🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
PH v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing15 sources retrieved model claude-sonnet-5 · 2026-08-05

Philippines

PH schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, Advennt, AIC

Last updated · 10 categories · 40 claims · 30 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
40Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 15 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The National Privacy Commission has moved on two enforcement and consultation fronts this cycle that together tighten the Philippine data-protection operating environment. The Commission has issued Show Cause Orders to Meta, Roblox, Reddit, and Discord over non-compliance with data privacy laws, with an emphasis on protection of youth in digital spaces, marking the cycle's most significant enforcement signal. At the same time, the NPC opened a public consultation on a draft Circular on Data Subject Rights, intended to consolidate and standardise procedural rules for exercising data-subject rights across all sectors, with comments due 5 October 2026.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute, dedicated regulator, and broad territorial scope are well-evidenced; registration/filing procedural detail is a residual gap.

Primary frameworkData Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations
Traffic-light rationale — GreenComprehensive statute, dedicated regulator, and broad territorial scope are well-evidenced; registration/filing procedural detail is a residual gap.

Sub-modules (5)

Regulator And AuthorityGreen

The NPC was established under the Act as the enforcing and rule-making authority.

Claims (1):

  • The Data Privacy Act of 2012 established the National Privacy Commission, which enforces and oversees the Act and is endowed with rulemaking power.

Act And InstrumentsGreen

RA 10173 plus its 2016 IRR form the operative instrument set.

Claims (1):

  • The final Implementing Rules and Regulations of the Data Privacy Act came into force on September 9, 2016, adding operative specificity to the statute.

Material ScopeGreen

The Act applies broadly to individuals and legal entities processing personal information, subject to enumerated exceptions.

Claims (1):

  • The Data Privacy Act is broadly applicable to individuals and legal entities that process personal information, with some statutory exceptions.

Territorial ScopeGreen

Extraterritorial scope extends to use of equipment located in the Philippines and to processing relating to Philippine citizens/residents, broader than GDPR Art 3.

Claims (1):

  • The Act provides broader extraterritorial application than the GDPR, applying to any use of equipment in the Philippines or acts related to Philippine citizens or residents, not only to entities established in the Philippines.

Regulator Registration And FilingAmber

NPC circulars (e.g. 2022-04, 17-01) govern registration of data processing systems and DPOs, but full operative text was not retrievable this run beyond title-level confirmation.

Absence provenance: unavailable. Searched: unavailable.

Category narrative79 words

The Philippines operates a comprehensive omnibus data protection regime under the Data Privacy Act of 2012 (Republic Act No. 10173, 'the Act'), enforced by the National Privacy Commission (NPC). The Act has broad extraterritorial reach and is supplemented by an extensive body of NPC circulars and advisories. Registration/filing content for specific NPC circulars (e.g. Circular 2022-04, 17-01) could not be retrieved in substantive form during this run (only cookie-boilerplate stubs returned), so registration mechanics are flagged as a gap.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedIAPP — The Data Privacy Act of 2012 established the National Privacy Commission, which enforces and oversees the Act and is endowed with rulemaking power.observed
  2. ConfirmedIAPP — The final Implementing Rules and Regulations of the Data Privacy Act came into force on September 9, 2016, adding operative specificity to the statute.observed
  3. ConfirmedIAPP — The Data Privacy Act is broadly applicable to individuals and legal entities that process personal information, with some statutory exceptions.observed
  4. ConfirmedDataGuidance — The Act provides broader extraterritorial application than the GDPR, applying to any use of equipment in the Philippines or acts related to Philippine citizens or residents, not only to entities established in the Philippines.observed

#

Special categories and prohibition/exception structure are well evidenced; consent-threshold operative detail and anonymisation/pseudonymisation safe-harbours are thin or explicitly absent.

Primary frameworkData Privacy Act of 2012 (RA 10173) and IRR
Traffic-light rationale — AmberSpecial categories and prohibition/exception structure are well evidenced; consent-threshold operative detail and anonymisation/pseudonymisation safe-harbours are thin or explicitly absent.

Sub-modules (4)

Lawful BasesGreen

Processing of sensitive personal information is prohibited absent an enumerated statutory basis; general personal information processing bases include contract, consent, legal obligation, vital interest, and legitimate interest (subject to override by data-subject rights).

Claims (2):

  • All processing of sensitive personal information under the Act is prohibited except under enumerated statutory exceptions, including necessity to protect the lawful rights of data subjects in court or legal proceedings.
  • Consent is not required for processing where the data subject is party to a contract for purposes of fulfilling that contract; exceptions to consent also exist for legal obligation, protection of vital interests, response to national emergency, and pursuit of legitimate interests not overridden by data-subject rights.

Special CategoriesGreen

Sensitive personal information is broadly defined and subject to a general processing prohibition with enumerated exceptions.

Claims (2):

  • The Act defines sensitive personal information to include data about race, ethnic origin, marital status, age, color, religious/philosophical/political affiliations, health, education, genetic or sexual life, offenses, government-issued unique identifiers, and information classified by executive order or act of Congress.
  • A pending House-approved substitute bill would expand the statutory definition of sensitive information to include biometric, genetic, and political affiliation data explicitly.

Pseudonymisation And AnonymisationAmber

Neither the Act nor the IRR explicitly define anonymised or pseudonymised data, beyond a brief reference to storage that does not permit identification of the data subject.

Claims (1):

  • Neither the Act nor its IRR explicitly define anonymised or pseudonymised data, beyond a brief reference to storing personal data that does not permit identification of the data subject.
Category narrative48 words

The Act adopts a prohibition-with-exceptions model for sensitive personal information and defines an expansive category of 'sensitive personal information'. Neither the Act nor the IRR provide explicit definitions of anonymisation/pseudonymisation, a documented gap relative to GDPR. Consent-guidelines circular content could not be retrieved in substantive form this run.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedIAPP — All processing of sensitive personal information under the Act is prohibited except under enumerated statutory exceptions, including necessity to protect the lawful rights of data subjects in court or legal proceedings.observed
  2. ConfirmedIAPP — Consent is not required for processing where the data subject is party to a contract for purposes of fulfilling that contract; exceptions to consent also exist for legal obligation, protection of vital interests, response to national emergency, and pursuit of legitimate interests not overridden by data-subject rights.observed
  3. ConfirmedIAPP — The Act defines sensitive personal information to include data about race, ethnic origin, marital status, age, color, religious/philosophical/political affiliations, health, education, genetic or sexual life, offenses, government-issued unique identifiers, and information classified by executive order or act of Congress.observed
  4. ProbableIAPP — A pending House-approved substitute bill would expand the statutory definition of sensitive information to include biometric, genetic, and political affiliation data explicitly.observed
  5. ConfirmedDataGuidance — Neither the Act nor its IRR explicitly define anonymised or pseudonymised data, beyond a brief reference to storing personal data that does not permit identification of the data subject.observed

#

Core rights are confirmed via secondary legal summary; granular statutory deadlines and restriction/objection procedure text are a gap.

Primary frameworkData Privacy Act of 2012 (RA 10173), Sections 16-18
Traffic-light rationale — AmberCore rights are confirmed via secondary legal summary; granular statutory deadlines and restriction/objection procedure text are a gap.

Sub-modules (5)

Access RightGreen

The Act enumerates rights related to notice, choice, access, and accuracy/integrity of data.

Claims (1):

  • The Act enumerates data-subject rights familiar to privacy professionals relating to the principles of notice, choice, access, and accuracy and integrity of data.

Rectification And ErasureGreen

The Act contains a right-to-be-forgotten analogue permitting a data subject to order removal (erasure/blocking) of personal data from a controller's filing system.

Claims (1):

  • The Act contains a right-to-be-forgotten analogue in the form of a right to erasure or blocking, under which a data subject may order removal of personal data from the controller's filing system.

Restriction And ObjectionAmber

Restriction/objection mechanics were not independently retrievable beyond the general rights enumeration this run.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityGreen

The Act provides a right to data portability.

Claims (1):

  • A right to data portability is provided under the Act.

Deadlines And Response WindowsAmber

Statutory response-window detail for subject-access/erasure requests specifically was not retrieved this run; only the 72-hour breach-notification deadline (a controller-to-regulator/subject obligation, not a DSR response window) is well evidenced.

Absence provenance: unavailable. Searched: unavailable.

Category narrative41 words

The Act enumerates data-subject rights aligned to notice, choice, access, accuracy/integrity, erasure/blocking ('right to be forgotten' analogue), and data portability. Detailed procedural mechanics (specific response-window statutory text, restriction/objection operative detail) were not fully retrievable in this run beyond summary-level secondary analysis.

Periodic update · new data 2026-09-28

Data Subject Rights

The National Privacy Commission has opened a public consultation on a draft Circular on Data Subject Rights, intended to update existing guidelines and prescribe consistent rules and procedures for exercising data-subject rights across all sectors. Comments on the draft are due 5 October 2026. This is a proposed instrument rather than an enacted one, so current data-subject-rights procedures remain those established under existing NPC guidance until the consultation concludes and any resulting circular is issued.

The consolidation aim is significant in itself: rather than sector-specific or fragmented procedural rules for exercising rights such as access and correction, the draft circular would establish a single cross-sectoral standard. This is confirmed as an active, primary-sourced development this cycle, giving it high confidence as to its existence and consultation deadline, even though the substantive content of any resulting circular remains to be seen.

Outlook

The consultation's 5 October 2026 close is the immediate date to track; whether the NPC proceeds promptly to finalise the circular thereafter, and whether the final text departs materially from the consultation draft, will determine how quickly organisations operating in the Philippines need to adjust their data-subject-rights procedures to a standardised cross-sectoral model.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedIAPP — The Act enumerates data-subject rights familiar to privacy professionals relating to the principles of notice, choice, access, and accuracy and integrity of data.observed
  2. ConfirmedIAPP — The Act contains a right-to-be-forgotten analogue in the form of a right to erasure or blocking, under which a data subject may order removal of personal data from the controller's filing system.observed
  3. ConfirmedIAPP — A right to data portability is provided under the Act.observed

#

Core accountability, DPO, security, and breach-notification obligations are well evidenced with specific dates and mechanics; DPIA is an explicit gap flagged by secondary sources themselves.

Primary frameworkData Privacy Act of 2012 (RA 10173), IRR, NPC Circular 2023-06
Traffic-light rationale — GreenCore accountability, DPO, security, and breach-notification obligations are well evidenced with specific dates and mechanics; DPIA is an explicit gap flagged by secondary sources themselves.

Sub-modules (7)

Accountability And DpiaAmber

Neither the Act nor the IRR name DPIAs by that term, but NPC Circular No. 2023-06 (Section 5) imposes a mandatory Privacy Impact Assessment (PIA) obligation on every PIC/PIP processing system, and NPC PIA guidance (Advisory No. 2017-03 and predecessor circulars) has existed since 2017 - materially narrowing, though not eliminating, the divergence from GDPR Art 35.

Claims (1):

  • Neither the Data Privacy Act nor its IRR explicitly refer to Data Protection Impact Assessments.

Dpo RequirementsGreen

Both the IRR and the Act provide for appointment of a DPO/compliance officer, though statutory text does not specify triggering thresholds; the NPC has issued clarifying advisories (e.g. NPC Advisory No. 2017-01).

Claims (1):

  • Both the Act's IRR and general practice require appointment of a DPO/compliance officer responsible for ensuring compliance with applicable data-protection laws and regulations, although the Act and IRR do not specify the precise triggering cases, group-appointment rules, or qualification requirements.

Ropa RequirementsAmber

Records-of-processing detail was not independently retrieved beyond the general privacy-program obligation this run.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsGreen

The Act requires that data-sharing be governed by an agreement providing adequate safeguards, subject to NPC review.

Claims (1):

  • The Act requires that data-sharing be covered by an agreement providing adequate safeguards for data-subject rights, with such agreements subject to review by the National Privacy Commission.

Security MeasuresGreen

NPC Circular 2023-06 (effective March 30, 2024, per NPC's own announcement - not the April 1, 2024 public-announcement date previously reported) updated security-of-processing requirements including business-continuity planning; the 12-month compliance transitory period runs through March 30, 2025.

Claims (1):

  • NPC Circular 2023-06, issued April 1, 2024, updates security requirements for personal data, detailing obligations for data protection officers, data processing systems, and privacy management programs, mandates business continuity plans, and repeals NPC Circular No. 16-01.

Breach NotificationGreen

Controllers face a concurrent 72-hour breach-notification obligation to the NPC and affected data subjects for breaches meeting statutory severity/harm thresholds; submissions must be made via the NPC's Data Breach Notification Management System.

Claims (3):

  • The Act places a concurrent obligation on controllers to notify the National Privacy Commission and affected data subjects within 72 hours of knowledge of, or reasonable belief of, a personal data breach that requires notification.
  • Notification is required only where the breached information is sensitive personal information or information usable for identity fraud, unauthorized acquisition is reasonably believed to have occurred, and the potential harm is serious; the Commission may determine that notification to data subjects is unwarranted based on the controller's compliance and good faith.
  • All personal data breach notifications and annual security incident reports must be submitted through the NPC's Data Breach Notification Management System; submissions by email, personal filing, ordinary mail, or courier are not accepted.

Retention And DisposalAmber

Retention/disposal duties are referenced generally (e.g. NPC/DICT/SEC joint advisory on lending-platform data retention) but no comprehensive statutory retention-period schedule was retrieved this run.

Claims (1):

  • A joint NPC, DICT and SEC advisory addressing online lending platforms sets retention expectations for personal data processed by such platforms as part of broader anti-harassment and consent safeguards.
Category narrative61 words

Controllers must implement privacy and security programs, appoint DPOs/compliance officers, execute reviewable data-sharing agreements, and comply with a 72-hour concurrent breach-notification obligation to the NPC and affected data subjects for qualifying breaches. NPC Circular 2023-06 (effective April 2024) updated security-of-processing obligations including business-continuity planning. DPIAs are not explicitly named in the Act or IRR, a documented divergence from GDPR Art 35.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Two distinct controller/processor developments are active this cycle. First, the NPC is understood to be preparing a draft circular, to supersede Advisory No. 2017-03, that would confine mandatory Privacy Impact Assessment obligations to eight defined high-risk categories, reportedly including AI systems, biometric data, children's data, large-scale processing, and high-risk cross-border transfers, replacing the current broader PIA requirement. This would narrow rather than expand the PIA obligation in scope, while sharpening its application to categories the NPC evidently considers highest-risk. The report is secondary-sourced, and the exact circular number and final text were not available this cycle, so this should be read as probable rather than confirmed, expected in the fourth quarter of 2026.

Second, NPC Advisory No. 2026-02 sets out guidelines on submitting personal data breach notifications through the Data Breach Notification Management System, specifically addressing how controllers and processors may request postponement, exemption, or alternative notification arrangements. This is a procedural clarification of an existing binding obligation rather than a new substantive duty, and is already in force.

Separately, all personal information controllers and processors were required to submit their 2025 Annual Security Incident Report via the Data Breach Notification Management System by 31 March 2026, a standing obligation applying regardless of registration classification under NPC Circular No. 2022-04.

Outlook

The PIA-scope-narrowing circular's progress toward finalisation, expected in the fourth quarter of 2026, is the item most likely to change controller/processor obligations materially; organisations should watch for the assigned circular number and final list of mandatory-PIA trigger categories once available.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (8)
  1. ConfirmedDataGuidance — Neither the Data Privacy Act nor its IRR explicitly refer to Data Protection Impact Assessments.observed
  2. ConfirmedDataGuidance — Both the Act's IRR and general practice require appointment of a DPO/compliance officer responsible for ensuring compliance with applicable data-protection laws and regulations, although the Act and IRR do not specify the precise triggering cases, group-appointment rules, or qualification requirements.observed
  3. ConfirmedIAPP — The Act requires that data-sharing be covered by an agreement providing adequate safeguards for data-subject rights, with such agreements subject to review by the National Privacy Commission.observed
  4. ConfirmedDataGuidance — NPC Circular 2023-06, issued April 1, 2024, updates security requirements for personal data, detailing obligations for data protection officers, data processing systems, and privacy management programs, mandates business continuity plans, and repeals NPC Circular No. 16-01.observed
  5. ConfirmedIAPP — The Act places a concurrent obligation on controllers to notify the National Privacy Commission and affected data subjects within 72 hours of knowledge of, or reasonable belief of, a personal data breach that requires notification.observed
  6. ConfirmedIAPP — Notification is required only where the breached information is sensitive personal information or information usable for identity fraud, unauthorized acquisition is reasonably believed to have occurred, and the potential harm is serious; the Commission may determine that notification to data subjects is unwarranted based on the controller's compliance and good faith.observed
  7. ConfirmedDataGuidance — All personal data breach notifications and annual security incident reports must be submitted through the NPC's Data Breach Notification Management System; submissions by email, personal filing, ordinary mail, or courier are not accepted.observed
  8. ProbableDataGuidance — A joint NPC, DICT and SEC advisory addressing online lending platforms sets retention expectations for personal data processed by such platforms as part of broader anti-harassment and consent safeguards.observed

