EnglishEspañol

Philippines DPA vs GDPR: Key Differences Compared (2026)

By Recording Law Editorial Team22 min read
Philippines DPA vs GDPR: Key Differences Compared (2026)

Frequently Asked Questions

Can someone actually go to prison under the Philippines Data Privacy Act?

RA 10173 Chapter VIII creates eight distinct criminal offenses with imprisonment ranges from 6 months (improper disposal of personal information) up to 7 years (processing sensitive personal information for unauthorized purposes). Where the offender is a corporation, the criminal penalty falls on the responsible officers who participated or, through gross negligence, allowed the violation, not on the entity itself. This is a real structural feature of the law, separate from and in addition to the NPC's administrative fines.

Does GDPR have any equivalent criminal penalties?

Not at the EU level. GDPR Article 83 is administrative-fines-only, up to EUR 20 million or 4% of global annual turnover. Article 84 allows individual EU member states to legislate their own criminal offenses for infringements outside Article 83's scope, and a few states such as Germany have narrow criminal provisions under their own implementing law, but there is no EU-wide criminal track and no imprisonment risk written into the Regulation itself.

Who has to register with the National Privacy Commission?

Under NPC Circular 2022-04, registration of data processing systems is mandatory for any personal information controller or processor with 250 or more employees, or that processes sensitive personal information of 1,000 or more individuals, or that engages in processing likely to pose a risk to data subjects, or that uses automated decision-making or profiling regardless of size. Registered entities must display a physical Seal of Registration at their business entrance and on their website, and renew within a 30-day window before annual expiry.

Why doesn't GDPR require this kind of registration?

The GDPR's 2018 framework deliberately replaced the EU's earlier 1995-Directive-era notification and registration system with an accountability model, in which organizations self-assess and maintain internal Records of Processing Activities under Article 30 rather than filing for regulator approval. EU legislators judged the older registration approach too bureaucratic without being meaningfully more protective. The Philippines took the opposite path, rebuilding a mandatory registration regime through NPC Circular 2022-04 in December 2022.

Does the Philippine Data Privacy Act give a right to be forgotten like GDPR?

Not in the same form. Section 16(e) gives data subjects the right to suspend, withdraw, or order the blocking, removal, or destruction of their personal information, but only upon discovery and substantial proof that the information is incomplete, outdated, false, unlawfully obtained, used for an unauthorized purpose, or no longer necessary. That is narrower than several of GDPR Article 17's independent grounds, such as simply withdrawing consent -- the Philippine right requires proving one of the listed defects.

How does Philippine breach notification timing compare to GDPR?

Both the National Privacy Commission and affected data subjects must be notified within 72 hours of a covered breach under NPC Circular 16-03, running from the same trigger. GDPR stages the two notices differently: 72 hours to the supervisory authority under Article 33, but only 'without undue delay' to affected individuals under Article 34, with no fixed hour count for the individual-notice leg.

What is the '100 persons' threshold in Philippine data privacy law, and is it the same everywhere it appears?

No -- there are two unrelated 100-person thresholds. RA 10173 Section 35 uses 'at least 100 persons' affected as the trigger for imposing the maximum criminal sentence in a large-scale violation under Sections 25-33. Separately, NPC Circular 16-03 Section 17(C) uses a 100-individual figure to set a bright line that the 72-hour breach-notification window cannot be stretched once that many data subjects are involved. One is a sentencing rule inside the criminal chapter; the other is a notification-urgency rule inside the breach-management circular. They should not be conflated.

Why does the Philippines' large outsourcing sector matter for this comparison?

The Philippines processes large volumes of US and EU customer data through its business-process-outsourcing industry. RA 10173 Section 14 fully binds a Philippine BPO as a personal information processor under Philippine law in its own right, Section 6 independently reaches a foreign entity with the statute's defined Philippine links, and Section 24 combines with Circular 2022-04's thresholds to put most large-scale BPO operations under the NPC's mandatory registration and DPO-designation requirements directly -- not only through a foreign client's own GDPR compliance program.

Updates

Initial publication. Covers RA 10173's Chapter VIII criminal penalties, the NPC Circular 2022-04 registration regime, extraterritorial/BPO reach under Sections 4 and 6, and the October 2025 Tools for Humanity cease-and-desist order.

Sources and References

  1. National Privacy Commission, Philippines -- full text of the Data Privacy Act of 2012 (RA 10173)(privacy.gov.ph).gov
  2. NPC Circular No. 2022-04 -- Registration of Personal Data Processing System, DPO Designation, and NPC Seal of Registration(privacy.gov.ph).gov
  3. NPC Circular No. 2022-01 -- Guidelines on Administrative Fines(privacy.gov.ph).gov
  4. NPC Circular No. 16-03 -- Personal Data Breach Management(privacy.gov.ph).gov
  5. NPC Cease-and-Desist Order against Tools for Humanity, press release(privacy.gov.ph).gov
  6. NPC PIPs/PICs registration walkthrough and fee reference(privacy.gov.ph).gov
  7. Regulation (EU) 2016/679 (General Data Protection Regulation) Full Text(eur-lex.europa.eu).gov
Share: