🇵🇭
Philippines
Applicability of the Philippines Data Privacy Act of 2012
The Philippines established its data protection framework through comprehensive legislation addressing the processing of personal information. The primary role of this framework is governed by Republic Act No. 10173 – Data Privacy Act of 2012, which serves as the country's principal data protection statute.
The Republic Act No. 10173 – Data Privacy Act of 2012 was adopted on August 15, 2012 and became effective on September 8, 2012. The Philippines has established a comprehensive data protection framework to regulate the processing of personal information. The primary role of the Implementing Rules and Regulations of Republic Act No. 10173, also known as the Data Privacy Act of 2012 is to provide detailed implementation guidelines and procedures for the Data Privacy Act of 2012.
The Implementing Rules and Regulations were adopted on August 24, 2016 and became effective on September 9, 2016.
Material Scope (DPA Section 4)
"This Act applies to the processing of all types of personal information and to any natural and juridical person involved in personal information processing..."
Key exemptions:
- Government employee/officer information related to their position
- Government contractor information related to services
- Public license and permit information
- Information processed for journalistic, artistic, literary or research purposes
- Information for public authority functions
- Information required by banks/financial institutions for regulatory compliance
- Personal information from foreign jurisdictions processed according to their laws
Territorial Scope (DPA Section 6)
Applies to acts done outside Philippines if:
- Related to personal information about Philippine citizens/residents
- Entity has links with Philippines through:
- Contract entered in Philippines
- Central management in Philippines
- Branch/agency/office with data access
- Entity has other links:
- Carries on business in Philippines
- Collects/holds data in Philippines
Analysis of Applicability
Material Applicability
- General Rule: The DPA applies broadly to all personal information processing by both public and private entities.
- Key Exemptions:
- Official information of public servants (transparency purposes)
- Government contractor information (accountability)
- Regulatory compliance data (avoiding duplicate regulation)
- Special purposes (balancing other rights/interests)
- Sectoral Considerations:
- Financial sector has specific exemptions for regulatory compliance
- Media/journalism has exemptions for freedom of expression
- Research has exemptions for public benefit purposes
Territorial Applicability
- Primary Connecting Factors:
- Processing in Philippines
- Processing about Philippine citizens/residents
- Use of equipment in Philippines
- Business presence in Philippines
- Extraterritorial Reach:
- Applies to foreign entities processing Philippine residents' data
- Covers foreign companies with Philippine operations
- Includes online businesses targeting Philippine market
- Establishment Requirements:
- Physical presence through office/branch
- Use of equipment in Philippines
- Contractual relationships in Philippines
- Business operations targeting Philippines
Practical Implications
- For Local Organizations:
- Must comply with DPA for all personal data processing
- Need to identify applicable exemptions
- Must implement appropriate safeguards
- For Foreign Organizations:
- Must assess Philippine connections
- Need to comply if targeting Philippine market
- Should consider local representation if processing Philippine data
- For Data Subjects:
- Rights protected regardless of processor location
- Special protections for sensitive personal information
- Exemptions may limit certain rights in specific contexts
Philippines
Gavel Factors: (16)
globe_book Resources (19)
GroupsConsultants: (34)
Philippines
Gavel Factors: (16)
globe_book Resources (19)
GroupsConsultants: (34)