Jurisdiction: Philippines
Last materially reviewed: September 21, 2026
Content type: Business compliance / coverage decision guide
Direct answer
Most Philippine businesses that collect, use, store, share, or otherwise process information about identifiable people must comply with the Data Privacy Act of 2012. Coverage is not limited to large corporations or online companies. A sole proprietor, small shop, clinic, school, employer, e-commerce seller, professional practice, association, nonprofit, or service provider can be covered. Company size matters when scaling safeguards and determining NPC registration—not when deciding whether the law applies at all.
Quick answer
Key takeaways
- The Data Privacy Act applies based on personal-data processing, not merely revenue, corporate form, or number of employees.
- A microbusiness can be covered after collecting customer names, delivery addresses, employee records, IDs, health information, CCTV footage, or online inquiries.
- A business may be a personal information controller (PIC), a personal information processor (PIP), or both in different activities.
- Outsourcing payroll, cloud hosting, customer support, or marketing does not automatically transfer all privacy accountability to the vendor.
- Compliance with RA 10173 and registration with the National Privacy Commission are related but different questions.
- Foreign organizations may be covered when their processing has the links to the Philippines described in the Act and its Implementing Rules and Regulations.
- The safest first step is a written data inventory showing what the business collects, why, where it goes, who can access it, and when it is deleted.
Jump to a section
- The basic coverage test
- Which businesses are usually covered?
- Which situations may fall outside the law?
- PIC, PIP, or both?
- Does a small business have to register with the NPC?
- What covered businesses must do
- Business scenarios
- Evidence to keep
- Frequently asked questions
Which situation applies?
| Business situation | Is the Data Privacy Act likely relevant? | What changes the answer? | First action |
|---|---|---|---|
| Employer keeps applicant and employee records | Yes | The data categories, lawful basis, access, retention, and security risks | Map the recruitment-to-separation data lifecycle |
| Online seller collects names, addresses, phone numbers, and payments | Yes | Whether vendors process data, marketing reuse, fraud controls, and retention | List every checkout, courier, payment, and messaging system |
| Small clinic stores patient records | Yes, with heightened risk | Health information is sensitive personal information | Restrict access and document lawful processing and safeguards |
| School or tutorial center keeps student and parent information | Yes | Children, education data, photos, online platforms, and third-party apps raise added issues | Inventory student systems and review child-oriented transparency |
| Freelancer keeps client contacts only for work | Often yes | Personal-data processing for business is not merely a household activity | Identify the data, purpose, storage, and deletion point |
| Payroll or cloud provider processes data for clients | Yes, usually as a PIP; it may also be a PIC for its own data | Contract terms, instructions, independent uses, security, and subprocessors | Separate client-instructed processing from the provider’s own purposes |
| Foreign SaaS company handles Philippine customer or employee data | Possibly | Apply RA 10173’s extraterritorial links and actual processing facts | Document Philippine links, contracting entity, systems, and data flows |
| Individual keeps a private address book for family use | Usually outside the PIC definition for that activity | Commercial use, disclosure, scale, or another purpose can change the analysis | Confirm the activity is genuinely personal, family, or household use |
The basic coverage test
Republic Act No. 10173 applies broadly to the processing of personal information by natural and juridical persons. Its Implementing Rules and Regulations state that the framework applies to personal-data processing in the government and private sectors, including specified processing outside the Philippines when there is a relevant Philippine connection.
A business should ask four questions:
- Does it process personal data? Processing includes collecting, recording, organizing, storing, updating, retrieving, consulting, using, sharing, blocking, erasing, or destroying personal information. Paper records can count when they form part of a structured filing system; the law is not limited to databases.
- Can the information identify an individual? Names, contact details, delivery addresses, employee files, account identifiers, device or online records, images, and transaction histories may be personal information depending on context.
- Does the business decide why or how the data is processed, or process it for someone else? The first role generally points to a PIC; the second generally points to a PIP.
- Does a specific exclusion or special rule apply to the information or activity? The exclusions are not a blanket license to ignore privacy duties. They must be read narrowly and in context.
The practical rule is straightforward: if a business handles identifiable information about customers, workers, applicants, suppliers, visitors, users, patients, students, tenants, borrowers, members, or leads, it should begin with the assumption that Philippine privacy requirements are relevant and verify the details from there.
Which businesses are usually covered?
Employers and recruiters
Even a small employer normally handles names, addresses, government identifiers, bank details, attendance records, evaluations, disciplinary records, health information, emergency contacts, and payroll data. The business needs lawful purposes and bases, clear access rules, reasonable safeguards, appropriate notices, retention limits, and procedures for employee rights and incidents.
Retail stores, restaurants, and service businesses
Customer orders, loyalty programs, reservations, delivery details, complaint records, CCTV, Wi-Fi registrations, and direct-marketing lists can all involve personal data. A physical storefront is not outside privacy law merely because it does not operate a sophisticated website.
E-commerce sellers and online platforms
Online businesses commonly process names, addresses, contact details, chat histories, transaction data, account information, device records, support tickets, and fraud signals. They also rely on payment processors, couriers, hosting providers, advertising platforms, and customer-support tools. Each flow must have a legitimate purpose, a defensible legal basis, appropriate transparency, and suitable vendor controls.
Clinics, pharmacies, wellness providers, and insurers
Health and medical information is sensitive personal information under RA 10173. These organizations may also process government identifiers, insurance details, prescriptions, test results, appointment histories, and payment information. The sensitivity and potential harm make stronger access control, confidentiality, incident response, and retention discipline essential.
Schools, training centers, and childcare businesses
Student files can contain education, health, family, financial, behavioral, image, and contact information. When children are involved, transparency and risk controls must be appropriate to the audience and processing activity. Schools should also examine learning platforms, messaging groups, CCTV, online forms, and outsourced student systems.
Professional practices and freelancers
Doctors, accountants, consultants, lawyers, real-estate brokers, designers, virtual assistants, and other professionals may be covered even when operating alone. Being self-employed does not turn business records into purely personal or household data.
BPOs, agencies, payroll providers, cloud services, and SaaS vendors
These organizations often process information on a client’s instructions and therefore operate as PIPs for that activity. They can still act as PICs for their own employees, marketing, billing, security, and product decisions. Their contracts, access controls, subprocessors, incident reporting, deletion practices, and cross-border transfers require careful review.
Associations, foundations, nonprofits, and membership groups
Nonprofit status does not create a general exemption. Membership lists, donor records, beneficiary files, volunteer information, event registrations, photos, and outreach databases can all involve personal-data processing.
Property managers, landlords, and accommodation providers
Applications, IDs, employment or income records, contracts, visitor logs, CCTV, access records, and payment histories can bring these operations within the privacy framework. Collecting more information than the transaction requires can create unnecessary risk.
Which situations may fall outside the law?
RA 10173 and its IRR identify specific information or activities that are outside the law’s application or receive special treatment to the minimum extent necessary for the stated purpose. Examples include certain information related to government positions or functions, specified public-service or regulatory activities, and processing for journalistic, artistic, literary, or research purposes under the conditions stated in the law.
The PIC definition also excludes a natural person processing personal data in connection with personal, family, or household affairs. This is not a general small-business exemption. A family address book used privately is different from a home-based seller’s customer database, a landlord’s tenant files, or a freelancer’s client records.
Do not rely on an exclusion merely because information is public, the business is small, or consent was obtained. Public availability does not automatically authorize every reuse, combination, profiling, disclosure, or retention practice. The exact information, purpose, role, and context matter.
PIC, PIP, or both?
A personal information controller decides what personal data is collected or determines the purpose or extent of processing. An online store deciding what customer information its checkout requires is usually acting as a PIC for that activity.
A personal information processor processes personal data on behalf of a PIC. A payroll service applying a client’s instructions to calculate wages may be acting as a PIP for that processing.
The same company can occupy both roles:
- A SaaS provider may be a PIP for customer data hosted on behalf of business clients.
- The provider is generally a PIC for its own employee, applicant, billing, security, and direct-marketing records.
- If it independently determines a new purpose for client data, the role analysis may change for that use.
Correctly identifying the role matters because it affects accountability, contracts, notices, instructions, security duties, data-subject requests, registration analysis, and incident response. See Cybercode’s guide to Personal Information Controllers and Personal Information Processors for the detailed distinction.
Does a small business have to register with the NPC?
Do not confuse coverage by the Data Privacy Act with mandatory registration of a data-processing system.
A small business may have to comply with RA 10173 even when it does not meet the mandatory registration criteria. Under NPC Circular No. 2022-04, mandatory registration generally applies to a PIC or PIP that:
- employs at least 250 persons;
- processes sensitive personal information of at least 1,000 individuals;
- processes data likely to pose a risk to the rights and freedoms of data subjects; or
- operates a data-processing system involving automated decision-making or profiling, which the Circular states must be registered in all instances.
The Circular also provides that a PIC or PIP outside mandatory registration that does not register voluntarily must submit the prescribed sworn declaration. A covered PIC or PIP must register a newly implemented data-processing system or inaugural DPO through the NPC’s official platform within the timeframe specified in the Circular.
These are registration rules, not exemptions from the rest of privacy law. A five-person clinic, online shop, or professional practice may still need lawful processing, privacy notices, security controls, records, vendor management, rights procedures, retention rules, incident response, and accountable privacy leadership.
Because registration processes and official platforms can change, verify the current requirements on the National Privacy Commission’s issuances page before filing.
What covered businesses must do
The exact program should be proportionate to the data, purpose, scale, systems, and risk. The core sequence is:
1. Inventory the data
List the personal and sensitive personal information handled across recruitment, employment, customers, marketing, sales, delivery, payments, websites, CCTV, support, vendors, backups, and paper files. Record the source, purpose, system, users, recipients, location, and retention period.
2. Identify roles and accountability
Determine where the business is a PIC, PIP, or both. Assign a DPO, compliance officer, or other accountable person as required by the IRR and current NPC rules. The role must have enough authority and resources to operate the program.
3. Establish a lawful basis and legitimate purpose
Consent is one legal basis, not the only one. Analyze each processing activity under the applicable provisions of RA 10173, with stricter attention to sensitive personal information. Do not reuse data for a new incompatible purpose merely because it is already in the system.
4. Inform people clearly
Use privacy notices that explain what is collected, why, how it is used, who receives it, how long it is retained, the rights available, and how to contact the responsible organization or DPO. A privacy notice and consent are not interchangeable.
5. Use proportionate security
The IRR requires reasonable and appropriate organizational, physical, and technical measures. NPC Circular No. 2023-06 provides the current security framework for personal data in government and the private sector. Controls should match the actual risk and may include access restriction, authentication, secure configuration, encryption where appropriate, logging, backups, physical protection, vendor controls, testing, training, and incident procedures.
6. Control vendors and processors
Before sharing data with a cloud platform, payroll provider, courier, agency, support vendor, or other processor, perform due diligence and use a contract that defines instructions, confidentiality, safeguards, incident reporting, subprocessors, retention, return or deletion, and accountability.
7. Handle rights and retention
Create a workflow for access, correction, objection, erasure or blocking, portability, complaints, and other applicable rights. Set defensible retention periods and securely dispose of data when the purpose and legal basis no longer justify keeping it.
8. Prepare for incidents
Define who investigates, contains, documents, and escalates a suspected incident. Preserve logs and original evidence. Assess whether the event is a personal data breach and whether notification duties are triggered. Use the Data Breach Response Checklist for the operational response.
For a complete implementation sequence, use the Data Privacy Compliance Checklist for Philippine Businesses.
Business scenarios
Scenario 1: Home-based online seller
A seller has three workers and receives orders through a website and messaging apps. It keeps buyer names, delivery addresses, phone numbers, chats, payment references, and courier records.
The business is small, but it processes personal data for commercial purposes. It should map its systems, limit collection, explain its uses, secure accounts, restrict worker access, control couriers and other vendors, define retention, and prepare for account compromise or misdirected deliveries. It must separately determine whether any registration criterion applies.
Scenario 2: Dental clinic
A clinic keeps patient identities, contact details, medical histories, treatment records, X-rays, prescriptions, government identifiers, and payment records.
Health information is sensitive personal information. The clinic needs a strong lawful-processing analysis, confidentiality controls, role-based access, secure storage and disposal, vendor oversight, an incident plan, and a documented NPC registration assessment. Its small headcount does not remove these obligations.
Scenario 3: Payroll software provider
A software company receives employee records from client employers and processes them according to client instructions. It also maintains its own staff files and product-usage logs.
The provider may be a PIP for client payroll data and a PIC for its own employment, billing, security, and product activities. It should keep those roles distinct in contracts, notices, access rules, retention, and incident handling.
Scenario 4: Foreign SaaS business
A foreign platform contracts with Philippine companies and hosts information about their Philippine workers or customers outside the country.
Location alone does not end the analysis. RA 10173 contains extraterritorial provisions covering specified acts or practices involving Philippine citizens or residents and entities with relevant links to the Philippines. The company should document the contracting structure, Philippine links, affected people, processing locations, roles, vendors, and transfer safeguards before reaching a conclusion.
Evidence to keep
A business should be able to show how it reached and implements its compliance decisions. Preserve and regularly update:
- data and system inventory;
- records of processing activities and data-flow maps;
- PIC/PIP role analysis;
- lawful-basis and purpose assessments;
- privacy notices and consent records where consent is used;
- DPO or accountable-person appointment records;
- privacy impact assessments;
- access-control lists and approval records;
- security policies, training records, test results, and incident logs;
- processor and data-sharing contracts;
- retention and secure-disposal schedules;
- data-subject request logs and responses;
- breach assessments and notification decisions;
- NPC registration, renewal, update, or sworn-declaration records, as applicable.
The goal is not paperwork for its own sake. Each record should help the business prove what it does, why it does it, who is responsible, which controls operate, and how decisions are reviewed.
Common mistakes
“We have fewer than 250 employees, so the DPA does not apply.”
Incorrect. The 250-person figure appears in the registration framework. It is not a general exemption from RA 10173.
“Only online businesses are covered.”
Incorrect. Paper personnel files, printed forms, visitor logs, CCTV, customer cards, and other structured records can involve personal-data processing.
“We use a cloud provider, so privacy is the vendor’s responsibility.”
Outsourcing does not automatically remove the PIC’s accountability. Both the business and provider can have duties depending on their roles and conduct.
“A privacy policy makes us compliant.”
A notice is only one control. Compliance also involves purpose, lawful basis, minimization, security, governance, vendor management, rights, retention, incident response, and evidence.
“Consent solves every issue.”
Consent is not a cure for excessive collection, poor security, indefinite retention, incompatible reuse, or processing prohibited by law. It is also not the only lawful basis.
“No registration means no compliance obligation.”
Registration is a separate administrative requirement. An organization outside mandatory registration can still be fully subject to the DPA and other NPC requirements.
Frequently asked questions
Does RA 10173 apply to a sole proprietorship?
It can. The law focuses on personal-data processing, not corporate form. A sole proprietor processing customer, worker, patient, tenant, or client information for business purposes may be a PIC, a PIP, or both.
Does every business need a Data Protection Officer?
The IRR requires a person involved in personal-data processing to designate an individual or individuals who function as DPO, compliance officer, or are otherwise accountable for privacy and security compliance. The exact appointment and registration treatment should be checked against current NPC rules and the organization’s structure.
Does a one-person freelancer have to comply?
Potentially, yes. Processing client, customer, applicant, or user information for professional work is not automatically a personal or household activity. The controls can be proportionate, but the legal analysis should still be performed.
Are nonprofits exempt?
There is no general nonprofit exemption. A nonprofit processing member, donor, volunteer, employee, or beneficiary data must examine the same coverage, role, purpose, security, and accountability questions.
Does the law apply if data is stored outside the Philippines?
It can. Storage location is only one fact. The Act and IRR include extraterritorial rules involving Philippine citizens or residents and entities with specified links to the Philippines.
Is public information outside the DPA?
Not automatically. The source, legal context, purpose, method, combination, disclosure, and effect of processing all matter. Public availability should not be treated as unlimited permission to collect or republish personal data for any purpose.
Does every covered business have to register with the NPC?
No. Mandatory registration has specific criteria under NPC Circular No. 2022-04. However, a business outside those criteria remains responsible for compliance and must check the Circular’s sworn-declaration rule if it does not register voluntarily.
What should a business do first?
Create a one-page inventory of every system or file containing personal data. Name the people involved, purpose, lawful basis, access, vendors, storage location, retention period, and risk. That inventory makes the rest of the compliance work concrete.
Official sources
Related Cybercode guides
Important: This article provides general educational information about Philippine data privacy, cybersecurity, and business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, National Privacy Commission procedures, technical standards, contracts, sector rules, and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when rights, deadlines, money, safety, or legal exposure may be affected.

