🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
PH · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 15 sources retrieved model claude-sonnet-5 ·

Philippines

PH schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 40 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
40Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

The National Privacy Commission's Circular No. 2023-06 took effect on March 30, 2024, correcting an earlier reported effective date of April 1, 2024. Section 5 of that circular imposes a mandatory Privacy Impact Assessment obligation on every processing system operated by a personal information controller or processor, and this obligation, layered onto National Privacy Commission Privacy Impact Assessment guidance dating to a 2017 advisory, materially narrows earlier commentary describing a divergence between the Philippine regime and GDPR Article 35's Data Protection Impact Assessment requirement. Neither the Data Privacy Act of 2012 nor its Implementing Rules and Regulations name Data Protection Impact Assessments by that term, though National Privacy Commission Privacy Impact Assessment guidance has existed since a 2017 advisory.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute, dedicated regulator, and broad territorial scope are well-evidenced; registration/filing procedural detail is a residual gap.

Primary frameworkData Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations
Traffic-light rationale — GreenComprehensive statute, dedicated regulator, and broad territorial scope are well-evidenced; registration/filing procedural detail is a residual gap.

Sub-modules (5)

Regulator And AuthorityGreen

The NPC was established under the Act as the enforcing and rule-making authority.

Claims: CLM-PH-a1b2c3d4

Act And InstrumentsGreen

RA 10173 plus its 2016 IRR form the operative instrument set.

Claims: CLM-PH-b2c3d4e5

Material ScopeGreen

The Act applies broadly to individuals and legal entities processing personal information, subject to enumerated exceptions.

Claims: CLM-PH-c3d4e5f6

Territorial ScopeGreen

Extraterritorial scope extends to use of equipment located in the Philippines and to processing relating to Philippine citizens/residents, broader than GDPR Art 3.

Claims: CLM-PH-d4e5f6a7

Regulator Registration And FilingAmber

NPC circulars (e.g. 2022-04, 17-01) govern registration of data processing systems and DPOs, but full operative text was not retrievable this run beyond title-level confirmation.

Absence provenance: not recorded. Searched: not recorded.

Category narrative79 words

The Philippines operates a comprehensive omnibus data protection regime under the Data Privacy Act of 2012 (Republic Act No. 10173, 'the Act'), enforced by the National Privacy Commission (NPC). The Act has broad extraterritorial reach and is supplemented by an extensive body of NPC circulars and advisories. Registration/filing content for specific NPC circulars (e.g. Circular 2022-04, 17-01) could not be retrieved in substantive form during this run (only cookie-boilerplate stubs returned), so registration mechanics are flagged as a gap.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedIAPPThe Data Privacy Act of 2012 established the National Privacy Commission, which enforces and oversees the Act and is endowed with rulemaking power.
  2. ConfirmedIAPPThe final Implementing Rules and Regulations of the Data Privacy Act came into force on September 9, 2016, adding operative specificity to the statute.
  3. ConfirmedIAPPThe Data Privacy Act is broadly applicable to individuals and legal entities that process personal information, with some statutory exceptions.
  4. ConfirmedDataGuidanceThe Act provides broader extraterritorial application than the GDPR, applying to any use of equipment in the Philippines or acts related to Philippine citizens or residents, not only to entities established in the Philippines.

#

Special categories and prohibition/exception structure are well evidenced; consent-threshold operative detail and anonymisation/pseudonymisation safe-harbours are thin or explicitly absent.

Primary frameworkData Privacy Act of 2012 (RA 10173) and IRR
Traffic-light rationale — AmberSpecial categories and prohibition/exception structure are well evidenced; consent-threshold operative detail and anonymisation/pseudonymisation safe-harbours are thin or explicitly absent.

Sub-modules (4)

Lawful BasesGreen

Processing of sensitive personal information is prohibited absent an enumerated statutory basis; general personal information processing bases include contract, consent, legal obligation, vital interest, and legitimate interest (subject to override by data-subject rights).

Claims: CLM-PH-e5f6a7b8, CLM-PH-f6a7b8c9

Special CategoriesGreen

Sensitive personal information is broadly defined and subject to a general processing prohibition with enumerated exceptions.

Claims: CLM-PH-a7b8c9d0, CLM-PH-b8c9d0e1

Pseudonymisation And AnonymisationAmber

Neither the Act nor the IRR explicitly define anonymised or pseudonymised data, beyond a brief reference to storage that does not permit identification of the data subject.

Claims: CLM-PH-c9d0e1f2

Category narrative48 words

The Act adopts a prohibition-with-exceptions model for sensitive personal information and defines an expansive category of 'sensitive personal information'. Neither the Act nor the IRR provide explicit definitions of anonymisation/pseudonymisation, a documented gap relative to GDPR. Consent-guidelines circular content could not be retrieved in substantive form this run.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedIAPPAll processing of sensitive personal information under the Act is prohibited except under enumerated statutory exceptions, including necessity to protect the lawful rights of data subjects in court or legal proceedings.
  2. ConfirmedIAPPConsent is not required for processing where the data subject is party to a contract for purposes of fulfilling that contract; exceptions to consent also exist for legal obligation, protection of vital interests, response to national emergency, and pursuit of legitimate interests not overridden by data-subject rights.
  3. ConfirmedIAPPThe Act defines sensitive personal information to include data about race, ethnic origin, marital status, age, color, religious/philosophical/political affiliations, health, education, genetic or sexual life, offenses, government-issued unique identifiers, and information classified by executive order or act of Congress.
  4. ProbableIAPPA pending House-approved substitute bill would expand the statutory definition of sensitive information to include biometric, genetic, and political affiliation data explicitly.
  5. ConfirmedDataGuidanceNeither the Act nor its IRR explicitly define anonymised or pseudonymised data, beyond a brief reference to storing personal data that does not permit identification of the data subject.

#

Core rights are confirmed via secondary legal summary; granular statutory deadlines and restriction/objection procedure text are a gap.

Primary frameworkData Privacy Act of 2012 (RA 10173), Sections 16-18
Traffic-light rationale — AmberCore rights are confirmed via secondary legal summary; granular statutory deadlines and restriction/objection procedure text are a gap.

Sub-modules (5)

Access RightGreen

The Act enumerates rights related to notice, choice, access, and accuracy/integrity of data.

Claims: CLM-PH-d0e1f2a3

Rectification And ErasureGreen

The Act contains a right-to-be-forgotten analogue permitting a data subject to order removal (erasure/blocking) of personal data from a controller's filing system.

Claims: CLM-PH-e1f2a3b4

Restriction And ObjectionAmber

Restriction/objection mechanics were not independently retrievable beyond the general rights enumeration this run.

Absence provenance: not recorded. Searched: not recorded.

Data PortabilityGreen

The Act provides a right to data portability.

Claims: CLM-PH-f2a3b4c5

Deadlines And Response WindowsAmber

Statutory response-window detail for subject-access/erasure requests specifically was not retrieved this run; only the 72-hour breach-notification deadline (a controller-to-regulator/subject obligation, not a DSR response window) is well evidenced.

Absence provenance: not recorded. Searched: not recorded.

Category narrative41 words

The Act enumerates data-subject rights aligned to notice, choice, access, accuracy/integrity, erasure/blocking ('right to be forgotten' analogue), and data portability. Detailed procedural mechanics (specific response-window statutory text, restriction/objection operative detail) were not fully retrievable in this run beyond summary-level secondary analysis.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedIAPPThe Act enumerates data-subject rights familiar to privacy professionals relating to the principles of notice, choice, access, and accuracy and integrity of data.
  2. ConfirmedIAPPThe Act contains a right-to-be-forgotten analogue in the form of a right to erasure or blocking, under which a data subject may order removal of personal data from the controller's filing system.
  3. ConfirmedIAPPA right to data portability is provided under the Act.

#

Core accountability, DPO, security, and breach-notification obligations are well evidenced with specific dates and mechanics; DPIA is an explicit gap flagged by secondary sources themselves.

Primary frameworkData Privacy Act of 2012 (RA 10173), IRR, NPC Circular 2023-06
Traffic-light rationale — GreenCore accountability, DPO, security, and breach-notification obligations are well evidenced with specific dates and mechanics; DPIA is an explicit gap flagged by secondary sources themselves.

