Philippines
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
The Philippines does not force data to stay in the country. Its privacy law lets data go abroad with no permit and no approved-country list. Instead it makes you stay responsible for the data after it leaves, register your systems with the regulator, and name a privacy officer. Get it badly wrong and a person can go to prison. Banks and government bodies face extra conditions.
Data governance in the Philippines
The eight things that decide how you handle data about people in the Philippines. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office in the Philippines. It applies if you process data about Philippine citizens or residents, if you use equipment in the country, or if you have enough of a link to the country such as carrying on business there. There is no revenue floor and no company-size floor that lets you out. There is no formal 'local representative' role, but in practice you must name a data protection officer and register with the regulator, and foreign companies must file apostilled corporate papers to do it.
Republic Act No. 10173 (the Data Privacy Act of 2012) section 4 covers processing by any natural or juridical person, including those outside the Philippines who use equipment located in the country or maintain an office, branch or agency there. Section 6 extends the Act to acts done outside the Philippines where the information concerns Philippine citizens or residents, where a contract is entered into in the Philippines, or where the entity carries on business in the Philippines. The regulator has taken the same line in its own rules: NPC Circular No. 2023-06 states in its scope clause that it applies to all natural or juridical persons engaged in the processing of personal data 'within and outside of the Philippines'. The 250-employee figure that appears in the Implementing Rules is not an exemption from the law; it is only a threshold in the registration rules, and it is disapplied where the processing is likely to pose a risk to rights and freedoms or involves sensitive personal information of at least 1,000 people. NPC Circular No. 2022-04 sets out a specific document list for foreign private entities registering: authenticated or apostilled secretary's certificate appointing the data protection officer, general information sheet or equivalent, registration certificate and business permit, with English translations.
Sources
- Official sourceNational Privacy CommissionRepublic Act No. 10173, Data Privacy Act of 2012, sections 4 and 6
privacy.gov.ph
“This Act applies to an act done or practice engaged in and outside of the Philippines by an entity if ... the entity has other links in the Philippines”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2023-06, Security of Personal Data in Government and Private Sector, scope clause
privacy.gov.ph
“This Circular shall apply to all natural or juridical persons engaged in the processing of personal data within and outside of the Philippines”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2022-04, Registration of Personal Data Processing System
privacy.gov.ph
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, and easily. The privacy law has no rule that keeps data in the country, no list of approved or banned destinations, and no permit to apply for. The regulator has said in writing that the law is not a barrier to sending data abroad. Two sectors change that answer. Banks and other firms the central bank supervises may only send work offshore if the destination country has confidentiality and privacy laws that do not clash with Philippine law. Government bodies and their contractors cannot take sensitive personal data off site in bulk at all.
General regime: open (data can be stored anywhere). Nothing in Republic Act No. 10173 or its Implementing Rules restricts transfer abroad. The only transfer-specific obligations are that the controller stays accountable for data it hands to anyone else, that a processor may transfer to another country only on the controller's documented instructions, and that proposed transfers outside the Philippines must be disclosed when registering a processing system. SECTOR OVERRIDES CHECKED ON 18 AUGUST 2026: - Banking and other supervised financial institutions (data can leave with paperwork). The Manual of Regulations for Banks, Section 112, permits offshore outsourcing of a bank's domestic operations only on two conditions, and the central bank may order the bank to terminate, modify or bring the activity back in-house if customer confidentiality, customer redress or the supervisor's ability to supervise cannot be assured. A local subsidiary of a foreign bank may use its parent group offshore without prior approval, but stays principally liable to customers for the offshore provider's errors and fraud. - Payments and e-money (data can leave with paperwork). Same Manual applies; the technology risk framework expressly extends to institutions with offshore data processing. - Government and public sector (data can leave with paperwork, in practice a wall for bulk work). Republic Act No. 10173 section 23 requires the head of the agency to approve any off-site or online access to sensitive personal information by agency staff, and caps it at 1,000 records. Section 24 pulls government contractors into the same regime and requires them to register. NPC Circular No. 2023-06 adds detailed security duties on top. - Insurance (no override found). We reviewed the Insurance Commission's published circular letters for 2021 to 2026 on 18 August 2026 and found no issuance on cloud, outsourcing, storage location or data privacy. No rule found; confidence medium. - Securities and markets, health, telecoms, education, mapping and geospatial, defence (no override found, checked 18 August 2026, confidence low to medium). We could not reach several regulator websites from this session, so this is a gap rather than a clean negative. See 'unconfirmed'. - Gambling (unverified). The gaming regulator's public regulatory pages carry only land-based casino manuals; we could not obtain the remote-gaming standards that are widely believed to require gaming servers to sit in the Philippines. Treat as unknown.
Sources
- Official sourceNational Privacy CommissionNPC Advisory No. 2024-01, Model Contractual Clauses for Cross-Border Transfers of Personal Data, 30 May 2024
privacy.gov.ph
“The DPA is not a barrier to cross-border transfers of personal data.”
Link checked 18 August 2026
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Section 112 (Outsourcing) — offshore outsourcing conditions
bsp.gov.ph
“Offshore outsourcing of bank's domestic operations is permitted only when: (i) the service agreement defines counterparties' right and responsibilities on confidentiality and data privacy; and (ii) the service provider operates in jurisdictions with existing confidentiality and/or data privacy laws that are not in conflict with existing Philippine laws and relevant regulations.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionRepublic Act No. 10173, sections 23 and 24 (access by agency personnel to sensitive personal information; government contractors)
privacy.gov.ph
Link checked 18 August 2026
- Official sourceInsurance CommissionInsurance Commission circular letters (2021-2026) — reviewed, no cloud, outsourcing or storage-location issuance found
insurance.gov.ph
Link checked 18 August 2026
Sending data out of the country
Nothing has to be approved before data leaves. There is no destination list to check, either of banned or of blessed countries, so the list question does not arise. What you must have is a paper trail: you stay legally responsible for the data after it goes, your supplier may only move it on your written instructions, and you have to declare planned overseas transfers when you register with the regulator. The regulator published a model contract in 2024, but using it is optional and it will not review your contract.
The model is best described as unrestricted with accountability. Republic Act No. 10173 section 21 states that each personal information controller is responsible for personal information under its control or custody, including information transferred to a third party, and must use contractual or other reasonable means to give it a comparable level of protection. Implementing Rules section 44(b)(1) requires a processor to act 'only upon the documented instructions of the personal information controller, including transfers of personal data to another country or an international organization, unless such transfer is authorized by law'. Implementing Rules section 47(a)(5) requires 'proposed transfers of personal data outside the Philippines' to be declared in the registration filing. NPC Advisory No. 2024-01 published model contractual clauses on 30 May 2024 and is explicit that they are voluntary: 'This guidance is intended for voluntary adoption and does not impose any additional rights or obligations' and 'The NPC does not require contractual parties to adopt the use of MCCs.' The Advisory also states that the Commission will not accept requests to review agreements for conformity. The Philippines also participates in cross-border privacy certification work, including the Global Cross-Border Privacy Rules arrangements and the ASEAN model contractual clauses, but none of that is a precondition to transfer.
Sources
- Official sourceNational Privacy CommissionRepublic Act No. 10173, section 21 (principle of accountability)
privacy.gov.ph
“Each personal information controller is responsible for personal information under its control or custody, including information that have been transferred to a third party.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionImplementing Rules and Regulations of the Data Privacy Act, sections 44 and 47
privacy.gov.ph
“only upon the documented instructions of the personal information controller, including transfers of personal data to another country or an international organization, unless such transfer is authorized by law”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Advisory No. 2024-01, Model Contractual Clauses for Cross-Border Transfers
privacy.gov.ph
“This guidance is intended for voluntary adoption and does not impose any additional rights or obligations.”
Link checked 18 August 2026
The regulator, and whether it actually acts
The National Privacy Commission enforces the privacy law, and it is genuinely working. It has a serving commissioner and two deputies, it publishes decisions and orders, and it ordered a face-scanning identity product to stop processing data in the Philippines in late 2025. It has a published fine schedule that scales with company income. The central bank supervises banks and payment firms and enforces its own technology and outsourcing rules. Rate the country as actively enforced, not dormant.
