Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
PHMEDIUM coverage2 enforcement actions

Philippines Data Privacy Act — AI Systems (NPC Advisory 2024-04): AI Compliance Requirements

The Philippines National Privacy Commission (NPC) issued Advisory No. 2024-04 on December 19, 2024: Guidelines on the Application of the Data Privacy Act of 2012 (Republic Act 10173) to AI Systems Processing Personal Data. This advisory is binding guidance under existing law — immediate compliance required for any organization processing personal data of Philippine residents using AI systems. Key obligations: (1) Data subjects retain full RA 10173 rights even when AI is involved. (2) Controllers are strictly liable for AI system outcomes. (3) Automated decisions affecting individuals require meaningful human oversight capability. (4) AI systems processing personal data must register with the NPC. (5) Data Protection Impact Assessments required for high-risk AI processing. Third-party AI providers do NOT reduce controller liability.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

December 19, 2024

Maximum Penalty

NPC administrative fines (Circular No. 2022-001): Grave Infractions 0.5-3% of annual gross income, Major Infractions 0.25-2%, capped at PHP 5,000,000 per act/omission. Separately, RA 10173 criminal penalties (Sections 25-33, court-imposed, tiered by offense): imprisonment 1-7 years and fines PHP 500,000-5,000,000.

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

AI Accountability & Liability Documentation

Critical

Under NPC Advisory 2024-04: you remain strictly liable for AI system outcomes even when using third-party AI providers (OpenAI, Google, Anthropic, etc.). Document: (1) Which AI systems process Philippine resident data. (2) Your accountability framework — who is responsible for AI decisions. (3) How you verify AI system compliance with RA 10173 principles. Third-party AI providers must be covered by Data Sharing Agreements.

NPC Advisory No. 2024-04 (2024-12-19)

Automated Decision Transparency & Human Oversight

High Priority

AI systems making significant decisions affecting Philippine residents must: (1) Be disclosed to affected individuals. (2) Have meaningful human intervention capability available. (3) Allow individuals to question and contest decisions. Document your human-in-the-loop procedures and provide a mechanism for individuals to request human review.

NPC Advisory No. 2024-04 (2024-12-19)

Data Protection Impact Assessment for High-Risk AI

High Priority

Required for AI systems that pose high risk to data subjects' rights, including: AI-based profiling, large-scale automated processing, AI using biometric or sensitive personal data. Conduct and document a DPIA before deploying such systems. NPC may request review.

NPC Advisory No. 2024-04 (2024-12-19)

NPC Registration & Privacy Officer

Medium Priority

Organizations processing personal data of Philippines residents with AI must register with the NPC and designate a Data Protection Officer (DPO). Registration is online at privacy.gov.ph. DPO must be knowledgeable in data privacy law and AI governance.

RA 10173, Section 26; NPC Advisory No. 2024-04

Who Does This Apply To?

Applies to any organization that processes the personal data of Philippine residents using AI systems, under NPC Advisory No. 2024-04 (issued December 19, 2024) — binding guidance applying the Data Privacy Act of 2012 (RA 10173) to AI, with immediate compliance and no grace period. In scope means: data subjects retain their full RA 10173 rights even when AI is involved; the controller is strictly liable for AI-system outcomes and a third-party AI provider does NOT reduce that liability (provider use requires an RA 10173-compliant Data Sharing Agreement); automated decisions with significant effects require a meaningful human-oversight capability; AI systems processing personal data must register with the NPC; and a Data Protection Impact Assessment is required before deploying high-risk AI processing. Scope turns on processing Philippine-resident personal data with AI, wherever the organization sits; enforced by the National Privacy Commission via administrative fines (Circular No. 2022-001: 0.25-3% of annual gross income, capped PHP 5,000,000) with RA 10173 criminal penalties (1-7 years imprisonment, PHP 500,000-5,000,000 fines) as a separate, court-imposed layer.

Recent Enforcement Actions

2019-10-04Source verified· as of 2026-08-22

Against:

2025-10-08Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024-12

NPC Advisory 2024-04 — Guidelines on AI and the Data Privacy Act (December 2024)

The NPC issued binding guidelines applying RA 10173 to AI systems: controllers remain strictly liable for AI system outcomes regardless of third-party provider; automated decisions with significant effects require meaningful human oversight capability; AI systems processing Philippine resident personal data must register with the NPC; DPIAs required before deploying high-risk AI; third-party AI providers must be covered by Data Sharing Agreements compliant with RA 10173.

guidance2026-03-18

NPC + DICT + SEC — joint advisory on online lending platforms (March 18, 2026)

The National Privacy Commission, Department of Information and Communications Technology, and Securities and Exchange Commission published a joint advisory addressing personal-data processing by online lending platforms — reiterating that finance entities must comply with RA 10173 and adopt reasonable policies for handling borrowers' personal data, including data collected or processed via AI-based credit scoring.

guidance2026-08

NPC draft Circular — overhauled Privacy Impact Assessment framework, PENDING (public consultation closed Aug 14, 2026)

The NPC published a draft circular overhauling the PIA framework for the first time since 2017 — narrowing mandatory PIA obligations for routine data processing while imposing new, explicit PIA requirements for AI systems, biometric enrollment programs, cross-border transfers, and processing touching children's personal information. As of this cycle it is still a DRAFT: the public-comment period closed 2026-08-14 and a consultation session was scheduled for 2026-08-25 — NOT YET a binding rule. Monitor for finalization; do not treat as a current enforceable duty.

Frequently Asked Questions

Does Philippines Data Privacy Act — AI Systems (NPC Advisory 2024-04) apply to my business?

The Philippines National Privacy Commission (NPC) issued Advisory No. 2024-04 on December 19, 2024: Guidelines on the Application of the Data Privacy Act of 2012 (Republic Act 10173) to AI Systems Processing Personal Data. This advisory is binding… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Philippines Data Privacy Act — AI Systems (NPC Advisory 2024-04) is: NPC administrative fines (Circular No. 2022-001): Grave Infractions 0.5-3% of annual gross income, Major Infractions 0.25-2%, capped at PHP 5,000,000 per act/omission. Separately, RA 10173 criminal penalties (Sections 25-33, court-imposed, tiered by offense): imprisonment 1-7 years and fines PHP 500,000-5,000,000.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Philippines Data Privacy Act — AI Systems (NPC Advisory 2024-04)?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://privacy.gov.ph/wp-content/uploads/2025/02/Advisory-2024.12.19-Guidelines-on-Artificial-Intelligence-w-SGD.pdf

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan