Last materially reviewed: September 3, 2026
Direct Answer
This glossary explains common Philippine technology-law terms in practical language for business owners, consumers, employees and digital teams. Terms link into Cybercode authority guides where a deeper legal or procedural explanation is available.
A-Z: A · B · C · D · E · I · L · M · O · P · S · T · V
A
- Administrative fine
- A monetary penalty imposed by a regulator for violations within its administrative jurisdiction, such as certain Data Privacy Act violations.
- Advisory
- Guidance issued by a regulator to explain how laws, rules or regulatory expectations apply to particular situations.
- Artificial intelligence (AI)
- Systems that perform tasks associated with human intelligence, including prediction, generation, classification or decision support. See AI law Philippines.
- Automated decision-making
- Processing in which a system makes or materially supports decisions with limited or no human involvement, potentially triggering privacy obligations.
- Authentication
- Verification of identity or origin, relevant to electronic signatures, account access and evidentiary reliability.
B
- Biometric data
- Data derived from biological or behavioral characteristics used to identify or verify a person, such as fingerprints or facial templates.
- Breach notification
- Formal notification to regulators and/or affected individuals when legal thresholds for a personal data breach are met. See NPC breach notification guide.
C
- Clickwrap agreement
- An online contract mechanism requiring a user to affirmatively click acceptance of terms.
- Cloud service provider
- A vendor providing hosted computing, storage, software or infrastructure services. Legal issues commonly include privacy, security, contracts and cross-border processing.
- Computer data
- Digital information represented in a form suitable for processing in a computer system, a key concept in cybercrime law.
- Computer-related fraud
- Fraud carried out by inputting, altering, deleting or interfering with computer data or systems. See computer-related fraud guide.
- Consent
- A freely given, specific and informed indication of agreement to personal-data processing when consent is the applicable lawful basis.
- Consumer
- An individual who purchases or uses goods or services, including in internet transactions subject to consumer-protection rules.
- Controller
- Short form for personal information controller: the person or organization that determines why and how personal data is processed.
- Cross-border data transfer
- Transfer or remote access of personal data across national borders, often requiring contractual and organizational safeguards.
- Cybercrime
- Criminal conduct involving computers, data, networks or online systems, including offenses under RA 10175. See RA 10175 guide.
- Cyber libel
- Libel committed through a computer system and prosecuted under applicable libel law together with the Cybercrime Prevention Act. See online libel guide.
D
- Data processing system
- A system or organized process used to collect, store, use, disclose or otherwise process personal data.
- Data Protection Officer (DPO)
- The person designated to oversee an organization’s compliance with data-protection obligations.
- Data sharing agreement
- An agreement governing defined sharing of personal data between parties, subject to applicable NPC rules.
- Data subject
- The individual whose personal data is processed.
- Data subject rights
- Rights granted to individuals under the Data Privacy Act, including rights to information, access, correction and other remedies.
- Deceptive design pattern
- A user-interface practice designed to manipulate or impair user choice, including privacy choices.
- Digital evidence
- Information in digital form offered as evidence, subject to rules on relevance, authenticity, admissibility and weight.
- Digital signature
- A type of electronic signature using cryptographic methods to verify identity and integrity. See digital vs electronic signatures.
- Digital platform
- An online service or system that enables interactions, transactions, content, marketplaces or other digital activity.
E
- Electronic Commerce Act
- Republic Act No. 8792, the principal Philippine law recognizing electronic documents, electronic signatures and electronic transactions. See RA 8792 guide.
- Electronic contract
- A contract formed through electronic means such as websites, apps, email or digital platforms.
- Electronic data message
- Information generated, sent, received or stored by electronic, optical or similar means, a core concept under RA 8792.
- Electronic document
- Information represented in electronic form that may receive legal recognition under the Electronic Commerce Act and evidentiary rules.
- Electronic evidence
- Electronic or digital information used in a legal proceeding. See electronic evidence guide.
- Electronic signature
- An electronic method, mark or process used to identify a person and indicate approval or authentication, subject to applicable legal requirements. See electronic signatures guide.
- E-marketplace
- A digital platform facilitating transactions between sellers and buyers, including marketplaces covered by the Internet Transactions Act.
