Last materially reviewed: September 3, 2026
Direct Answer
There is no single Philippine law that says every website must have the exact same set of legal pages. What a website needs depends on what it does. A simple informational website has fewer obligations than an online store, booking site, SaaS platform, marketplace, membership site, or lead-generation website.
In practice, most Philippine business websites should review at least four legal areas: data privacy, e-commerce rules, consumer protection, and contractual terms. If the website collects personal data, the Data Privacy Act of 2012 and National Privacy Commission rules may apply. If it sells goods or services online, Republic Act No. 11967 or the Internet Transactions Act of 2023, the Consumer Act, and related DTI rules may also apply.
The safest approach is not to copy a generic privacy policy or terms template and assume the website is compliant. The legal pages and disclosures should accurately describe how the website actually operates.
Primary authorities: Republic Act No. 11967 — Internet Transactions Act, Republic Act No. 10173 — Data Privacy Act, and applicable DTI consumer-protection guidance.
Key Takeaways
- A website that collects personal data should provide a clear privacy notice explaining what data is collected, why it is processed, who receives it, how long it is kept, and what rights users have.
- Terms and Conditions are not legally mandatory for every basic informational website, but they are strongly recommended whenever the website creates a commercial, subscription, account, or service relationship.
- Online sellers must give consumers clear information about the goods or services being sold, including price, description, and condition.
- E-retailers covered by RA 11967 have additional disclosure, privacy, receipt or invoice, and complaint-handling obligations.
- A blanket “No Return, No Exchange” policy cannot remove a consumer’s statutory remedies for defective or non-conforming goods.
- The Philippines does not have one blanket rule requiring every website that uses cookies to show the same cookie-consent banner. However, cookies and trackers that process personal data must still comply with the Data Privacy Act, including transparency and a valid lawful basis.
- Collecting personal data creates security, retention, access-control, data-subject-rights, and breach-response responsibilities.
Jump to a Section
- Privacy policy and privacy notice
- Terms and conditions
- Refund and return policies
- Cookie consent
- Online seller disclosures
- What RA 11967 requires
- What happens when a website collects personal data
- Consumer-protection rules
- Website legal compliance checklist
- Frequently asked questions
Decision Snapshot
| Website feature | Main legal issue | What to consider |
|---|---|---|
| Contact form | Personal data collection | Privacy notice, lawful basis, security and retention |
| Newsletter signup | Personal data and direct marketing | Transparency, consent where applicable, unsubscribe process |
| Online store | E-commerce and consumer protection | Seller disclosures, pricing, returns, receipts, complaints, privacy |
| User accounts | Contracts, privacy and security | Terms, privacy notice, authentication, access controls |
| Analytics or advertising trackers | Tracking and personal data | Transparent disclosure and appropriate lawful basis |
| Paid subscription | Contract and billing | Price, renewal, cancellation, refund and service terms |
1. Do Philippine Websites Need a Privacy Policy?
If a website processes personal data, the website operator must comply with the Data Privacy Act of 2012 and its implementing rules. The National Privacy Commission explains that data subjects have a right to be informed before their personal data is processed or at the next practical opportunity.
That information commonly includes:
- the personal data being collected;
- the purpose of processing;
- the lawful basis for processing when it is not based on consent;
- the scope and method of processing;
- the recipients or classes of recipients;
- the identity and contact details of the personal information controller;
- the retention period; and
- the rights available to the data subject.
For a website, the most practical way to provide this information is normally through a clear privacy notice or privacy policy. A privacy policy should not simply say “we respect your privacy.” It should explain the actual data flows on the site.
What should a website privacy notice cover?
A useful website privacy notice should usually explain:
- what information is collected through forms, accounts, checkout, analytics, cookies, chat tools and integrations;
- why the information is collected;
- whether it is shared with hosting providers, payment processors, email providers, analytics services or other vendors;
- how long different types of information are retained;
- how users may exercise their privacy rights;
- how users can contact the organization or its privacy contact; and
- what happens if the privacy practices materially change.
For the wider framework, see Data Privacy Act of 2012 Philippines and the Data Privacy Compliance Checklist for Philippine Businesses.
2. Do I Need Terms and Conditions?
Not every basic website is legally required to have a Terms and Conditions page. A small company website that only publishes information about its services may not have the same contractual risks as an e-commerce store or SaaS platform.
However, Terms and Conditions become increasingly important when users can:
- buy goods or services;
- create an account;
- subscribe to a service;
- book an appointment;
- upload content;
- download digital products;
- use software or an online platform; or
- enter into any ongoing relationship with the website operator.
Well-written terms can explain the rules before a dispute happens.
What should website terms normally cover?
- who operates the website;
- eligibility to use the service;
- pricing and payment;
- order acceptance and cancellation;
- delivery or service-performance rules;
- refunds, replacements and returns;
- account responsibilities;
- acceptable use;
- intellectual-property ownership;
- limitations and disclaimers that are lawful and reasonable;
- suspension or termination of accounts;
- complaint and dispute procedures; and
- governing law and jurisdiction where appropriate.
