Skip to content

RA 10173 - Data Privacy Act (2012)

Philippine lawLegal status not independently verified

In brief

AI summary. Verify against the source below.

The Data Privacy Act of 2012 protects personal information in both government and private sectors, establishing the National Privacy Commission to enforce compliance and outlining rights of data subjects and penalties for violations.

Who it affects: It applies to any natural or juridical person who processes personal information in the Philippines, including foreign entities with a presence or link in the country.

Key provisions

  • Short title. The law is officially called the "Data Privacy Act of 2012". [Sec. 1]
  • Definitions – personal and sensitive data. Personal information is any data that can identify an individual; sensitive personal information includes details about race, health, government IDs, and other categories listed in the law. [Sec. 3(g) & Sec. 3(l)]
  • Scope of application. The Act covers all processing of personal information by any person or organization in the Philippines, and also applies to foreign entities that use equipment located in the Philippines or have a branch there. [Sec. 4]
  • Extraterritorial reach. It applies to processing done abroad if it involves personal data of Philippine citizens or residents and the entity has a link to the Philippines, such as a contract or a local office. [Sec. 6]
  • Lawful bases for processing. Processing is allowed when the data subject consents, when needed for a contract, legal obligation, vital interests, public emergency, public authority functions, or legitimate interests that do not override the data subject’s rights. [Sec. 12]
  • Rights of data subjects. Data subjects can be informed about processing, access their data, correct errors, object to processing, request deletion or blocking, and claim damages for misuse. [Sec. 16]
  • Security obligations. Controllers must adopt reasonable organizational, physical, and technical safeguards to protect personal data from accidental or unlawful loss, alteration, or disclosure, and must notify breaches to the Commission and affected individuals. [Sec. 20]
  • National Privacy Commission functions. The Commission monitors compliance, receives complaints, conducts investigations, issues cease‑and‑desist orders, and advises on policy and legislation related to data protection. [Sec. 7]
  • Penalties for unauthorized processing. Unauthorized processing of personal data can lead to imprisonment of 1‑3 years and fines of ₱500,000‑₱2,000,000; for sensitive data the penalties are higher, up to 6 years imprisonment and fines up to ₱4,000,000. [Sec. 25]

Common questions

What is the Data Privacy Act of 2012?
It is a law that protects the fundamental right to privacy by regulating how personal information is collected, processed, stored, and shared in both the public and private sectors. [Sec. 2]
Who must comply with the Data Privacy Act?
All natural and juridical persons who process personal information in the Philippines, as well as foreign entities that have equipment, offices, or contracts in the Philippines, must comply. [Sec. 4]
What rights do data subjects have under the Act?
Data subjects are entitled to be informed about processing, access their data, correct inaccuracies, object to processing, request suspension or deletion, and seek indemnification for damages. [Sec. 16]
When can personal data be processed without the data subject’s consent?
Processing without consent is permitted when it is necessary for contract performance, legal obligations, vital interests, public emergencies, public authority functions, or legitimate interests that do not override the data subject’s constitutional rights. [Sec. 12]
What are the penalties for violating the Data Privacy Act?
Violations such as unauthorized processing, negligent access, improper disposal, or failure to notify breaches can result in imprisonment ranging from six months to seven years and fines from ₱100,000 to ₱5,000,000, depending on the offense and the type of data involved. [Sec. 25-33]
How does the Act apply to foreign companies?
Foreign companies are covered if they process personal data of Philippine citizens or residents and have a link to the Philippines, such as a contract, a local branch, or use of equipment located in the country. [Sec. 6]
What is the role of the National Privacy Commission?
The Commission enforces the Act by monitoring compliance, handling complaints, conducting investigations, issuing orders to stop unlawful processing, and providing guidance on data protection policies. [Sec. 7]
What constitutes sensitive personal information?
Sensitive personal information includes data about race, health, genetic or sexual life, government‑issued IDs, financial records, and any information classified as privileged or specially protected by law. [Sec. 3(l)]

Legal information, not legal advice

Tatsulok checks that this text faithfully reproduces its published source, but Tatsulok is not an official publisher and does not independently verify whether the text is currently in force, amended, or repealed. Always confirm against an official source, such as the Official Gazette or the issuing government authority, before relying on it. This is legal information for study, not legal advice. For your situation, consult a lawyer or Philippine legal aid.