#

Transfer-mechanism (data-sharing agreement) requirement is confirmed; adequacy-received/granted and TIA/localisation sub-modules lack direct sourcing this run.

Primary frameworkData Privacy Act of 2012 (RA 10173), Section 7(o)
Traffic-light rationale — AmberTransfer-mechanism (data-sharing agreement) requirement is confirmed; adequacy-received/granted and TIA/localisation sub-modules lack direct sourcing this run.

Sub-modules (6)

Transfer MechanismsGreen

Cross-border data sharing must be governed by an agreement providing adequate safeguards, reviewable by the NPC; Section 7(o) empowers the NPC to negotiate and contract with foreign data-privacy authorities for cross-border enforcement.

Claims (2):

  • The Act requires that data-sharing, including cross-border sharing, be covered by an agreement providing adequate safeguards for data-subject rights, subject to NPC review.
  • Section 7(o) of the Data Privacy Act grants the National Privacy Commission the ability to negotiate and contract with other data privacy authorities of other countries for cross-border application and implementation of respective privacy laws and to facilitate cross-border enforcement.

Adequacy ReceivedRed

No formal foreign adequacy decision recognizing the Philippine regime was identified in this run.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

No PH-issued adequacy determinations toward other regimes were identified.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsAmber

No PH-specific standard contractual clause template or BCR-approval mechanism was identified this run beyond the general data-sharing-agreement requirement.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No explicit statutory or NPC-circular TIA requirement analogous to Schrems II practice was identified this run.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No general data-localisation mandate was identified for the Philippines in this run.

Absence provenance: unavailable. Searched: unavailable.

Category narrative64 words

The Act requires data-sharing agreements (domestic or cross-border) to provide adequate safeguards and be subject to NPC review; no formal EU-style adequacy decision covering the Philippines was identified. The Philippines has bilateral cooperation MoUs with the UK ICO and Canadian OPC facilitating cross-border enforcement cooperation, though these MoUs expressly do not compel information-sharing. No evidence of a Philippine data-localisation mandate was found this run.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedIAPP — The Act requires that data-sharing, including cross-border sharing, be covered by an agreement providing adequate safeguards for data-subject rights, subject to NPC review.observed
  2. ConfirmedOffice of the Privacy Commissioner of Canada — Section 7(o) of the Data Privacy Act grants the National Privacy Commission the ability to negotiate and contract with other data privacy authorities of other countries for cross-border application and implementation of respective privacy laws and to facilitate cross-border enforcement.observed

#

Financial-sector and telecoms overlays are well evidenced; health, education, insurance, credit-scoring, and employment sub-modules lack direct sourcing this run.

Primary frameworkData Privacy Act of 2012 (RA 10173); Bank Secrecy Act (RA 1405); Foreign Currency Deposit Act (RA 6426); Credit Information System Act (RA 9510); SIM Registration Act (RA 11934)
Traffic-light rationale — AmberFinancial-sector and telecoms overlays are well evidenced; health, education, insurance, credit-scoring, and employment sub-modules lack direct sourcing this run.

Sub-modules (7)

Financial Sector OverlayAmber

The Act and IRR explicitly interact with the Bank Secrecy Act, Foreign Currency Deposit Act, and Credit Information System Act; NPC Circular 20-01 and a joint NPC/DICT/SEC advisory govern loan-related and online-lending data processing.

Claims (3):

  • The Act and IRR are supplemented by the Secrecy of Bank Deposits Act (RA 1405), the Foreign Currency Deposit Act (RA 6426), and the Credit Information System Act (RA 9510) as overlay financial-sector instruments.
  • NPC Circular No. 20-01 sets guidelines on the processing of personal data for loan-related transactions.
  • A joint NPC, DICT and SEC advisory (issued March 18, 2026) addresses processing of personal data by online lending platforms, requiring separate consent interfaces for guarantors/character references and prohibiting excessive data processing and harassment in debt collection.

Health Sector OverlayRed

No dedicated health-sector DP overlay instrument was retrieved this run beyond the Act's general 'health' special-category coverage.

Absence provenance: unavailable. Searched: unavailable.

Telecoms And EprivacyGreen

The SIM-Card Registration Act requires telecommunications providers to conduct Privacy Impact Assessments and implement organisational, technical and physical security measures to prevent unauthorised disclosure of subscriber personal data.

Claims (1):

  • The SIM-Card Registration Act requires telecommunications providers to conduct Privacy Impact Assessments, train employees and supply chains to prevent data breaches, and afford appropriate organisational, technical, and physical security measures to secure subscriber personal data and prevent unauthorised disclosure.

