Qualysec
Blog

Data Privacy Act Philippines: Security Requirements Every Business Must Meet

Is your business compliant with the Data Privacy Act Philippines? Explore NPC Circular 2023-06 security measures, penalties, and an audit checklist.

Published on August 4, 2026
Read Time: 19 min
CONNECT WITH US

Your company just received notice from the National Privacy Commission. A customer reported that their personal data may have been compromised through your systems. The NPC wants documentation showing what security measures you had in place, when you conducted vulnerability assessments, and how quickly you discovered the breach.

You start scrambling. Your spreadsheet of security initiatives exists somewhere. Your last penetration test was two years ago. You’re not even sure which systems hold the most sensitive customer data. You’re about to learn what every Philippine business operating with customer data discovers eventually: the Data Privacy Act isn’t optional, and regulatory fines are calculated in percentages of annual gross income (capped at PHP 5 million under current NPC rules).

The Data Privacy Act Philippines (Republic Act No. 10173) is clear in its core requirement. If your business collects, stores, uses, or shares personal data of Philippine citizens or residents, or any processing that falls under the Act’s territorial or extraterritorial scope, you need reasonable security measures protecting that data. What counts as “reasonable” depends on your industry, your size, the risks you’ve identified, and what your customers expect. The National Privacy Commission enforces the law and has been increasingly clear about what they’re looking for.

Key Takeaways

  1. Data Privacy Act compliance is mandatory for any Philippine business processing personal data, regardless of size.
  2. Security requires proportional organizational, physical, and technical measures appropriate to your risks and resources.
  3. Testing provides the evidence regulators expect when investigating your due diligence and compliance.
  4. Non-compliance carries criminal imprisonment, NPC administrative fines of up to 3% of annual gross income (capped at PHP 5 million), and civil liability.
  5. Ongoing compliance beats one-time projects; treat security as continuous improvement, not checkbox compliance.

What Is the Data Privacy Act of the Philippines?

The Data Privacy Act of 2012 (RA 10173) is the primary Philippine law protecting personal information. It applies to both government and private sector organizations. The law says if you’re a Personal Information Controller (the entity deciding what data gets collected and how it’s used) or a Personal Information Processor (the entity handling data on someone else’s behalf), you have obligations.

Personal information under the law covers any data that can identify someone or reasonably lead to identifying them. Sensitive personal information gets extra protection and includes things like health records, government-issued ID numbers, genetic data, and information about an individual’s race, ethnicity, or political affiliations.

The law covers:

  • Any Philippine business collecting customer data
  • Foreign companies processing data of Philippine residents
  • Companies that outsource data processing to third parties
  • Organizations using cloud services to store personal data
  • Startups and small businesses (size doesn’t exempt you)

The National Privacy Commission (NPC) administers the law, issues detailed guidance through circulars, investigates complaints, and enforces compliance through administrative fines and other measures. The most recent and detailed security guidance comes from NPC Circular 2023-06, which took effect in March 2024 and sets out specific organizational, physical, and technical security requirements.

Who Must Comply with the Data Privacy Act?

If your business processes personal data at any scale, Data Privacy Act compliance Philippines is mandatory. The law applies to your organization regardless of whether you’re a startup with five employees or a large corporation. The NPC doesn’t grant exemptions based on company size. What changes with size is the proportionality of your security approach, meaning a small online shop doesn’t need the same infrastructure as a bank, but both need documented, appropriate security for the data they hold.

Your organization is covered if you:

  • Collect customer names, email addresses, or phone numbers
  • Store transaction data or purchase history
  • Process employee information
  • Handle government ID numbers, dates of birth, or addresses
  • Use customer data for analytics or marketing
  • Outsource any of these functions to vendors or cloud providers
  • Operate an e-commerce site, fintech platform, healthcare app, or SaaS product

The NPC has been issuing increasingly detailed circulars on privacy engineering, AI systems using personal data, and breach notification procedures. These advisories expand on the core security requirements but don’t change the fundamental obligation. Your business remains fully liable even when using third-party tools or cloud providers to process personal data. Responsibility doesn’t transfer to your vendor just because they’re the ones running the servers.

