Philippines
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in the Philippines — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
The Philippines does not force data to stay in the country. Its privacy law lets data go abroad with no permit and no approved-country list. Instead you stay responsible for the data after it leaves. You must also register your systems with the regulator and name a privacy officer. Get it badly wrong and a person can go to prison. Banks and government bodies face extra conditions.
Data governance in the Philippines
The eight things that decide how you handle data about people in the Philippines. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office in the Philippines. It applies if you use or store data about Philippine citizens or residents. It also applies if you use equipment in the country, or if you have enough of a link to it, such as carrying on business there. There is no revenue floor and no company-size floor that lets you out. There is no formal 'local representative' role. But you must name a data protection officer and register with the regulator. Foreign companies must file apostilled corporate papers to do that.
- What you have to do here:
- Appoint a data protection officer · Register or notify
Republic Act No. 10173, the Data Privacy Act of 2012, covers in section 4 any person or company that uses or stores personal data. That includes those outside the Philippines who use equipment located in the country, or who keep an office, branch or agency there. Section 6 extends the Act to things done outside the Philippines. It applies where the information concerns Philippine citizens or residents, where a contract is entered into in the Philippines, or where the company carries on business in the Philippines. The regulator takes the same line in its own rules. NPC Circular No. 2023-06 says it applies to anyone using personal data 'within and outside of the Philippines'. The 250-employee figure in the Implementing Rules is not an exemption from the law. It is only a threshold in the registration rules. It does not apply where the work is likely to pose a risk to rights and freedoms, or involves sensitive personal information of at least 1,000 people. NPC Circular No. 2022-04 lists what a foreign private company must file to register. That is an authenticated or apostilled secretary's certificate appointing the data protection officer, a general information sheet or equivalent, a registration certificate and a business permit, all with English translations.
Sources
- Official sourceNational Privacy CommissionRepublic Act No. 10173, Data Privacy Act of 2012, sections 4 and 6
privacy.gov.ph
“This Act applies to an act done or practice engaged in and outside of the Philippines by an entity if ... the entity has other links in the Philippines”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2023-06, Security of Personal Data in Government and Private Sector, scope clause
privacy.gov.ph
“This Circular shall apply to all natural or juridical persons engaged in the processing of personal data within and outside of the Philippines”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2022-04, Registration of Personal Data Processing System
privacy.gov.ph
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, and easily. The privacy law has no rule keeping data in the country. There is no list of approved or banned destinations. There is no permit to apply for. The regulator has said in writing that the law is not a barrier to sending data abroad. Two industries change that answer. Banks and other firms the central bank supervises may only send work abroad if the destination country has confidentiality and privacy laws that do not clash with Philippine law. Government bodies and their contractors cannot take sensitive personal data off site in bulk at all.
General position: open (data can leave freely). Nothing in Republic Act No. 10173 or its Implementing Rules restricts sending data abroad. There are only three transfer-specific duties. You stay accountable for data you hand to anyone else. A supplier may send data to another country only on your written instructions. You must disclose planned transfers outside the Philippines when you register a system. INDUSTRY OVERRIDES CHECKED ON 18 AUGUST 2026: - Banking and other supervised financial institutions (data can leave only if conditions are met). The Manual of Regulations for Banks, Section 112, lets a bank outsource its domestic operations abroad only on two conditions. The central bank may order the bank to end the activity, change it, or bring it back in-house. It can do that if customer confidentiality, customer redress or its own ability to supervise cannot be assured. A local subsidiary of a foreign bank may use its parent group abroad without prior approval. It still carries the main liability to customers for the foreign provider's errors and fraud. - Payments and e-money (data can leave only if conditions are met). The same Manual applies. The technology risk rules expressly extend to institutions that handle data abroad. - Government and public sector (data can leave only if conditions are met, and a hard stop for bulk work). Republic Act No. 10173 section 23 requires the head of the agency to approve any off-site or online access to sensitive personal information by agency staff. It caps that access at 1,000 records. Section 24 brings government contractors under the same rules and requires them to register. NPC Circular No. 2023-06 adds detailed security duties on top. - Insurance (no override found). We reviewed the Insurance Commission's published circular letters for 2021 to 2026 on 18 August 2026. We found nothing on cloud, outsourcing, storage location or data privacy. No rule found, confidence medium. - Securities and markets, health, telecoms, education, mapping and geospatial, defence (no override found, checked 18 August 2026, confidence low to medium). We could not reach several regulator websites, so this is a gap rather than a clean negative. See 'unconfirmed'. - Gambling (unverified). The gaming regulator's public pages carry only land-based casino manuals. We could not obtain the remote-gaming standards that are widely believed to require gaming servers to sit in the Philippines. Treat as unknown.
Sources
- Official sourceNational Privacy CommissionNPC Advisory No. 2024-01, Model Contractual Clauses for Cross-Border Transfers of Personal Data, 30 May 2024
privacy.gov.ph
“The DPA is not a barrier to cross-border transfers of personal data.”
Link checked 18 August 2026
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Section 112 (Outsourcing) — offshore outsourcing conditions
bsp.gov.ph
“Offshore outsourcing of bank's domestic operations is permitted only when: (i) the service agreement defines counterparties' right and responsibilities on confidentiality and data privacy; and (ii) the service provider operates in jurisdictions with existing confidentiality and/or data privacy laws that are not in conflict with existing Philippine laws and relevant regulations.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionRepublic Act No. 10173, sections 23 and 24 (access by agency personnel to sensitive personal information; government contractors)
privacy.gov.ph
Link checked 18 August 2026
- Official sourceInsurance CommissionInsurance Commission circular letters (2021-2026) — reviewed, no cloud, outsourcing or storage-location issuance found
insurance.gov.ph
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
Nothing has to be approved before data leaves. There is no destination list to check, banned or approved. What you must have is a paper trail. You stay legally responsible for the data after it goes. Your supplier may only move it on your written instructions. You must declare planned overseas transfers when you register with the regulator. The regulator published a model contract in 2024. Using it is optional, and the regulator will not review your contract.
- What you have to do here:
- Put a transfer safeguard in place · Written vendor contract
- Ways to send data out:
- Nothing required · Standard contract clauses
The model is unrestricted, but you stay accountable. Republic Act No. 10173 section 21 says each company that decides how data is used is responsible for that data, including data it hands to a third party. It must use contracts or other reasonable means to give the data comparable protection. Implementing Rules section 44(b)(1) requires a supplier to act 'only upon the documented instructions of the personal information controller, including transfers of personal data to another country or an international organization, unless such transfer is authorized by law'. Implementing Rules section 47(a)(5) requires 'proposed transfers of personal data outside the Philippines' to be declared in the registration filing. NPC Advisory No. 2024-01 published model contract clauses on 30 May 2024. It is explicit that they are voluntary: 'This guidance is intended for voluntary adoption and does not impose any additional rights or duties' and 'The NPC does not require contractual parties to adopt the use of MCCs.' The Advisory also says the Commission will not accept requests to review agreements for conformity. The Philippines also takes part in cross-border privacy certification work, including the Global Cross-Border Privacy Rules arrangements and the ASEAN model contract clauses. None of that is a precondition to sending data abroad.
Sources
- Official sourceNational Privacy CommissionRepublic Act No. 10173, section 21 (principle of accountability)
privacy.gov.ph
“Each personal information controller is responsible for personal information under its control or custody, including information that have been transferred to a third party.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionImplementing Rules and Regulations of the Data Privacy Act, sections 44 and 47
privacy.gov.ph
“only upon the documented instructions of the personal information controller, including transfers of personal data to another country or an international organization, unless such transfer is authorized by law”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Advisory No. 2024-01, Model Contractual Clauses for Cross-Border Transfers
privacy.gov.ph
“This guidance is intended for voluntary adoption and does not impose any additional rights or obligations.”
Link checked 18 August 2026
What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.
The regulator, and whether it actually acts
The National Privacy Commission enforces the privacy law, and it really works. It has a serving commissioner and two deputies. It publishes decisions and orders. In late 2025 it ordered a face-scanning identity product to stop handling data in the Philippines. It has a published fine schedule that scales with company income. The central bank supervises banks and payment firms, and enforces its own technology and outsourcing rules. Treat the country as actively enforced.