Employment DataRed

No employment-sector-specific DP instrument was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Credit And ScoringAmber

The Credit Information System Act (RA 9510) is flagged as an overlay instrument alongside the Act, but detailed credit-scoring rules were not retrieved.

Claims (1):

  • The Credit Information System Act (RA 9510) is referenced as an overlay statute interacting with the Data Privacy Act's general regime, though detailed credit-scoring-specific data rules were not retrieved.

EducationRed

No education-sector-specific DP overlay was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

InsuranceRed

No insurance-sector-specific DP overlay was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Category narrative51 words

Sector-specific overlays interact with the general DP regime particularly in financial services (bank-secrecy and credit-information statutes referenced alongside the Act; NPC Circular 20-01 for loan-related transaction data; joint NPC/DICT/SEC advisory on online lending platforms) and telecoms (SIM Registration Act). No dedicated health, education, or insurance-sector DP overlay was retrieved this run.

Periodic update · new data 2026-09-28

Sectoral Watch

The National Privacy Commission and PAGCOR are reported to have signed a memorandum of understanding aimed at enhancing data-privacy governance within the gaming industry, for a three-year term. This would represent the NPC extending sector-specific data-governance attention to the gambling sector, a sector already subject to its own regulatory reorganisation this cycle under PAGCOR's separate restructuring. The MoU is reported through a single secondary source, capping confidence at Uncertain pending further primary confirmation of its existence, scope, and specific commitments.

If confirmed, the MoU would likely address how gaming-sector personal data, including player identification and transaction data collected under PAGCOR's own regulatory requirements, intersects with Data Privacy Act obligations, an area where sector-specific overlay guidance has previously been limited.

Outlook

Confirmation of the MoU's existence and specific content through a primary NPC or PAGCOR source is the immediate item to watch; absent that confirmation, this development should continue to be treated as an uncertain signal rather than an established sectoral-governance development.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedDataGuidance — The Act and IRR are supplemented by the Secrecy of Bank Deposits Act (RA 1405), the Foreign Currency Deposit Act (RA 6426), and the Credit Information System Act (RA 9510) as overlay financial-sector instruments.observed
  2. ConfirmedNational Privacy Commission — NPC Circular No. 20-01 sets guidelines on the processing of personal data for loan-related transactions.observed
  3. ConfirmedDataGuidance — A joint NPC, DICT and SEC advisory (issued March 18, 2026) addresses processing of personal data by online lending platforms, requiring separate consent interfaces for guarantors/character references and prohibiting excessive data processing and harassment in debt collection.observed
  4. ConfirmedDataGuidance — The SIM-Card Registration Act requires telecommunications providers to conduct Privacy Impact Assessments, train employees and supply chains to prevent data breaches, and afford appropriate organisational, technical, and physical security measures to secure subscriber personal data and prevent unauthorised disclosure.observed
  5. UncertainDataGuidance — The Credit Information System Act (RA 9510) is referenced as an overlay statute interacting with the Data Privacy Act's general regime, though detailed credit-scoring-specific data rules were not retrieved.observed

#

Data-scraping advisory is well evidenced; cookie/tracker, opt-out-signal, clean-room, cross-context-advertising, and direct-marketing sub-modules lack direct PH-specific sourcing this run.

Primary frameworkData Privacy Act of 2012 (RA 10173); NPC Advisory No. 2026-01
Traffic-light rationale — AmberData-scraping advisory is well evidenced; cookie/tracker, opt-out-signal, clean-room, cross-context-advertising, and direct-marketing sub-modules lack direct PH-specific sourcing this run.

Sub-modules (6)

Cookies And TrackersRed

No PH-specific cookie/tracker consent instrument distinct from the general Act consent framework was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Dark PatternsAmber

No general-audience dark-pattern prohibition was retrieved this run outside the children-specific advisory (see children_and_vulnerable_groups).

Absence provenance: unavailable. Searched: unavailable.

Opt Out SignalsRed

No PH-specific Global Privacy Control/DAA-equivalent opt-out-signal mechanism was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific PH guidance was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingAmber

The NPC's data-scraping advisory addresses processing of publicly available personal data that may be exploited for advertising/profiling purposes, requiring PICs to define legitimate purposes and conduct Privacy Impact Assessments.

Claims (1):

  • NPC Advisory No. 2026-01, issued April 13, 2026, provides guidelines on the scraping of publicly available personal data and reiterates that Data Privacy Act protections continue to apply even where personal data is publicly accessible online, requiring PICs to define legitimate purposes, inform data subjects, implement security measures, and conduct Privacy Impact Assessments for scraping activities.

Direct MarketingRed

No PH-specific direct-marketing consent/suppression instrument was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Category narrative59 words

NPC Advisory No. 2026-01 (issued April 13, 2026) is the most direct recent evidence in this module, addressing lawful scraping of publicly available personal data for commercial/adtech-adjacent uses. No dedicated cookie-consent, dark-pattern, opt-out-signal, clean-room, or direct-marketing-specific NPC instrument was retrieved this run beyond the general consent/transparency framework and the child-oriented advisory's prohibition on deceptive design patterns (cross-referenced in children_and_vulnerable_groups).

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

NPC Advisory No. 2026-01, dated 13 April 2026, establishes guidelines confirming that publicly available personal data obtained through scraping for purposes including market research, marketing, recruitment, or AI development remains subject to the Data Privacy Act of 2012. This closes off any argument that the public availability of personal data removes it from the Act's coverage, a clarification directly relevant to commercial actors engaged in data scraping for marketing or AI-training purposes. The advisory is confirmed and already in force, based on secondary reporting of its content and date.

This tightens the compliance environment for AdTech and commercial-data practices that rely on scraped, publicly available data, since such practices must now be understood as falling within the ordinary lawful-processing and accountability framework of the Data Privacy Act rather than outside it.

Outlook

How the NPC applies Advisory No. 2026-01 in practice, including whether enforcement actions follow against specific data-scraping practices for marketing or AI-development purposes, is the item to track in coming cycles.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (1)
  1. ConfirmedDataGuidance — NPC Advisory No. 2026-01, issued April 13, 2026, provides guidelines on the scraping of publicly available personal data and reiterates that Data Privacy Act protections continue to apply even where personal data is publicly accessible online, requiring PICs to define legitimate purposes, inform data subjects, implement security measures, and conduct Privacy Impact Assessments for scraping activities.observed

#

ADM/profiling notification duty is confirmed at IRR-provision level; AI-specific binding guidance and biometric/genetic/state-surveillance sub-modules are thinly sourced.

Primary frameworkData Privacy Act of 2012 IRR, Section 48
Traffic-light rationale — AmberADM/profiling notification duty is confirmed at IRR-provision level; AI-specific binding guidance and biometric/genetic/state-surveillance sub-modules are thinly sourced.

Sub-modules (6)

Profiling RestrictionsGreen

The IRR defines 'profiling' as automated processing used to evaluate personal aspects such as work performance, economic situation, health, preferences, reliability, behaviour, location or movements.

Claims (1):

  • Section 3(p) of the IRR defines 'profiling' as any form of automated processing of personal data used to evaluate personal aspects such as a natural person's work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.

Automated Decision Making TransparencyGreen

Section 48 of the IRR requires a personal information controller to notify the NPC when automated processing becomes the sole basis for decisions significantly affecting a data subject.

Claims (1):

  • Section 48 of the IRR requires a personal information controller carrying out wholly or partly automated processing operations to notify the NPC when the automated processing becomes the sole basis for making decisions about a data subject that would significantly affect that data subject.

Ai Risk AssessmentsAmber

Per an IAPP conference description, the NPC has issued 'binding guidance on AI systems' under the Data Privacy Act, but the underlying advisory text was not independently retrieved this run.

Claims (1):

  • The NPC has developed binding guidance applying the Data Privacy Act to AI systems, according to industry-conference descriptions of Philippine regulatory practice as of mid-2026.

Biometric RegimeAmber

No standalone biometric-data statute was retrieved; biometric data is proposed for explicit inclusion in the sensitive-information definition via the pending amendment bill.

Absence provenance: unavailable. Searched: unavailable.

Genetic DataAmber

Genetic data is already covered under the existing 'health...genetic or sexual life' limb of sensitive personal information; the pending amendment bill would make genetic data an explicit standalone category.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsRed

No specific national-security/state-surveillance carve-out provision was retrieved this run beyond the general statutory exceptions to the sensitive-data processing prohibition.

Absence provenance: unavailable. Searched: unavailable.

Category narrative85 words

The IRR requires notification to the NPC where automated processing becomes the sole basis for decisions significantly affecting a data subject, and defines 'profiling' in terms tracking GDPR Art 22. The NPC has reportedly issued binding guidance on AI systems under the Data Privacy Act per an IAPP conference description, though the underlying advisory's full text was not independently retrieved this run. No dedicated biometric-regime or genetic-data-specific statute was retrieved beyond the pending amendment bill's proposal to add biometric/genetic data to sensitive-information definitions (see lawful_processing_and_special_data).

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

Two threads touch algorithmic and biometric governance this cycle, both at an early or uncertain stage. The NPC's draft PIA-scope circular, reported to supersede Advisory No. 2017-03, would reportedly name AI systems and biometric data among the eight defined high-risk categories triggering mandatory Privacy Impact Assessment obligations, a signal that the NPC intends to treat algorithmic and biometric processing as inherently higher-risk within its accountability framework, even as the overall PIA requirement is narrowed in scope elsewhere. This remains a probable, secondary-sourced development pending the circular's final text.

Separately, and outside the NPC's own rule-making, the Supreme Court of the Philippines adopted a governance framework for AI use within the Judiciary, emphasising human-centred AI and ethical principles. This is a distinct institutional development, addressing AI governance within judicial administration rather than data-protection regulation generally, and is noted here as an emerging, uncertain-confidence signal of broader Philippine institutional attention to AI governance.

Outlook

Whether the draft PIA circular's final text retains AI systems and biometric data as named high-risk triggers, once published, and whether the NPC issues any dedicated AI-specific guidance beyond the PIA-scope circular, are the developments to track for algorithmic and biometric governance specifically.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedDataGuidance — Section 3(p) of the IRR defines 'profiling' as any form of automated processing of personal data used to evaluate personal aspects such as a natural person's work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.observed
  2. ConfirmedDataGuidance — Section 48 of the IRR requires a personal information controller carrying out wholly or partly automated processing operations to notify the NPC when the automated processing becomes the sole basis for making decisions about a data subject that would significantly affect that data subject.observed
  3. UncertainIAPP — The NPC has developed binding guidance applying the Data Privacy Act to AI systems, according to industry-conference descriptions of Philippine regulatory practice as of mid-2026.observed

#

Child-oriented transparency guidance is well evidenced and recent; statutory age-of-consent/parental-consent thresholds and dependent-adult protections remain thinly sourced.