Philippine law recognizes electronic transactions and electronic contracts. Read Are Online Contracts Legally Binding in the Philippines? and Are Electronic Signatures Legally Valid in the Philippines?.
3. Do Online Shops Need Refund and Return Policies?
An online store should publish a clear return, replacement, refund and complaint policy. But that policy cannot take away rights given to consumers by law.
The Department of Trade and Industry states that a blanket “No Return, No Exchange” policy is not allowed when a product has an imperfection or defect. Depending on the situation, consumers may be entitled to repair, replacement or refund.
RA 11967 also gives online consumers remedies where goods are defective, malfunctioning, lost without the consumer’s fault, or fail to conform with warranties or contractual obligations.
When is a seller generally not required to refund simply because the buyer changed their mind?
Consumer protection against defective goods is different from a voluntary “change of mind” return policy. DTI guidance notes situations where a seller may not be required to replace or refund, such as where the product has no defect, the buyer merely changed their mind, or the damage resulted from mishandling by the buyer.
So the policy should clearly distinguish:
- legal remedies for defective or non-conforming products; and
- voluntary store policies for change-of-mind returns.
4. Do Philippine Websites Need Cookie Consent?
There is no single Philippine rule that says every website using any cookie must display the same European-style consent banner. The correct analysis depends on what the cookie or tracking technology does and whether it processes personal data.
For example, cookies may be used for:
- essential login or shopping-cart functions;
- security and fraud prevention;
- analytics;
- personalization;
- advertising;
- cross-site tracking; or
- profiling.
If a cookie, pixel, SDK or similar technology processes personal data, the website operator must still apply the Data Privacy Act. That means the processing should be transparent, have a valid lawful basis, be proportionate to the stated purpose, and be subject to appropriate security and retention controls.
What is the safest practical approach?
At minimum, identify the cookies and trackers actually used on the website and explain them in the privacy notice or a separate cookie notice. For non-essential tracking that relies on consent as its lawful basis, obtain valid consent before activating the relevant tracker.
Do not install a cookie banner merely for appearance while allowing every advertising tracker to fire before the user has any real choice. A banner should reflect the website’s actual technical behavior.
5. What Information Must an Online Seller Disclose?
The Internet Transactions Act imposes specific transparency duties across e-marketplaces, digital platforms, e-retailers and online merchants.
Product offers on covered platforms should clearly state core information such as:
- the name and brand of the goods or services;
- the price;
- the description; and
- the condition.
Other digital platforms that do not oversee completion of the transaction may also have to require seller contact information.
For an e-retailer, RA 11967 goes further. The law requires certain information to be published on the homepage, including:
- corporate, trade or business name;
- address of the physical shop or place of business;
- contact details, including a mobile or landline number and a valid email address; and
- professional registration details where the service involves a regulated profession.
This is one reason anonymous-looking e-commerce websites with no business identity, address or working contact channel create both legal and trust problems.
See the dedicated Internet Transactions Act Philippines guide.
6. What Does RA 11967 Require From Online Businesses?
Republic Act No. 11967, the Internet Transactions Act of 2023, is one of the central laws for Philippine e-commerce. Its obligations differ depending on whether the business is an e-marketplace, digital platform, e-retailer or online merchant.
For many online sellers, the practical compliance areas include:
- accurate pricing;
- clear product descriptions;
- proper disclosure of product condition;
- delivery of goods consistent with what was advertised or described;
- privacy and information-security precautions;
- paper or electronic invoices or receipts for sales;
- an accessible complaint or redress mechanism;
- compliance with rules for regulated goods; and
- consumer remedies where goods or services do not conform with the contract.
Complaint handling matters
RA 11967 requires an internal redress mechanism. An aggrieved party generally must use the platform, marketplace or e-retailer’s internal complaint process before filing elsewhere. The mechanism is considered exhausted if the complaint remains unresolved after seven calendar days from filing.
That means an online shop should not rely only on a social-media inbox that nobody checks. A clear complaint channel, documented escalation process and response workflow are important parts of compliance.
7. What Happens If a Website Collects Personal Data?
The moment a website starts collecting identifiable personal information, the operator should think beyond the privacy-policy page itself.
Common collection points include:
- contact forms;
- checkout forms;
- account registration;
- newsletter signup;
- job applications;
- support tickets;
- chat widgets;
- surveys;
- analytics tools;
- CRM integrations;
- payment and delivery systems; and
- cookies and tracking technologies.
The organization should determine why each data field is needed and avoid collecting excessive information “just in case.” It should also control who can access the data, how vendors process it, how long it is kept, and how it is securely deleted.
Security is part of privacy compliance
Privacy compliance is not limited to posting legal text. The website and the systems behind it should use reasonable organizational, physical and technical safeguards.
Depending on risk, these may include:
- strong authentication and MFA for administrators;
- role-based access;
- software updates and patching;
- secure backups;
- TLS/HTTPS;
- logging and monitoring;
- secure payment processing;
- vendor due diligence;
- staff training; and
- a personal-data-breach response process.
If a breach occurs, use Cybercode’s Data Breach Response Checklist and Company Personal Data Breach Response Guide.
8. What Consumer-Protection Rules Apply?
A website that sells to consumers should not treat its own Terms and Conditions as superior to Philippine consumer law. Contract language cannot simply erase statutory consumer rights.
Important areas include:
- truthful product descriptions and advertising;
- clear prices;
- delivery consistent with what was ordered;
- remedies for defective or non-conforming goods;
- clear complaint procedures;
- proper invoices or receipts where required;
- accurate promotional terms; and
- reasonable handling of consumer data.
Do not hide material information
Shipping costs, renewal terms, subscription conditions, material limitations, delivery restrictions and other information that could affect the purchasing decision should be made clear before the customer commits to the transaction.
9. Philippine Website Legal Compliance Checklist
Use this as a practical first-pass audit. Not every item applies to every site.
Business identity
- Is the legal or business name clearly stated?
- Can users find a valid contact email or phone number?
- If you are an e-retailer, are the homepage disclosures required by RA 11967 present?
- Is the physical business address disclosed where required?
Privacy
- Do you have an accurate privacy notice?
- Does it describe all major collection points and third-party services?
- Have you identified the lawful basis for each important processing activity?
- Can users exercise their data-subject rights?
- Do you have a privacy contact or DPO contact where applicable?
- Are retention periods defined?
Cookies and tracking
- Do you know which cookies, pixels and SDKs the website uses?
- Are users told about analytics and advertising tracking?
- Where consent is relied upon, are non-essential trackers held until consent is obtained?
E-commerce
- Are prices clear?
- Are products accurately described?
- Is the condition of products disclosed?
- Are delivery rules clear?
- Are refund, repair and replacement rights explained correctly?
- Is there an effective complaint process?
- Are invoices or receipts issued?
Terms
- Do the Terms and Conditions match the actual service?
- Are payment, cancellation and renewal rules clear?
- Are prohibited activities and account rules explained?
- Are intellectual-property rules clear?
Security
- Is the website served over HTTPS?
- Are administrator accounts protected with strong authentication?
- Are plugins, themes, frameworks and server software patched?
- Are backups tested?
- Is there an incident-response process?
Common Mistakes Philippine Websites Make
- Copying a foreign privacy policy. A policy written for another country may cite the wrong laws and may not match the website’s actual processing.
- Using a fake cookie banner. A banner is useless if tracking scripts load regardless of the user’s choice.
- Hiding business identity. E-commerce sites should make it easy to identify and contact the seller.
- Using “No Refund” language too broadly. Store policies cannot cancel statutory remedies for defective goods.
- Collecting too much data. Ask only for information reasonably necessary for the purpose.
- Ignoring third-party tools. Your CRM, analytics, email, payment, chat and advertising services are part of the data flow.
- Having no complaint channel. A real redress process matters under RA 11967.
- Thinking HTTPS alone means compliance. Security requires more than installing an SSL certificate.
Frequently Asked Questions
Is a privacy policy legally required in the Philippines?
If your website processes personal data, the Data Privacy Act requires transparency about the processing. A privacy notice is the standard practical method of providing that information.
Does every Philippine website need Terms and Conditions?
No. A simple informational website may not need extensive contractual terms. Terms become much more important when the site sells, accepts subscriptions, creates user accounts, provides online services or otherwise enters into agreements with users.
Does every Philippine website need a cookie banner?
Not necessarily. What matters is what the cookies or trackers do, whether they process personal data, and what lawful basis applies. Non-essential tracking based on consent should not be activated before valid consent is obtained.
Can an online shop say “No Return, No Exchange”?
Not as a blanket rule that removes remedies for defective goods. DTI states that consumers may exercise repair, replacement and refund rights where products have defects or imperfections, subject to the circumstances of the case.
What must an e-retailer display on its homepage?
RA 11967 requires an e-retailer to publish identifying and contact information including its corporate or business name, physical shop or business address, phone contact and valid email address, plus professional registration details where applicable.
Do online sellers need to issue receipts?
RA 11967 provides that e-retailers or online merchants shall issue paper or electronic invoices or receipts for sales.
What if my website only has a contact form?
A contact form can still collect personal data such as a name, email address, phone number and message. You should explain the purpose of collection, protect the data, retain it only as needed, and honor applicable data-subject rights.
Related Cybercode Guides
- Internet Transactions Act Philippines
- Data Privacy Act of 2012 Philippines
- Data Privacy Compliance Checklist
- Are Online Contracts Legally Binding?
- Electronic Signatures in the Philippines
- Data Breach Response Checklist
Official Sources
- Republic Act No. 11967 — Internet Transactions Act of 2023
- National Privacy Commission — Data Privacy Act of 2012
- National Privacy Commission — Right to Be Informed
- National Privacy Commission — Implementing Rules and Regulations
- DTI Fair Trade Enforcement Bureau — No Return, No Exchange Policy
This guide provides general information and is not a substitute for advice from a lawyer or privacy professional regarding a specific website, business model or transaction.
