Data Privacy Act (Philippines)
Definition
Data Privacy Act (Philippines)
The Data Privacy Act Philippines, or Republic Act 10173, is the law that protects personal data across every private and government body in the country. It sets rules for consent, storage, transfer, and breach response, and binds every BPO handling Filipino data.
Signed on 15 August 2012 by President Benigno Aquino III, RA 10173 created the National Privacy Commission, or NPC. The NPC enforces the law, runs registrations, and investigates breaches. Fines range from PHP 500,000 to PHP 5 million per violation.
The law reaches beyond Philippine borders. Any BPO or offshore team processing data on Filipino citizens, or any foreign customer whose record flows through a Philippine contact center, falls under NPC jurisdiction.
Key takeaways
- RA 10173, signed in 2012, is the Philippines’ core personal-data law.
- The National Privacy Commission enforces it and demands breach reports within 72 hours.
- Every BPO handling personal data must appoint a Data Protection Officer.
- Penalties top out at PHP 5 million plus six years’ jail per violation.
How it works
The National Privacy Commission enforces RA 10173 through three tools: registration of processing systems, mandatory breach notification within 72 hours, and audits. Every organization handling personal data must appoint a Data Protection Officer (DPO).
The DPO acts as the NPC’s contact inside the company. They log processing activities, run privacy impact assessments, and file the annual data-processing registration for firms with 1,000 or more data subjects.
RA 10173 sorts data into three tiers. Personal information covers name, address, and job title. Sensitive information adds race, health, religion, and government IDs. Privileged information tracks legally protected exchanges, attorney-client and doctor-patient.
RA 10173’s reach doesn’t stop at the coast. Section 6 applies the law to any entity outside the Philippines that processes personal information about a Philippine citizen or resident.
That clause is the reason foreign clients audit their Philippine BPO partners against the DPA.
Here’s what the law demands of a data controller in practice:
| Obligation | Trigger | Deadline or limit |
|---|---|---|
| Appoint a Data Protection Officer | Any org processing personal data | Before processing starts |
| Notify NPC of a breach | Real risk of harm to subjects | Within 72 hours |
| Register the data-processing system | Processing 1,000+ subjects | Annual renewal |
| Fine for unauthorized processing | Section 25 violation | PHP 500K–5M + up to 6 years jail |
Consent must be freely given, specific, and informed. Blanket check-boxes fail the test. A customer can withdraw consent at any point, and the controller then has to stop processing and, if asked, delete the record.
Data subjects have specific statutory rights: to be informed, to access, to correct, to erase or block, and to damages when their rights are infringed. NPC Circular 2016-01 spells out how a controller answers each request.
Examples
Enforcement under RA 10173 shows how the law bites in practice. From the 2016 Comelec breach, dubbed “Comeleak” after voter data hit the web, to recent NPC compliance orders, the pattern is clear: cases target both government and private handlers.
Comeleak, 2016. Hackers dumped the personal information of 55 million voters from the Commission on Elections in March 2016. In April 2017 the NPC recommended criminal charges against then-Chair Andres Bautista under Section 26, the biggest breach in Philippine history.
BPO call-center compliance. Global banks route customer support through Manila. Every conversation about a Filipino cardholder triggers RA 10173. Providers staff Filipino DPOs on Manila floors and pair the DPA with ISO 27001 or SOC 2 audits.
Sanction levels. Section 25 sets one to three years’ jail and PHP 500,000 to PHP 2 million fines for unauthorized processing. Section 26 lifts penalties to six years and PHP 5 million where sensitive data is mishandled. Corporate officers can be personally liable.
Foreign audits. US and EU clients now build DPA compliance into RFPs. A Manila call center wanting UK bank work needs to show its DPO records, its 72-hour incident response plan, and its NPC-registered processing systems before contracts move to signature.
Related terms
The Data Privacy Act sits at the middle of a broader compliance stack that Philippine outsourcing providers carry. These five terms come up alongside it most often on client audits and RFPs.
- GDPR: europe’s parallel regime; RA 10173 is often called “the GDPR of Southeast Asia”.
- Data privacy: the umbrella concept the Philippine act encodes into statute.
- ISO 27001: the certification most Philippine BPOs pair with DPA compliance.
- SOC 2: the US audit standard many Manila-based providers also carry for US clients.
- BPO: the sector most affected by RA 10173 and the biggest employer of Philippine DPOs.
FAQ
Buyers evaluating Philippine outsourcing partners ask four questions about RA 10173. The answers below cover scope, enforcement, penalties, and how the law compares to GDPR: the four points that shape most vendor selection scorecards.
Who does the Data Privacy Act Philippines apply to?
Any person or organization processing personal data about a Philippine resident, whether the processor sits in Manila, London, or Denver. The law’s extraterritorial reach is why foreign BPO buyers watch it.
What are the penalties under RA 10173?
Fines range from PHP 500,000 to PHP 5 million per offence, plus jail terms of one to six years. Section 26 lifts penalties when sensitive personal information (health, religion, government IDs) is involved.
How does the DPA compare to GDPR?
Both require consent, breach notification, and a Data Protection Officer. GDPR fines cap at 4% of global turnover; the Philippine act uses fixed peso ranges. Both apply to processors outside their home jurisdiction when a resident’s data is handled.
Does a BPO need a Data Protection Officer?
Yes. Every BPO handling personal data has to name a DPO under NPC Circular 2016-01.
If you’re building an outsourcing partner shortlist that clears RA 10173 from day one, Outsource Accelerator’s provider hub surfaces DPA-ready teams.







Independent




