Philippines DPA vs GDPR: Key Differences Compared (2026)

The Philippines' Data Privacy Act of 2012 (RA 10173) and the EU's GDPR share a common ancestor in the EU's 1995 Data Protection Directive, and on paper their rights chapters look similar. The difference that actually matters for compliance is structural: RA 10173 embeds real criminal imprisonment into the statute itself for eight distinct offenses, and it still runs a mandatory registration system that GDPR abolished in 2018. Neither of those is a footnote. They are the two biggest reasons a business that is comfortable with GDPR compliance can still be exposed under Philippine law.
Information last verified on 2026-07-23. This article has not yet been reviewed by a licensed lawyer.
Jurisdiction scope: This article compares the Philippines' Data Privacy Act of 2012 (RA 10173), administered by the National Privacy Commission (NPC), with the EU's General Data Protection Regulation. For the country-level detail on the Philippine framework, see our Philippines data privacy laws guide. For a full walkthrough of the GDPR itself, see What Is GDPR.
Philippines DPA vs GDPR: At a Glance
| Feature | GDPR | Philippines DPA (RA 10173) |
|---|---|---|
| Regulator | National DPAs, coordinated by the EDPB | National Privacy Commission (NPC) |
| Criminal liability | None at the EU level (Art. 83 is fines-only; Art. 84 leaves criminal law to member states) | Eight distinct criminal offenses (Chapter VIII, Secs. 25-33), imprisonment 6 months-7 years plus fines up to PHP 5,000,000 for combined acts |
| Registration / notification | Abolished in 2018 in favor of an accountability model (Records of Processing Activities, Art. 30, self-assessed) | Mandatory registration of data processing systems with the NPC above defined thresholds (Circular 2022-04), renewed annually, with a physical Seal of Registration requirement |
| Extraterritorial test | Targeting-based (Art. 3(2)): offering goods/services to, or monitoring, EU data subjects | Link-and-nationality-based (Sec. 6): PH contract, PH-based management/control, PH branch/subsidiary with data access, or processing about a PH citizen/resident |
| Erasure right | Right to erasure / 'right to be forgotten' (Art. 17), multiple independent grounds including consent withdrawal | 'Suspend, withdraw, or order blocking, removal or destruction' (Sec. 16(e)), conditioned on substantial proof of a specific listed defect |
| Breach notification | 72 hours to the regulator; 'without undue delay' to affected individuals (staggered) | 72 hours to both the NPC and affected data subjects, same clock, same trigger (Circular 16-03, Secs. 17-18) |
| Administrative fines | Up to EUR 20 million or 4% of global annual turnover (Art. 83(5)) | Grave 0.5-3%, major 0.25-2% of annual gross income, other PHP 50,000-200,000, aggregate cap PHP 5,000,000 (Circular 2022-01) |
| Cross-border transfer mechanism | Adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules (Chapter V, Arts. 44-50) | No statutory adequacy/SCC apparatus; accountability follows the controller via 'contractual or other reasonable means' (Sec. 21) |
| Data portability | Art. 20, tied to consent- or contract-basis processing | Sec. 18, scoped generally to 'personal information,' no explicit consent/contract tie |

Background and Legislative Context
The Philippines enacted the Data Privacy Act of 2012 (Republic Act No. 10173) and created the National Privacy Commission as its dedicated regulator. Like the GDPR, RA 10173 traces its lineage back to the EU's 1995 Data Protection Directive, which is part of why the two laws share a similar rights vocabulary. The NPC has since built out the Act's implementing apparatus through circulars and advisories -- most consequentially Circular 2022-01 (administrative fines, effective August 2022) and Circular 2022-04 (registration, notification of automated decision-making, and DPO designation, December 2022).
The GDPR has applied across the EEA since May 25, 2018. Where the GDPR's 2018 overhaul deliberately moved away from the EU's earlier registration-heavy model, the Philippines went the other direction in the same period, rebuilding and formalizing its own registration system through Circular 2022-04. That divergence -- one regime shedding registration, the other reinforcing it -- is the throughline for most of the practical differences below.

Scope and Extraterritorial Reach
RA 10173 Section 4 applies to the processing of personal information by any natural or juridical person, including controllers and processors not established in the Philippines, if they use equipment located in the Philippines or maintain an office, branch, or agency there. Section 4 carves out several categories: certain government-employee information, journalistic/artistic/literary/research use, central-bank and law-enforcement functions, and bank-secrecy/anti-money-laundering processing.
One carve-out matters specifically for outsourcing: Section 4(g) excludes "personal information originally collected from residents of foreign jurisdictions in accordance with the laws of those foreign jurisdictions... which is being processed in the Philippines" from the Act's own coverage. In practice, this means data an EU customer's information collected under GDPR and then processed in the Philippines is not automatically double-regulated under RA 10173 for that same information; the originating jurisdiction's law governs its collection. That is a narrower point than it might sound -- it applies to the information's original collection, not to a Philippine processor's own separate obligations under the Act for how it handles that data.
Section 6 (Extraterritorial Application) reaches acts done outside the Philippines when: the processing relates to a Philippine citizen or resident; the entity has a Philippine link and is processing information in or about the Philippines (a contract entered in the Philippines, PH-based central management and control, or a PH branch/agency/subsidiary with data access); or the entity otherwise carries on business in the Philippines or has information collected or held by a PH-based entity.
This is a different test from GDPR Article 3(2), which turns on targeting -- offering goods or services to EU data subjects, or monitoring their behavior. Section 6 is broader in a different way: it is link-and-establishment-based, and it can catch a Philippine entity's own processing regardless of whose data is involved, independently of whether any EU-style targeting is happening at all. Describing the two as simply "both have extraterritorial reach" understates how differently they're built.
Why This Matters for BPO
The Philippines runs one of the world's largest business-process-outsourcing sectors, processing US and EU customer data for call centers, back-office functions, claims processing, and healthcare BPO under contract. Three provisions combine to determine how RA 10173 reaches that work:
- Section 14 binds personal information processors fully: "The personal information processor shall comply with all the requirements of this Act and other applicable laws." A Philippine BPO processing a foreign principal's customer data is a personal information processor under the Act in its own right, not a passthrough exempt from Philippine law.
- Section 6 independently reaches a foreign entity that operates remotely but has the Philippine links described above -- separate from whether the BPO itself is compliant.
- Section 24 sets a registration trigger for government contractors and processors handling sensitive personal information of 1,000 or more individuals, which combines with Circular 2022-04's general thresholds (below) to mean that most BPOs handling sensitive data at scale, or with 250-plus employees, fall under the NPC's mandatory registration, DPO-designation, and Seal-of-Registration requirements directly -- not only through their foreign client's own compliance program.

Definitions: Personal vs. Sensitive Personal Information
| Concept | GDPR | Philippines DPA |
|---|---|---|
| Protected individual | Data subject | Data subject |
| Protected data | Personal data | Personal information |
| Sensitive category | Special categories (Art. 9): racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data, sex life/orientation | Sensitive personal information (Sec. 3(l)): race, ethnic origin, marital status, age, color, religious/philosophical/political affiliations, health, education, genetic/sexual-life info, offenses/proceedings, government-issued IDs (SSS, GSIS, TIN, health records) |
| Consent definition | Freely given, specific, informed, unambiguous indication (Art. 4(11)) | "Freely given, specific, informed indication of will," evidenced by written, electronic, or recorded means (Sec. 3(b)) |
The two consent definitions read almost identically, reflecting their shared Directive-era origin. The practical differences show up downstream, in how each law treats legal bases and rights rather than in the definitions themselves.

Legal Bases for Processing
RA 10173 Section 12 sets six grounds for processing ordinary personal information, at least one of which must apply and none of which override an independent legal prohibition: consent; necessity for contract performance or pre-contract steps; compliance with a legal obligation; protecting the vitally important interests (life or health) of the data subject; responding to a national emergency or public order/safety need, or fulfilling a public authority's function; and legitimate interests of the controller or a third party, "except where such interests are overridden by fundamental rights and freedoms of the data subject which require protection under the Philippine Constitution."
Section 13 governs sensitive personal information and privileged information, which is prohibited by default and permitted only under six listed exceptions: specific prior consent (for privileged information, from all parties to the exchange); a law or regulation that itself guarantees protection; protecting life or health where the subject cannot consent; a public organization's lawful non-commercial objectives, confined to its bona fide members with prior consent; medical treatment with adequate safeguards; or legal claims, court proceedings, or a government/public authority function.
This structure is broadly parallel to GDPR Article 6 (six bases) and Article 9 (special-category default prohibition plus exceptions). Three differences are worth flagging. First, Section 12(f)'s legitimate-interest override references the Philippine Constitution rather than a codified statutory balancing test. Second, RA 10173 has no direct equivalent to GDPR's general "public interest task" basis -- Section 12(e) is narrower, tied to emergencies, public order/safety, or a public authority's own mandated function. Third, Section 13(a) requires consent "specific to the purpose prior to processing" from every party to a privileged-information exchange, a stricter two-sided structure GDPR Article 9 does not have an exact match for.
Data Subject Rights
RA 10173 Section 16 lists rights broadly comparable to GDPR's rights chapter, with some structural differences worth noting individually:
- To be informed processing is occurring, and to receive specific disclosures before entry into a processing system (Sec. 16(b)): purpose, scope and method, recipients, automated-access methods, controller identity, retention period, and the existence of these rights.
- Reasonable access to the contents, sources, recipients, methods, and reasons for processing, plus automated-processing information and the last access date (Sec. 16(c)).
- To dispute inaccuracy and have it corrected, with an obligation on the controller to notify third parties who received the inaccurate data (Sec. 16(d)).
- Section 16(e) -- to "suspend, withdraw or order the blocking, removal or destruction" of personal information, but only "upon discovery and substantial proof" that the information is incomplete, outdated, false, unlawfully obtained, used for an unauthorized purpose, or no longer necessary. This is the correctly-termed "erasure or blocking" right, and it is conditioned on proving one of those five specific defects -- it is not a freestanding right to be forgotten that a subject can invoke simply by withdrawing consent, the way several of GDPR Article 17's grounds work.
- Section 16(f) -- a statutory right to be indemnified for damages sustained from inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized-use processing.
- Section 17 (Transmissibility) -- heirs and assigns may invoke these rights after the data subject's death or incapacity, something GDPR generally does not extend at the EU level.
- Section 18 (Data Portability) -- the right to obtain a copy of electronically processed, structured, commonly-used-format personal information, with the NPC empowered to prescribe technical standards. Comparable in shape to GDPR Article 20, though scoped more generally to "personal information" without GDPR's explicit tie to consent- or contract-basis processing.
- Section 19 (Non-Applicability) -- the rights chapter does not apply to information used solely for scientific or statistical research where no subject-specific decisions result, or to information gathered for criminal, administrative, or tax-liability investigations.
The Registration Regime: A Structural Fork From GDPR
This is where the two laws diverge most visibly in day-to-day compliance obligations. The GDPR's 2018 overhaul deliberately replaced the 1995 Directive's supervisory-authority notification and registration system with an accountability model: organizations self-assess and maintain Records of Processing Activities under Article 30, without filing them with a regulator for approval. EU legislators judged pre-2018 registration too bureaucratic and not protective enough to keep.
The Philippines went the other way. NPC Circular No. 2022-04 rebuilt a mandatory registration system for Data Processing Systems. Registration is required for any personal information controller or processor that:
- Employs 250 or more employees; or
- Processes sensitive personal information of 1,000 or more individuals; or
- Engages in processing that is likely to pose a risk to the rights and freedoms of data subjects; or
- Engages in automated decision-making or profiling, regardless of the organization's size.
A registered entity receives a Certificate of Registration and Seal of Registration, valid for one year, renewable only within a 30-day window before expiry. The Seal must be physically displayed at the organization's main business entrance and on its website -- a visible compliance marker with no GDPR analog. Circular 2022-04 also covers notification of automated decision-making/profiling and designation of a data protection officer as part of the same registration package. Registration-related violations feed into the administrative fine schedule under Circular 2022-01, separately from any criminal exposure that might also attach if the underlying unregistered processing independently violates Chapter VIII.
For organizations building out a DPO function to meet this requirement, see our guide to data protection officer requirements across jurisdictions.
Breach Notification: Same Clock, Two Recipients
NPC Circular 16-03 sets the notification rule. Section 17 requires notice to the NPC "within seventy-two (72) hours upon knowledge of or the reasonable belief" that a personal data breach has occurred, with a full report due within five days. Section 18 requires notice to affected data subjects on the identical 72-hour clock, running from the same trigger.
That is a structurally different pattern from GDPR, which stages the two notices: 72 hours to the supervisory authority (Article 33), but only "without undue delay" to affected individuals (Article 34), with no fixed hour count on the individual-notice side. The Philippines runs both notices on one parallel clock.
Notification is required when the breach involves sensitive personal information or identity-fraud-enabling data, is reasonably believed to have been acquired by an unauthorized person, and is likely to give rise to a real risk of serious harm (Circular 16-03, Sec. 11 and 13). Section 13 also lists "at least one hundred (100) individuals" as one of four factors -- alongside national-security impact, legally-required confidentiality, and vulnerable-group data -- that a controller weighs in borderline cases about whether the duty applies at all.
This is a different 100 from the one that appears in the criminal-penalties chapter, and the two should never be conflated. Section 17(C) uses the 100-individual figure for a narrower, separate purpose: it sets a bright line that "there shall be no delay in the notification" -- meaning the 72-hour ceiling itself cannot be stretched -- once a breach involving 100 or more data subjects, or harmful sensitive-data disclosure, is already subject to the notification duty. It governs urgency within the window, not whether the duty to notify exists. Section 35, discussed below, uses its own "at least 100 persons" figure for something else entirely: the trigger for the maximum criminal sentence in a large-scale violation. Keep these two thresholds separate -- one is a notification-timing rule, the other is a sentencing rule, and they sit in different circulars/sections governing different questions.
See our broader roundup of data breach notification deadlines by country for how the Philippines' same-clock, dual-recipient structure compares against the more common pattern of a single regulator clock with a separate or absent individual-notice requirement.
Cross-Border Data Transfers
RA 10173 Section 21 (Principle of Accountability) makes each personal information controller responsible for personal information under its control or custody, including information transferred to a third party for processing, domestically or internationally. Section 21(a) requires the controller to "use contractual or other reasonable means to provide a comparable level of protection" while a third party processes the data. Section 21(b) requires the controller to designate an accountable individual whose identity is disclosed to data subjects on request.
This is an accountability-follows-the-controller model with no statutory adequacy-decision or Standard Contractual Clauses apparatus built into the Act itself -- a sharp contrast with GDPR Chapter V (Articles 44-50), which sets out adequacy decisions, SCCs, Binding Corporate Rules, and derogations as a structured pre-authorization system for transfers out of the EEA. The Philippine model does not gate the transfer itself on a pre-approved mechanism; instead it makes the controller liable for what happens to the data afterward, wherever it goes, through whatever contractual or reasonable means it puts in place.
This has a direct, two-sided consequence for BPO arrangements: a US or EU company sending customer data to a Philippine BPO must satisfy GDPR's own outbound transfer-mechanism requirements on its side of the relationship, while the Philippine BPO receiving and processing that data operates under RA 10173's accountability model on its side. The two regimes' cross-border rules point in different directions and do not automatically satisfy each other -- compliance with one does not substitute for compliance with the other.
Criminal Penalties: The Core Differentiator
This is the single biggest structural difference between the two laws. GDPR Article 83 is administrative-fines-only at the EU level -- the Regulation itself creates no criminal offense. Article 84 permits individual member states to legislate their own criminal penalties for infringements outside Article 83's scope, and a few states (Germany's BDSG is commonly cited) have adopted narrow criminal provisions, but there is no EU-wide criminal track and no imprisonment risk written into the Regulation itself.
RA 10173 Chapter VIII (Sections 25-37) is a full criminal code embedded inside a data-protection statute. Every offense below carries an actual imprisonment range, stacked on top of the administrative fines the NPC separately assesses under Circular 2022-01:
| Offense | Section | Imprisonment | Fine |
|---|---|---|---|
| Unauthorized processing -- personal info | 25(a) | 1-3 years | PHP 500,000-2,000,000 |
| Unauthorized processing -- sensitive personal info | 25(b) | 3-6 years | PHP 500,000-4,000,000 |
| Accessing due to negligence -- personal info | 26(a) | 1-3 years | PHP 500,000-2,000,000 |
| Accessing due to negligence -- sensitive personal info | 26(b) | 3-6 years | PHP 500,000-4,000,000 |
| Improper disposal -- personal info | 27(a) | 6 months-2 years | PHP 100,000-500,000 |
| Improper disposal -- sensitive personal info | 27(b) | 1-3 years | PHP 100,000-1,000,000 |
| Processing for unauthorized purposes -- personal info | 28 | 1.5-5 years | PHP 500,000-1,000,000 |
| Processing for unauthorized purposes -- sensitive personal info | 28 | 2-7 years | PHP 500,000-2,000,000 |
| Unauthorized access / intentional breach | 29 | 1-3 years | PHP 500,000-2,000,000 |
| Concealment of a security breach | 30 | 1.5-5 years | PHP 500,000-1,000,000 |
| Malicious disclosure | 31 | 1.5-5 years | PHP 500,000-1,000,000 |
| Unauthorized disclosure -- personal info | 32(a) | 1-3 years | PHP 500,000-1,000,000 |
| Unauthorized disclosure -- sensitive personal info | 32(b) | 3-5 years | PHP 500,000-2,000,000 |
| Combination/series of acts | 33 | 3-6 years | PHP 1,000,000-5,000,000 |
That is eight distinct substantive offenses (several split into a personal-information tier and a more severe sensitive-personal-information tier), ranging from six months for improper disposal up to seven years for processing sensitive personal information for unauthorized purposes.
Aggravating mechanics (Sections 34-36): where the offender is a corporation, partnership, or other juridical person, the criminal penalty falls on the responsible officers who participated in the act or, through gross negligence, allowed it -- the entity itself cannot be imprisoned, though a court may suspend or revoke its rights under the Act. An alien offender is deported after serving the sentence. A public official convicted under Sections 27-28 faces perpetual or temporary disqualification from public office in addition to the criminal penalty, and Section 36 generally doubles the disqualification term for public-officer offenders.
Section 35 ("Large-Scale") imposes the maximum penalty within the applicable scale when personal information of at least 100 persons is harmed, affected, or involved. This is a distinct threshold from the 100-subject figure in Circular 16-03's breach-notification urgency rule discussed above -- Section 35's 100 is a sentencing-aggravation trigger for a criminal offense already established under Sections 25-33; it has nothing to do with whether or when a breach notification is due.
Administrative Fines
Alongside the criminal track, NPC Circular 2022-01 (effective August 27, 2022) sets administrative fines for violations that don't necessarily rise to criminal conduct: grave violations at 0.5-3% of annual gross income, major violations at 0.25-2%, and other violations -- including registration failures -- at PHP 50,000-200,000. All of these are subject to an aggregate cap of PHP 5,000,000 per proceeding. The often-quoted "3%" figure is the top of the grave-violation band, not an absolute ceiling; the actual ceiling across any combination of violations in a single case is the PHP 5 million aggregate cap.
By comparison, GDPR Article 83(5) sets a maximum administrative fine of up to EUR 20 million or 4% of global annual turnover, whichever is higher, with no equivalent aggregate cap in absolute terms -- the percentage-of-turnover structure means the practical ceiling scales with the size of the organization involved, unlike the Philippines' flat PHP 5 million cap.
Recent NPC Instruments
- NPC Advisory 2024-04 (December 19, 2024) -- AI Guidelines.
- NPC Circular 2024-02 -- CCTV Systems, repealing Advisory 2020-04. Directly relevant to recording-law compliance in the Philippines, though this article does not detail its specific consent or signage mechanics.
- NPC Circular 2025-01 -- Body-Worn Camera processing.
- NPC Advisory 2026-01 -- Data Scraping of publicly available personal data.
- NPC Cease-and-Desist Order against Tools for Humanity, issued October 8, 2025, targeting the World App/Orb iris-scanning biometric collection program. The NPC's order cited invalid consent (monetary incentives undermining freely-given consent), inadequate transparency, excessive collection of biometric data disproportionate to the stated "proof of humanity" purpose, and the immutability risk inherent in biometric data, and noted that Tools for Humanity's operations had already been halted in Kenya and Hong Kong on related grounds. This is a regulatory cease-and-desist order, not a criminal conviction -- RA 10173's Chapter VIII criminal penalties were not applied in this matter, and this order should not be read as an example of the criminal track described above actually resulting in imprisonment.
Dual-Compliance Guidance
| Issue | GDPR Requirement | Philippines DPA Requirement | Compliance Approach |
|---|---|---|---|
| Criminal exposure | None at the EU level; check member-state law separately | Eight offenses with imprisonment 6 months-7 years (Ch. VIII) | Treat RA 10173 compliance as carrying personal criminal risk for responsible officers, not just corporate fine risk |
| Registration | Not required; self-assessed Records of Processing Activities (Art. 30) | Mandatory above defined thresholds, with a physically displayed Seal of Registration (Circular 2022-04) | Check headcount, sensitive-data volume, and automated-decision use against the Circular 2022-04 thresholds independently of any GDPR ROPA already maintained |
| Extraterritorial trigger | Targeting EU data subjects (Art. 3(2)) | PH contract, PH-based management/control, PH branch/subsidiary with data access, or PH citizen/resident data (Sec. 6) | Do not assume GDPR-targeting analysis answers whether Sec. 6 applies -- run the link-based Philippine test separately |
| Erasure right | Right to erasure on multiple independent grounds (Art. 17) | Blocking/removal/destruction conditioned on substantial proof of a specific listed defect (Sec. 16(e)) | Build a Philippine erasure workflow around evidentiary proof of a defect, not a GDPR-style consent-withdrawal trigger |
| Breach notification | Staggered: 72h to regulator, undue delay to individuals | Same 72h clock to both NPC and data subjects (Circular 16-03) | Do not rely on a GDPR-paced breach response plan for Philippine incidents -- the individual-notice clock is as tight as the regulator clock |
| Cross-border transfer | Adequacy decisions, SCCs, BCRs (Ch. V) | Accountability follows the controller via contractual means (Sec. 21) | Maintain GDPR transfer mechanisms on the outbound EU side; separately confirm the Philippine PIC/PIP has its own accountability measures in place, since neither regime substitutes for the other |
| BPO/vendor obligations | Processor obligations under Art. 28 | Full Sec. 14 compliance as a personal information processor, plus possible independent Sec. 24/Circular 2022-04 registration | Confirm a Philippine BPO vendor's own NPC registration status and DPO designation, not only its contractual GDPR processor terms |
Disclaimer
This article presents general legal information about the Philippines' Data Privacy Act of 2012 (RA 10173) and the EU's General Data Protection Regulation. It does not constitute legal advice. The NPC's CCTV (Circular 2024-02), Body-Worn Camera (Circular 2025-01), and data-scraping (Advisory 2026-01) instruments are referenced here by title and date only; their substantive provisions were not independently verified for this article. Organizations subject to RA 10173 or GDPR should consult a lawyer licensed in the relevant jurisdiction before relying on this article for a compliance decision.
Authorities Cited
- National Privacy Commission, Philippines -- full text of the Data Privacy Act of 2012 (RA 10173). https://privacy.gov.ph/data-privacy-act/
- NPC Circular No. 2022-04 -- Registration of Personal Data Processing System, Notification Regarding Automated Decision-Making or Profiling, Designation of Data Protection Officer, and the NPC Seal of Registration (December 5, 2022). https://privacy.gov.ph/wp-content/uploads/2023/05/Circular-2022-04-1.pdf
- NPC Circular No. 2022-01 -- Guidelines on Administrative Fines (August 8, 2022). https://privacy.gov.ph/wp-content/uploads/2022/08/NPC-CIRCULAR-NO.-2022-01-GUIDELINES-ON-ADMINISTRATIVE-FINES-dated-08-AUGUST-2022-w-SGD.pdf
- NPC Circular No. 16-03 -- Personal Data Breach Management (December 15, 2016). https://privacy.gov.ph/wp-content/uploads/2022/01/sgd-npc-circular-16-03-personal-data-breach-management.pdf
- National Privacy Commission -- Cease-and-Desist Order against Tools for Humanity, press release (October 8, 2025). https://privacy.gov.ph/npc-issues-cease-and-desist-order-against-tools-for-humanity/
- National Privacy Commission -- registration walkthrough and fee reference. https://privacy.gov.ph/pips-and-pics/register/
- Regulation (EU) 2016/679 (General Data Protection Regulation). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Last updated: 2026-07-23.
Frequently Asked Questions
Can someone actually go to prison under the Philippines Data Privacy Act?
RA 10173 Chapter VIII creates eight distinct criminal offenses with imprisonment ranges from 6 months (improper disposal of personal information) up to 7 years (processing sensitive personal information for unauthorized purposes). Where the offender is a corporation, the criminal penalty falls on the responsible officers who participated or, through gross negligence, allowed the violation, not on the entity itself. This is a real structural feature of the law, separate from and in addition to the NPC's administrative fines.
Does GDPR have any equivalent criminal penalties?
