Philippine Data Privacy
Definition
Philippine Data Privacy
Philippine data privacy is the regime organisations work under when they handle personal information in the country, set by Republic Act 10173 and the National Privacy Commission. Registration is mandatory above set thresholds, and most offshore operations clear them.
Knowing the statute is not the same as complying with it.
The operating requirements come from the regulator rather than the text: register, appoint someone accountable, report breaches on time, and keep the paperwork current.
Most delivery centres clear the registration thresholds on headcount alone — which makes this an administrative obligation rather than a judgement call.
Key takeaways
- Registration is required above defined headcount and sensitive data thresholds.
- A registration certificate is valid for one year and must be renewed.
- An accountable individual must be designated for compliance with the Act.
- Breaches requiring notification must be reported within seventy-two hours.
How it works
Registration is threshold based. Entities must register where they employ two hundred and fifty (250) or more persons or process sensitive personal information of one thousand or more individuals.
The certificate is not permanent — it is valid for one year from its date of issue, with renewal required within thirty days before expiry, which makes it a recurring administrative task.
Accountability has to be a person. Organisations must appoint someone accountable for compliance with the Act, which is the role most delivery sites label a data protection officer.
The statute behind the regime remains the operative text. It requires a controller to ensure that third parties processing personal information on its behalf implement the security measures it demands.
| Obligation | Trigger | Practical effect on a delivery site |
|---|---|---|
| Registration | 250 staff or 1,000 sensitive records | Almost every established site qualifies |
| Annual renewal | One year from issue | A calendar item, not a project |
| Accountable person | Any processing organisation | A named individual, reachable by the regulator |
| Breach notification | Reportable breach identified | Seventy-two hours from knowledge or belief |
| Security measures | All personal information | Verified rather than asserted |
Breach reporting is where offshore arrangements strain. Notification is required within seventy-two (72) hours upon knowledge of, or when there is reasonable belief that a reportable breach has occurred.
The notification duty sits with the controller — a provider that discovers the breach is usually not the party obliged to report it, which is why escalation clauses matter more than reporting clauses.
Examples
A Philippine delivery site meets these obligations as a matter of routine operations, not legal strategy. Every example below involves data leaving a jurisdiction that had opinions about it.
A Manila healthcare outsourcing site employs six hundred coders. Headcount alone puts it above the registration threshold, regardless of what it processes.
A Cebu analytics team handles a thousand patient records for a United States client. Sensitive personal information at that volume triggers registration independently of headcount.
A provider discovers a breach on a Saturday and reports it to its client on Monday. The seventy-two hour clock belongs to the controller, and two days of it are gone.
A small Davao startup assumes the rules apply only to large operations. The sensitive information threshold has no headcount element, so scale is not a shield.
Related terms
Philippine compliance vocabulary spans privacy, zone registration and labour law, often inside a single conversation. Each definition below fences off a concept that buyers routinely blur together.
- Data Privacy Act Philippines: the statute underneath this operating regime.
- ISO 27001 outsourcing: the security certification clients request alongside local compliance.
- Philippines BPO: the sector this regime governs most heavily.
- PEZA: the zone authority, a separate registration on a separate track.
- Healthcare outsourcing: the service line most exposed to sensitive information thresholds.
- Back office outsourcing: the delivery model behind most processing here.
- Compliance outsourcing: contracting the compliance function rather than performing the processing.
FAQ
Who has to register with the regulator?
Entities employing two hundred and fifty or more people, or processing sensitive personal information of a thousand or more individuals.
How long is a registration valid?
One year from the date of issue, with renewal required within thirty days before it expires.
Is a data protection officer mandatory?
An accountable individual must be designated for compliance with the Act. That role is what most organisations staff as a data protection officer.
How quickly must a breach be reported?
Within seventy-two hours of knowledge, or of a reasonable belief that a reportable breach has occurred.
Does the provider or the client report a breach?
The controller carries the notification duty. Providers escalate, and the contract should set a timescale far shorter than the statutory one.
Is zone registration the same thing?
No. Zone registration is an incentives matter and runs on an entirely separate track.
Compare source partners in the Outsource Accelerator hubs directory and keep the firms whose privacy documentation predates your enquiry.







Independent




