Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Regulatory landscape ยท Southeast Asia

Philippines: file security and audit obligations

The Data Privacy Act 2012 and its NPC circulars remain the operative regime, with proposed amendments extending data protection officer obligations to designated public and private entities.

At a glance

How Philippines regulates file security

  • 01

    Regime

    Data Privacy Act with an active regulator issuing binding circulars

  • 02

    File security

    NPC security-measures circulars over personal data processing systems

  • 03

    Audit and evidence

    72-hour breach notification to the NPC; registration and compliance reporting

Overview

The regulatory picture

The Data Privacy Act of 2012 (RA 10173) is the anchor, administered by the National Privacy Commission (NPC), which has been notably active in issuing implementing circulars. Personal information controllers must implement reasonable and appropriate organisational, physical and technical security measures, register data processing systems, appoint a Data Protection Officer, and notify the NPC and affected data subjects of qualifying breaches within 72 hours.

In December 2024 the NPC proposed amendments extending obligations to appoint a data protection officer and designated management personnel to government agencies and to private entities the Commission designates. The BSP separately imposes technology risk expectations on supervised financial institutions.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
Data Privacy Act of 2012 (RA 10173)NPCIn forceDirect

NPC

Data Privacy Act of 2012 (RA 10173)

Requires reasonable and appropriate organisational, physical and technical security measures over personal data, registration of processing systems, DPO appointment, and 72-hour breach notification.

Why it matters for file security. The technical security measures obligation reaches personal data held in documents, and the 72-hour notification clock rewards having processing evidence available quickly.

How Glasswall addresses it. Find & Redact reduces personal data held in documents, addressing the technical measures obligation concretely. The per-file verdict record shortens the time needed to establish what was affected when a 72-hour notification decision has to be made.

Find & RedactPer-file verdict recordStorage Monitor + SM AuditGlasswall Halo

Source: NPC

Latest developments

What has changed in Philippines

Most recent first.

  1. ConsultationContext

    NPC proposes extending DPO obligations to designated entities

    The National Privacy Commission proposed amendments imposing obligations on government agencies and private entities designated by the Commission to appoint a data protection officer and designated management personnel responsible for data protection.

    Why it matters for file security. Widens the population of organisations required to hold accountable ownership of data protection controls, including over personal data held in documents.

    • government
    • banking
    • healthcare

    Source: NPC

Scope

About this page

This page is a working reference for organisations operating in Philippines.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in Philippines?