CyberCode.ph · Philippines

Personal Information Controller vs Personal Information Processor

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 2, 2026

Direct Answer: Under the Philippine Data Privacy Act, a Personal Information Controller (PIC) is the person or organization that decides what personal data is collected and the purpose or extent of its processing. A Personal Information Processor (PIP) processes personal data on behalf of, or under the instructions of, a PIC. In simple terms: the PIC decides; the PIP processes. (NPC IRR definitions) Outsourcing to a PIP does not remove the PIC’s accountability for personal data under its control or custody.

Primary authority: NPC — Implementing Rules and Regulations of RA 10173.

Key Takeaways

  • A PIC determines the purpose or extent of personal-data processing.
  • A PIP processes personal data for a PIC under instructions.
  • A service provider is not automatically a PIP; its actual role depends on who determines the purposes and means of processing.
  • A company can be a PIC for one processing activity and a PIP for another.
  • Outsourcing does not eliminate the PIC’s accountability.
  • PICs and PIPs both have privacy and security obligations under the Data Privacy Act and NPC issuances.
  • Processing arrangements should be documented clearly in contracts and privacy-governance records.

Jump to a Section

Decision Snapshot

Question Practical Answer
Who decides why personal data is processed? The PIC.
Who processes data under another organization’s instructions? The PIP.
Can a cloud provider be a PIP? Yes, depending on the arrangement.
Can one company be both PIC and PIP? Yes, for different processing activities.
Does outsourcing remove the PIC’s accountability? No.
Do PIPs have privacy obligations? Yes.

What Is a Personal Information Controller?

Republic Act No. 10173 defines a Personal Information Controller as a person or organization that controls the collection, holding, processing or use of personal information, including one that instructs another person or organization to process personal information on its behalf.

The Data Privacy Act and its Implementing Rules make the concept of control central. There is control when the person or organization decides what information is collected, or the purpose or extent of its processing.

In practical terms, the PIC usually answers questions such as:

  • Why are we collecting this data?
  • What categories of data do we need?
  • How will the data be used?
  • How long will we retain it?
  • Who may receive it?
  • Which service providers will process it for us?

If an organization determines these core decisions, it is likely acting as a PIC for that processing activity.

What Is a Personal Information Processor?

A Personal Information Processor is a natural or juridical person, or other body, to whom a PIC may outsource or instruct the processing of personal data relating to a data subject.

A PIP generally does not determine the independent purpose of the processing. Instead, it processes data according to the PIC’s instructions and the applicable agreement.

Typical PIP activities may include cloud hosting, payroll processing, email delivery, customer-support processing, data storage and backup, outsourced analytics, IT support involving access to personal data, and software services that process customer or employee data for the client.

PIC vs PIP: Quick Comparison

Issue Personal Information Controller Personal Information Processor
Main role Determines purpose or extent of processing Processes data for the PIC
Decides why data is processed? Yes Usually no
Can instruct another party? Yes Acts under instructions
May outsource processing? Yes May perform outsourced processing
Accountability for outsourced data Remains accountable under applicable law Must comply with applicable processing and security obligations
Example Retailer deciding how customer data is used Cloud or email provider processing that data for the retailer

Practical Examples

Example 1: Online Store and Cloud Provider

An online retailer decides to collect customer names, addresses, email addresses and order histories to process purchases and manage customer accounts. The retailer chooses a cloud platform to store that information.

Likely PIC: the online retailer, because it decides why the customer data is collected and how it will be used.

Likely PIP: the cloud provider, to the extent it stores and processes the data under the retailer’s instructions.

Example 2: Employer and Payroll Provider

An employer determines what employee information is needed for payroll and benefits administration, then sends that information to an outsourced payroll company.

Likely PIC: the employer.

Likely PIP: the payroll provider, if it processes employee data only under the employer’s instructions.

Example 3: SaaS Company

A SaaS provider may be a PIP when it processes customer data solely to provide the contracted service. But the same SaaS company may be a PIC for its own employee records, billing contacts, marketing lists or other processing where it determines the purpose.

This is why organizations should classify roles per processing activity, not simply label a company permanently as either a PIC or PIP.

Can a Company Be Both a PIC and a PIP?

Yes. The same organization can act as a PIC for one activity and a PIP for another. For example, a BPO company may process customer records for a client as a PIP while acting as a PIC for its own employee records, recruitment data and vendor contacts.

What Happens When Processing Is Outsourced?

Outsourcing personal-data processing does not mean the PIC can simply transfer all responsibility to the vendor. Under the Data Privacy Act framework, the PIC remains responsible for personal data under its control or custody, including information outsourced or transferred to a PIP for processing.

Organizations should perform appropriate due diligence before engaging a processor and should document the processing relationship through a suitable agreement.

What Should a PIC-PIP Agreement Cover?

  • the subject and purpose of processing;
  • categories of personal data;
  • types of data subjects;
  • processing instructions;
  • confidentiality;
  • security measures;
  • subcontracting or sub-processing;
  • incident and breach notification;
  • data retention and deletion;
  • return of data after termination;
  • audit or compliance rights; and
  • assistance with data-subject requests where applicable.

Responsibilities of Personal Information Controllers

A PIC’s responsibilities can include ensuring that personal-data processing has an appropriate legal basis, providing transparency, respecting data subject rights, implementing safeguards, governing retention, supervising processors, and responding appropriately to security incidents and data breaches.

A PIC should also understand what personal information it processes and whether any of that data qualifies as sensitive personal information.

Responsibilities of Personal Information Processors

A PIP is not merely a passive vendor with no privacy obligations. The Data Privacy Act and NPC guidance impose relevant security, confidentiality and compliance responsibilities on processors as well.

What If a Processor Uses the Data for Its Own Purpose?

If a service provider begins independently deciding why personal data will be used, the legal analysis may change. If a vendor receives customer data solely to provide a contracted service but later decides to reuse that data for its own unrelated marketing, profiling or product-development purpose, it may no longer be acting only as a processor for that activity.

Do PICs and PIPs Need to Register With the NPC?

The National Privacy Commission operates the NPC Registration System (NPCRS) for registration of Data Protection Officers and Data Processing Systems under applicable NPC rules.

The NPC’s current 2026 registration guidance expressly recognizes both PICs and PIPs as users of the registration system. Whether a particular organization or processing system must register depends on the applicable registration rules and thresholds.

Common Classification Mistakes

We use their software, so they are automatically the controller

Not necessarily. A software company may simply process data under the customer’s instructions.

We outsourced the data, so it is no longer our responsibility

Incorrect. Outsourcing does not automatically remove the PIC’s accountability.

A vendor can only ever be a processor

Incorrect. The same vendor may act as a PIP for client data and as a PIC for its own independent processing activities.

The contract label decides the legal role

Not by itself. The real issue is who actually determines the purpose or extent of processing.

Frequently Asked Questions

What is the simplest difference between a PIC and PIP?

The PIC decides; the PIP processes.

Is an employer a PIC?

Usually, an employer acts as a PIC for employee information when it determines why and how that employee data is processed.

Is a cloud provider a PIP?

It can be when it processes or stores personal data on behalf of a client and under that client’s instructions.

Can a processor make its own decisions?

A processor can make operational decisions necessary to provide the service, but if it independently determines a separate purpose for using the data, its legal role for that processing may change.

Does the PIC remain responsible after outsourcing?

Yes.

Can a company be both PIC and PIP?

Yes. Classification depends on the specific processing activity.

Do both PICs and PIPs need security controls?

Yes. Both should implement reasonable and appropriate measures relevant to the personal data they process and their role.

Official Sources

Related Cybercode Guides

Cybercode.ph provides general educational information about technology, cybersecurity, privacy and related legal issues. It is not a substitute for legal, cybersecurity or professional advice for a specific situation.