Sub-modules (7)

Accountability And DpiaAmber

Neither the Act nor the IRR name DPIAs by that term, but NPC Circular No. 2023-06 (Section 5) imposes a mandatory Privacy Impact Assessment (PIA) obligation on every PIC/PIP processing system, and NPC PIA guidance (Advisory No. 2017-03 and predecessor circulars) has existed since 2017 - materially narrowing, though not eliminating, the divergence from GDPR Art 35.

Claims: CLM-PH-a3b4c5d6

Dpo RequirementsGreen

Both the IRR and the Act provide for appointment of a DPO/compliance officer, though statutory text does not specify triggering thresholds; the NPC has issued clarifying advisories (e.g. NPC Advisory No. 2017-01).

Claims: CLM-PH-b4c5d6e7

Ropa RequirementsAmber

Records-of-processing detail was not independently retrieved beyond the general privacy-program obligation this run.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsGreen

The Act requires that data-sharing be governed by an agreement providing adequate safeguards, subject to NPC review.

Claims: CLM-PH-c5d6e7f8

Security MeasuresGreen

NPC Circular 2023-06 (effective March 30, 2024, per NPC's own announcement - not the April 1, 2024 public-announcement date previously reported) updated security-of-processing requirements including business-continuity planning; the 12-month compliance transitory period runs through March 30, 2025.

Claims: CLM-PH-d6e7f8a9

Breach NotificationGreen

Controllers face a concurrent 72-hour breach-notification obligation to the NPC and affected data subjects for breaches meeting statutory severity/harm thresholds; submissions must be made via the NPC's Data Breach Notification Management System.

Claims: CLM-PH-e7f8a9b0, CLM-PH-f8a9b0c1, CLM-PH-a9b0c1d2

Retention And DisposalAmber

Retention/disposal duties are referenced generally (e.g. NPC/DICT/SEC joint advisory on lending-platform data retention) but no comprehensive statutory retention-period schedule was retrieved this run.

Claims: CLM-PH-b0c1d2e3

Category narrative61 words

Controllers must implement privacy and security programs, appoint DPOs/compliance officers, execute reviewable data-sharing agreements, and comply with a 72-hour concurrent breach-notification obligation to the NPC and affected data subjects for qualifying breaches. NPC Circular 2023-06 (effective April 2024) updated security-of-processing obligations including business-continuity planning. DPIAs are not explicitly named in the Act or IRR, a documented divergence from GDPR Art 35.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedDataGuidanceNeither the Data Privacy Act nor its IRR explicitly refer to Data Protection Impact Assessments.
  2. ConfirmedDataGuidanceBoth the Act's IRR and general practice require appointment of a DPO/compliance officer responsible for ensuring compliance with applicable data-protection laws and regulations, although the Act and IRR do not specify the precise triggering cases, group-appointment rules, or qualification requirements.
  3. ConfirmedIAPPThe Act requires that data-sharing be covered by an agreement providing adequate safeguards for data-subject rights, with such agreements subject to review by the National Privacy Commission.
  4. ConfirmedDataGuidanceNPC Circular 2023-06, issued April 1, 2024, updates security requirements for personal data, detailing obligations for data protection officers, data processing systems, and privacy management programs, mandates business continuity plans, and repeals NPC Circular No. 16-01.
  5. ConfirmedIAPPThe Act places a concurrent obligation on controllers to notify the National Privacy Commission and affected data subjects within 72 hours of knowledge of, or reasonable belief of, a personal data breach that requires notification.
  6. ConfirmedIAPPNotification is required only where the breached information is sensitive personal information or information usable for identity fraud, unauthorized acquisition is reasonably believed to have occurred, and the potential harm is serious; the Commission may determine that notification to data subjects is unwarranted based on the controller's compliance and good faith.
  7. ConfirmedDataGuidanceAll personal data breach notifications and annual security incident reports must be submitted through the NPC's Data Breach Notification Management System; submissions by email, personal filing, ordinary mail, or courier are not accepted.
  8. ProbableDataGuidanceA joint NPC, DICT and SEC advisory addressing online lending platforms sets retention expectations for personal data processed by such platforms as part of broader anti-harassment and consent safeguards.

#

Transfer-mechanism (data-sharing agreement) requirement is confirmed; adequacy-received/granted and TIA/localisation sub-modules lack direct sourcing this run.

Primary frameworkData Privacy Act of 2012 (RA 10173), Section 7(o)
Traffic-light rationale — AmberTransfer-mechanism (data-sharing agreement) requirement is confirmed; adequacy-received/granted and TIA/localisation sub-modules lack direct sourcing this run.

Sub-modules (6)

Transfer MechanismsGreen

Cross-border data sharing must be governed by an agreement providing adequate safeguards, reviewable by the NPC; Section 7(o) empowers the NPC to negotiate and contract with foreign data-privacy authorities for cross-border enforcement.

Claims: CLM-PH-c1d2e3f4, CLM-PH-d2e3f4a5

Adequacy ReceivedRed

No formal foreign adequacy decision recognizing the Philippine regime was identified in this run.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

No PH-issued adequacy determinations toward other regimes were identified.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsAmber

No PH-specific standard contractual clause template or BCR-approval mechanism was identified this run beyond the general data-sharing-agreement requirement.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No explicit statutory or NPC-circular TIA requirement analogous to Schrems II practice was identified this run.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No general data-localisation mandate was identified for the Philippines in this run.

Absence provenance: not recorded. Searched: not recorded.

Category narrative64 words

The Act requires data-sharing agreements (domestic or cross-border) to provide adequate safeguards and be subject to NPC review; no formal EU-style adequacy decision covering the Philippines was identified. The Philippines has bilateral cooperation MoUs with the UK ICO and Canadian OPC facilitating cross-border enforcement cooperation, though these MoUs expressly do not compel information-sharing. No evidence of a Philippine data-localisation mandate was found this run.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedIAPPThe Act requires that data-sharing, including cross-border sharing, be covered by an agreement providing adequate safeguards for data-subject rights, subject to NPC review.
  2. ConfirmedOffice of the Privacy Commissioner of CanadaSection 7(o) of the Data Privacy Act grants the National Privacy Commission the ability to negotiate and contract with other data privacy authorities of other countries for cross-border application and implementation of respective privacy laws and to facilitate cross-border enforcement.

#

Financial-sector and telecoms overlays are well evidenced; health, education, insurance, credit-scoring, and employment sub-modules lack direct sourcing this run.

Primary frameworkData Privacy Act of 2012 (RA 10173); Bank Secrecy Act (RA 1405); Foreign Currency Deposit Act (RA 6426); Credit Information System Act (RA 9510); SIM Registration Act (RA 11934)
Traffic-light rationale — AmberFinancial-sector and telecoms overlays are well evidenced; health, education, insurance, credit-scoring, and employment sub-modules lack direct sourcing this run.

Sub-modules (7)

Financial Sector OverlayAmber

The Act and IRR explicitly interact with the Bank Secrecy Act, Foreign Currency Deposit Act, and Credit Information System Act; NPC Circular 20-01 and a joint NPC/DICT/SEC advisory govern loan-related and online-lending data processing.

Claims: CLM-PH-e3f4a5b6, CLM-PH-f4a5b6c7, CLM-PH-a5b6c7d8

Health Sector OverlayRed

No dedicated health-sector DP overlay instrument was retrieved this run beyond the Act's general 'health' special-category coverage.

Absence provenance: not recorded. Searched: not recorded.

Telecoms And EprivacyGreen

The SIM-Card Registration Act requires telecommunications providers to conduct Privacy Impact Assessments and implement organisational, technical and physical security measures to prevent unauthorised disclosure of subscriber personal data.

Claims: CLM-PH-b6c7d8e9

Employment DataRed

No employment-sector-specific DP instrument was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Credit And ScoringAmber

The Credit Information System Act (RA 9510) is flagged as an overlay instrument alongside the Act, but detailed credit-scoring rules were not retrieved.

Claims: CLM-PH-c7d8e9f0

EducationRed

No education-sector-specific DP overlay was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

InsuranceRed

No insurance-sector-specific DP overlay was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Category narrative51 words

Sector-specific overlays interact with the general DP regime particularly in financial services (bank-secrecy and credit-information statutes referenced alongside the Act; NPC Circular 20-01 for loan-related transaction data; joint NPC/DICT/SEC advisory on online lending platforms) and telecoms (SIM Registration Act). No dedicated health, education, or insurance-sector DP overlay was retrieved this run.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe Act and IRR are supplemented by the Secrecy of Bank Deposits Act (RA 1405), the Foreign Currency Deposit Act (RA 6426), and the Credit Information System Act (RA 9510) as overlay financial-sector instruments.
  2. ConfirmedNational Privacy CommissionNPC Circular No. 20-01 sets guidelines on the processing of personal data for loan-related transactions.
  3. ConfirmedDataGuidanceA joint NPC, DICT and SEC advisory (issued March 18, 2026) addresses processing of personal data by online lending platforms, requiring separate consent interfaces for guarantors/character references and prohibiting excessive data processing and harassment in debt collection.
  4. ConfirmedDataGuidanceThe SIM-Card Registration Act requires telecommunications providers to conduct Privacy Impact Assessments, train employees and supply chains to prevent data breaches, and afford appropriate organisational, technical, and physical security measures to secure subscriber personal data and prevent unauthorised disclosure.
  5. UncertainDataGuidanceThe Credit Information System Act (RA 9510) is referenced as an overlay statute interacting with the Data Privacy Act's general regime, though detailed credit-scoring-specific data rules were not retrieved.

#

Data-scraping advisory is well evidenced; cookie/tracker, opt-out-signal, clean-room, cross-context-advertising, and direct-marketing sub-modules lack direct PH-specific sourcing this run.

Primary frameworkData Privacy Act of 2012 (RA 10173); NPC Advisory No. 2026-01
Traffic-light rationale — AmberData-scraping advisory is well evidenced; cookie/tracker, opt-out-signal, clean-room, cross-context-advertising, and direct-marketing sub-modules lack direct PH-specific sourcing this run.

Sub-modules (6)

Cookies And TrackersRed

No PH-specific cookie/tracker consent instrument distinct from the general Act consent framework was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Dark PatternsAmber

No general-audience dark-pattern prohibition was retrieved this run outside the children-specific advisory (see children_and_vulnerable_groups).

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsRed

No PH-specific Global Privacy Control/DAA-equivalent opt-out-signal mechanism was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific PH guidance was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingAmber

The NPC's data-scraping advisory addresses processing of publicly available personal data that may be exploited for advertising/profiling purposes, requiring PICs to define legitimate purposes and conduct Privacy Impact Assessments.

Claims: CLM-PH-d8e9f0a1

Direct MarketingRed

No PH-specific direct-marketing consent/suppression instrument was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Category narrative59 words

NPC Advisory No. 2026-01 (issued April 13, 2026) is the most direct recent evidence in this module, addressing lawful scraping of publicly available personal data for commercial/adtech-adjacent uses. No dedicated cookie-consent, dark-pattern, opt-out-signal, clean-room, or direct-marketing-specific NPC instrument was retrieved this run beyond the general consent/transparency framework and the child-oriented advisory's prohibition on deceptive design patterns (cross-referenced in children_and_vulnerable_groups).

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ConfirmedDataGuidanceNPC Advisory No. 2026-01, issued April 13, 2026, provides guidelines on the scraping of publicly available personal data and reiterates that Data Privacy Act protections continue to apply even where personal data is publicly accessible online, requiring PICs to define legitimate purposes, inform data subjects, implement security measures, and conduct Privacy Impact Assessments for scraping activities.

#

ADM/profiling notification duty is confirmed at IRR-provision level; AI-specific binding guidance and biometric/genetic/state-surveillance sub-modules are thinly sourced.

Primary frameworkData Privacy Act of 2012 IRR, Section 48
Traffic-light rationale — AmberADM/profiling notification duty is confirmed at IRR-provision level; AI-specific binding guidance and biometric/genetic/state-surveillance sub-modules are thinly sourced.

Sub-modules (6)

Profiling RestrictionsGreen

The IRR defines 'profiling' as automated processing used to evaluate personal aspects such as work performance, economic situation, health, preferences, reliability, behaviour, location or movements.

