Data Protection Atlas

Philippines

Tier 3 Comprehensive law Asia-Pacific

Principal framework: Data Privacy Act 2012 (2012). Regulator: NPC. The 2012 Act is enforced by an active NPC; modernising amendments have been under discussion in Congress.

At a glance

Principal law
Data Privacy Act 2012
Regulator
NPC
Breach notification
72 hours to the NPC and affected subjects for qualifying breaches
Maximum penalty
NPC administrative fines (2022 circular) plus criminal penalties in the Act
DPO required
DPO mandatory and registered with the NPC
Digital consent age
Parental consent for minors
Extraterritorial reach
Yes — equipment in the Philippines or Filipino citizens’ data

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
PH

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

No source recorded yet. This record cannot rise above Tier 3 until it has one — see depth tiers.

Never independently verified — seeded from the prototype.