- What it costs if you get it wrong:
- Percentage of global turnover · Order to stop · Criminal liability
The National Privacy Commission has been operating since 2016. It is currently led by Privacy Commissioner and Chairman Atty. Johann Carlos S. Barcena, with Deputy Privacy Commissioners Atty. Jose Amelito S. Belarmino and Atty. Juan Paolo F. Fajardo. Here is what it did in the last two years. It issued a cease and desist order in case CID CDO 25-001 against World App, dated 23 September 2025. On 8 October 2025 it announced a cease and desist order against Tools For Humanity. It issued breach-notification enforcement orders against DMCI Project Developers in April 2024, PLDT in May 2024, HSBC in August 2024 and a hospital operator in August 2024. It concluded an investigation into a reported GCash data exposure in October 2025 and found no breach. It issued new binding circulars in 2024 and 2025 on closed-circuit television and body-worn cameras. It issued new advisories in 2026 on data scraping and on breach notification. NPC Circular No. 2022-01 sets administrative fines of 0.5 to 3 percent of the previous year's annual gross income for grave infractions, and 0.25 to 2 percent for major ones. The cap is five million pesos for a single act, roughly ninety thousand United States dollars. We could not find a specific named company fined a specific peso amount under that circular on the Commission's own published pages. That is the one weak point. The Commission cannot bring criminal charges itself. It recommends prosecution to the Department of Justice. The Bangko Sentral ng Pilipinas separately supervises banks. It enforces its own outsourcing, technology-risk and incident-reporting rules, with directives and penalties on institutions, directors and officers.
Sources
- Official sourceNational Privacy CommissionNational Privacy Commission — Officials
privacy.gov.ph
“Atty. Johann Carlos S. Barcena, CESO III”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Orders — including CID CDO 25-001 (World App), 23 September 2025
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC news — cease and desist order against Tools For Humanity, 8 October 2025
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2022-01, Guidelines on Administrative Fines
privacy.gov.ph
“0.5% to 3% of the annual gross income of the immediately preceding year”
Link checked 18 August 2026
How long you must keep it — and when to delete it
The privacy law sets no fixed number of years. It says keep personal data only as long as you need it for the purpose. Then destroy it safely and be able to show how. The hard minimum periods come from other rules. Banks and other financial firms must keep records for at least five years. Money-laundering records must be kept five years after an account closes. If a money-laundering case is filed, you keep everything until the case is finished, with no end date.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Keep logs
MAXIMUM. The Data Privacy Act says personal data may be kept only as long as it is needed for the declared purpose. NPC Circular No. 2023-06 requires you to set and write down keeping periods. You must dispose of data by methods that make any further use impossible, such as degaussing, secure wiping or shredding. NPC Advisory No. 2026-01 repeats the point for scraped data. It 'shall be retained only for as long as necessary' for the declared purpose. The same circular says security logs need to be kept longer than ordinary system logs, but it fixes no number. MINIMUM. Manual of Regulations for Banks Section 172: 'Records shall be retained for a period of at least five (5) years, unless they are otherwise required by law or other regulations, or as directed by the Bangko Sentral to be retained for a longer period'. Records touching an unresolved supervisory examination issue must be kept until that issue is finally resolved. Manual of Regulations for Banks Section 924 sets more. Customer identification records must be kept as long as the account exists. Transaction records must be kept five years from the transaction. Records of closed accounts and ended relationships must be kept at least five years after closure. Where a money laundering case has been filed, records must be kept beyond five years, until the Anti-Money Laundering Council secretariat confirms the case is finally resolved. Electronic copies of covered and suspicious transaction reports must be kept at least five years from submission. HOW CONFLICTS RESOLVE. The privacy law's keeping limit gives way to another law that requires you to keep the record. Using data to comply with a legal duty is a lawful basis. So a legal minimum period beats the privacy maximum. That applies only to those records, and only for that period. Tax and company minimum periods are real and important in the Philippines. We could not confirm them from an official government source. See 'unconfirmed'.
Sources
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Sections 172 (Financial Records) and 924 (Record Keeping)
bsp.gov.ph
“Records shall be retained for a period of at least five (5) years, unless they are otherwise required by law or other regulations, or as directed by the Bangko Sentral to be retained for a longer period.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2023-06 — retention periods and secure disposal
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Advisory No. 2026-01, Guidelines on Data Scraping of Publicly Available Personal Data, 13 April 2026
privacy.gov.ph
“Personal data obtained through data scraping shall be retained only for as long as necessary”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are at least two clocks, and they are very different lengths. For personal data, you have seventy-two hours to tell the regulator and the affected people. That runs from the moment you know or reasonably believe a serious breach happened. If you are a bank or other firm supervised by the central bank, you have two hours from discovery to tell your supervisor about a major cyber incident. A fuller report follows within twenty-four hours. Everyone covered by the privacy law also files a yearly summary of all incidents, due by the thirty-first of March.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
CLOCK ONE, privacy, 72 hours. NPC Circular No. 16-03 and the Implementing Rules require you to notify the Commission and the affected people within seventy-two hours. The clock starts when you know of, or reasonably believe in, a notifiable breach. Notification is compulsory when three things are true together. The data is sensitive personal information, or information that could enable identity fraud. There is reason to believe an unauthorised person acquired it. And that is likely to give rise to a real risk of serious harm. Not being able to restore the system yet is expressly not a reason to delay. In May 2026 the Commission issued Advisory No. 2026-02. It clarified that breach notifications go through its Data Breach Notification Management System. CLOCK TWO, banking, 2 hours then 24 hours. Manual of Regulations for Banks Section 148 sets this. The compliance officer, or a designated officer, must notify the right supervising department of the central bank within two hours. The clock starts on discovering a reportable major cyber-related incident, or a disruption of financial services. The notice must state at least the nature of the incident and the system or business function involved. A fuller written report follows within twenty-four hours. A service disruption lasting more than two hours can itself be reportable. CLOCK THREE, annual. All covered organisations file an annual security incident report. It summarises every incident and breach, classified by impact on availability, integrity and confidentiality. The Commission set 31 March 2026 as the deadline for the 2025 report. The overlap is the trap. A card-data incident at a bank triggers the two-hour central bank clock, the seventy-two-hour privacy clock and the annual report. The two-hour clock starts at discovery. That is usually earlier than the point where you 'reasonably believe' the privacy test is met.
Sources
- Official sourceNational Privacy CommissionNPC Circular No. 16-03, Personal Data Breach Management
privacy.gov.ph
“inability to immediately secure or restore integrity to the information and communications system shall not be a ground for any delay”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionImplementing Rules and Regulations of the Data Privacy Act — breach notification
privacy.gov.ph
“The Commission and affected data subjects shall be notified by the personal information controller within seventy-two (72) hours upon knowledge of, or when there is reasonable belief ... that, a personal data breach requiring notification has occurred.”
Link checked 18 August 2026
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Section 148 — reporting and notification standards
bsp.gov.ph
“shall notify the appropriate supervising department of the Bangko Sentral within two (2) hours from discovery of the reportable major cyber-related incidents”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Advisory No. 2026-02, Clarification on Submission of Personal Data Breach Notification through the Data Breach Notification Management System, 11 May 2026
privacy.gov.ph
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. A child is anyone under eighteen, not thirteen or sixteen. Breaking the privacy law can put a named individual in prison, not just cost the company money. You have to register your systems with the regulator, and a foreign company has to file apostilled corporate papers to do it. Bank deposit secrecy is a separate criminal law, and a data protection contract does not fix it. And government files cannot go off site in bulk at all.
