Asia Pacific

Philippines Data Privacy Act (DPA, Republic Act 10173) + NPC AI Advisory: AI Compliance Requirements

The Philippines Data Privacy Act (DPA 2012, RA 10173) is enforced by the National Privacy Commission (NPC). The DPA applies to any organization processing personal data of Philippine citizens, regardless of location. The Philippines has 115M people and one of the highest internet penetration rates in Southeast Asia. The NPC has actively pursued enforcement, with multi-million-peso fines against major violators. The NPC issued AI-specific advisory circulars in 2023-2024 addressing automated decision-making, AI profiling, and generative AI data risks.

Key Facts

Effective Date

September 8, 2012

Enforcement Begins

September 9, 2016

Maximum Penalty

PHP 5,000,000 (~$90,000 USD) per violation. Criminal penalties: up to 6 years imprisonment for sensitive personal information breaches.

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Consent and Privacy Notice Requirements

Critical

DPA Section 13 requires freely given, specific, informed, and indicated consent before processing personal data. AI systems collecting data of Philippine residents must provide a clear Privacy Notice describing: identity of the personal information controller, purposes of processing, AI-specific processing activities, and data subject rights. The NPC requires notices to be available in Filipino and English for Philippine-based users.

Data Subject Rights (DPA Sections 16-18)

Critical

DPA Sections 16-18 grant Philippine residents rights to: be informed, access their data, object to processing, erase data (right to be forgotten), rectify inaccuracies, and receive data portability. AI automated decisions significantly affecting individuals must provide human review on request and a clear explanation of the decision logic. Organizations must respond within 10 business days.

NPC Registration and Data Protection Officer Appointment

High Priority

DPA Section 26 requires organizations processing data of 500+ data subjects to register with the NPC and designate an accountable Data Protection Officer (DPO). The DPO must be appointed in writing, have access to personal data inventory, and file an annual compliance report with the NPC. AI organizations above the threshold must complete NPC registration before deploying systems.

NPC AI Advisory Compliance (2023-2024)

High Priority

The NPC issued advisory circulars addressing: (1) AI profiling and automated decision-making must comply with DPA consent requirements; (2) Generative AI must not train on Philippine personal data without consent; (3) Sensitive personal information processed by AI (health, financial, biometric) requires Privacy Impact Assessments (PIAs); (4) Third-party AI processors must sign DPA-compliant data sharing agreements. Organizations must document their AI processing activities in their Personal Data Processing Systems (PDPS) inventory.

Frequently Asked Questions

Does Philippines Data Privacy Act (DPA, Republic Act 10173) + NPC AI Advisory apply to my business?

The Philippines Data Privacy Act (DPA 2012, RA 10173) is enforced by the National Privacy Commission (NPC). The DPA applies to any organization processing personal data of Philippine citizens, regardless of location. The Philippines has 115M people a. Use ComplianceIQ's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Philippines Data Privacy Act (DPA, Republic Act 10173) + NPC AI Advisory is: PHP 5,000,000 (~$90,000 USD) per violation. Criminal penalties: up to 6 years imprisonment for sensitive personal information breaches.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Philippines Data Privacy Act (DPA, Republic Act 10173) + NPC AI Advisory?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. ComplianceIQ generates all required documents automatically.

Official Source

https://www.privacy.gov.ph/data-privacy-act/

Last updated: 2026-04-14 — verify at source before relying on this information.

Don't leave compliance to chance

ComplianceIQ scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan