requires the complainant to establish two things before the NPC will take the case in the ordinary course:

  1. That the complainant gave written notice of the violation to the organisation responsible; and
  2. That the organisation failed to respond within fifteen (15) calendar days from receipt of that written information, or took no appropriate action on the matter.

This is not a formality. It is the single most common reason a complaint goes nowhere. Write to the company, keep proof of sending and of the date of receipt, and count fifteen calendar days — not working days.

The Rules allow the Commission to waive the requirement where the violation is serious enough to cause grave and irreparable damage, or where the conduct complained of is patently unlawful. That is an exception, and it should not be assumed.

Form and contents

Under Rule II, Section 3, a complaint must be in writing, verified and signed. It must identify the complainant and the respondent, give contact details, set out the material facts with supporting evidence, state the relief sought, and include a certification against forum shopping.

The NPC publishes a Complaint-Affidavit form on its website. The published procedure is to download and print the form, fill it out, have it notarised, and submit it in person, by courier, or by scanning and emailing it to the address listed on the NPC’s filing page. A filing fee of ₱500.00 applies under NPC Circular No. 2023-01 dated 17 May 2023, with exemptions for government agencies and qualified indigent litigants.

What you attach usually decides the case. Our guide on evidence for a data privacy complaint sets out what to preserve, and how to file a data privacy complaint with the NPC walks through the mechanics.

Is there a deadline to file?

There is no single number to quote here, and pages that give one are overstating the law. Rule I, Section 6 of the 2021 Rules states that the Commission adopts the periods of prescription for violations penalised by special acts as provided under Act No. 3326 and any amendments to it. Act No. 3326 sets different prescriptive periods according to the penalty attached to the offence, so the applicable period depends on which violation is alleged. The practical advice is to file promptly rather than to rely on a remembered figure.

What Happens After You File

A complaint does not automatically proceed to a full hearing. Rule IV, Section 1 permits outright dismissal within thirty calendar days of receipt on any of five grounds:

  1. The complaint is not in the required form;
  2. The complainant failed to give the respondent an opportunity to comment — the exhaustion point above;
  3. The matter does not involve a violation of the Data Privacy Act;
  4. There is insufficient information to substantiate the allegations;
  5. The parties cannot be identified despite diligent effort.

If the complaint survives, the process may involve evaluation, investigation by the Complaints and Investigation Division, a preliminary conference, submission of position papers, and a decision. Under Rule VI, the parties may jointly request mediation at the preliminary conference or at any time before the Commission renders its decision; mediation suspends the proceedings for sixty calendar days, extendable by a further thirty days for good cause.

NPC Circular No. 2024-01, signed on 26 January 2024, amended and renumbered substantial parts of the 2021 Rules, including the provisions on outright dismissal and sua sponte investigation, and added a new rule on compliance checks. Anyone working from an older copy of the Rules should check the amended text.

When the NPC Investigates Without a Complaint

The Commission does not have to wait for a complainant. Under the sua sponte investigation rule, the NPC — through its Complaints and Investigation Division or a special committee or task force — may initiate an investigation on its own initiative. The recognised triggers include pending cases before the Commission, news reports, studies, substantiated anonymous tips, and reports from other agencies.

The practical implication for organisations is straightforward: a breach that becomes a news story can bring an NPC investigation even if no affected individual ever files anything. This is one of the strongest arguments for handling an incident properly at the outset rather than hoping it stays quiet.

Registration of Data Processing Systems

NPC Circular No. 2022-04, issued 5 December 2022, governs registration. Registration is mandatory for a personal information controller or processor that:

  • employs 250 or more persons; or
  • processes sensitive personal information of 1,000 or more individuals; or
  • processes data that will likely pose a risk to the rights and freedoms of data subjects.

Separately, and regardless of size, a data processing system involving automated decision-making or profiling must in all instances be registered.

Question Answer under Circular 2022-04
When must a covered system be registered? Within twenty (20) days from the commencement of the system
What if the system changes? Minor amendments must be updated within ten (10) days of the update
How long is registration valid? One (1) year from the date of issuance of the Certificate of Registration
When can it be renewed? From thirty (30) days before expiry
What if we fall below the thresholds? Voluntary registration is available; entities declining both must submit a sworn declaration
Initial registration fee ₱500 for an individual or professional; ₱1,000 regional, provincial or Metro Manila; ₱2,500 multinational, national or foreign branch (Circular 2023-01)

A Seal of Registration is issued together with the Certificate. The Circular requires it to be displayed at the main entrance of the registered entity and on its website, and it is for the exclusive use of the registered PIC or PIP. Our guide on NPC registration and seal requirements covers the process in more detail.

Breach Notification to the NPC

Notification is not required for every security incident. Under the NPC’s published breach reporting guidance, mandatory notification arises only when all three of the following are present:

  1. The personal data involves sensitive personal information, or any other information that may be used to enable identity fraud;
  2. There is reason to believe that the information may have been acquired by an unauthorised person; and
  3. The personal information controller believes that the breach is likely to give rise to a real risk of serious harm to the affected data subject.

Where those conditions are met, the Commission and the affected data subjects must both be notified within seventy-two (72) hours upon knowledge of, or reasonable belief in, the breach.

One procedural point carries disproportionate weight. The NPC states that it accepts submission of Personal Data Breach Notification Forms through the Data Breach Notification Management System only, and that any form submitted outside the DBNMS shall not be considered valid. An organisation that emails a notification within 72 hours and never enters it in the DBNMS has, on the face of that statement, not validly notified. See our guide to data breach notification to the NPC and the data breach response checklist.

Administrative Fines vs Criminal Penalties

This is the distinction most competing pages blur, and getting it wrong changes what an organisation should be worried about and what a complainant can realistically expect.

What the NPC itself can impose

NPC Circular No. 2022-01, dated 8 August 2022, sets out the administrative fines the Commission may impose:

Classification Triggering conduct Fine
Grave infraction Infraction of the general privacy principles under Section 11 of the DPA, or of data subject rights under Section 16, where affected data subjects exceed 1,000 (1,001 or more); also repetitions of prior infractions 0.5% to 3% of annual gross income of the immediately preceding year
Major infraction The same principles or rights infractions where affected data subjects number 1 to 1,000; also security failures, failures to oversee third-party security, and breach notification failures 0.25% to 2% of annual gross income of the immediately preceding year
Other infractions Registration and identity-disclosure failures Not less than ₱50,000 and not more than ₱200,000
Other infractions Non-compliance with Commission orders Not exceeding ₱50,000
Aggregate ceiling Maximum total fine ₱5,000,000

Section 3 of the same Circular lists the factors the Commission weighs in fixing an amount: whether the infraction was negligent or intentional, the harm caused to data subjects, the nature and duration of the infraction, the protective measures in place beforehand, prior violations, the categories of data affected, how the infraction was discovered and whether the Commission was notified, mitigating action taken, and any other aggravating or mitigating circumstances, including financial benefits gained or losses avoided.

Note what the base is. A grave infraction is priced off annual gross income, not profit and not the number of records. For a large-revenue, thin-margin business — a BPO, a retailer, a distributor — that formula can produce a figure far above what an intuitive reading of ‘up to ₱5 million’ suggests, until the aggregate ceiling bites.

What the courts impose

Chapter VIII of RA 10173 creates criminal offences. These carry imprisonment, and they are imposed by courts following prosecution — not by the NPC.

Offence Personal information Sensitive personal information
Unauthorized processing (Sec. 25) 1–3 years; ₱500,000–₱2,000,000 3–6 years; ₱500,000–₱4,000,000
Accessing due to negligence (Sec. 26) 1–3 years; ₱500,000–₱2,000,000 3–6 years; ₱500,000–₱4,000,000
Improper disposal (Sec. 27) 6 months–2 years; ₱100,000–₱500,000 1–3 years; ₱100,000–₱1,000,000
Processing for unauthorized purposes (Sec. 28) 1 year 6 months–5 years; ₱500,000–₱1,000,000 2–7 years; ₱500,000–₱2,000,000
Unauthorized access or intentional breach (Sec. 29) 1–3 years; ₱500,000–₱2,000,000
Concealment of security breaches (Sec. 30) 1 year 6 months–5 years; ₱500,000–₱1,000,000
Malicious disclosure (Sec. 31) 1 year 6 months–5 years; ₱500,000–₱1,000,000
Unauthorized disclosure (Sec. 32) 1–3 years; ₱500,000–₱1,000,000 3–5 years; ₱500,000–₱2,000,000
Combination or series of acts (Sec. 33) 3–6 years; ₱1,000,000–₱5,000,000

Three qualifiers in the same chapter are easy to miss. Section 34 extends liability to the responsible officers of a juridical person, allows the court to suspend or revoke corporate rights, and provides for deportation of an alien offender after service of sentence. Section 35 applies the maximum penalty where the personal information of at least one hundred persons is harmed. Section 36 adds disqualification from public office for public officers. Our page on penalties under the Data Privacy Act goes through these in detail.

Advisory Opinions

Where a question is genuinely unsettled — a novel processing arrangement, an unusual sharing structure, a new technology — the NPC entertains requests for advisory opinions. Under NPC Circular No. 2023-01, the fee for a request for an advisory opinion is ₱7,500.00.

An advisory opinion is guidance on the facts presented. It is not a ruling in a dispute, and it does not substitute for the Commission’s adjudicatory process. Organisations facing a recurring compliance question often find a privacy impact assessment the more useful instrument, because it documents the reasoning as well as the conclusion.

NPC Issuances That Matter

The Act is short; the circulars and advisories are where most operational detail lives. As listed on the NPC’s advisories and circulars index at the time of review:

Issuance Subject
Advisory No. 2026-02 Clarification on submission of personal data breach notification through the DBNMS
Advisory No. 2026-01 Guidelines on data scraping of publicly available personal data
Circular No. 2025-01 Processing of personal data collected using body-worn cameras
Advisory No. 2025-02 Privacy engineering in systems life cycle processes
Advisory No. 2025-01 Clarification of certain provisions of Circular 2020-03 on data sharing agreements
Circular No. 2024-02 Closed-circuit television (CCTV) systems
Circular No. 2024-01 Amendments to the 2021 Rules of Procedure
Advisory No. 2024-04 Application of the DPA to artificial intelligence systems
Advisory No. 2024-03 Child-oriented transparency
Advisory No. 2024-02 Processing based on Section 13(f) of the DPA
Advisory No. 2024-01 Model contractual clauses for cross-border transfers

The 2026 data scraping advisory is the one most businesses have not yet absorbed; we cover it in data scraping in the Philippines. A fuller index is maintained in our NPC issuances database.

Common Mistakes

  • Filing without exhausting the company’s own channel. The fifteen-calendar-day rule is a precondition, and failure to observe it is an express ground for outright dismissal.
  • Treating ‘up to ₱5 million’ as the exposure. The grave and major fine bands are percentages of annual gross income; the ₱5 million figure is the aggregate ceiling, not the tariff.
  • Emailing a breach notification and stopping there. The NPC’s position is that only DBNMS submissions are valid.
  • Assuming registration is only for big companies. Automated decision-making or profiling triggers registration in all instances, regardless of headcount.
  • Expecting the NPC to jail someone. The Commission recommends prosecution; the courts convict and sentence.
  • Working from the 2021 Rules without the 2024 amendments. Circular 2024-01 renumbered and amended several rules.
  • Bringing a non-privacy grievance. A refund dispute or an ordinary scam is a matter for the DTI, the BSP, the SEC or the police.

How to Contact the NPC

As published on the Commission’s contact page:

  • Address: 25th–27th Floors, The Upper Class Tower, Quezon Avenue corner Scout Reyes Street, Quezon City, Philippines
  • Telephone: (+63) 2 5322 1322
  • Office hours: Monday to Friday, 08:00 to 17:00
  • Email: the NPC lists separate addresses for complaints, registration and compliance, advisory opinions and general inquiries on its contact page; use the one matching your matter rather than a general address

For cybercrime rather than data privacy, the relevant bodies are different; see our directory of Philippine government cybersecurity agencies.

Frequently Asked Questions

Is the National Privacy Commission a court?

No. The NPC is an administrative body with adjudicatory powers. It can decide complaints, issue cease and desist orders and impose administrative fines, but it does not try criminal cases. Imprisonment under the Data Privacy Act follows a conviction in court after prosecution, which the NPC may recommend to the Department of Justice.

How much does it cost to file a complaint with the NPC?

Under NPC Circular No. 2023-01 dated 17 May 2023, the filing fee for complaints is ₱500.00. Government agencies and qualified indigent litigants are exempt. Mediation carries a ₱500.00 fee shared equally among the parties, and an application for a cease-and-desist order is ₱1,000.00.

Do I have to complain to the company first?

Ordinarily, yes. Rule II, Section 2 of the 2021 Rules of Procedure requires the complainant to show written notice to the responsible organisation and a failure to respond within fifteen calendar days of receipt, or a failure to take appropriate action. The Commission may waive this where the violation causes grave and irreparable damage or the conduct is patently unlawful.

How long do I have to file a complaint?

The Rules do not set a single deadline. Rule I, Section 6 adopts the prescriptive periods for special-act violations under Act No. 3326, and those periods vary with the offence alleged. Because the applicable period depends on the violation, the safe course is to file as soon as the fifteen-day exhaustion period has run.

Does my company need to register with the NPC?

Registration is mandatory under NPC Circular No. 2022-04 if you employ 250 or more persons, process sensitive personal information of 1,000 or more individuals, or process data likely to pose a risk to data subjects’ rights and freedoms. It is also mandatory in all instances for a system involving automated decision-making or profiling. Entities below the thresholds may register voluntarily, and those doing neither must submit a sworn declaration.

Do we have to report every data breach to the NPC?

No. Notification is mandatory only where all three conditions are met: the data is sensitive personal information or information enabling identity fraud; there is reason to believe it was acquired by an unauthorised person; and the controller believes the breach is likely to give rise to a real risk of serious harm. Where those apply, notify within 72 hours through the DBNMS.

Can the NPC fine a company a percentage of its revenue?

Yes. Under NPC Circular No. 2022-01, grave infractions carry a fine of 0.5% to 3% of annual gross income for the immediately preceding year, and major infractions 0.25% to 2%. The aggregate fine is capped at ₱5,000,000.

Can the NPC investigate without anyone complaining?

Yes. The Commission may initiate an investigation on its own motion, and the recognised triggers include news reports, studies, substantiated anonymous tips and reports from other agencies, as well as pending cases before it.

Is the NPC part of the DICT?

The NPC is attached to the Department of Information and Communications Technology under Section 9 of RA 10173 for purposes of policy and programme coordination, but it is a distinct body with its own mandate, leadership and adjudicatory powers.

Official Sources


Last materially reviewed: September 12, 2026

Author: Cybercode.ph Editorial Team. This page was written from the primary sources listed above, each of which was retrieved and read during preparation. It has not been reviewed by a named external legal reviewer; where that changes, the reviewer will be credited here.

Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.