Skip to the content
Global Data RulesData governance rules, country by country

Philippines

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Active

The Philippines does not force data to stay in the country. Its privacy law lets data go abroad with no permit and no approved-country list. Instead it makes you stay responsible for the data after it leaves, register your systems with the regulator, and name a privacy officer. Get it badly wrong and a person can go to prison. Banks and government bodies face extra conditions.

Data governance in the Philippines

The eight things that decide how you handle data about people in the Philippines. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office in the Philippines. It applies if you process data about Philippine citizens or residents, if you use equipment in the country, or if you have enough of a link to the country such as carrying on business there. There is no revenue floor and no company-size floor that lets you out. There is no formal 'local representative' role, but in practice you must name a data protection officer and register with the regulator, and foreign companies must file apostilled corporate papers to do it.

High confidenceNational rulesAppoint a data protection officerRegister or notify

Where the data is allowed to live

In general, yes, and easily. The privacy law has no rule that keeps data in the country, no list of approved or banned destinations, and no permit to apply for. The regulator has said in writing that the law is not a barrier to sending data abroad. Two sectors change that answer. Banks and other firms the central bank supervises may only send work offshore if the destination country has confidentiality and privacy laws that do not clash with Philippine law. Government bodies and their contractors cannot take sensitive personal data off site in bulk at all.

Medium confidenceDepends on your industryNo restrictionYes, with paperwork

Sending data out of the country

Nothing has to be approved before data leaves. There is no destination list to check, either of banned or of blessed countries, so the list question does not arise. What you must have is a paper trail: you stay legally responsible for the data after it goes, your supplier may only move it on your written instructions, and you have to declare planned overseas transfers when you register with the regulator. The regulator published a model contract in 2024, but using it is optional and it will not review your contract.

High confidenceNo restrictionNothing requiredStandard contract clausesPut a transfer safeguard in placeWritten vendor contract

The regulator, and whether it actually acts

The National Privacy Commission enforces the privacy law, and it is genuinely working. It has a serving commissioner and two deputies, it publishes decisions and orders, and it ordered a face-scanning identity product to stop processing data in the Philippines in late 2025. It has a published fine schedule that scales with company income. The central bank supervises banks and payment firms and enforces its own technology and outsourcing rules. Rate the country as actively enforced, not dormant.

High confidenceActivePercentage of global turnoverOrder to stopCriminal liability

How long you must keep it — and when to delete it

The privacy law sets no fixed number of years. It says keep personal data only as long as you need it for the purpose, then destroy it safely and be able to show how. The hard minimum periods come from other rules. Banks and other financial firms must keep records for at least five years, and money-laundering records for five years after an account closes. If a money-laundering case is filed, you keep everything until the case is finished, with no end date.

Medium confidenceDelete data after a periodKeep data for a minimum periodKeep logs

If something goes wrong

There are at least two clocks and they are very different lengths. For personal data, you have seventy-two hours from the moment you know or reasonably believe a serious breach happened to tell the regulator and the affected people. If you are a bank or other firm supervised by the central bank, you have two hours from discovery to tell your supervisor about a major cyber incident, then a fuller report within twenty-four hours. Everyone covered by the privacy law also files a yearly summary of all incidents, due by the thirty-first of March.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things catch people out. A child is anyone under eighteen, not thirteen or sixteen. Breaking the privacy law can put a named individual in prison, not just cost the company money. You have to register your processing systems with the regulator, and a foreign company has to file apostilled corporate papers to do it. Bank deposit secrecy is a separate criminal law that a data-processing contract does not fix. And government files cannot go off site in bulk at all.

High confidenceChildren's dataGet a parent's consent for childrenCriminal liabilityRegister or notifyExtra vendor secrecy terms

What's changing next

Nothing forces data to stay in the Philippines in the next twelve months, as far as we can see. The regulator is the busy one: it issued new guidance on data scraping in April 2026, changed how breaches are reported in May 2026, and was consulting in August 2026 on updated risk-assessment guidelines. A bill to strengthen the privacy law has been circulating in Congress for years and is still only a proposal. Treat the regulator's power to issue binding circulars as the switch that can flip fastest.

Medium confidenceProposedDraft lawRegulator guideline

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Data Privacy Act of 2012, sections 22 to 24 (security of sensitive personal information in government)

Act of parliament · Republic Act No. 10173, sections 22-24

In forceYes, with paperwork

Government bodies and the companies that work for them cannot move sensitive personal data off site freely. Each instance needs the agency head's written approval and is limited to one thousand records, which in practice blocks bulk offshore processing of government files. Contractors must also register with the privacy regulator.

Enforced by National Privacy Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Banking

Manual of Regulations for Banks, Sections 112 (Outsourcing), 148 (Information Technology Risk Management), 172 (Financial Records) and 924 (Record Keeping)

Directly binding regulation · Manual of Regulations for Banks, 2022 consolidated edition

In forceYes, with paperwork

Banks and other supervised financial firms may send work and data offshore, but only if the contract spells out confidentiality duties and the destination country's own confidentiality and privacy laws do not clash with Philippine law. The central bank can order the arrangement unwound at any time. Cyber incidents must be reported within two hours, and records kept at least five years and produced without delay.

Enforced by Bangko Sentral ng Pilipinas

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Data Privacy Act of 2012

Act of parliament · Republic Act No. 10173

In forceYes — store it anywhere

The general privacy law. It reaches foreign companies, demands consent or another lawful basis, gives people rights over their data, and does not restrict sending data abroad. Breaches of it can be criminal, and the regulator can fine up to three percent of last year's gross income, capped at five million pesos per act, roughly ninety thousand United States dollars.

Enforced by National Privacy Commission

Transfer model: No restriction · Accepted routes: Nothing required, Standard contract clauses

High confidence

Registration of Personal Data Processing System

Regulator directive · NPC Circular No. 2022-04

In forceYes — store it anywhere

Medium and larger organisations, and anyone doing automated decision-making or profiling at any size, must register their data processing systems with the regulator and name a privacy officer. Overseas transfers you plan to make must be declared on the form.

Enforced by National Privacy Commission

High confidence

Personal Data Breach Management

Regulator directive · NPC Circular No. 16-03

In forceYes — store it anywhere

You have seventy-two hours from knowing or reasonably believing a serious breach happened to tell both the regulator and the people affected. Everyone also files a yearly summary of all incidents, and hiding a breach of sensitive data is a crime.

Enforced by National Privacy Commission

High confidence

Who you would hear from

  • National Privacy Commission (Pambansang Komisyon sa Pagkapribado)

    General privacy law: enforcement, registration, breach notification, binding circulars and advisories

    Fully staffed and active. Led as of 18 August 2026 by Privacy Commissioner and Chairman Atty. Johann Carlos S. Barcena with two deputy commissioners. Issues binding circulars, publishes decisions and orders, and issued cease and desist orders in September and October 2025. Has a published administrative fine schedule of up to 3 percent of annual gross income, though we could not evidence a named company being fined a specific amount from its own published pages.

  • Bangko Sentral ng Pilipinas

    Banks, quasi-banks, electronic money issuers and payment systems: outsourcing, technology risk, incident reporting, record keeping

    Long-established prudential supervisor. Runs a two-hour cyber incident reporting regime, examines institutions on site, and can order outsourcing arrangements terminated or brought back in-house.

  • Insurance Commission

    Insurance and pre-need companies, health maintenance organisations

    Actively issuing circular letters through 2026, but on 18 August 2026 we found no circular letter on cloud, outsourcing, data storage location or data privacy in its published list for 2021 to 2026. Insurers appear to fall back on the general privacy law.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether the Philippine government's Cloud First Policy restricts where government data may be hosted

    The Department of Information and Communications Technology website blocked every automated request from this session, so we could not read the current department circular. A policy of this kind is widely reported to classify government data and to steer sensitive classifications to a government cloud, but we will not assert it without the department's own text. Anyone doing government work should read the current circular directly.

  • Whether licensed online gaming operators must keep gaming servers and player data inside the Philippines

    The gaming regulator's public regulatory pages publish only land-based casino manuals. The remote-gaming and electronic-gaming standards pages carried no documents when checked on 18 August 2026.

  • Sector rules for securities firms, hospitals, telecommunications companies and mapping or geospatial data

    The securities regulator's search pages, the health department, the telecommunications regulator, the statistics authority and the official gazette all refused automated requests from this session. We found no evidence of storage-location rules in these sectors, but this is an unchecked gap rather than a verified negative.

  • The tax and company-law minimum retention periods, commonly stated as ten years for books of accounts

    The tax bureau's website serves its regulations through a script-driven interface that we could not read, so we have no official citation for the period. Treat the ten-year figure as unverified.

  • Current status in Congress of the bills amending the Data Privacy Act

    Both chambers' websites refused automated requests. The only official material we could reach is a regulator news item from 2021 describing a committee-approved substitute bill. The amendments may have advanced, lapsed or been refiled since; treat the whole package as proposed with unknown standing.

  • Whether the National Privacy Commission has actually collected an administrative fine under its 2022 fine schedule

    The published decisions and orders we could read describe damages and cease and desist orders rather than named peso fines. The power plainly exists; the collection record is not evidenced on the regulator's own pages.

  • That the 2022 consolidated Manual of Regulations for Banks is the current text of the banking rules

    It is the consolidated edition the central bank publishes for download, but the Manual is amended continuously by circulars and the site's regulation index blocked automated access. Later circulars may have modified the outsourcing, incident-reporting or record-keeping sections.

  • The exact commencement date of the Data Privacy Act and of several regulator circulars

    The Act and the circulars all take effect fifteen days after publication in newspapers, and the publication dates are not stated in the texts we could read. Only the signing dates are recorded here.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Philippines versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.