CyberCode.ph · Philippines

Privacy Notice Requirements Philippines: What Businesses Must Tell Customers and Employees

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 3, 2026

Direct Answer

Philippine businesses that process personal data should provide clear privacy information to the people whose data they collect. NPC Circular No. 2023-04 states as a general rule that a privacy notice is required in any instance of processing, whether processing is based on consent or another lawful criterion, subject to the circular’s specific exceptions. The notice should be easy to access, understandable and accurate to the actual processing activity.

Key Takeaways

  • A privacy notice is generally required when personal data is processed.
  • The notice should explain what data is processed, why, on what basis, who receives it, retention and data-subject rights.
  • A website privacy notice should reflect real practices, not copied generic text.
  • Consent is not the only lawful basis for processing.
  • Update notices when material processing practices change.

What should a privacy notice explain?

NPC guidance on the right to be informed identifies core information including the description of personal data, purposes, basis when not based on consent, scope and method of processing, recipients or classes of recipients, automated access where relevant, identity and contact details of the controller, retention period and the existence of data-subject rights.

Where should the notice appear?

Place privacy information where people encounter the processing. Examples include a website form, e-commerce checkout, employee onboarding process, event registration page, mobile app, customer account creation flow or physical collection point. A single website policy may not always be enough if the processing context requires more specific information.

Privacy notice versus consent form

A privacy notice informs the data subject about processing. Consent is one possible lawful basis and has its own validity requirements. NPC Circular No. 2023-04 notes that when a consent form already contains the essential information for the specific processing activity, a separate notice for that same activity may not be necessary.

Common privacy-notice mistakes

  • Copying another company’s policy without matching actual data flows.
  • Saying ‘we never share data’ while using cloud, analytics or payment vendors.
  • Failing to explain retention.
  • Listing consent as the basis for every activity even when another lawful basis is relied on.
  • Using vague purposes such as ‘business purposes’ with no meaningful explanation.
  • Not updating the notice after adding new tools or processing activities.

Website cookies and analytics

There is no single blanket Philippine rule requiring the same EU-style cookie banner for every website. However, where cookies, pixels, SDKs or analytics tools process personal data, the Data Privacy Act’s transparency, lawful-processing and security requirements remain relevant. The business should understand the specific technology and processing rather than adding a banner that does not match actual controls.

Employee privacy notices

Employees should also receive clear information about relevant processing such as payroll, benefits, attendance, security monitoring, device management or HR systems. Employer-employee processing does not eliminate the right to meaningful information about how personal data is handled.

Practical privacy-notice checklist

  • Controller identity and contact information
  • Categories of personal data
  • Specific purposes
  • Lawful basis where relevant
  • Recipients or categories of recipients
  • Retention period or criteria
  • Automated decision-making or profiling where applicable
  • Data-subject rights and complaint channels
  • Effective date and update process

FAQs

Does every website need a privacy policy?

If the website processes personal data, it should provide appropriate privacy information. The exact format depends on the processing activities.

Is a privacy notice the same as terms and conditions?

No. Terms govern the commercial or contractual relationship; a privacy notice explains personal-data processing.

Can a business rely only on consent?

No. Consent is only one lawful criterion under the Data Privacy Act, and it should not be used mechanically where another lawful basis is more appropriate.

Related Cybercode Guides

Official Sources