Primary frameworkNPC Advisory Opinion No. 2024-03 (Guidelines on Child-Oriented Transparency); Data Privacy Act of 2012
Traffic-light rationale — AmberChild-oriented transparency guidance is well evidenced and recent; statutory age-of-consent/parental-consent thresholds and dependent-adult protections remain thinly sourced.

Sub-modules (5)

Age VerificationAmber

No dedicated statutory age-verification mechanism was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Minor Profiling BansAmber

The Advisory prohibits deceptive design patterns that compromise children's privacy, an adjacent but not identical protection to an outright profiling ban.

Claims (1):

  • The Advisory mandates that privacy notices addressed to children be accessible and understandable and prohibits deceptive design patterns that compromise children's privacy.

Education SettingsRed

No education-setting-specific children's-data instrument was retrieved this run beyond the general child-oriented transparency advisory.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsAmber

The Advisory's definition of 'child' extends coverage to persons 18 or over who are unable to care for themselves due to disability, providing partial coverage of dependent adults.

Claims (1):

  • NPC Advisory Opinion No. 2024-03 defines a 'child' to include a person below eighteen years of age or a person 18 or over who is unable to fully take care of themselves or protect themselves from abuse, neglect, cruelty, exploitation, or discrimination due to a physical or mental disability or condition.
Category narrative69 words

NPC Advisory Opinion No. 2024-03 (issued December 17, 2024) establishes child-oriented transparency guidelines, defining 'child' broadly and requiring age-appropriate privacy notices, Child Privacy Impact Assessments, prohibition of deceptive design patterns, and parental/guardian involvement. No age-of-consent threshold or COPPA/GDPR-Art-8-style parental-consent age was located in retrieved sources; the Act and IRR reportedly do not define 'child' or provide minor-specific processing requirements, a gap the 2024 Advisory Opinion appears to address administratively.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

The National Privacy Commission issued Show Cause Orders to Meta, Roblox, Reddit, and Discord, citing non-compliance with data privacy laws with a specific emphasis on protection of youth in digital spaces. This is the cycle's most significant children-and-vulnerable-groups signal and reflects active enforcement attention directed at major global platforms with substantial youth user bases operating in the Philippines. The orders are reported through secondary sourcing, with no primary NPC release detailing the specific allegations against each platform reaching this cycle, so the exact substantive basis for each order should be treated as probable rather than confirmed.

The scale of this action, four platforms simultaneously, indicates the NPC is treating youth digital-privacy protection as a priority enforcement area rather than addressing platforms individually on an ad hoc basis.

Outlook

The resolution of the Show Cause Orders, whether through platform compliance commitments, negotiated remediation, or escalation to penalty proceedings, is the primary item to track; any published NPC decision or settlement would also clarify the specific substantive standards being applied to youth-data protection on these platforms.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedDataGuidance — NPC Advisory Opinion No. 2024-03 highlights the involvement of parents or guardians in data-processing activities concerning children's personal information and requires notification of data breaches involving children's personal information.observed
  2. ConfirmedDataGuidance — The Advisory mandates that privacy notices addressed to children be accessible and understandable and prohibits deceptive design patterns that compromise children's privacy.observed
  3. ConfirmedDataGuidance — NPC Advisory Opinion No. 2024-03 defines a 'child' to include a person below eighteen years of age or a person 18 or over who is unable to fully take care of themselves or protect themselves from abuse, neglect, cruelty, exploitation, or discrimination due to a physical or mental disability or condition.observed

#

Penalty structure, criminal sanctions, and recent 180-day developments are well evidenced; enforcement-activity-index and regulator-funding/capacity sub-modules lack quantified sourcing this run.

Primary frameworkData Privacy Act of 2012 (RA 10173); NPC Circular on Administrative Fines
Traffic-light rationale — AmberPenalty structure, criminal sanctions, and recent 180-day developments are well evidenced; enforcement-activity-index and regulator-funding/capacity sub-modules lack quantified sourcing this run.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The NPC has corrective and investigative powers akin to GDPR DPAs; administrative fines are capped at PHP 5,000,000 per controller/processor; criminal penalties include imprisonment ranging up to six years and fines up to roughly $100,000 for combined offences.

Claims (3):

  • The Act provides the NPC with corrective and investigative powers similar to data protection authorities under the GDPR.
  • The NPC updated administrative-fine rules to cap penalties at 5,000,000 pesos, whether arising from a single violation or multiple violations, by a personal information controller or processor, replacing an earlier scheme of 0.25%-3% of gross income for grave violations and 0.25%-2% for major violations.
  • Combinations or series of criminal acts under the Act (e.g. unauthorized processing, negligent access, malicious disclosure) can subject an offender to imprisonment ranging from three to six years and fines of approximately $20,000 to $100,000, separate from concealment penalties of 1.5 to 5 years imprisonment and $10,000-$20,000 fines for failure to report a breach.

Enforcement Activity IndexAmber

No aggregated 12-month enforcement-activity index (case counts, total fines) was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Regulator Funding And CapacityRed

No headcount/budget capacity data for the NPC was retrieved this run.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsAmber

No dedicated class-action/collective-redress mechanism specific to data-privacy claims was retrieved this run beyond the general private right of action.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionGreen

The Act provides a private right of action for damages available to data subjects independent of NPC administrative/criminal enforcement.

Claims (1):

  • The Act provides for a private right of action for damages available to affected data subjects, applicable alongside criminal and administrative penalties.