- E-retailer
- An online seller operating its own digital channel or site rather than only through a third-party marketplace.
I
- Identity theft
- Unauthorized acquisition, use or misuse of identifying information, including computer-related identity theft under RA 10175. See identity theft guide.
- Illegal access
- Access to the whole or part of a computer system without right, an offense under the Cybercrime Prevention Act.
- Internet transaction
- A transaction conducted through the internet and potentially governed by RA 11967 and other consumer, contract and privacy laws.
- Internet Transactions Act
- Republic Act No. 11967, governing duties and protections in internet transactions. See RA 11967 guide.
- Intermediary
- A service or entity that transmits, hosts, facilitates or otherwise participates between parties in digital communications or transactions, depending on the law involved.
L
- Lawful basis
- A legally recognized ground permitting processing of personal data, such as consent, contract, legal obligation or legitimate interest depending on the circumstances.
- Legitimate interest
- A lawful basis for certain processing when the controller’s legitimate purpose is necessary and does not override the rights and interests of the data subject.
- License agreement
- A contract granting defined rights to use software, content, intellectual property or technology. See software licensing guide.
M
- Marketplace liability
- The potential legal responsibility of an online marketplace for duties, disclosures, consumer remedies or prohibited conduct under applicable law. See marketplace liability guide.
- Model contractual clauses
- Standard contract clauses published by a regulator to help organizations structure compliant cross-border personal-data transfers.
- Multi-factor authentication (MFA)
- An authentication method requiring two or more verification factors; recognized in several security and financial regulations.
O
- Online merchant
- A seller offering goods or services through the internet and subject to applicable registration, disclosure and consumer-protection duties.
- Online contract
- A contract entered into electronically, including through websites, apps, clickwrap terms or email. See online contracts guide.
- Online terms and conditions
- Contractual terms presented on a website or digital service governing use, purchases, liability and other obligations. See terms and conditions guide.
- Outsourcing
- Engaging another organization to process data or perform technology functions, usually requiring contractual controls, security and accountability.
P
- Personal data
- A collective term for personal information, sensitive personal information and privileged information under Philippine privacy law.
- Personal information
- Information from which an individual can be identified directly or when combined with other information. See personal information guide.
- Personal information controller (PIC)
- The person or organization that controls the collection, holding, processing or use of personal data.
- Personal information processor (PIP)
- A person or organization processing personal data on behalf of a controller.
- Privacy impact assessment (PIA)
- A structured assessment of privacy risks, impacts and safeguards associated with a processing activity or system.
- Privacy notice
- A transparency notice explaining how an organization collects, uses, shares, retains and protects personal data. See privacy notice requirements.
- Profiling
- Automated processing used to evaluate or predict aspects of an individual’s behavior, preferences, performance or circumstances.
S
- SaaS agreement
- A contract for software delivered as an online service, often addressing access, security, privacy, availability, support and termination. See SaaS agreements guide.
- Security incident
- An event affecting or potentially affecting confidentiality, integrity or availability of personal data or information systems.
- Sensitive personal information
- Categories of personal information given heightened protection under the Data Privacy Act, including certain health, education, government-issued and other sensitive data.
- SIM Registration Act
- Republic Act No. 11934, requiring registration of subscriber identity modules and regulating related registration information.
- Software license
- The legal permission defining how software may be installed, copied, accessed, modified or distributed.
T
- Technology vendor
- A supplier of software, cloud, infrastructure, cybersecurity or other digital services that may create contractual, privacy and security obligations.
- Terms of use
- Contractual rules governing access to and use of a website, application or digital service.
- Trade secret
- Confidential business information that derives value from secrecy and is protected through contractual and other legal measures.
V
- Vendor due diligence
- Review of a supplier’s legal, security, privacy, operational and contractual risk before engagement.
- Verification
- A process of checking identity, authenticity, integrity or compliance depending on the legal context.
Official Sources
- Republic Act No. 8792 — Electronic Commerce Act
- Republic Act No. 10175 — Cybercrime Prevention Act
- Republic Act No. 10173 — Data Privacy Act (NPC)
- Republic Act No. 11967 — Internet Transactions Act