The National Privacy Commission has been operating since 2016 and is currently led by Privacy Commissioner and Chairman Atty. Johann Carlos S. Barcena, with Deputy Privacy Commissioners Atty. Jose Amelito S. Belarmino and Atty. Juan Paolo F. Fajardo. Observable evidence of activity in the last two years: a cease and desist order in case CID CDO 25-001 against World App, dated 23 September 2025, and a public announcement on 8 October 2025 of a cease and desist order against Tools For Humanity; breach-notification enforcement orders against DMCI Project Developers (April 2024), PLDT (May 2024), HSBC (August 2024) and a hospital operator (August 2024); a concluded investigation into a reported GCash data exposure in October 2025 that found no breach; new binding circulars in 2024 and 2025 on closed-circuit television and body-worn cameras; and new advisories in 2026 on data scraping and on breach notification. NPC Circular No. 2022-01 sets administrative fines of 0.5 to 3 percent of the previous year's annual gross income for grave infractions and 0.25 to 2 percent for major ones, capped at five million pesos for a single act, roughly ninety thousand United States dollars. We could not evidence a specific named company being fined a specific peso amount under that circular from the Commission's own published pages, so the monetary-fine track record is the one weak point in the picture. Criminal prosecution is not the Commission's to bring: it recommends prosecution to the Department of Justice. The Bangko Sentral ng Pilipinas separately supervises banks and enforces its own outsourcing, technology-risk and incident-reporting rules with directives and sanctions on institutions, directors and officers.
Sources
- Official sourceNational Privacy CommissionNational Privacy Commission — Officials
privacy.gov.ph
“Atty. Johann Carlos S. Barcena, CESO III”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Orders — including CID CDO 25-001 (World App), 23 September 2025
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC news — cease and desist order against Tools For Humanity, 8 October 2025
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2022-01, Guidelines on Administrative Fines
privacy.gov.ph
“0.5% to 3% of the annual gross income of the immediately preceding year”
Link checked 18 August 2026
How long you must keep it — and when to delete it
The privacy law sets no fixed number of years. It says keep personal data only as long as you need it for the purpose, then destroy it safely and be able to show how. The hard minimum periods come from other rules. Banks and other financial firms must keep records for at least five years, and money-laundering records for five years after an account closes. If a money-laundering case is filed, you keep everything until the case is finished, with no end date.
CEILING. The Data Privacy Act's storage limitation principle requires personal data to be kept only for as long as necessary for the declared purpose, and NPC Circular No. 2023-06 requires organisations to establish and document retention periods and to dispose of data by methods that make further processing impossible, such as degaussing, secure wiping or shredding. NPC Advisory No. 2026-01 repeats the point for scraped data: it 'shall be retained only for as long as necessary' for the declared purpose. The same circular treats security logs as needing longer retention than ordinary system logs but does not fix a number. FLOOR. Manual of Regulations for Banks Section 172: 'Records shall be retained for a period of at least five (5) years, unless they are otherwise required by law or other regulations, or as directed by the Bangko Sentral to be retained for a longer period', and records touching an unresolved supervisory examination issue must be preserved until that issue is finally resolved. Manual of Regulations for Banks Section 924: customer identification records must be kept as long as the account exists; transaction records for five years from the transaction; records of closed accounts and terminated relationships for at least five years after closure; and where a money laundering case has been filed, records must be kept beyond five years until the Anti-Money Laundering Council secretariat confirms the case is finally resolved. Electronic copies of covered and suspicious transaction reports must be kept at least five years from submission. HOW CONFLICTS RESOLVE. The privacy law's storage limit yields to another law that requires keeping the record. Processing to comply with a legal obligation is a lawful basis, so a statutory minimum period beats the privacy ceiling for the records it covers, but only for those records and only for that period. Tax and corporate minimum periods are real and material in the Philippines, but we could not verify them from an official government source in this session; see 'unconfirmed'.
Sources
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Sections 172 (Financial Records) and 924 (Record Keeping)
bsp.gov.ph
“Records shall be retained for a period of at least five (5) years, unless they are otherwise required by law or other regulations, or as directed by the Bangko Sentral to be retained for a longer period.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2023-06 — retention periods and secure disposal
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Advisory No. 2026-01, Guidelines on Data Scraping of Publicly Available Personal Data, 13 April 2026
privacy.gov.ph
“Personal data obtained through data scraping shall be retained only for as long as necessary”
Link checked 18 August 2026
If something goes wrong
There are at least two clocks and they are very different lengths. For personal data, you have seventy-two hours from the moment you know or reasonably believe a serious breach happened to tell the regulator and the affected people. If you are a bank or other firm supervised by the central bank, you have two hours from discovery to tell your supervisor about a major cyber incident, then a fuller report within twenty-four hours. Everyone covered by the privacy law also files a yearly summary of all incidents, due by the thirty-first of March.
CLOCK ONE, privacy, 72 hours. NPC Circular No. 16-03 and the Implementing Rules require the Commission and affected data subjects to be notified within seventy-two hours upon knowledge of, or reasonable belief of, a notifiable breach. Notification is mandatory when three things are true together: the data is sensitive personal information or information that could enable identity fraud; there is reason to believe an unauthorised person acquired it; and the acquisition is likely to give rise to a real risk of serious harm. Not being able to restore the system yet is expressly not a ground for delay. In May 2026 the Commission issued Advisory No. 2026-02 clarifying that breach notifications go through its Data Breach Notification Management System. CLOCK TWO, banking, 2 hours then 24 hours. Manual of Regulations for Banks Section 148 requires the compliance officer or designated officer to notify the appropriate supervising department of the central bank within two hours from discovery of a reportable major cyber-related incident or a disruption of financial services, disclosing at minimum the nature of the incident and the system or business function involved, followed by a fuller written report within twenty-four hours. A service disruption lasting more than two hours can itself be reportable. CLOCK THREE, annual. All covered organisations file an annual security incident report summarising every incident and breach, classified by impact on availability, integrity and confidentiality. The Commission set 31 March 2026 as the deadline for the 2025 report. The overlap is the operational trap: a card-data incident at a bank triggers the two-hour central bank clock, the seventy-two-hour privacy clock and the annual report, and the two-hour clock starts at discovery, which is usually earlier than the point at which you 'reasonably believe' the privacy test is met.
Sources
- Official sourceNational Privacy CommissionNPC Circular No. 16-03, Personal Data Breach Management
privacy.gov.ph
“inability to immediately secure or restore integrity to the information and communications system shall not be a ground for any delay”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionImplementing Rules and Regulations of the Data Privacy Act — breach notification
privacy.gov.ph
“The Commission and affected data subjects shall be notified by the personal information controller within seventy-two (72) hours upon knowledge of, or when there is reasonable belief ... that, a personal data breach requiring notification has occurred.”
Link checked 18 August 2026
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Section 148 — reporting and notification standards
bsp.gov.ph
“shall notify the appropriate supervising department of the Bangko Sentral within two (2) hours from discovery of the reportable major cyber-related incidents”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Advisory No. 2026-02, Clarification on Submission of Personal Data Breach Notification through the Data Breach Notification Management System, 11 May 2026
privacy.gov.ph
Link checked 18 August 2026
What catches people out
Five things catch people out. A child is anyone under eighteen, not thirteen or sixteen. Breaking the privacy law can put a named individual in prison, not just cost the company money. You have to register your processing systems with the regulator, and a foreign company has to file apostilled corporate papers to do it. Bank deposit secrecy is a separate criminal law that a data-processing contract does not fix. And government files cannot go off site in bulk at all.
1. CHILDREN ARE UNDER EIGHTEEN. NPC Advisory No. 2024-03 defines a child as 'a person below eighteen (18) years of age' and extends the definition to adults unable to protect themselves because of a disability. Product teams that copied a thirteen or sixteen year old threshold from another market are non-compliant by several years. The same advisory bans design patterns that nudge children toward privacy-reducing choices. 2. PRISON, NOT JUST FINES. Republic Act No. 10173 carries criminal penalties: one to three years for unauthorised processing of personal information, three to six years for sensitive personal information, three to six years for negligent access to sensitive personal information, one and a half to five years for concealing a security breach, and three to six years with fines up to five million pesos, roughly ninety thousand United States dollars, for a combination of offences. These attach to responsible individuals. The Commission does not prosecute; it refers cases to the Department of Justice, which means the timeline is a criminal one and outside the regulator's control. 3. REGISTRATION IS COMPULSORY AND IT IS A FILING, NOT A TICK-BOX. Under NPC Circular No. 2022-04 you must register if you have 250 or more employees, or process sensitive personal information of at least 1,000 people, or your processing is likely to pose a risk to rights and freedoms. Any system doing automated decision-making or profiling must be registered in all cases, with no size threshold at all. Registration is due within twenty days of implementing the system or appointing the data protection officer. Foreign entities must supply authenticated or apostilled documents with English translations, which takes weeks. 4. BANK DEPOSIT SECRECY IS CRIMINAL AND SEPARATE. The banking rules treat disclosure of deposit information under Republic Act No. 1405 and the foreign currency deposit law, Republic Act No. 6426, as a criminal matter distinct from privacy compliance. A standard data processing agreement with a cloud provider does not create the depositor's written permission those laws require, and the banking rules record that a person who discloses in breach of them is deemed to have violated those statutes. 5. GOVERNMENT DATA CANNOT LEAVE THE BUILDING IN BULK. Republic Act No. 10173 section 23 requires the head of the agency to approve any off-site or online access by agency staff to sensitive personal information and caps it at one thousand records. Section 24 applies the same regime to government contractors, who must also register. A contractor planning an offshore shared-services model for a government client runs into this before it runs into any transfer rule. 6. THE REGULATOR'S SECURITY RULES FOLLOW YOU ABROAD. NPC Circular No. 2023-06 applies by its own terms to processing 'within and outside of the Philippines', so an offshore processor is not outside the detailed security regime just because the servers are.
Sources
- Official sourceNational Privacy CommissionNPC Advisory No. 2024-03, Guidelines on Child-Oriented Transparency, 17 December 2024
privacy.gov.ph
“a person below eighteen (18) years of age or those eighteen (18) or over but are unable to fully take care of themselves”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionRepublic Act No. 10173, sections 23, 24 and the penalty chapter
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2022-04 — registration thresholds and foreign entity documents
privacy.gov.ph
“A Data Processing System processing personal or sensitive personal information involving automated decision-making or profiling shall, in all instances, be registered”
Link checked 18 August 2026
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks — references to Republic Act No. 1405 and Republic Act No. 6426 deposit secrecy
bsp.gov.ph
Link checked 18 August 2026
What's changing next
Nothing forces data to stay in the Philippines in the next twelve months, as far as we can see. The regulator is the busy one: it issued new guidance on data scraping in April 2026, changed how breaches are reported in May 2026, and was consulting in August 2026 on updated risk-assessment guidelines. A bill to strengthen the privacy law has been circulating in Congress for years and is still only a proposal. Treat the regulator's power to issue binding circulars as the switch that can flip fastest.
LANDING OR JUST LANDED, all verified on the regulator's own site: - NPC Advisory No. 2026-01, Guidelines on Data Scraping of Publicly Available Personal Data, dated 13 April 2026. Guidance rather than a binding circular, but it sets the Commission's expectations: declare a specific purpose, identify a lawful basis, tell people before you scrape, run a privacy impact assessment, and do not scrape sensitive personal information unless you can demonstrate a lawful basis and safeguards. This is the item most likely to bite artificial-intelligence training pipelines. - NPC Advisory No. 2026-02, dated 11 May 2026, moving breach notification onto the Commission's Data Breach Notification Management System. - A public consultation open in August 2026 on updated privacy impact assessment guidelines, which would replace guidance dating from 2017. - NPC Advisory No. 2024-04, issued 19 December 2024, applying the privacy law to artificial intelligence systems, and NPC Circular No. 2025-01 on body-worn cameras, both already in effect. PROPOSED ONLY, NOT BINDING. Amendments to Republic Act No. 10173 have been pushed since at least 2021, when a substitute bill was approved in committee in the House of Representatives. The package would give the Commission summons, subpoena and contempt powers, add biometric and genetic data to the sensitive categories, set a digital age of consent, and let courts choose between imprisonment and a fine. We could not confirm from an official source what stage, if any, this has reached in the current Congress. Do not plan around it. DORMANT SWITCHES, the ones that matter more than the bills: - The Commission can issue binding circulars without primary legislation. It has done so repeatedly, most recently on closed-circuit television in 2024 and body-worn cameras in 2025. A localisation or transfer-restriction circular would need no act of Congress, only publication. - NPC Circular No. 2023-06 already asserts reach over processing outside the Philippines, so a future security or storage requirement could be applied extraterritorially on the same basis. - The central bank can order a supervised institution to terminate an offshore arrangement or bring the activity back in-house whenever it judges that customer confidentiality or its own supervisory access cannot be assured. That is a per-institution, no-notice power that no published list will warn you about. - Government cloud policy is set by department circular, not statute, and can be rewritten administratively.
Sources
- Official sourceNational Privacy CommissionNPC Advisory No. 2026-01, Guidelines on Data Scraping of Publicly Available Personal Data, 13 April 2026
privacy.gov.ph
“Data scraping involving sensitive personal information is prohibited, unless the PIC can demonstrate”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNational Privacy Commission — public consultation on updated Privacy Impact Assessment Guidelines, August 2026
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionA Stronger Data Privacy Law Sought in Proposed Amendments
privacy.gov.ph
“issue summons, subpoenas, contempt powers, and to impose administrative penalties”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC advisories index — 2026-01, 2026-02, 2025-02, 2024-04
privacy.gov.ph
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Data Privacy Act of 2012, sections 22 to 24 (security of sensitive personal information in government)
Act of parliament · Republic Act No. 10173, sections 22-24
Government bodies and the companies that work for them cannot move sensitive personal data off site freely. Each instance needs the agency head's written approval and is limited to one thousand records, which in practice blocks bulk offshore processing of government files. Contractors must also register with the privacy regulator.
Enforced by National Privacy Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Secure the dataAgency heads must secure sensitive personal information using the most appropriate standard recognised by the information and communications technology industry.
- Put a transfer safeguard in place — applies at: no more than 1,000 records per off-site instanceOff-site or online access by agency staff needs written approval from the head of the agency and is capped at 1,000 records.
- Register or notify — applies at: government contractors holding sensitive personal information of 1,000 or more individuals
- Written vendor contract
What it costs if you get it wrong
- Criminal liability: PHP 4,000,000 and 6 years imprisonment — about $70 thousandUnauthorised or negligent access to sensitive personal information
Sources
- Official sourceNational Privacy CommissionRepublic Act No. 10173, sections 22, 23 and 24
privacy.gov.ph
“not more than one thousand (1,000) records”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2023-06 — security measures now covering government and private sector
privacy.gov.ph
Link checked 18 August 2026
Manual of Regulations for Banks, Sections 112 (Outsourcing), 148 (Information Technology Risk Management), 172 (Financial Records) and 924 (Record Keeping)
Directly binding regulation · Manual of Regulations for Banks, 2022 consolidated edition
Banks and other supervised financial firms may send work and data offshore, but only if the contract spells out confidentiality duties and the destination country's own confidentiality and privacy laws do not clash with Philippine law. The central bank can order the arrangement unwound at any time. Cyber incidents must be reported within two hours, and records kept at least five years and produced without delay.
Enforced by Bangko Sentral ng Pilipinas
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractThe service agreement must define both sides' rights and responsibilities on confidentiality and data privacy.
- Put a transfer safeguard in placeThe destination country must have confidentiality or data privacy laws that do not conflict with Philippine law. There is no published list of qualifying countries; the bank makes the assessment and the supervisor can disagree.
- Independent auditThe bank must verify the provider's security controls through third-party or internal audit, and the supervisor may demand direct access to the offshore provider.
- Report cyber incidents — within 2 hoursTwo hours from discovery to notify the supervising department, then a fuller report within 24 hours.
- Keep data for a minimum period — 5 yearsAt least five years for bank records, and five years from the transaction, or from account closure, for anti-money-laundering records. Records must be readily available without delay during examinations.
- Secure the data
What it costs if you get it wrong
- Order to stopThe supervisor may require the bank to terminate, modify or re-integrate an outsourced activity if customer confidentiality, customer redress or supervisory access cannot be assured
- Loss of your licenceEnforcement actions may limit or suspend a business activity and may be imposed on directors, officers and employees
Sources
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Section 112 — Other types of outsourcing arrangements, item (c) Offshore outsourcing
bsp.gov.ph
“Offshore outsourcing of bank's domestic operations is permitted only when: (i) the service agreement defines counterparties' right and responsibilities on confidentiality and data privacy; and (ii) the service provider operates in jurisdictions with existing confidentiality and/or data privacy laws that are not in conflict with existing Philippine laws and relevant regulations.”
Link checked 18 August 2026
- Official sourceBangko Sentral ng PilipinasManual of Regulations for Banks, Section 924 — Record Keeping
bsp.gov.ph
“All transaction records and documents of covered persons shall be maintained and safely stored for five (5) years from the date of transaction.”
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Data Privacy Act of 2012
Act of parliament · Republic Act No. 10173
The general privacy law. It reaches foreign companies, demands consent or another lawful basis, gives people rights over their data, and does not restrict sending data abroad. Breaches of it can be criminal, and the regulator can fine up to three percent of last year's gross income, capped at five million pesos per act, roughly ninety thousand United States dollars.
Enforced by National Privacy Commission
Transfer model: No restriction · Accepted routes: Nothing required, Standard contract clauses
What it makes you do
- Get consent
- Document a legitimate interestDetailed conditions set by NPC Circular No. 2023-07 on legitimate interest.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Let people take their data elsewhere
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Appoint a data protection officer
- Put a transfer safeguard in placeAccountability only: the controller stays responsible after transfer and must use contractual or other reasonable means to secure comparable protection. No approval, no destination list.
- Written vendor contractProcessor may transfer to another country only on the controller's documented instructions.
- Delete data after a periodKeep only as long as necessary for the declared purpose, then dispose securely.
- Get a parent's consent for children — applies at: under 18
What it costs if you get it wrong
- Criminal liability: PHP 5,000,000 and 6 years imprisonment — about $88 thousandCombination or series of acts under the Act; sensitive personal information offences carry 3 to 6 years
- Criminal liability: PHP 1,000,000 and 5 years imprisonment — about $18 thousandConcealment of a security breach involving sensitive personal information
- Percentage of global turnover: 3% of annual gross income of the preceding year, total capped at PHP 5,000,000 per act — about $88 thousandGrave infraction under NPC Circular No. 2022-01
- Order to stopCease and desist order under NPC Circular No. 20-02
Sources
- Official sourceNational Privacy CommissionRepublic Act No. 10173, Data Privacy Act of 2012
privacy.gov.ph
“Each personal information controller is responsible for personal information under its control or custody, including information that have been transferred to a third party.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionImplementing Rules and Regulations of the Data Privacy Act of 2012
privacy.gov.ph
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Circular No. 2022-01, Guidelines on Administrative Fines, 8 August 2022
privacy.gov.ph
“the total imposable fine for a single act of a PIC or PIP ... shall not exceed Five Million Pesos (Php 5,000,000.00)”
Link checked 18 August 2026
Registration of Personal Data Processing System
Regulator directive · NPC Circular No. 2022-04
Medium and larger organisations, and anyone doing automated decision-making or profiling at any size, must register their data processing systems with the regulator and name a privacy officer. Overseas transfers you plan to make must be declared on the form.
Enforced by National Privacy Commission
What it makes you do
- Register or notify — applies at: 250 or more employees, or sensitive personal information of 1,000 or more people, or processing likely to pose a risk to rights and freedoms; automated decision-making or profiling must be registered in all casesRegister within 20 days of implementing the system or appointing the data protection officer. Foreign entities must file authenticated or apostilled corporate documents with English translations.
- Appoint a data protection officer
- Keep records of processing
- Put a transfer safeguard in placeProposed transfers of personal data outside the Philippines must be declared in the registration filing.
What it costs if you get it wrong
- Fixed maximum fine: PHP 200,000 — about $4 thousandFailure to register, as an 'other infraction' under NPC Circular No. 2022-01
Sources
- Official sourceNational Privacy CommissionNPC Circular No. 2022-04, Registration of Personal Data Processing System
privacy.gov.ph
“A PIC or PIP that employs two hundred fifty (250) or more persons”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionImplementing Rules and Regulations, section 47 — registration content
privacy.gov.ph
“Proposed transfers of personal data outside the Philippines”
Link checked 18 August 2026
Personal Data Breach Management
Regulator directive · NPC Circular No. 16-03
You have seventy-two hours from knowing or reasonably believing a serious breach happened to tell both the regulator and the people affected. Everyone also files a yearly summary of all incidents, and hiding a breach of sensitive data is a crime.
Enforced by National Privacy Commission
What it makes you do
- Report breaches to the regulator — within 72 hoursClock starts on knowledge of, or reasonable belief in, a notifiable breach. Being unable to restore the system is not a ground for delay.
- Tell affected people — within 72 hours
- Keep records of processingAnnual security incident report summarising all incidents and breaches. The 2025 report was due 31 March 2026.
- Secure the data
What it costs if you get it wrong
- Percentage of global turnover: 2% of annual gross income, or 3% where more than 1,000 people are affectedFailure to notify a personal data breach
- Criminal liability: PHP 1,000,000 and 5 years imprisonment — about $18 thousandConcealing a breach involving sensitive personal information
Sources
- Official sourceNational Privacy CommissionNPC Circular No. 16-03, Personal Data Breach Management
privacy.gov.ph
“inability to immediately secure or restore integrity to the information and communications system shall not be a ground for any delay”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC Advisory No. 2026-02 on breach notification through the Data Breach Notification Management System, 11 May 2026
privacy.gov.ph
Link checked 18 August 2026
Security of Personal Data in Government and Private Sector
Regulator directive · NPC Circular No. 2023-06
The regulator's detailed security rulebook, replacing the older government-only version from 2016 and now covering private companies too. It applies by its own terms to processing done outside the Philippines, so moving the servers abroad does not move you out of it.
Enforced by National Privacy Commission
What it makes you do
- Secure the dataMulti-factor authentication for online access to sensitive information; encryption for removable media; no fax for documents containing personal data.
- Keep logsSecurity logs are to be kept longer than ordinary system logs. No fixed number of months is set.
- Delete data after a periodRetention periods must be established and documented; disposal must render further processing impossible.
- Keep records of processing
What it costs if you get it wrong
- Percentage of global turnover: up to 3% of annual gross income, capped at PHP 5,000,000 per act — about $88 thousandFailure to implement reasonable and appropriate security measures
Sources
- Official sourceNational Privacy CommissionNPC Circular No. 2023-06, signed 1 December 2023
privacy.gov.ph
“This Circular expressly repeals NPC Circular No. 16-01.”
Link checked 18 August 2026
- Official sourceNational Privacy CommissionNPC circulars index
privacy.gov.ph
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether the Philippine government's Cloud First Policy restricts where government data may be hosted
The Department of Information and Communications Technology website blocked every automated request from this session, so we could not read the current department circular. A policy of this kind is widely reported to classify government data and to steer sensitive classifications to a government cloud, but we will not assert it without the department's own text. Anyone doing government work should read the current circular directly.
Whether licensed online gaming operators must keep gaming servers and player data inside the Philippines
The gaming regulator's public regulatory pages publish only land-based casino manuals. The remote-gaming and electronic-gaming standards pages carried no documents when checked on 18 August 2026.
Sector rules for securities firms, hospitals, telecommunications companies and mapping or geospatial data
The securities regulator's search pages, the health department, the telecommunications regulator, the statistics authority and the official gazette all refused automated requests from this session. We found no evidence of storage-location rules in these sectors, but this is an unchecked gap rather than a verified negative.
The tax and company-law minimum retention periods, commonly stated as ten years for books of accounts
The tax bureau's website serves its regulations through a script-driven interface that we could not read, so we have no official citation for the period. Treat the ten-year figure as unverified.
Current status in Congress of the bills amending the Data Privacy Act
Both chambers' websites refused automated requests. The only official material we could reach is a regulator news item from 2021 describing a committee-approved substitute bill. The amendments may have advanced, lapsed or been refiled since; treat the whole package as proposed with unknown standing.
Whether the National Privacy Commission has actually collected an administrative fine under its 2022 fine schedule
The published decisions and orders we could read describe damages and cease and desist orders rather than named peso fines. The power plainly exists; the collection record is not evidenced on the regulator's own pages.
That the 2022 consolidated Manual of Regulations for Banks is the current text of the banking rules
It is the consolidated edition the central bank publishes for download, but the Manual is amended continuously by circulars and the site's regulation index blocked automated access. Later circulars may have modified the outsourcing, incident-reporting or record-keeping sections.
The exact commencement date of the Data Privacy Act and of several regulator circulars
The Act and the circulars all take effect fifteen days after publication in newspapers, and the publication dates are not stated in the texts we could read. Only the signing dates are recorded here.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Philippines versus
Compare