Recent Developments 180DAmber

Within the last 180 days, the NPC issued Advisory No. 2026-01 on data scraping (April 13, 2026) and joined DICT/SEC in a March 18, 2026 advisory on online lending platforms; a House-approved substitute bill to amend the Data Privacy Act remains pending.

Claims (2):

  • On April 13, 2026, the NPC issued Advisory No. 2026-01 providing guidelines on lawful scraping of publicly available personal data and reiterating that Data Privacy Act protections apply even to publicly accessible online data.
  • On March 18, 2026, the NPC, DICT, and SEC issued a joint advisory addressing personal-data processing by online lending platforms, warning that violations may result in fines and revocation of operating authority.
Category narrative93 words

The NPC has corrective and investigative powers comparable to GDPR authorities. Administrative fines are capped at 5,000,000 pesos per controller/processor regardless of the number of violations, replacing an earlier percentage-of-gross-income model; criminal penalties (imprisonment plus fines) apply separately for specific offences including unauthorized processing, breach concealment, and malicious disclosure, alongside a private right of action for damages. A pending House-approved substitute bill would further empower the NPC, including introducing a new fine scheme, and update extraterritorial scope. Recent 180-day developments include the April 2026 data-scraping advisory and the March 2026 joint online-lending advisory.

Periodic update · new data 2026-09-28

Enforcement & Redress

The cycle's most consequential enforcement development is the NPC's issuance of Show Cause Orders against Meta, Roblox, Reddit, and Discord over data-privacy non-compliance, with particular emphasis on youth protection. This represents active, multi-platform enforcement attention directed at global technology companies operating in the Philippines, a more assertive posture than case-by-case or complaint-driven enforcement. The underlying substantive allegations against each platform were not detailed in a primary NPC release reaching this cycle, so specifics should be treated as probable pending fuller disclosure.

Alongside this enforcement escalation, the standing administrative fine framework under NPC Circular No. 2022-01 remains unchanged this cycle: fines for grave violations range from 0.5% to 3% of annual gross income, and for major violations from 0.25% to 2%, capped at PHP 5,000,000 in aggregate per violation. This framework provides the financial-penalty backdrop against which any escalation of the Show Cause Orders would proceed, should the NPC move from show-cause proceedings to formal penalty action.

Outlook

Whether the Show Cause Orders proceed to formal findings of violation and, if so, whether penalties are assessed under the existing Circular 2022-01 fine schedule, is the central enforcement question for coming cycles. The outcome would also serve as a signal of how the NPC intends to apply its existing fine framework against major global platforms specifically, as distinct from domestic controllers.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedDataGuidance — The Act provides the NPC with corrective and investigative powers similar to data protection authorities under the GDPR.observed
  2. ConfirmedIAPP — The NPC updated administrative-fine rules to cap penalties at 5,000,000 pesos, whether arising from a single violation or multiple violations, by a personal information controller or processor, replacing an earlier scheme of 0.25%-3% of gross income for grave violations and 0.25%-2% for major violations.observed
  3. ConfirmedIAPP — Combinations or series of criminal acts under the Act (e.g. unauthorized processing, negligent access, malicious disclosure) can subject an offender to imprisonment ranging from three to six years and fines of approximately $20,000 to $100,000, separate from concealment penalties of 1.5 to 5 years imprisonment and $10,000-$20,000 fines for failure to report a breach.observed
  4. ConfirmedIAPP — The Act provides for a private right of action for damages available to affected data subjects, applicable alongside criminal and administrative penalties.observed
  5. ConfirmedDataGuidance — On April 13, 2026, the NPC issued Advisory No. 2026-01 providing guidelines on lawful scraping of publicly available personal data and reiterating that Data Privacy Act protections apply even to publicly accessible online data.observed
  6. ConfirmedDataGuidance — On March 18, 2026, the NPC, DICT, and SEC issued a joint advisory addressing personal-data processing by online lending platforms, warning that violations may result in fines and revocation of operating authority.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct25.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Philippines
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s) (40 category placement(s)), 30 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (32 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

T1/T2-grounded coverage was achieved for regulator identity/authority (NPC), breach-notification mechanics, the SIM-Card Registration Act overlay, and the 2024 child-oriented-transparency and 2026 data-scraping advisories. Most other findings rest on T3 secondary legal-analysis sources (IAPP, DataGuidance) summarizing the Act, IRR, and NPC circulars, since primary NPC circular PDFs beyond Circular 20-01 returned only cookie-boilerplate content when fetched via search. Cross-border adequacy (received/granted), data-localisation, TIA, SCC/BCR, ROPA, DPIA, consent-guideline operative text, and several sectoral overlays (health, education, insurance, employment) carry absent_field_provenance and red/amber traffic lights reflecting genuine evidentiary gaps rather than an assumption of non-regulation.

Unresolved questions (5):

  • What is the current legislative status (Senate reading/enactment date) of the House-approved substitute bill amending RA 10173?
  • What are the specific statutory response-window deadlines (in calendar/business days) for subject access, rectification, and erasure requests under the Act/IRR?
  • Does the Philippines have any operative TIA requirement, SCC template, or BCR-approval mechanism for cross-border transfers beyond the general data-sharing-agreement review?
  • What is the substantive text and legal status ('binding guidance' vs. advisory) of the NPC's AI-systems guidance referenced at the IAPP Asia Forum 2026 agenda?
  • What quantified enforcement activity (case counts, total fines imposed) has the NPC recorded in the trailing 12 months?

Escalate to primary-source review: yes