Not at the EU level. GDPR Article 83 is administrative-fines-only, up to EUR 20 million or 4% of global annual turnover. Article 84 allows individual EU member states to legislate their own criminal offenses for infringements outside Article 83's scope, and a few states such as Germany have narrow criminal provisions under their own implementing law, but there is no EU-wide criminal track and no imprisonment risk written into the Regulation itself.
Who has to register with the National Privacy Commission?
Under NPC Circular 2022-04, registration of data processing systems is mandatory for any personal information controller or processor with 250 or more employees, or that processes sensitive personal information of 1,000 or more individuals, or that engages in processing likely to pose a risk to data subjects, or that uses automated decision-making or profiling regardless of size. Registered entities must display a physical Seal of Registration at their business entrance and on their website, and renew within a 30-day window before annual expiry.
Why doesn't GDPR require this kind of registration?
The GDPR's 2018 framework deliberately replaced the EU's earlier 1995-Directive-era notification and registration system with an accountability model, in which organizations self-assess and maintain internal Records of Processing Activities under Article 30 rather than filing for regulator approval. EU legislators judged the older registration approach too bureaucratic without being meaningfully more protective. The Philippines took the opposite path, rebuilding a mandatory registration regime through NPC Circular 2022-04 in December 2022.
Does the Philippine Data Privacy Act give a right to be forgotten like GDPR?
Not in the same form. Section 16(e) gives data subjects the right to suspend, withdraw, or order the blocking, removal, or destruction of their personal information, but only upon discovery and substantial proof that the information is incomplete, outdated, false, unlawfully obtained, used for an unauthorized purpose, or no longer necessary. That is narrower than several of GDPR Article 17's independent grounds, such as simply withdrawing consent -- the Philippine right requires proving one of the listed defects.
How does Philippine breach notification timing compare to GDPR?
Both the National Privacy Commission and affected data subjects must be notified within 72 hours of a covered breach under NPC Circular 16-03, running from the same trigger. GDPR stages the two notices differently: 72 hours to the supervisory authority under Article 33, but only 'without undue delay' to affected individuals under Article 34, with no fixed hour count for the individual-notice leg.
What is the '100 persons' threshold in Philippine data privacy law, and is it the same everywhere it appears?
No -- there are two unrelated 100-person thresholds. RA 10173 Section 35 uses 'at least 100 persons' affected as the trigger for imposing the maximum criminal sentence in a large-scale violation under Sections 25-33. Separately, NPC Circular 16-03 Section 17(C) uses a 100-individual figure to set a bright line that the 72-hour breach-notification window cannot be stretched once that many data subjects are involved. One is a sentencing rule inside the criminal chapter; the other is a notification-urgency rule inside the breach-management circular. They should not be conflated.
Why does the Philippines' large outsourcing sector matter for this comparison?
The Philippines processes large volumes of US and EU customer data through its business-process-outsourcing industry. RA 10173 Section 14 fully binds a Philippine BPO as a personal information processor under Philippine law in its own right, Section 6 independently reaches a foreign entity with the statute's defined Philippine links, and Section 24 combines with Circular 2022-04's thresholds to put most large-scale BPO operations under the NPC's mandatory registration and DPO-designation requirements directly -- not only through a foreign client's own GDPR compliance program.
Updates
Initial publication. Covers RA 10173's Chapter VIII criminal penalties, the NPC Circular 2022-04 registration regime, extraterritorial/BPO reach under Sections 4 and 6, and the October 2025 Tools for Humanity cease-and-desist order.
Sources and References
- National Privacy Commission, Philippines -- full text of the Data Privacy Act of 2012 (RA 10173)(privacy.gov.ph).gov
- NPC Circular No. 2022-04 -- Registration of Personal Data Processing System, DPO Designation, and NPC Seal of Registration(privacy.gov.ph).gov
- NPC Circular No. 2022-01 -- Guidelines on Administrative Fines(privacy.gov.ph).gov
- NPC Circular No. 16-03 -- Personal Data Breach Management(privacy.gov.ph).gov
- NPC Cease-and-Desist Order against Tools for Humanity, press release(privacy.gov.ph).gov
- NPC PIPs/PICs registration walkthrough and fee reference(privacy.gov.ph).gov
- Regulation (EU) 2016/679 (General Data Protection Regulation) Full Text(eur-lex.europa.eu).gov