- What you have to do here:
- Get a parent's consent for children · Register or notify · Extra vendor secrecy terms
- What it costs if you get it wrong:
- Criminal liability
1. CHILDREN ARE UNDER EIGHTEEN. NPC Advisory No. 2024-03 defines a child as 'a person below eighteen (18) years of age'. It extends the definition to adults who cannot protect themselves because of a disability. If your product copied a thirteen or sixteen year old threshold from another market, you are breaking the rules by several years. The same advisory bans designs that nudge children toward choices that reduce their privacy. 2. PRISON, NOT JUST FINES. Republic Act No. 10173 carries criminal penalties. Unauthorised use of personal information carries one to three years. For sensitive personal information it is three to six years. Careless access to sensitive personal information carries three to six years. Concealing a security breach carries one and a half to five years. A combination of offences carries three to six years, with fines up to five million pesos, roughly ninety thousand United States dollars. These attach to responsible individuals. The Commission does not prosecute. It refers cases to the Department of Justice. So the timeline is a criminal one, outside the regulator's control. 3. REGISTRATION IS COMPULSORY, AND IT IS A REAL FILING. Under NPC Circular No. 2022-04 you must register if you have 250 or more employees. You must also register if you handle sensitive personal information of at least 1,000 people, or if your work is likely to pose a risk to rights and freedoms. Any system doing automated decision-making or profiling must be registered, with no size threshold at all. Registration is due within twenty days of putting the system in place, or of appointing the data protection officer. Foreign companies must supply authenticated or apostilled documents with English translations. That takes weeks. 4. BANK DEPOSIT SECRECY IS CRIMINAL AND SEPARATE. The banking rules treat disclosure of deposit information as a criminal matter, under Republic Act No. 1405 and the foreign currency deposit law, Republic Act No. 6426. That sits apart from privacy compliance. A standard data protection contract with a cloud provider does not create the depositor's written permission those laws require. The banking rules record that a person who discloses in breach of them is treated as having violated those statutes. 5. GOVERNMENT DATA CANNOT LEAVE THE BUILDING IN BULK. Republic Act No. 10173 section 23 requires the head of the agency to approve any off-site or online access by agency staff to sensitive personal information. It caps that at one thousand records. Section 24 applies the same rules to government contractors, who must also register. A contractor planning a shared-services model abroad for a government client hits this before it hits any transfer rule. 6. THE REGULATOR'S SECURITY RULES FOLLOW YOU ABROAD. NPC Circular No. 2023-06 applies by its own terms to work done 'within and outside of the Philippines'. Moving the servers abroad does not take you outside the detailed security rules.
Sources
- Official sourceNational Privacy CommissionNPC Advisory No. 2024-03, Guidelines on Child-Oriented Transparency, 17 December 2024
privacy.gov.ph
“a person below eighteen (18) years of age or those eighteen (18) or over but are unable to fully take care of themselves”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionRepublic Act No. 10173, sections 23, 24 and the penalty chapter
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2022-04 — registration thresholds and foreign entity documents
privacy.gov.ph
“A Data Processing System processing personal or sensitive personal information involving automated decision-making or profiling shall, in all instances, be registered”
Link checked 18 August 2026
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks — references to Republic Act No. 1405 and Republic Act No. 6426 deposit secrecy
bsp.gov.ph
Link checked 18 August 2026
What's changing next
Nothing forces data to stay in the Philippines in the next twelve months, as far as we can see. The regulator is the busy one. It issued new guidance on data scraping in April 2026. It changed how breaches are reported in May 2026. It was consulting in August 2026 on updated risk-assessment guidelines. A bill to strengthen the privacy law has been circulating in Congress for years and is still only a proposal. The fastest thing that can change is the regulator's power to issue binding circulars.
LANDING OR JUST LANDED, all verified on the regulator's own site: - NPC Advisory No. 2026-01, Guidelines on Data Scraping of Publicly Available Personal Data, dated 13 April 2026. It is guidance, not a binding circular. But it sets out what the Commission expects. Declare a specific purpose. Identify a lawful basis. Tell people before you scrape. Run a privacy impact assessment. Do not scrape sensitive personal information unless you can show a lawful basis and safeguards. This is the item most likely to hit artificial-intelligence training pipelines. - NPC Advisory No. 2026-02, dated 11 May 2026, moving breach notification onto the Commission's Data Breach Notification Management System. - A public consultation open in August 2026 on updated privacy impact assessment guidelines. They would replace guidance dating from 2017. - NPC Advisory No. 2024-04, issued 19 December 2024, applying the privacy law to artificial intelligence systems. Also NPC Circular No. 2025-01 on body-worn cameras. Both are already in effect. PROPOSED ONLY, NOT BINDING. Changes to Republic Act No. 10173 have been pushed since at least 2021. That year a substitute bill was approved in committee in the House of Representatives. The package would give the Commission summons, subpoena and contempt powers. It would add biometric and genetic data to the sensitive categories. It would set a digital age of consent. And it would let courts choose between imprisonment and a fine. We could not confirm from an official source what stage, if any, this has reached in the current Congress. Do not plan around it. POWERS THAT MATTER MORE THAN THE BILLS: - The Commission can issue binding circulars without new legislation. It has done so repeatedly, most recently on closed-circuit television in 2024 and body-worn cameras in 2025. A rule keeping data in the country, or restricting transfers, would need no act of Congress. It would only need publication. - NPC Circular No. 2023-06 already claims reach over work done outside the Philippines. So a future security or storage requirement could be applied to companies with no office there, on the same basis. - The central bank can order a supervised institution to end an arrangement abroad, or bring the activity back in-house. It can do that whenever it judges that customer confidentiality or its own supervisory access cannot be assured. That is a power used one institution at a time, with no notice. No published list will warn you. - Government cloud policy is set by department circular, not by statute. It can be rewritten without Congress.
Sources
- Official sourceNational Privacy CommissionNPC Advisory No. 2026-01, Guidelines on Data Scraping of Publicly Available Personal Data, 13 April 2026
privacy.gov.ph
“Data scraping involving sensitive personal information is prohibited, unless the PIC can demonstrate”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNational Privacy Commission — public consultation on updated Privacy Impact Assessment Guidelines, August 2026
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionA Stronger Data Privacy Law Sought in Proposed Amendments
privacy.gov.ph
“issue summons, subpoenas, contempt powers, and to impose administrative penalties”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC advisories index — 2026-01, 2026-02, 2025-02, 2024-04
privacy.gov.ph
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data rules (Government)
Official name: Data Privacy Act of 2012, sections 22 to 24 (security of sensitive personal information in government) · Republic Act No. 10173, sections 22-24 · Act of parliament
Government bodies and the companies that work for them cannot move sensitive personal data off site freely. Each time needs the agency head's written approval, and is limited to one thousand records. That blocks bulk handling of government files abroad. Contractors must also register with the privacy regulator.
Enforced by National Privacy Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Secure the dataAgency heads must secure sensitive personal information using the most appropriate standard recognised by the information and communications technology industry.
- Put a transfer safeguard in place — applies at: no more than 1,000 records per off-site instanceOff-site or online access by agency staff needs written approval from the head of the agency and is capped at 1,000 records.
- Register or notify — applies at: government contractors holding sensitive personal information of 1,000 or more individuals
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: PHP 4,000,000 and 6 years imprisonment — about $70 thousandUnauthorised or negligent access to sensitive personal information
Sources
- Official sourceNational Privacy CommissionRepublic Act No. 10173, sections 22, 23 and 24
privacy.gov.ph
“not more than one thousand (1,000) records”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2023-06 — security measures now covering government and private sector
privacy.gov.ph
Link checked 18 August 2026
Banking rules
Official name: Manual of Regulations for Banks, Sections 112 (Outsourcing), 148 (Information Technology Risk Management), 172 (Financial Records) and 924 (Record Keeping) · Manual of Regulations for Banks, 2022 consolidated edition · Directly binding regulation
Banks and other supervised financial firms may send work and data abroad. There are two conditions. The contract must spell out confidentiality duties. And the destination country's own confidentiality and privacy laws must not clash with Philippine law. The central bank can order the arrangement unwound at any time. Cyber incidents must be reported within two hours. Records must be kept at least five years and produced without delay.
Enforced by Bangko Sentral ng Pilipinas
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractThe service agreement must define both sides' rights and responsibilities on confidentiality and data privacy.
- Put a transfer safeguard in placeThe destination country must have confidentiality or data privacy laws that do not conflict with Philippine law. There is no published list of qualifying countries; the bank makes the assessment and the supervisor can disagree.
- Independent auditThe bank must verify the provider's security controls through third-party or internal audit, and the supervisor may demand direct access to the offshore provider.
- Report cyber incidents — within 2 hoursTwo hours from discovery to notify the supervising department, then a fuller report within 24 hours.
- Keep data for a minimum period — 5 yearsAt least five years for bank records, and five years from the transaction, or from account closure, for anti-money-laundering records. Records must be readily available without delay during examinations.
- Secure the data
What it costs if you get it wrong
- Order to stopThe supervisor may require the bank to terminate, modify or re-integrate an outsourced activity if customer confidentiality, customer redress or supervisory access cannot be assured
- Loss of your licenceEnforcement actions may limit or suspend a business activity and may be imposed on directors, officers and employees
Sources
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Section 112 — Other types of outsourcing arrangements, item (c) Offshore outsourcing
bsp.gov.ph
“Offshore outsourcing of bank's domestic operations is permitted only when: (i) the service agreement defines counterparties' right and responsibilities on confidentiality and data privacy; and (ii) the service provider operates in jurisdictions with existing confidentiality and/or data privacy laws that are not in conflict with existing Philippine laws and relevant regulations.”
Link checked 18 August 2026
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Section 924 — Record Keeping
bsp.gov.ph
“All transaction records and documents of covered persons shall be maintained and safely stored for five (5) years from the date of transaction.”
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Data Privacy Act of 2012 · Republic Act No. 10173 · Act of parliament
The general privacy law. It reaches foreign companies. It demands consent or another lawful basis. It gives people rights over their data. It does not restrict sending data abroad. Breaking it can be a crime. The regulator can fine up to three percent of last year's gross income, capped at five million pesos per act, roughly ninety thousand United States dollars.
Enforced by National Privacy Commission
How this country controls where data goes: No restriction · Accepted routes: Nothing required, Standard contract clauses
What you have to do
- Get consent
- Document a legitimate interestDetailed conditions set by NPC Circular No. 2023-07 on legitimate interest.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Let people take their data elsewhere
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Appoint a data protection officer
- Put a transfer safeguard in placeYou stay responsible after the data is transferred. You must use a contract or other reasonable means to get comparable protection. No approval is needed and there is no destination list.
- Written vendor contractA supplier may send data to another country only on your written instructions.
- Delete data after a periodKeep only as long as necessary for the declared purpose, then dispose securely.
- Get a parent's consent for children — applies at: under 18
What it costs if you get it wrong
- Criminal liability: PHP 5,000,000 and 6 years imprisonment — about $88 thousandCombination or series of acts under the Act; sensitive personal information offences carry 3 to 6 years
- Criminal liability: PHP 1,000,000 and 5 years imprisonment — about $18 thousandConcealment of a security breach involving sensitive personal information
- Percentage of global turnover: 3% of annual gross income of the preceding year, total capped at PHP 5,000,000 per act — about $88 thousandGrave infraction under NPC Circular No. 2022-01
- Order to stopCease and desist order under NPC Circular No. 20-02
Sources
- Official sourceNational Privacy CommissionRepublic Act No. 10173, Data Privacy Act of 2012
privacy.gov.ph
“Each personal information controller is responsible for personal information under its control or custody, including information that have been transferred to a third party.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionImplementing Rules and Regulations of the Data Privacy Act of 2012
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2022-01, Guidelines on Administrative Fines, 8 August 2022
privacy.gov.ph
“the total imposable fine for a single act of a PIC or PIP ... shall not exceed Five Million Pesos (Php 5,000,000.00)”
Link checked 18 August 2026
Rules for sending data abroad
Official name: Registration of Personal Data Processing System · NPC Circular No. 2022-04 · Regulator directive
Medium and larger organisations must register their systems with the regulator and name a privacy officer. So must anyone doing automated decision-making or profiling, at any size. You must declare on the form any overseas transfers you plan to make.
Enforced by National Privacy Commission
What you have to do
- Register or notify — applies at: 250 or more employees, or sensitive personal information of 1,000 or more people, or processing likely to pose a risk to rights and freedoms; automated decision-making or profiling must be registered in all casesRegister within 20 days of implementing the system or appointing the data protection officer. Foreign entities must file authenticated or apostilled corporate documents with English translations.
- Appoint a data protection officer
- Keep records of how you use data
- Put a transfer safeguard in placeProposed transfers of personal data outside the Philippines must be declared in the registration filing.
What it costs if you get it wrong
- Fixed maximum fine: PHP 200,000 — about $4 thousandFailure to register, as an 'other infraction' under NPC Circular No. 2022-01
Sources
- Official sourceNational Privacy CommissionNPC Circular No. 2022-04, Registration of Personal Data Processing System
privacy.gov.ph
“A PIC or PIP that employs two hundred fifty (250) or more persons”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionImplementing Rules and Regulations, section 47 — registration content
privacy.gov.ph
“Proposed transfers of personal data outside the Philippines”
Link checked 18 August 2026
Breach reporting rules
Official name: Personal Data Breach Management · NPC Circular No. 16-03 · Regulator directive
You have seventy-two hours from knowing or reasonably believing a serious breach happened to tell both the regulator and the people affected. Everyone also files a yearly summary of all incidents, and hiding a breach of sensitive data is a crime.
Enforced by National Privacy Commission
What you have to do
- Report breaches to the regulator — within 72 hoursClock starts on knowledge of, or reasonable belief in, a notifiable breach. Being unable to restore the system is not a ground for delay.
- Tell affected people — within 72 hours
- Keep records of how you use dataAnnual security incident report summarising all incidents and breaches. The 2025 report was due 31 March 2026.
- Secure the data
What it costs if you get it wrong
- Percentage of global turnover: 2% of annual gross income, or 3% where more than 1,000 people are affectedFailure to notify a personal data breach
- Criminal liability: PHP 1,000,000 and 5 years imprisonment — about $18 thousandConcealing a breach involving sensitive personal information
Sources
- Official sourceNational Privacy CommissionNPC Circular No. 16-03, Personal Data Breach Management
privacy.gov.ph
“inability to immediately secure or restore integrity to the information and communications system shall not be a ground for any delay”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Advisory No. 2026-02 on breach notification through the Data Breach Notification Management System, 11 May 2026
privacy.gov.ph
Link checked 18 August 2026
Government data rules
Official name: Security of Personal Data in Government and Private Sector · NPC Circular No. 2023-06 · Regulator directive
The regulator's detailed security rulebook. It replaces the older government-only version from 2016 and now covers private companies too. By its own terms it applies to work done outside the Philippines. Moving the servers abroad does not take you out of it.
Enforced by National Privacy Commission
What you have to do
- Secure the dataMulti-factor authentication for online access to sensitive information; encryption for removable media; no fax for documents containing personal data.
- Keep logsSecurity logs are to be kept longer than ordinary system logs. No fixed number of months is set.
- Delete data after a periodYou must set and write down keeping periods. Disposal must make any further use of the data impossible.
- Keep records of how you use data
What it costs if you get it wrong
- Percentage of global turnover: up to 3% of annual gross income, capped at PHP 5,000,000 per act — about $88 thousandFailure to implement reasonable and appropriate security measures
Sources
- Official sourceNational Privacy CommissionNPC Circular No. 2023-06, signed 1 December 2023
privacy.gov.ph
“This Circular expressly repeals NPC Circular No. 16-01.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC circulars index
privacy.gov.ph
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether the Philippine government's Cloud First Policy restricts where government data may be hosted
We could not confirm the current department circular on government cloud from the Department of Information and Communications Technology. A policy of this kind is widely reported to classify government data and to steer sensitive classifications to a government cloud. We will not state that without the department's own text. If you do government work, read the current circular directly.
Whether licensed online gaming operators must keep gaming servers and player data inside the Philippines
We could not confirm the remote-gaming standards. The gaming regulator's public pages publish only land-based casino manuals. Its remote-gaming and electronic-gaming standards pages carried no documents when checked on 18 August 2026. If you run online gaming, check with the regulator.
Sector rules for securities firms, hospitals, telecommunications companies and mapping or geospatial data
We could not confirm storage-location rules against the securities regulator, the health department, the telecommunications regulator, the statistics authority or the official gazette. We found no evidence that such rules exist. This is an unchecked gap, not a confirmed clear. If you work in these industries, check before you rely on it.
The tax and company-law minimum retention periods, commonly stated as ten years for books of accounts
We could not confirm the tax record-keeping period against an official source. Treat the ten-year figure as unverified. Check with the tax bureau before you rely on it.
Current status in Congress of the bills amending the Data Privacy Act
We could not confirm the current standing of the proposed amendments. The only official material we could reach is a regulator news item from 2021, describing a committee-approved substitute bill. The amendments may have advanced, lapsed or been refiled since. Treat the whole package as proposed, with unknown standing.
Whether the National Privacy Commission has actually collected an administrative fine under its 2022 fine schedule
The published decisions and orders we could read describe damages and cease and desist orders, not named peso fines. The power to fine plainly exists. We could not confirm any record of fines actually collected on the regulator's own pages.
That the 2022 consolidated Manual of Regulations for Banks is the current text of the banking rules
This is the consolidated edition the central bank publishes for download. The Manual is amended continuously by circulars, and we could not confirm the full list of those circulars. Later ones may have changed the outsourcing, incident-reporting or record-keeping sections.
The exact commencement date of the Data Privacy Act and of several regulator circulars
The Act and the circulars all take effect fifteen days after publication in newspapers, and the publication dates are not stated in the texts we could read. Only the signing dates are recorded here.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.