CyberCode.ph · Philippines

Online Business Compliance Checklist Philippines: DTI, BIR, Privacy and E-Commerce Rules

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 3, 2026.

Direct answer: A Philippine online business should not treat compliance as only a DTI or BIR registration task. A properly run online store, marketplace seller, social-commerce business, SaaS seller, booking site, or direct-to-consumer website may need to comply with business-registration rules, BIR registration and invoicing, the Internet Transactions Act, consumer-protection rules, the Data Privacy Act, cybersecurity safeguards, complaint-handling requirements, advertising rules, and platform-specific obligations.

This guide is designed as a working checklist. It separates the major compliance areas so a business owner can review the operation one section at a time instead of trying to interpret several laws at once.

Primary authorities: Republic Act No. 11967, BIR RMC No. 91-2024, and National Privacy Commission guidance.

Key Takeaways

  • Register the business and the names actually used online.
  • Complete BIR registration and display the required Certificate of Registration or QR code where applicable (BIR RMC No. 91-2024).
  • Issue proper invoices or receipts for online transactions.
  • Clearly disclose the seller’s identity, contact details, prices, terms, delivery conditions and complaint channels.
  • Use a clear privacy notice when collecting personal information.
  • Do not use blanket policies such as “No Return, No Exchange” to remove legal consumer remedies for defective goods.
  • Maintain a real complaint and redress process.
  • Protect customer and employee data with reasonable organizational, physical and technical security measures.
  • Keep records that can prove sales, payments, fulfillment, refunds, complaints and tax compliance.

Jump to a Section

1. Business registration · 2. BIR compliance · 3. Seller disclosures · 4. Data privacy · 5. Consumer protection · 6. Complaints · 7. Cybersecurity · 8. Records · 9. Platform obligations

Decision Snapshot

If your business sells goods or services through a website, marketplace, social-media account, app or other digital channel, assume that the same basic compliance duties that apply to an offline business still matter online. The digital channel may add more obligations, especially around disclosures, electronic transactions, privacy and online consumer protection.

1. Business Registration Checklist

Register the legal business

A sole proprietor commonly registers the business name with the Department of Trade and Industry. Corporations and partnerships generally register with the Securities and Exchange Commission, while cooperatives follow the Cooperative Development Authority process. Registration requirements depend on the legal structure and activity.

Do not stop at the legal entity name. If you trade online under a store name, brand name or account name, make sure that name is properly reflected in your registrations where required.

Check local permits

Depending on the business and location, local government permits may also apply. Online operation does not automatically remove local business-permit obligations simply because customers order through a website or social platform.

2. BIR Registration, Tax and Invoicing Checklist

BIR compliance is one of the areas online sellers most often underestimate. The Bureau of Internal Revenue has specifically clarified duties for persons doing business online.

Register the business and online store names

BIR Revenue Memorandum Circular No. 91-2024 explains that online sellers should register their business or trade names and declare the store names used on online pages, accounts, websites or e-commerce platforms so that they are properly reflected in the Certificate of Registration.

Display the BIR Certificate of Registration

For online sellers, BIR guidance states that an electronic copy of the Certificate of Registration should be posted on the seller’s website or profile page on the e-commerce platform. Where the Certificate of Registration contains an eligible QR code generated through BIR systems, that QR code may be posted instead of the full electronic copy.

Issue invoices or receipts

Republic Act No. 11967, the Internet Transactions Act, requires online merchants and e-retailers to issue paper or electronic invoices or receipts for transactions. This also supports tax compliance and gives the customer a record of the purchase.

Keep tax records

Keep copies of sales records, invoices, receipts, payment records, refunds, adjustments and relevant accounting documentation. Digital records should be organized and backed up rather than scattered across chat messages, marketplace dashboards and personal devices.

3. Online Seller Disclosure Checklist

One of the core principles of RA 11967 is that buyers should be able to identify who they are dealing with before paying.

Review whether your website or seller page clearly shows, as applicable:

  • registered business name or trade name;
  • physical or business address;
  • email address and other contact information;
  • price of the goods or services;
  • important product or service characteristics;
  • payment methods;
  • delivery or fulfillment terms;
  • refund, return, replacement and cancellation policies;
  • warranty information where relevant;
  • complaint or customer-service process;
  • other information required by applicable law or regulation.

If your site hides the seller’s identity, gives only a social-media username, or makes customers hunt for basic contact information, that is both a trust problem and a compliance risk.

For a broader explanation, see Cybercode’s Website Legal Requirements in the Philippines and Internet Transactions Act Philippines guide.

4. Data Privacy Checklist

If your online business collects names, addresses, phone numbers, emails, IDs, payment-related information, account details, location information, support messages or other identifiable information, the Data Privacy Act may apply.

Publish a clear privacy notice

The privacy notice should explain what personal data you collect, why you collect it, the lawful basis for processing, who receives it, how long it is retained, how people can exercise their rights, and how they can contact the organization about privacy issues.

Collect only what you need

Do not ask customers for unnecessary personal information simply because a form allows you to. Data minimization reduces both legal exposure and breach risk.

Know your service providers

Review payment processors, couriers, CRM providers, email platforms, analytics services, cloud storage, chat tools and other vendors that receive personal data. Your obligations do not disappear merely because another company hosts or processes the information.

Prepare for data-subject requests

Customers may have rights to access, correct, object to certain processing, and in appropriate cases request erasure or blocking. Build a workflow for receiving and documenting these requests.

Prepare for data breaches

Maintain an incident-response process. If a personal data breach occurs, assess whether notification to the National Privacy Commission and affected data subjects is required. Cybercode’s Data Breach Response Checklist can be used as a working guide.

5. Consumer Protection Checklist

Online businesses are still subject to Philippine consumer-protection principles. Digital selling is not a loophole that allows misleading advertising, defective products or unfair contract terms.

Use accurate product descriptions

Photos, specifications, dimensions, ingredients, compatibility claims, delivery promises and other material details should not mislead consumers.

Show the real price

Do not advertise a low headline price and reveal unavoidable charges only at the final step. Be transparent about mandatory fees and shipping where applicable.

Do not rely on a blanket “No Return, No Exchange” rule

A store may set reasonable policies for changes of mind, but it cannot use a blanket policy to remove statutory remedies when goods are defective or do not conform to what was promised. The correct policy should distinguish discretionary returns from legally protected remedies.

Honor warranties and commitments

If the product or service carries a warranty, guarantee or specific performance promise, document the terms and train customer-service personnel to apply them consistently.

6. Complaint and Redress Checklist

A legitimate online business should have a defined process for complaints, refunds, defective items, failed deliveries, disputed transactions and other customer issues.

Your process should answer:

  • Where does the customer file the complaint?
  • What information should the customer submit?
  • Who is responsible for handling it?
  • How quickly should the business acknowledge it?
  • How are refunds or replacements approved?
  • How is the outcome documented?
  • How can unresolved cases be escalated?

This becomes especially important for the E-Commerce Philippine Trustmark because the DTI currently asks applicants for a step-by-step description of their internal redress mechanism.

7. Cybersecurity Checklist

Compliance is not only paperwork. A business that collects personal information or accepts online transactions should take reasonable security measures.

At minimum, review:

  • multi-factor authentication for administrator accounts;
  • strong passwords and password-manager use;
  • software and plugin updates;
  • role-based access;
  • regular backups;
  • malware and phishing protection;
  • secure payment processing;
  • HTTPS and certificate configuration;
  • logging and monitoring;
  • employee access termination;
  • incident reporting procedures.

Businesses can adapt Cybercode’s Employee Cybersecurity Policy Template and Cyber Incident Response Checklist.

8. Records and Evidence Checklist

A good compliance system leaves an evidence trail. Keep organized records of:

  • business registrations and permits;
  • BIR Certificate of Registration;
  • invoices and receipts;
  • sales and transaction records;
  • product listings and material advertisements;
  • customer complaints and resolutions;
  • refunds and replacements;
  • privacy notices and policy versions;
  • consents where consent is the lawful basis;
  • security incidents and corrective actions;
  • vendor agreements and data-processing arrangements;
  • employee policies and training.

Records matter because a business may need to prove what the customer was shown, what was agreed, what was delivered and how a complaint or incident was handled.

9. Marketplace and Digital Platform Checklist

If you sell through an e-marketplace or digital platform, comply with both Philippine law and the platform’s rules. Platform terms do not replace legal obligations.

Keep your business identity, BIR information, product listings and contact details current. Avoid creating multiple identities to bypass enforcement or platform restrictions. When a platform requests verification documents, make sure the information matches your registered business.

10. Monthly Online Business Compliance Review

A simple monthly review is often more effective than waiting for an annual legal audit. Ask:

  • Have our registration or contact details changed?
  • Are our BIR details and online store names current?
  • Are invoices being issued consistently?
  • Are our prices and product descriptions accurate?
  • Does our privacy notice match what the site actually collects?
  • Have we added any new analytics, CRM or marketing tools?
  • Are complaints and refunds being documented?
  • Are critical systems patched and backed up?
  • Have any employees or contractors retained access they no longer need?

Common Compliance Mistakes

  • Registering the company but not the store names actually used online.
  • Failing to display the BIR Certificate of Registration or applicable QR code.
  • Not issuing proper invoices or receipts.
  • Using a copied privacy policy that does not describe the site’s real data practices.
  • Publishing a blanket “No Return, No Exchange” rule.
  • Hiding contact information.
  • Collecting excessive personal information.
  • Having no written complaint-handling process.
  • Giving every employee administrator access.
  • Keeping no evidence of refunds, complaints, incidents or policy changes.

FAQs

Do online sellers in the Philippines need BIR registration?

Generally, persons engaged in business are subject to BIR registration and tax obligations. BIR has also issued guidance specifically addressing businesses and sellers operating through online channels.

Do online sellers need to display their BIR Certificate of Registration?

BIR guidance states that online sellers should post an electronic copy of their Certificate of Registration on their website or e-commerce platform profile. Where an eligible BIR-generated QR code is available, it may be posted instead.

Does every online business need a privacy policy?

If the business processes personal data, it should provide the transparency required by the Data Privacy Act and NPC rules. A privacy notice is the normal way to explain those processing activities to users and customers.

Does RA 11967 apply only to large e-commerce platforms?

No. The Internet Transactions Act contains obligations relevant to digital platforms, e-marketplaces, online merchants and e-retailers. The exact duties differ according to the role of the business.

Can a small Facebook seller ignore these rules?

Operating through social media does not automatically remove business, tax, consumer or privacy obligations. The scale and legal structure may affect what registrations apply, but selling through a Facebook page is still online commerce.

Official Sources

This guide provides general information and is not a substitute for legal, tax or accounting advice tailored to a specific business.