Claims: CLM-PH-e9f0a1b2

Automated Decision Making TransparencyGreen

Section 48 of the IRR requires a personal information controller to notify the NPC when automated processing becomes the sole basis for decisions significantly affecting a data subject.

Claims: CLM-PH-f0a1b2c3

Ai Risk AssessmentsAmber

Per an IAPP conference description, the NPC has issued 'binding guidance on AI systems' under the Data Privacy Act, but the underlying advisory text was not independently retrieved this run.

Claims: CLM-PH-a1b2c3d5

Biometric RegimeAmber

No standalone biometric-data statute was retrieved; biometric data is proposed for explicit inclusion in the sensitive-information definition via the pending amendment bill.

Absence provenance: not recorded. Searched: not recorded.

Genetic DataAmber

Genetic data is already covered under the existing 'health...genetic or sexual life' limb of sensitive personal information; the pending amendment bill would make genetic data an explicit standalone category.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsRed

No specific national-security/state-surveillance carve-out provision was retrieved this run beyond the general statutory exceptions to the sensitive-data processing prohibition.

Absence provenance: not recorded. Searched: not recorded.

Category narrative85 words

The IRR requires notification to the NPC where automated processing becomes the sole basis for decisions significantly affecting a data subject, and defines 'profiling' in terms tracking GDPR Art 22. The NPC has reportedly issued binding guidance on AI systems under the Data Privacy Act per an IAPP conference description, though the underlying advisory's full text was not independently retrieved this run. No dedicated biometric-regime or genetic-data-specific statute was retrieved beyond the pending amendment bill's proposal to add biometric/genetic data to sensitive-information definitions (see lawful_processing_and_special_data).

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedDataGuidanceSection 3(p) of the IRR defines 'profiling' as any form of automated processing of personal data used to evaluate personal aspects such as a natural person's work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
  2. ConfirmedDataGuidanceSection 48 of the IRR requires a personal information controller carrying out wholly or partly automated processing operations to notify the NPC when the automated processing becomes the sole basis for making decisions about a data subject that would significantly affect that data subject.
  3. UncertainIAPPThe NPC has developed binding guidance applying the Data Privacy Act to AI systems, according to industry-conference descriptions of Philippine regulatory practice as of mid-2026.

#

Child-oriented transparency guidance is well evidenced and recent; statutory age-of-consent/parental-consent thresholds and dependent-adult protections remain thinly sourced.

Primary frameworkNPC Advisory Opinion No. 2024-03 (Guidelines on Child-Oriented Transparency); Data Privacy Act of 2012
Traffic-light rationale — AmberChild-oriented transparency guidance is well evidenced and recent; statutory age-of-consent/parental-consent thresholds and dependent-adult protections remain thinly sourced.

Sub-modules (5)

Age VerificationAmber

No dedicated statutory age-verification mechanism was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Minor Profiling BansAmber

The Advisory prohibits deceptive design patterns that compromise children's privacy, an adjacent but not identical protection to an outright profiling ban.

Claims: CLM-PH-c3d4e5f7

Education SettingsRed

No education-setting-specific children's-data instrument was retrieved this run beyond the general child-oriented transparency advisory.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsAmber

The Advisory's definition of 'child' extends coverage to persons 18 or over who are unable to care for themselves due to disability, providing partial coverage of dependent adults.

Claims: CLM-PH-d4e5f6a8

Category narrative69 words

NPC Advisory Opinion No. 2024-03 (issued December 17, 2024) establishes child-oriented transparency guidelines, defining 'child' broadly and requiring age-appropriate privacy notices, Child Privacy Impact Assessments, prohibition of deceptive design patterns, and parental/guardian involvement. No age-of-consent threshold or COPPA/GDPR-Art-8-style parental-consent age was located in retrieved sources; the Act and IRR reportedly do not define 'child' or provide minor-specific processing requirements, a gap the 2024 Advisory Opinion appears to address administratively.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedDataGuidanceNPC Advisory Opinion No. 2024-03 highlights the involvement of parents or guardians in data-processing activities concerning children's personal information and requires notification of data breaches involving children's personal information.
  2. ConfirmedDataGuidanceThe Advisory mandates that privacy notices addressed to children be accessible and understandable and prohibits deceptive design patterns that compromise children's privacy.
  3. ConfirmedDataGuidanceNPC Advisory Opinion No. 2024-03 defines a 'child' to include a person below eighteen years of age or a person 18 or over who is unable to fully take care of themselves or protect themselves from abuse, neglect, cruelty, exploitation, or discrimination due to a physical or mental disability or condition.

#

Penalty structure, criminal sanctions, and recent 180-day developments are well evidenced; enforcement-activity-index and regulator-funding/capacity sub-modules lack quantified sourcing this run.

Primary frameworkData Privacy Act of 2012 (RA 10173); NPC Circular on Administrative Fines
Traffic-light rationale — AmberPenalty structure, criminal sanctions, and recent 180-day developments are well evidenced; enforcement-activity-index and regulator-funding/capacity sub-modules lack quantified sourcing this run.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The NPC has corrective and investigative powers akin to GDPR DPAs; administrative fines are capped at PHP 5,000,000 per controller/processor; criminal penalties include imprisonment ranging up to six years and fines up to roughly $100,000 for combined offences.

Claims: CLM-PH-e5f6a7b9, CLM-PH-f6a7b8c0, CLM-PH-a7b8c9d1

Enforcement Activity IndexAmber

No aggregated 12-month enforcement-activity index (case counts, total fines) was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Regulator Funding And CapacityRed

No headcount/budget capacity data for the NPC was retrieved this run.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsAmber

No dedicated class-action/collective-redress mechanism specific to data-privacy claims was retrieved this run beyond the general private right of action.

Absence provenance: not recorded. Searched: not recorded.

Private Right Of ActionGreen

The Act provides a private right of action for damages available to data subjects independent of NPC administrative/criminal enforcement.

Claims: CLM-PH-b8c9d0e2

Recent Developments 180DAmber

Within the last 180 days, the NPC issued Advisory No. 2026-01 on data scraping (April 13, 2026) and joined DICT/SEC in a March 18, 2026 advisory on online lending platforms; a House-approved substitute bill to amend the Data Privacy Act remains pending.

Claims: CLM-PH-c9d0e1f3, CLM-PH-d0e1f2a4

Category narrative93 words

The NPC has corrective and investigative powers comparable to GDPR authorities. Administrative fines are capped at 5,000,000 pesos per controller/processor regardless of the number of violations, replacing an earlier percentage-of-gross-income model; criminal penalties (imprisonment plus fines) apply separately for specific offences including unauthorized processing, breach concealment, and malicious disclosure, alongside a private right of action for damages. A pending House-approved substitute bill would further empower the NPC, including introducing a new fine scheme, and update extraterritorial scope. Recent 180-day developments include the April 2026 data-scraping advisory and the March 2026 joint online-lending advisory.

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedDataGuidanceThe Act provides the NPC with corrective and investigative powers similar to data protection authorities under the GDPR.
  2. ConfirmedIAPPThe NPC updated administrative-fine rules to cap penalties at 5,000,000 pesos, whether arising from a single violation or multiple violations, by a personal information controller or processor, replacing an earlier scheme of 0.25%-3% of gross income for grave violations and 0.25%-2% for major violations.
  3. ConfirmedIAPPCombinations or series of criminal acts under the Act (e.g. unauthorized processing, negligent access, malicious disclosure) can subject an offender to imprisonment ranging from three to six years and fines of approximately $20,000 to $100,000, separate from concealment penalties of 1.5 to 5 years imprisonment and $10,000-$20,000 fines for failure to report a breach.
  4. ConfirmedIAPPThe Act provides for a private right of action for damages available to affected data subjects, applicable alongside criminal and administrative penalties.
  5. ConfirmedDataGuidanceOn April 13, 2026, the NPC issued Advisory No. 2026-01 providing guidelines on lawful scraping of publicly available personal data and reiterating that Data Privacy Act protections apply even to publicly accessible online data.
  6. ConfirmedDataGuidanceOn March 18, 2026, the NPC, DICT, and SEC issued a joint advisory addressing personal-data processing by online lending platforms, warning that violations may result in fines and revocation of operating authority.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Philippines
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s), 15 source(s) in the cumulative register.