Regulatory landscape ยท Southeast Asia
Philippines: file security and audit obligations
The Data Privacy Act 2012 and its NPC circulars remain the operative regime, with proposed amendments extending data protection officer obligations to designated public and private entities.
At a glance
How Philippines regulates file security
- 01
Regime
Data Privacy Act with an active regulator issuing binding circulars
- 02
File security
NPC security-measures circulars over personal data processing systems
- 03
Audit and evidence
72-hour breach notification to the NPC; registration and compliance reporting
Overview
The regulatory picture
The Data Privacy Act of 2012 (RA 10173) is the anchor, administered by the National Privacy Commission (NPC), which has been notably active in issuing implementing circulars. Personal information controllers must implement reasonable and appropriate organisational, physical and technical security measures, register data processing systems, appoint a Data Protection Officer, and notify the NPC and affected data subjects of qualifying breaches within 72 hours.
In December 2024 the NPC proposed amendments extending obligations to appoint a data protection officer and designated management personnel to government agencies and to private entities the Commission designates. The BSP separately imposes technology risk expectations on supervised financial institutions.
The landscape
Instruments that reach file security and audit
| Instrument | Authority | Status | Relevance |
|---|---|---|---|
| Data Privacy Act of 2012 (RA 10173) | NPC | In force | Direct |
NPC
Data Privacy Act of 2012 (RA 10173)
Requires reasonable and appropriate organisational, physical and technical security measures over personal data, registration of processing systems, DPO appointment, and 72-hour breach notification.
Why it matters for file security. The technical security measures obligation reaches personal data held in documents, and the 72-hour notification clock rewards having processing evidence available quickly.
How Glasswall addresses it. Find & Redact reduces personal data held in documents, addressing the technical measures obligation concretely. The per-file verdict record shortens the time needed to establish what was affected when a 72-hour notification decision has to be made.
Find & RedactPer-file verdict recordStorage Monitor + SM AuditGlasswall Halo
Latest developments
What has changed in Philippines
Most recent first.
-
NPC proposes extending DPO obligations to designated entities
The National Privacy Commission proposed amendments imposing obligations on government agencies and private entities designated by the Commission to appoint a data protection officer and designated management personnel responsible for data protection.
Why it matters for file security. Widens the population of organisations required to hold accountable ownership of data protection controls, including over personal data held in documents.
- government
- banking
- healthcare
Scope
About this page
This page is a working reference for organisations operating in Philippines.
It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.