Don’t do SECURITY. Do business SECURELY.

Philippines enacts the Data Privacy Act of 2012

The Philippines enacts Republic Act 10173, the Data Privacy Act of 2012.

The Philippines has enacted the Data Privacy Act of 2012 (Republic Act 10173), establishing a comprehensive data protection law and a new regulator.

Key points

  • Requires organisational, physical and technical security measures.
  • Creates the National Privacy Commission.
  • Registration of processing systems and DPO above thresholds.
  • Breach notification duties apply.
  • The law applies extraterritorially in certain circumstances.

The law is highly relevant for UK organisations that offshore service desks, business process outsourcing or data processing to the Philippines, as providers will need to meet its security requirements.

Source: Republic Act 10173 – Data Privacy Act of 2012 (National Privacy Commission)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights