PIC PIP
Definition
PIC PIP
PIC PIP is the Philippine shorthand for personal information controller and personal information processor, the two roles the Data Privacy Act assigns to organisations that handle data. Only one of them carries accountability, and outsourcing does not move it.
Every organisation touching personal data in the Philippines is one, the other, or both at once.
The classification is not a matter of preference. It follows from who decides why and how the data is processed, which is a question of fact rather than a term you negotiate.
Providers get this wrong in a specific direction — they describe themselves as processors for everything, including data where they plainly make the decisions.
Key takeaways
- The controller decides the purpose and means; the processor acts on instruction.
- A single company is usually a controller for some data and a processor for other data.
- Accountability for transferred data stays with the controller under the Act.
- Misclassification shifts obligations onto a party that never accepted them.
How it works
The statutory definitions are the starting point, and they are drawn around decision making rather than around who physically handles the data or where the servers sit.
A controller controls the collection, holding, processing or use of personal information, including one who instructs another person or organization to collect, hold, process, use, transfer or disclose personal information on his or her behalf.
The processor is defined by the relationship. It is the party to whom a controller may outsource processing, which means the role exists only because somebody else’s instruction created it.
The dual role is the part buyers miss — a Manila provider is a processor for its client’s customer data and a controller for its own employees’ records, and both roles run at the same time.
| Data set | Provider’s role | Who decides |
|---|---|---|
| Client customer records | Processor | The client |
| Provider’s own employee files | Controller | The provider |
| Recruitment applicants | Controller | The provider |
| Client data reused for provider analytics | Controller | The provider, and that is the problem |
| Subcontracted overflow work | Processor, with a sub-processor beneath | The client, in principle |
Row four is where classification disputes start — a provider that reuses client data for its own purposes has decided the purpose, which makes it a controller for that use whatever the contract says.
Registration duties also follow the role and the scale. Entities that employ two hundred and fifty (250) or more persons or process sensitive personal information of a thousand or more individuals must register with the regulator.
Examples
Role classification decides who answers a complaint, who reports a breach and who pays. The four situations here are the ones that generate the most confusion in tenders.
A Cebu provider handles claims for an Australian insurer. It is a processor for claims data, and a controller for the payroll records of the four hundred staff doing the work.
A recruitment outsourcing firm collects applicant data for client vacancies. It decides retention and screening methods, which makes it a controller rather than the processor its contract calls it.
A provider aggregates anonymised client call data to improve its own quality models. If the data is not truly anonymous, it has become a controller for that processing.
A client asks a provider to sign as controller to simplify its own paperwork. The label does not follow the signature, and a regulator will look at who actually decided.
Related terms
Philippine privacy roles map onto other regimes imperfectly, and the mismatch causes contract errors. The entries here are the ones most often cited alongside this one in tenders.
- Data Privacy Act Philippines: the statute that creates both roles.
- GDPR outsourcing: the European controller and processor split these terms mirror.
- ISO 27701: the privacy certification that distinguishes the roles in its scope.
- Philippines BPO: the sector where dual roles are most common.
- Back office outsourcing: the delivery model that creates most processor relationships.
- Business process outsourcing (BPO): the wider category this vocabulary applies across.
- Compliance outsourcing: contracting the compliance function rather than the processing.
FAQ
Can one company be both?
Yes, and most are. A provider is typically a processor for client data and a controller for its own employee and applicant records.
Does the contract decide the role?
No. Classification follows who actually determines the purpose and means, and a regulator will look past the label.
Who answers a data subject complaint?
The controller, though the processor is usually required by contract to assist within a defined timeframe.
What happens if a processor uses data for its own purposes?
It becomes a controller for that processing, with the obligations that attach, including a lawful basis of its own.
Do processors have to register?
Registration depends on thresholds rather than role, including headcount and volumes of sensitive personal information.
Does the role change who is liable for a breach?
It changes what each party owes, and the controller’s accountability for transferred data remains.
Browse source partners in the Outsource Accelerator hubs directory and choose partners who can name their processing agreements on request.







Independent




