Republic Act 10173
Definition
Republic Act 10173
Republic Act 10173 is the Philippine Data Privacy Act of 2012, the statute on how organisations collect, hold and process personal data. It permits outsourcing without shifting responsibility, keeping the controller answerable for the data it hands to a processor.
The law took effect on 8 September 2012 and created the National Privacy Commission four years later to administer it.
Its timing was deliberate. The Philippines was already a major destination for outsourced data work, and the country needed a regime its clients’ regulators would recognise.
The Act therefore reads as if outsourcing were the normal case rather than the exception — a drafting choice that makes it unusually useful to buyers and providers alike.
Key takeaways
- The Act was written with outsourced processing in view rather than as an afterthought.
- Subcontracting is expressly permitted and expressly does not transfer responsibility.
- The controller must ensure third parties implement the same security measures.
- Accountability follows the data across borders as well as across companies.
How it works
The Act sets two roles. A personal information controller decides how data is handled, and a personal information processor is the party to whom a controller may outsource the processing of personal data pertaining to a data subject.
Section 14 addresses subcontracting head on — a controller may subcontract processing provided it ensures proper safeguards are in place, prevents unauthorised use and complies with the Act’s requirements generally.
Section 20 goes further on security. The controller must ensure that third parties processing personal information on its behalf implement the security measures the section requires.
| Section | What it settles |
|---|---|
| Section 3 | Who is a controller and who is a processor |
| Section 14 | Subcontracting is allowed, with safeguards |
| Section 20 | Third parties must implement the required security measures |
| Section 21 | Accountability stays with the controller, including after transfer |
| Sections 25–32 | The criminal penalties for unauthorised processing and disclosure |
Section 21 is the sentence that decides most disputes — each controller is responsible for personal information under its control or custody, including information transferred to a third party for processing, whether domestically or internationally.
Registration then applies above defined thresholds. Entities that employ two hundred and fifty (250) or more persons or process sensitive personal information of a thousand or more individuals must register.
Examples
Almost every offshore delivery centre in the country is a processor under this Act. Every example here involves a boundary that two competent parties drew differently.
An Australian bank sends customer servicing to a Manila provider. The bank is the controller under its own law, the provider is a processor here, and both descriptions apply to the same keystrokes.
A United States healthcare group uses a Cebu team for medical coding. The group’s business associate agreement and the Philippine processor obligations have to coexist in a single contract.
A domestic telecommunications company outsources its retention desk. It stays accountable under Section 21 even though it never touches the call recordings the vendor creates.
A provider subcontracts overnight quality review to a smaller firm in Davao. That second firm is a sub-processor, and the chain is only as protected as its weakest written agreement.
Related terms
Philippine privacy vocabulary is precise, and the statute rewards using it correctly rather than approximately. The entries below are the ones buyers most often reach for by mistake.
- Data Privacy Act Philippines: the same statute under its common name.
- GDPR outsourcing: the European processor regime many Philippine clients also answer to.
- HIPAA outsourcing: the United States health rules that often sit on the same contract.
- ISO 27701: the privacy certification providers use to shorten diligence.
- Philippines BPO: the delivery sector this Act was written around.
- Back office outsourcing: the work type that generates most processor relationships here.
- Compliance outsourcing: contracting the compliance function rather than the data handling.
FAQ
Does the Act allow offshore clients to send data here?
Yes. It contemplates outsourced processing directly and sets the conditions under which a controller may subcontract it.
Who is liable when a Philippine provider causes a breach?
The controller remains accountable under Section 21. The provider carries its own duties and can face penalties, but that does not relieve the controller.
Is registration with the Commission mandatory?
It is above defined thresholds, including headcount and volumes of sensitive personal information. Most sizeable delivery operations clear them.
Does the Act apply to a foreign company with no office here?
It can. The law reaches processing of Philippine residents’ data and equipment located in the country, subject to its own scope provisions.
Are there criminal penalties?
Yes. The Act creates imprisonable offences for unauthorised processing, improper disposal and unauthorised disclosure, among others.
Does a certificate satisfy Section 20?
No. Section 20 requires the controller to ensure that measures are implemented, which is a verification duty rather than a document collection exercise.
Start with source partners in the Outsource Accelerator hubs directory and pick the partners who know the local rule cold.







Independent




