Philippine Labor Law Glossary
Definition: The Data Privacy Act of 2012 (Republic Act No. 10173) is the Philippine statute that regulates how personal information is collected, processed and protected by government agencies and private organizations, enforced by the National Privacy Commission.
Sa Filipino · Filipino Explanation
Ano ang Data Privacy Act?
Ang Data Privacy Act of 2012 (RA 10173) ang batas na nagpoprotekta sa personal na impormasyon ng mga Pilipino, at nagbibigay-kapangyarihan sa National Privacy Commission (NPC) na ipatupad ito.
I-check kung may lawful basis, paunang abiso (notice), at sapat na proteksyon ang paggamit ng iyong personal data.
What the Data Privacy Act of 2012 Means
Republic Act No. 10173, the Data Privacy Act of 2012, is the Philippines’ comprehensive statute governing the collection, use, storage and disclosure of personal information. It applies to any natural or juridical person—government agency, private company of any size, or individual acting in a business capacity—that processes personal data in the Philippines, and in certain cases to processing done abroad involving a Philippine resident’s data.
The law created the National Privacy Commission (NPC) as the independent body that administers and enforces it, issues implementing rules and circulars, investigates complaints, and imposes administrative sanctions. It works alongside the older constitutional right to privacy of communication in Article III, Section 3 of the 1987 Constitution, which restrains government intrusion specifically, while the Data Privacy Act regulates both public and private-sector data handling more broadly.
Core Legal Rules
- Processing personal data requires a lawful basis—typically consent, contract necessity, legal obligation, or legitimate interest.
- “Sensitive personal information”—health, race, religion, government ID numbers and similar data—requires a stricter lawful basis than ordinary personal information.
- Data subjects have statutory rights: to be informed, to access, to correct, to object, to erasure or blocking, to damages, and to data portability.
- Controllers must implement reasonable security measures and notify the NPC and affected individuals of breaches involving sensitive personal information.
- Violations can trigger both criminal penalties (imprisonment and fines under Secs. 25–36) and separate NPC administrative fines of up to ₱5,000,000 per act.
Key Provisions at a Glance
| Element | Requirement |
|---|---|
| Lawful basis for processing | Consent, contract necessity, legal obligation, vital interest, or legitimate interest (Secs. 11–13) |
| Data subject rights | To be informed, access, correct, object, erasure/blocking, damages, and portability (Secs. 16–18) |
| Security duty | Reasonable organizational, physical, and technical safeguards proportionate to risk (Sec. 20) |
| Breach notification | NPC and affected data subjects must be notified for breaches involving sensitive personal information (Sec. 20) |
| Enforcement body | National Privacy Commission (Sec. 7) |
| Penalties | Imprisonment of six months to seven years plus fines (Secs. 25–36); separate NPC administrative fines of up to ₱5,000,000 per act (NPC Circular No. 2022-01) |
Why the Term Matters
The Data Privacy Act touches nearly every employer in the Philippines, not just technology or data-heavy companies. Payroll records, government ID numbers, and health data collected for HMO enrollment all qualify as personal or sensitive personal information, which means ordinary HR processes carry Data Privacy Act obligations. It is also the primary legal basis employers rely on—or are constrained by—when monitoring remote or telecommuting staff.
For the complete legal framework—key provisions, who must comply, penalties, and data subject rights—see the full guide: What Is the Privacy Law in the Philippines? For how this statute applies specifically to workplace surveillance, see Employer Monitoring of Remote Workers in the Philippines. For who must be designated to oversee compliance, see Is a Data Protection Officer Mandatory in the Philippines?
Practical Example
Hypothetical example: A small business collects customers’ names and delivery addresses through its website, and separately keeps employees’ SSS and TIN numbers and HMO health records for payroll. Because it processes both personal information and sensitive personal information, it is a personal information controller under the Data Privacy Act regardless of its size, and should have a lawful basis for each category of data, a designated compliance contact, and reasonable security measures in place.
Common Misunderstanding
Misunderstanding: The Data Privacy Act only applies to large companies, tech platforms, or government agencies.
Correct approach: The law applies to any natural or juridical person that processes personal data in the Philippines, including small businesses and individual employers. Size and industry do not create an exemption—what matters is whether personal or sensitive personal information is being processed.
Sources and Legal Citations
- Republic Act No. 10173, Data Privacy Act of 2012 — defines personal and sensitive personal information, lawful processing, data subject rights, security obligations, and penalties. Official text via LawPhil.
- National Privacy Commission Circular No. 2022-01, Guidelines on Administrative Fines, dated August 8, 2022 — sets the administrative fine structure and the ₱5,000,000 cap per act. Official NPC circular.
Disclaimer
This glossary entry is for general educational and legal-information purposes and is not legal advice. Data privacy compliance and violations depend on specific facts and current law. LaborCode.ph is independent and is not a government website, tribunal or law firm.

