{
 "jurisdiction_id": "PH",
 "jurisdiction": "Philippines",
 "url": "https://dataprotection.gi/jurisdictions/philippines/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 40,
  "sub_modules": 57,
  "source_register": 15
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive statute, dedicated regulator, and broad territorial scope are well-evidenced; registration/filing procedural detail is a residual gap.",
   "claims": [
    {
     "statement": "The Data Privacy Act of 2012 established the National Privacy Commission, which enforces and oversees the Act and is endowed with rulemaking power.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The final Implementing Rules and Regulations of the Data Privacy Act came into force on September 9, 2016, adding operative specificity to the statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Privacy Act is broadly applicable to individuals and legal entities that process personal information, with some statutory exceptions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act provides broader extraterritorial application than the GDPR, applying to any use of equipment in the Philippines or acts related to Philippine citizens or residents, not only to entities established in the Philippines.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Special categories and prohibition/exception structure are well evidenced; consent-threshold operative detail and anonymisation/pseudonymisation safe-harbours are thin or explicitly absent.",
   "claims": [
    {
     "statement": "All processing of sensitive personal information under the Act is prohibited except under enumerated statutory exceptions, including necessity to protect the lawful rights of data subjects in court or legal proceedings.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Consent is not required for processing where the data subject is party to a contract for purposes of fulfilling that contract; exceptions to consent also exist for legal obligation, protection of vital interests, response to national emergency, and pursuit of legitimate interests not overridden by data-subject rights.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act defines sensitive personal information to include data about race, ethnic origin, marital status, age, color, religious/philosophical/political affiliations, health, education, genetic or sexual life, offenses, government-issued unique identifiers, and information classified by executive order or act of Congress.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A pending House-approved substitute bill would expand the statutory definition of sensitive information to include biometric, genetic, and political affiliation data explicitly.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/b/npc-announces-bill-to-amend-philippines-privacy-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Neither the Act nor its IRR explicitly define anonymised or pseudonymised data, beyond a brief reference to storing personal data that does not permit identification of the data subject.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights are confirmed via secondary legal summary; granular statutory deadlines and restriction/objection procedure text are a gap.",
   "claims": [
    {
     "statement": "The Act enumerates data-subject rights familiar to privacy professionals relating to the principles of notice, choice, access, and accuracy and integrity of data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act contains a right-to-be-forgotten analogue in the form of a right to erasure or blocking, under which a data subject may order removal of personal data from the controller's filing system.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A right to data portability is provided under the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability, DPO, security, and breach-notification obligations are well evidenced with specific dates and mechanics; DPIA is an explicit gap flagged by secondary sources themselves.",
   "claims": [
    {
     "statement": "Neither the Data Privacy Act nor its IRR explicitly refer to Data Protection Impact Assessments.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Both the Act's IRR and general practice require appointment of a DPO/compliance officer responsible for ensuring compliance with applicable data-protection laws and regulations, although the Act and IRR do not specify the precise triggering cases, group-appointment rules, or qualification requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act requires that data-sharing be covered by an agreement providing adequate safeguards for data-subject rights, with such agreements subject to review by the National Privacy Commission.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NPC Circular 2023-06, issued April 1, 2024, updates security requirements for personal data, detailing obligations for data protection officers, data processing systems, and privacy management programs, mandates business continuity plans, and repeals NPC Circular No. 16-01.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/philippines-npc-issues-circulars-further-strengthen",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act places a concurrent obligation on controllers to notify the National Privacy Commission and affected data subjects within 72 hours of knowledge of, or reasonable belief of, a personal data breach that requires notification.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Notification is required only where the breached information is sensitive personal information or information usable for identity fraud, unauthorized acquisition is reasonably believed to have occurred, and the potential harm is serious; the Commission may determine that notification to data subjects is unwarranted based on the controller's compliance and good faith.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "All personal data breach notifications and annual security incident reports must be submitted through the NPC's Data Breach Notification Management System; submissions by email, personal filing, ordinary mail, or courier are not accepted.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/philippines-npc-publishes-statement-regarding",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A joint NPC, DICT and SEC advisory addressing online lending platforms sets retention expectations for personal data processed by such platforms as part of broader anti-harassment and consent safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/philippines-npc-dict-and-sec-issue-joint-advisory",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer-mechanism (data-sharing agreement) requirement is confirmed; adequacy-received/granted and TIA/localisation sub-modules lack direct sourcing this run.",
   "claims": [
    {
     "statement": "The Act requires that data-sharing, including cross-border sharing, be covered by an agreement providing adequate safeguards for data-subject rights, subject to NPC review.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 7(o) of the Data Privacy Act grants the National Privacy Commission the ability to negotiate and contract with other data privacy authorities of other countries for cross-border application and implementation of respective privacy laws and to facilitate cross-border enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Privacy Commissioner of Canada",
     "source_url": "https://www.priv.gc.ca/en/about-the-opc/what-we-do/international-collaboration/memorandums-of-understanding/mou-philippines/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial-sector and telecoms overlays are well evidenced; health, education, insurance, credit-scoring, and employment sub-modules lack direct sourcing this run.",
   "claims": [
    {
     "statement": "The Act and IRR are supplemented by the Secrecy of Bank Deposits Act (RA 1405), the Foreign Currency Deposit Act (RA 6426), and the Credit Information System Act (RA 9510) as overlay financial-sector instruments.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NPC Circular No. 20-01 sets guidelines on the processing of personal data for loan-related transactions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "National Privacy Commission",
     "source_url": "https://www.privacy.gov.ph/wp-content/uploads/2020/10/NPC-Circular-No.-20-01.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A joint NPC, DICT and SEC advisory (issued March 18, 2026) addresses processing of personal data by online lending platforms, requiring separate consent interfaces for guarantors/character references and prohibiting excessive data processing and harassment in debt collection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/philippines-npc-dict-and-sec-issue-joint-advisory",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SIM-Card Registration Act requires telecommunications providers to conduct Privacy Impact Assessments, train employees and supply chains to prevent data breaches, and afford appropriate organisational, technical, and physical security measures to secure subscriber personal data and prevent unauthorised disclosure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/philippines-house-representatives-approves-act-sim-card",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Credit Information System Act (RA 9510) is referenced as an overlay statute interacting with the Data Privacy Act's general regime, though detailed credit-scoring-specific data rules were not retrieved.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Data-scraping advisory is well evidenced; cookie/tracker, opt-out-signal, clean-room, cross-context-advertising, and direct-marketing sub-modules lack direct PH-specific sourcing this run.",
   "claims": [
    {
     "statement": "NPC Advisory No. 2026-01, issued April 13, 2026, provides guidelines on the scraping of publicly available personal data and reiterates that Data Privacy Act protections continue to apply even where personal data is publicly accessible online, requiring PICs to define legitimate purposes, inform data subjects, implement security measures, and conduct Privacy Impact Assessments for scraping activities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/philippines-npc-issues-advisory-data-scraping",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "ADM/profiling notification duty is confirmed at IRR-provision level; AI-specific binding guidance and biometric/genetic/state-surveillance sub-modules are thinly sourced.",
   "claims": [
    {
     "statement": "Section 3(p) of the IRR defines 'profiling' as any form of automated processing of personal data used to evaluate personal aspects such as a natural person's work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 48 of the IRR requires a personal information controller carrying out wholly or partly automated processing operations to notify the NPC when the automated processing becomes the sole basis for making decisions about a data subject that would significantly affect that data subject.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NPC has developed binding guidance applying the Data Privacy Act to AI systems, according to industry-conference descriptions of Philippine regulatory practice as of mid-2026.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/conference/iapp-asia-forum/agenda/af26-how-asian-regulators-are-shaping-ai-and-data-governance",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Child-oriented transparency guidance is well evidenced and recent; statutory age-of-consent/parental-consent thresholds and dependent-adult protections remain thinly sourced.",
   "claims": [
    {
     "statement": "NPC Advisory Opinion No. 2024-03 highlights the involvement of parents or guardians in data-processing activities concerning children's personal information and requires notification of data breaches involving children's personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/philippines-npcs-advisory-child-oriented",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Advisory mandates that privacy notices addressed to children be accessible and understandable and prohibits deceptive design patterns that compromise children's privacy.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/philippines-npcs-advisory-child-oriented",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NPC Advisory Opinion No. 2024-03 defines a 'child' to include a person below eighteen years of age or a person 18 or over who is unable to fully take care of themselves or protect themselves from abuse, neglect, cruelty, exploitation, or discrimination due to a physical or mental disability or condition.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/philippines-npc-issues-advisory-opinion-guidelines",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/philippines/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Penalty structure, criminal sanctions, and recent 180-day developments are well evidenced; enforcement-activity-index and regulator-funding/capacity sub-modules lack quantified sourcing this run.",
   "claims": [
    {
     "statement": "The Act provides the NPC with corrective and investigative powers similar to data protection authorities under the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v_data_privacy_act_and_irrs_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NPC updated administrative-fine rules to cap penalties at 5,000,000 pesos, whether arising from a single violation or multiple violations, by a personal information controller or processor, replacing an earlier scheme of 0.25%-3% of gross income for grave violations and 0.25%-2% for major violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/b/philippines-npc-implements-cap-on-penalties-for-violations-of-the-data-privacy-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Combinations or series of criminal acts under the Act (e.g. unauthorized processing, negligent access, malicious disclosure) can subject an offender to imprisonment ranging from three to six years and fines of approximately $20,000 to $100,000, separate from concealment penalties of 1.5 to 5 years imprisonment and $10,000-$20,000 fines for failure to report a breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act provides for a private right of action for damages available to affected data subjects, applicable alongside criminal and administrative penalties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/summary-philippines-data-protection-act-and-implementing-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On April 13, 2026, the NPC issued Advisory No. 2026-01 providing guidelines on lawful scraping of publicly available personal data and reiterating that Data Privacy Act protections apply even to publicly accessible online data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/philippines-npc-issues-advisory-data-scraping",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On March 18, 2026, the NPC, DICT, and SEC issued a joint advisory addressing personal-data processing by online lending platforms, warning that violations may result in fines and revocation of operating authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/philippines-npc-dict-and-sec-issue-joint-advisory",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}