Skip to content

RA 10173 - Data Privacy Act (2012)

Philippine lawLegal status not independently verified

In brief

AI summary. Verify against the source below.

The Data Privacy Act of 2012 protects personal information in both government and private sectors, establishing the National Privacy Commission to enforce data protection standards and outlining the rights of individuals and obligations of data handlers.

Who it affects: It applies to any natural or juridical person who processes personal information in the Philippines, including foreign entities with a link to the Philippines.

Key provisions

  • Short title. The law is officially called the "Data Privacy Act of 2012". [Section 1]
  • Scope of application. The Act covers processing of all personal information by any person or organization, even if located abroad, provided they have equipment in the Philippines or maintain an office, branch, or agency here, subject to the requirements of Section 5. [Section 4]
  • Extraterritorial application. The law also applies to processing done outside the Philippines when it involves personal data of Philippine citizens or residents and the entity has a link to the Philippines, such as a contract, central management, or a local branch. [Section 6]
  • National Privacy Commission (NPC) functions. The NPC monitors compliance, receives complaints, conducts investigations, issues cease‑and‑desist orders, advises on policy, and can recommend prosecution for violations. [Section 7]
  • Lawful bases for processing personal data. Processing is allowed only if the data subject consents or if it is necessary for a contract, legal obligation, vital interests, public emergency, public authority functions, or legitimate interests that do not override the data subject’s rights. [Section 12]
  • Sensitive personal information. Sensitive data includes information on race, health, genetics, government‑issued IDs, and other categories listed in Section 3(l); its processing is prohibited except in specific situations such as consent, legal requirement, or protection of life and health. [Section 3(l)]
  • Rights of data subjects. Individuals have the right to be informed, to access and correct their data, to object to processing, to suspend or delete inaccurate data, to data portability, and to seek indemnification for damages. [Section 16]
  • Security measures for personal information. Data controllers must adopt reasonable organizational, physical, and technical safeguards—such as security policies, vulnerability assessments, and breach notification—to protect data from accidental or unlawful loss, alteration, or disclosure. [Section 20]
  • Penalties for unauthorized processing. Unauthorized processing of personal data can lead to imprisonment of 1–3 years and a fine of ₱500,000–₂,000,000; unauthorized processing of sensitive data carries higher penalties of 3–6 years imprisonment and fines up to ₱4,000,000. [Section 25]

Common questions

What is the Data Privacy Act of 2012?
It is a law that protects the privacy of personal information in both the government and private sectors and creates the National Privacy Commission to enforce data protection standards. [Section 1]
Who is considered a data subject under the Act?
A data subject is any individual whose personal information is being processed. [Section 3(c)]
What are the lawful bases for processing personal data?
Processing is lawful if the data subject gives consent, or if it is needed for a contract, legal duty, vital interests, public emergency, public authority functions, or legitimate interests that do not outweigh the data subject’s rights. [Section 12]
What rights do individuals have under the Data Privacy Act?
Individuals can be informed about processing, access and correct their data, object to processing, suspend or delete inaccurate data, obtain a portable copy of their data, and claim damages for violations. [Section 16]
Does the Act apply to foreign companies?
Yes, it applies to foreign entities that process personal data of Philippine citizens or residents and have a link to the Philippines, such as a contract, local branch, or use of equipment located in the Philippines. [Section 4]
What is considered sensitive personal information?
Sensitive personal information includes data on race, health, genetics, government‑issued IDs, and other categories listed in Section 3(l), and it receives higher protection. [Section 3(l)]
What penalties exist for unauthorized processing of personal data?
Unauthorized processing of personal data can result in 1–3 years imprisonment and a fine of ₱500,000–₂,000,000; for sensitive data the penalty is 3–6 years imprisonment and a fine of up to ₱4,000,000. [Section 25]
How does the National Privacy Commission enforce the law?
The NPC monitors compliance, receives complaints, conducts investigations, issues cease‑and‑desist orders, and can recommend prosecution or impose penalties for violations. [Section 7]

Legal information, not legal advice

Tatsulok checks that this text faithfully reproduces its published source, but Tatsulok is not an official publisher and does not independently verify whether the text is currently in force, amended, or repealed. Always confirm against an official source, such as the Official Gazette or the issuing government authority, before relying on it. This is legal information for study, not legal advice. For your situation, consult a lawyer or Philippine legal aid.