Skip to content
Esta es una traduccion de conveniencia. La version en ingles es la version oficial y legalmente vinculante. Ver version en ingles
Asia PacificMEDIUM coverage1 enforcement action

Philippines Data Privacy Act (DPA, Republic Act 10173) + NPC AI Advisory: AI Compliance Requirements

The Philippines Data Privacy Act (DPA 2012, RA 10173) is enforced by the National Privacy Commission (NPC). The DPA applies to any organization processing personal data of Philippine citizens, regardless of location. The Philippines has 115M people and one of the highest internet penetration rates in Southeast Asia. The NPC has actively pursued enforcement, with multi-million-peso fines against major violators. The NPC issued AI-specific advisory circulars in 2023-2024 addressing automated decision-making, AI profiling, and generative AI data risks.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

September 8, 2012

Enforcement Begins

September 9, 2016

Maximum Penalty

Two layers. (1) NPC administrative fines (Circular No. 2022-001, effective 2022-08-27): Grave Infractions 0.5-3% of annual gross income, Major Infractions 0.25-2% of annual gross income, capped at PHP 5,000,000 total per act/omission. (2) RA 10173 criminal penalties (Sections 25-33, tiered by offense): imprisonment ranging 1-7 years and fines of PHP 500,000-5,000,000, e.g. up to 7 years for unauthorized processing of sensitive personal information for unauthorized purposes (Sec. 28) and up to 6 years for a combination/series of acts (Sec. 33, fine up to PHP 5,000,000).

What Your Business Must Do

4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Consent and Privacy Notice Requirements

Critical

DPA Section 13 requires freely given, specific, informed, and indicated consent before processing personal data. AI systems collecting data of Philippine residents must provide a clear Privacy Notice describing: identity of the personal information controller, purposes of processing, AI-specific processing activities, and data subject rights. The NPC requires notices to be available in Filipino and English for Philippine-based users.

RA 10173, Section 13; NPC Circular No. 2022-001

Data Subject Rights (DPA Sections 16-18)

Critical

DPA Sections 16-18 grant Philippine residents rights to: be informed, access their data, object to processing, erase data (right to be forgotten), rectify inaccuracies, and receive data portability. AI automated decisions significantly affecting individuals must provide human review on request and a clear explanation of the decision logic. Organizations must respond within 10 business days.

RA 10173, Sections 16-18

NPC Registration and Data Protection Officer Appointment

High Priority

DPA Section 26 requires organizations processing data of 500+ data subjects to register with the NPC and designate an accountable Data Protection Officer (DPO). The DPO must be appointed in writing, have access to personal data inventory, and file an annual compliance report with the NPC. AI organizations above the threshold must complete NPC registration before deploying systems.

RA 10173, Section 26

NPC AI Advisory Compliance (2023-2024)

High Priority

The NPC issued advisory circulars addressing: (1) AI profiling and automated decision-making must comply with DPA consent requirements; (2) Generative AI must not train on Philippine personal data without consent; (3) Sensitive personal information processed by AI (health, financial, biometric) requires Privacy Impact Assessments (PIAs); (4) Third-party AI processors must sign DPA-compliant data sharing agreements. Organizations must document their AI processing activities in their Personal Data Processing Systems (PDPS) inventory.

NPC Advisory Guidelines on AI Systems (2024-12-19)

Recent Enforcement Actions

2025-10-08Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024-12

Philippines NPC — AI Advisory Guidelines (Dec 2024) + NPC Privacy Toolkit

The Philippines National Privacy Commission (NPC) issued Advisory Guidelines on the Application of the Data Privacy Act to AI Systems Processing Personal Data on December 19, 2024: personal information controllers must register data-processing systems (including AI) with the NPC; a DPIA is required before AI processing likely to result in high risk; AI-driven automated decisions affecting Filipinos trigger access, correction, objection, and human-review rights; and cross-border transfers to AI vendors require contractual protections meeting NPC standards. Separately, the NPC Privacy Toolkit provides general DPA-compliance templates and the Five Pillars of Accountability (DPO, privacy impact assessment, privacy management program, security measures, breach reporting). BSP Circular 1108 imposes parallel technology and cyber-risk obligations on banks using AI.

Frequently Asked Questions

Does Philippines Data Privacy Act (DPA, Republic Act 10173) + NPC AI Advisory apply to my business?

The Philippines Data Privacy Act (DPA 2012, RA 10173) is enforced by the National Privacy Commission (NPC). The DPA applies to any organization processing personal data of Philippine citizens, regardless of location. The Philippines has 115M people… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Philippines Data Privacy Act (DPA, Republic Act 10173) + NPC AI Advisory is: Two layers. (1) NPC administrative fines (Circular No. 2022-001, effective 2022-08-27): Grave Infractions 0.5-3% of annual gross income, Major Infractions 0.25-2% of annual gross income, capped at PHP 5,000,000 total per act/omission. (2) RA 10173 criminal penalties (Sections 25-33, tiered by offense): imprisonment ranging 1-7 years and fines of PHP 500,000-5,000,000, e.g. up to 7 years for unauthorized processing of sensitive personal information for unauthorized purposes (Sec. 28) and up to 6 years for a combination/series of acts (Sec. 33, fine up to PHP 5,000,000).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Philippines Data Privacy Act (DPA, Republic Act 10173) + NPC AI Advisory?

The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.privacy.gov.ph/data-privacy-act/

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan