Skip to the content
Global Data RulesData governance rules, country by country

Philippines

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in the Philippines — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

The Philippines does not force data to stay in the country. Its privacy law lets data go abroad with no permit and no approved-country list. Instead you stay responsible for the data after it leaves. You must also register your systems with the regulator and name a privacy officer. Get it badly wrong and a person can go to prison. Banks and government bodies face extra conditions.

Data governance in the Philippines

The eight things that decide how you handle data about people in the Philippines. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office in the Philippines. It applies if you use or store data about Philippine citizens or residents. It also applies if you use equipment in the country, or if you have enough of a link to it, such as carrying on business there. There is no revenue floor and no company-size floor that lets you out. There is no formal 'local representative' role. But you must name a data protection officer and register with the regulator. Foreign companies must file apostilled corporate papers to do that.

What you have to do here:
Appoint a data protection officer · Register or notify

Where the data is allowed to live

In general, yes, and easily. The privacy law has no rule keeping data in the country. There is no list of approved or banned destinations. There is no permit to apply for. The regulator has said in writing that the law is not a barrier to sending data abroad. Two industries change that answer. Banks and other firms the central bank supervises may only send work abroad if the destination country has confidentiality and privacy laws that do not clash with Philippine law. Government bodies and their contractors cannot take sensitive personal data off site in bulk at all.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

Nothing has to be approved before data leaves. There is no destination list to check, banned or approved. What you must have is a paper trail. You stay legally responsible for the data after it goes. Your supplier may only move it on your written instructions. You must declare planned overseas transfers when you register with the regulator. The regulator published a model contract in 2024. Using it is optional, and the regulator will not review your contract.

What you have to do here:
Put a transfer safeguard in place · Written vendor contract
Ways to send data out:
Nothing required · Standard contract clauses

What to do: Get the approved standard contract clauses signed with every vendor that touches this data, before it leaves.

The regulator, and whether it actually acts

The National Privacy Commission enforces the privacy law, and it really works. It has a serving commissioner and two deputies. It publishes decisions and orders. In late 2025 it ordered a face-scanning identity product to stop handling data in the Philippines. It has a published fine schedule that scales with company income. The central bank supervises banks and payment firms, and enforces its own technology and outsourcing rules. Treat the country as actively enforced.

What it costs if you get it wrong:
Percentage of global turnover · Order to stop · Criminal liability

How long you must keep it — and when to delete it

The privacy law sets no fixed number of years. It says keep personal data only as long as you need it for the purpose. Then destroy it safely and be able to show how. The hard minimum periods come from other rules. Banks and other financial firms must keep records for at least five years. Money-laundering records must be kept five years after an account closes. If a money-laundering case is filed, you keep everything until the case is finished, with no end date.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are at least two clocks, and they are very different lengths. For personal data, you have seventy-two hours to tell the regulator and the affected people. That runs from the moment you know or reasonably believe a serious breach happened. If you are a bank or other firm supervised by the central bank, you have two hours from discovery to tell your supervisor about a major cyber incident. A fuller report follows within twenty-four hours. Everyone covered by the privacy law also files a yearly summary of all incidents, due by the thirty-first of March.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. A child is anyone under eighteen, not thirteen or sixteen. Breaking the privacy law can put a named individual in prison, not just cost the company money. You have to register your systems with the regulator, and a foreign company has to file apostilled corporate papers to do it. Bank deposit secrecy is a separate criminal law, and a data protection contract does not fix it. And government files cannot go off site in bulk at all.

What you have to do here:
Get a parent's consent for children · Register or notify · Extra vendor secrecy terms
What it costs if you get it wrong:
Criminal liability

What's changing next

Nothing forces data to stay in the Philippines in the next twelve months, as far as we can see. The regulator is the busy one. It issued new guidance on data scraping in April 2026. It changed how breaches are reported in May 2026. It was consulting in August 2026 on updated risk-assessment guidelines. A bill to strengthen the privacy law has been circulating in Congress for years and is still only a proposal. The fastest thing that can change is the regulator's power to issue binding circulars.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data rules (Government)

Official name: Data Privacy Act of 2012, sections 22 to 24 (security of sensitive personal information in government) · Republic Act No. 10173, sections 22-24 · Act of parliament

In forceYes, with paperwork

Government bodies and the companies that work for them cannot move sensitive personal data off site freely. Each time needs the agency head's written approval, and is limited to one thousand records. That blocks bulk handling of government files abroad. Contractors must also register with the privacy regulator.

Enforced by National Privacy Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Banking rules

Official name: Manual of Regulations for Banks, Sections 112 (Outsourcing), 148 (Information Technology Risk Management), 172 (Financial Records) and 924 (Record Keeping) · Manual of Regulations for Banks, 2022 consolidated edition · Directly binding regulation

In forceYes, with paperwork

Banks and other supervised financial firms may send work and data abroad. There are two conditions. The contract must spell out confidentiality duties. And the destination country's own confidentiality and privacy laws must not clash with Philippine law. The central bank can order the arrangement unwound at any time. Cyber incidents must be reported within two hours. Records must be kept at least five years and produced without delay.

Enforced by Bangko Sentral ng Pilipinas

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Data Privacy Act of 2012 · Republic Act No. 10173 · Act of parliament

In forceYes — store it anywhere

The general privacy law. It reaches foreign companies. It demands consent or another lawful basis. It gives people rights over their data. It does not restrict sending data abroad. Breaking it can be a crime. The regulator can fine up to three percent of last year's gross income, capped at five million pesos per act, roughly ninety thousand United States dollars.

Enforced by National Privacy Commission

How this country controls where data goes: No restriction · Accepted routes: Nothing required, Standard contract clauses

Rules for sending data abroad

Official name: Registration of Personal Data Processing System · NPC Circular No. 2022-04 · Regulator directive

In forceYes — store it anywhere

Medium and larger organisations must register their systems with the regulator and name a privacy officer. So must anyone doing automated decision-making or profiling, at any size. You must declare on the form any overseas transfers you plan to make.

Enforced by National Privacy Commission

Breach reporting rules

Official name: Personal Data Breach Management · NPC Circular No. 16-03 · Regulator directive

In forceYes — store it anywhere

You have seventy-two hours from knowing or reasonably believing a serious breach happened to tell both the regulator and the people affected. Everyone also files a yearly summary of all incidents, and hiding a breach of sensitive data is a crime.

Enforced by National Privacy Commission

Who you would hear from

  • National Privacy Commission (Pambansang Komisyon sa Pagkapribado)

    General privacy law: enforcement, registration, breach notification, binding circulars and advisories

    Fully staffed and active. Led as of 18 August 2026 by Privacy Commissioner and Chairman Atty. Johann Carlos S. Barcena with two deputy commissioners. Issues binding circulars, publishes decisions and orders, and issued cease and desist orders in September and October 2025. Has a published fine schedule of up to 3 percent of annual gross income. But we could not confirm any named company fined a specific amount from its own published pages.

  • Bangko Sentral ng Pilipinas

    Banks, quasi-banks, electronic money issuers and payment systems: outsourcing, technology risk, incident reporting, record keeping

    Long-established financial supervisor. It runs a two-hour cyber incident reporting rule, examines institutions on site, and can order outsourcing arrangements ended or brought back in-house.

  • Insurance Commission

    Insurance and pre-need companies, health maintenance organisations

    Actively issuing circular letters through 2026. But on 18 August 2026 we found none on cloud, outsourcing, data storage location or data privacy. That covers its published list for 2021 to 2026. Insurers appear to fall back on the general privacy law.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether the Philippine government's Cloud First Policy restricts where government data may be hosted

    We could not confirm the current department circular on government cloud from the Department of Information and Communications Technology. A policy of this kind is widely reported to classify government data and to steer sensitive classifications to a government cloud. We will not state that without the department's own text. If you do government work, read the current circular directly.

  • Whether licensed online gaming operators must keep gaming servers and player data inside the Philippines

    We could not confirm the remote-gaming standards. The gaming regulator's public pages publish only land-based casino manuals. Its remote-gaming and electronic-gaming standards pages carried no documents when checked on 18 August 2026. If you run online gaming, check with the regulator.

  • Sector rules for securities firms, hospitals, telecommunications companies and mapping or geospatial data

    We could not confirm storage-location rules against the securities regulator, the health department, the telecommunications regulator, the statistics authority or the official gazette. We found no evidence that such rules exist. This is an unchecked gap, not a confirmed clear. If you work in these industries, check before you rely on it.

  • The tax and company-law minimum retention periods, commonly stated as ten years for books of accounts

    We could not confirm the tax record-keeping period against an official source. Treat the ten-year figure as unverified. Check with the tax bureau before you rely on it.

  • Current status in Congress of the bills amending the Data Privacy Act

    We could not confirm the current standing of the proposed amendments. The only official material we could reach is a regulator news item from 2021, describing a committee-approved substitute bill. The amendments may have advanced, lapsed or been refiled since. Treat the whole package as proposed, with unknown standing.

  • Whether the National Privacy Commission has actually collected an administrative fine under its 2022 fine schedule

    The published decisions and orders we could read describe damages and cease and desist orders, not named peso fines. The power to fine plainly exists. We could not confirm any record of fines actually collected on the regulator's own pages.

  • That the 2022 consolidated Manual of Regulations for Banks is the current text of the banking rules

    This is the consolidated edition the central bank publishes for download. The Manual is amended continuously by circulars, and we could not confirm the full list of those circulars. Later ones may have changed the outsourcing, incident-reporting or record-keeping sections.

  • The exact commencement date of the Data Privacy Act and of several regulator circulars

    The Act and the circulars all take effect fifteen days after publication in newspapers, and the publication dates are not stated in the texts we could read. Only the signing dates are recorded here.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.