Schedule a quick technical gap assessment with our security team.

Key Security Requirements Under the Data Privacy Act

The Data Privacy Act security requirements center on reasonable and appropriate organizational, physical, and technical measures. The law balances practicality with protection. It doesn’t demand perfection or spending unlimited money. It demands proportionality. You implement measures that match the nature of the data, the risks your organization faces, your size, current best practices, and what implementation actually costs.

NPC Circular 2023-06 specifies what “reasonable and appropriate” means in detail.

Organisational Security Measures (The People and Process Side)

Your organization needs clear governance around data handling. Designate someone responsible for privacy compliance, ideally a dedicated Data Protection Officer, and establish the policies that govern how data gets collected, used, retained, shared, and eventually deleted.

Key organizational controls:

  • Create an inventory documenting every system processing personal data and what information each one holds
  • Require vendors and contractors handling your data to sign agreements committing to confidentiality and security
  • Establish confidentiality clauses for employees that survive their employment
  • Implement access controls so employees only see data required for their specific job
  • Conduct regular privacy and security training for staff, documenting attendance and dates
  • Develop an incident response plan specifying who gets called, what steps happen first, how to notify affected people, and when to report to the NPC
  • Test your incident response plan regularly to verify it actually works

Priority first steps:

Run Privacy Impact Assessments for new systems or when you significantly change how data gets used. These assessments identify risks specific to your business, document them clearly, and specify what controls you’ll implement to address them.

The difference between organizations that handle breaches well and those that don’t typically comes down to documentation. When something goes wrong, you need to show you had plans, controls, and evidence of execution. Without documentation, you’re claiming compliance you can’t prove.

Physical Security Measures (The Infrastructure and Space Side)

Personal data on servers and paper records needs protection from physical access. Restrict who can enter your server rooms and areas storing paper records using access cards, biometric readers, or key management systems. Track who accessed which areas and when. Install cameras in sensitive zones and maintain visitor logs.

Workstation and device security:

  • Implement clean-desk policies so customer data stays off monitors visible to others
  • Position screens away from walkways and public areas
  • Secure laptops with cable locks when unattended or require them locked in drawers
  • Prevent unauthorized device removal from facilities

Secure media destruction:

When you retire old hard drives, USB drives, or paper records, destruction must be secure. Generic deletion doesn’t erase data sufficiently. Hard drives require certified wiping tools that overwrite data multiple times or physical destruction. Paper documents need shredding. Discarded media can be recovered through physical retrieval, exposing everything previously stored on it.

Environmental protection:

Protect your facilities from risks specific to your location. Fire suppression systems protect in-house servers. Backup power systems maintain operations during outages. Flood prevention matters depending on whether your facility sits in a flood-prone area. These measures prevent data loss from environmental incidents beyond your control.

Technical Security Measures (The Technology and Systems Side)

Technical requirements need attention because they keep changing. Most organizations find this part difficult because it requires both expertise and regular updates.

Essential technical controls:

  • Encryption: Lock up data using strong encryption both on your servers and when it travels across the internet. This prevents thieves from reading data if they steal a server or intercept it online.
  • Strong passwords and Multi-factor authentication: Require passwords that are long and complex (12+ characters with numbers and special characters). Better yet, require a second verification step like a code sent to someone’s phone. This prevents login even if someone steals a password.
  • Access control: Give employees access only to data they need for their job. A customer service person shouldn’t access payment systems. A developer shouldn’t see customer financial details. Review who has access every three months.
  • Secure backups: Back up important data regularly in encrypted form. Test that you can actually restore from backups so you know they work.
  • Endpoint protection: Install security software on all computers and devices that touch customer data. This software watches for threats and alerts your team.
  • Logging and monitoring: Keep records of who accessed what data and when. Save these records for at least 12 months. Watch for odd activity like someone accessing data at 3 AM or downloading records to a USB drive.
  • Vulnerability and Patch management: Check your systems for security problems at least once a year. Fix problems quickly. Install security updates on schedule instead of delaying.
  • Network and API security: Use firewalls and network separation. Secure any remote access. Test web applications and APIs for problems before they go live.
  • Cloud security: When using cloud services, verify the provider has proper security. Understand what each side is responsible for protecting.
  • Secure development: When building software, use secure coding practices. Review code for security issues before releasing it.

Core Technical Controls and What They Protect

Technical Control Protects Against How It Works
Encryption (at rest and in transit) Unauthorized viewing of data if systems get breached or data is intercepted Data becomes unreadable without the encryption key
Strong authentication and MFA Unauthorized access even if passwords get compromised Attackers need the password AND a second factor like a phone code
Access control and least privilege Damage from compromised accounts Attackers only access data the compromised account can access
Secure backups Data loss from ransomware or system failures Regular encrypted backups allow recovery without paying ransomware demands
Endpoint protection Malware and compromised devices Antivirus and EDR detect and stop threats on individual computers
Logging and monitoring Undetected breaches Logs create evidence of what happened; monitoring alerts to suspicious activity
Vulnerability and patch management Exploitation of known weaknesses Regular scanning and timely patching close security holes before attackers find them
Network security Unauthorized network access Firewalls, segmentation, and intrusion detection prevent network-based attacks
Cloud security configuration Misconfigured cloud storage exposing data Proper identity management, encryption, and access controls prevent cloud breaches

Why Security Testing Is Essential for Data Privacy Act Compliance

Data Privacy Act Security Requirements at a Glance

The law requires you to find vulnerabilities and fix them. The catch is you can’t fix what you don’t know exists. Security testing reveals gaps before real attackers find them, creating documented proof that you took compliance seriously.

When the NPC investigates, testing reports show you were actively checking your security rather than hoping nothing went wrong. This matters because testing documents your due diligence.

Types of testing you need:

Let’s say an online lending platform tests their web portal and mobile app annually. A recent test found authentication flaws letting attackers view other customers’ loan applications. The flaw existed for months undetected. Testing caught it before real attackers did, preventing a breach notification.

Test critical systems more frequently than less-sensitive ones. Use results to prioritize fixes by severity. This creates continuous improvement.

Common Compliance Challenges Businesses Face

Most businesses face similar obstacles when trying to implement data privacy compliance.

Data and Systems:

  • Don’t know where all personal data actually lives across their organization
  • Haven’t done Privacy Impact Assessments or did them and filed them away without taking action
  • Can’t patch older systems because updates would break existing functionality
  • Have insufficient or no logging, making it impossible to investigate incidents

Third-Party Management:

  • Assess vendors once and never check them again
  • Don’t have contracts requiring vendors to maintain security
  • Can’t track which vendors access sensitive data

Technical Gaps:

  • Lack internal expertise to set up technical security controls
  • Use cloud and AI tools without reviewing privacy implications first
  • Don’t have centralized monitoring for security threats

People and Process:

  • Train staff once at hire and never refresh that training
  • Have no clear incident response plan
  • Don’t document security decisions or testing results

These gaps don’t cause issues immediately. Problems accumulate silently until a breach happens and the NPC demands answers. At that point, organizations scramble to document what they should have been tracking all along.

Data Privacy Act Compliance Checklist

Use this checklist to assess your current compliance status. Go through each item and mark whether you’ve completed it or need to work on it.

Data Inventory and Assessment:

  • Created an inventory of all systems processing personal data
  • Documented what information each system holds
  • Ranked systems by sensitivity level
  • Conducted Privacy Impact Assessments for high-risk systems
  • Identified risks and documented control plans

Organizational Structure:

  • Assigned someone responsible for privacy compliance
  • Created data protection policies covering collection, use, retention, and deletion
  • Established protocols for handling customer requests about their data
  • Created confidentiality agreements for employees
  • Developed agreements with vendors covering data security

Access and Permissions:

  • Implemented role-based access control
  • Documented who has access to what systems
  • Reviewed access permissions in the last three months
  • Removed access for former employees

Technical Security:

  • Enabled encryption for sensitive data at rest and in transit
  • Implemented strong password requirements
  • Activated multi-factor authentication on critical systems
  • Deployed antivirus and endpoint protection
  • Enabled logging and monitoring of data access
  • Conducted vulnerability scans in the last 12 months
  • Applied security patches on schedule
  • Secured cloud configurations

Physical Security:

  • Restricted physical access to server rooms and file storage areas
  • Implemented clean-desk policies
  • Planned secure destruction of old media and paper records

Backups and Disaster Recovery:

  • Created encrypted backups of critical data
  • Tested backup restoration procedures
  • Documented backup schedules and retention periods

Staff Training and Incident Response:

  • Conducted privacy and security training for all staff
  • Documented training completion dates
  • Created an incident response plan
  • Tested the incident response plan
  • Identified who to contact if a breach occurs

Testing and Monitoring:

  • Conducted a vulnerability assessment in the last 12 months
  • Performed penetration testing on critical systems
  • Reviewed configuration settings against security baselines
  • Monitor systems continuously for suspicious activity

Documentation:

  • Maintained records of all policies and procedures
  • Documented all risk assessments and remediation decisions
  • Kept training records with dates
  • Saved all security testing reports
  • Created an incident log with dates and responses

NPC Compliance:

  • Registered with the NPC if required by data volume
  • Understand breach notification requirements
  • Know the 72-hour notification timeline
  • Have contact information for NPC reporting

Is Your Business NPC Compliant? Get a Free Compliance Security Audit Today.

Penalties for Non-Compliance

Non-compliance with the Data Privacy Act carries serious consequences. Understanding what you face helps prioritize compliance efforts.

Criminal Penalties:

Violation Type Imprisonment Fines When It Applies
Unauthorized processing of personal information 1-3 years PHP 500,000 to PHP 2,000,000 Processing data without legal basis
Unauthorized processing of sensitive personal information 3-6 years PHP 500,000 to PHP 4,000,000 Processing sensitive personal information without permission
Unauthorized disclosure of personal information 1-3 years PHP 500,000 to PHP 1,000,000 Sharing ordinary personal data with unauthorized parties
Unauthorized disclosure of sensitive personal information 3-5 years PHP 500,000 to PHP 2,000,000 Sharing sensitive personal data with unauthorized parties
Negligent data access 1-3 years PHP 500,000 to PHP 2,000,000 Careless handling allowing unauthorized access
Large-scale violations (100+ people affected) Maximum penalties apply Maximum penalties apply Breaches affecting substantial numbers of individuals

Administrative Penalties:

Violation Severity Fine Amount Maximum Cap What Triggers It
Grave infractions 0.5% to 3% of annual gross income PHP 5 million per act Major security failures, repeated violations, or affecting 1,001+ data subjects
Major infractions 0.25% to 2% of annual gross income PHP 5 million per act Significant compliance gaps

Other Consequences:

  • Corporate officers who allowed violations through negligence face personal liability
  • Civil claims from affected individuals seeking damages
  • Business loss as customers leave after data breaches
  • Reputation damage affecting customer trust
  • Increased regulatory scrutiny on future compliance efforts
  • Failure to notify the NPC within 72 hours becomes a separate violation

Breach Notification Timeline:

You must notify affected individuals and the NPC within 72 hours if a breach poses risk of harm. Delayed or failed notification creates additional violations and penalties.

Best Practices for Maintaining Continuous Compliance

Compliance works best when you treat it as an ongoing program rather than a one-time project. Build these practices into your normal business operations.

During System Development:

  • Embed privacy considerations from the beginning (privacy-by-design) rather than adding security at the end
  • Review new systems for data privacy risks before they go live
  • Include security requirements in vendor contracts upfront
  • Test security before systems move to production

Regular Ongoing Work:

  • Conduct Privacy Impact Assessments on a risk-based schedule
  • Schedule security testing regularly (at least annually for critical systems)
  • Update your data inventory whenever you add new systems or vendors
  • Assess new vendors immediately when you bring them on
  • Review and update access permissions quarterly

Staying Current:

  • Monitor NPC circulars and advisories for requirement changes
  • Follow NPC guidance on new threats and technology shifts
  • Review your security controls annually against recognized frameworks like ISO 27001 or NIST standards
  • Keep your security appropriate to your actual business risks, not overkill

Documentation:

  • Document all policies and procedures
  • Keep records of every assessment and test you run
  • Maintain training completion records with dates
  • Save all testing reports and remediation decisions
  • Archive incident logs showing what happened and how you responded

Why Documentation Matters:

Documentation proves you took compliance seriously. When something goes wrong, it speeds up investigations. Without records, you can claim you implemented controls but can’t prove it.

How Qualysec Helps Businesses Strengthen Data Privacy Compliance

Testing is the bridge between policy and proof. Qualysec provides vulnerability assessments, penetration testing across web applications, mobile apps, APIs, cloud environments, and networks, plus configuration reviews. These services identify technical gaps before they become breach incidents, prioritize remediation by actual risk, and generate documentation showing your control framework is real and tested.

What testing addresses:

  • Encryption verification
  • Authentication and MFA effectiveness
  • Access control implementation
  • Backup security and recoverability
  • Endpoint protection functionality
  • Logging and monitoring coverage
  • Vulnerability and patch management execution
  • Network segmentation and protection
  • Cloud configuration correctness
  • API security

Testing results feed directly into your continuous improvement cycle. Instead of guessing whether your security works, you have independent evidence of what actually works and what needs attention.

Protect Your Business from NPC Fines

Talk to our cybersecurity experts to schedule a Data Privacy Act penetration test today.

Talk to an Expert

Talk to a Cybersecurity Expert

Conclusion

The Data Privacy Act requires your Philippine business to protect personal data through reasonable organizational, physical, and technical security measures. What counts as reasonable depends on your industry, size, the risks you identified, and best practices. Regular testing provides the evidence regulators expect to see.

Staying compliant doesn’t demand perfection. It demands knowing where you stand, documenting what you’re doing about it, and continuously improving. Understanding the Data Privacy Act security requirements and documenting how you meet them is what separates organizations that handle scrutiny well from those that scramble when something goes wrong. Organizations that treat compliance as an ongoing program rather than a checkbox exercise avoid the scrambling and penalties that come when things go wrong.

Frequently Asked Questions

What is the Data Privacy Act of the Philippines?

Republic Act No. 10173 protects personal information in government and private sectors. The National Privacy Commission (NPC) administers and enforces it through oversight, guidance, and penalties.

Who must comply with the Data Privacy Act?

Any organization processing personal data in the Philippines or of Philippine residents must comply. This includes small businesses, startups, nonprofits, and foreign companies regardless of size.

What are the security requirements under the Data Privacy Act?

Organizations must implement reasonable organizational, physical, and technical measures protecting personal data against destruction, alteration, disclosure, and unauthorized processing. NPC Circular 2023-06 provides detailed specifications.

What is the role of the National Privacy Commission (NPC)?

The NPC administers the Data Privacy Act, issues guidance and circulars, monitors organizational compliance, receives and investigates complaints, and enforces requirements through administrative actions and penalties.

Does the Data Privacy Act require penetration testing?

The law doesn’t mandate penetration testing by name but requires identifying vulnerabilities and implementing preventive, corrective, and mitigating measures. Independent testing effectively demonstrates compliance with this obligation.

How often should organisations perform vulnerability assessments?

Conduct assessments on risk-based schedules, commonly at least annually. Test more frequently for critical systems or after significant changes. Document your schedule and the reasons behind it.

What happens if a company fails to comply with the Data Privacy Act?

Criminal penalties include imprisonment of one to six years plus fines up to PHP 4,000,000. Administrative fines range from 0.25% to 3% of annual gross income (capped at PHP 5 million per act). Civil liability also applies.

How can businesses improve Data Privacy Act compliance?

Appoint a compliance officer, conduct Privacy Impact Assessments, implement documented security measures, train staff regularly, manage third-party vendors, test controls, and maintain incident-response readiness and procedures.

Is cloud data covered under the Data Privacy Act?

Yes. Personal data processed in cloud services remains subject to the Act. Organizations must ensure appropriate security, contractual protections, and accountability regardless of the cloud provider’s location.

How can Qualysec help businesses comply with the Data Privacy Act?

Qualysec provides vulnerability assessments, penetration testing on web and mobile apps, API testing, cloud assessments, and configuration reviews to identify and remediate technical security gaps supporting compliance.

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.