Five pillars of data privacy compliance in the Philippines under the Data Privacy Act
Data privacy compliance is an ongoing organizational responsibility—not simply a privacy policy.

Compliance with data privacy regulations is no longer simply a matter of having a privacy policy. For organizations that collect, use, store, share, or process personal information, compliance is an ongoing responsibility that touches nearly every part of the business.

 

Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), requires organizations to observe the principles of transparency, legitimate purpose, and proportionality when processing personal information. It also requires personal information controllers (PICs) and personal information processors (PIPs) to implement reasonable and appropriate organizational, physical, and technical measures to protect personal data.

 

The National Privacy Commission (NPC) has identified five pillars that organizations, as PICs and PIPs, can use as a framework for building a robust privacy compliance program, which are discussed below.

 

1. Appoint a Data Protection Officer

 

The first step is accountability. Organizations should designate a Data Protection Officer (DPO) or another individual who is responsible for overseeing compliance with data privacy requirements.

 

The DPO is not merely the person who handles privacy complaints. The role may include advising management, assisting with data-subject requests, overseeing privacy policies, coordinating with the NPC, and helping ensure that security incidents and personal data breaches are properly managed and reported.

 

More importantly, the DPO should have sufficient knowledge, independence, and access to management to perform the role effectively.

 

2. Conduct a Privacy Risk or Impact Assessment


Organizations cannot protect information properly if they do not understand the risks involved in processing it.

 

A Privacy Impact Assessment (PIA) helps an organization identify what personal information it collects, why it collects the information, where the information goes, who has access to it, how long it is retained, and what could happen if the information is compromised.

 

The assessment should consider the nature, scope, context, and purposes of processing, as well as the potential impact on the rights and freedoms of data subjects. A PIA can help an organization identify privacy risks early and determine the measures necessary to address them.

 

3. Establish a Privacy Management Program

 

Privacy compliance should not depend on individual employees remembering what they are supposed to do.

 

Organizations should establish policies and procedures that translate the requirements of the DPA into everyday business practices. These may cover data collection, retention and disposal, access controls, data sharing, outsourcing, employee responsibilities, data-subject requests, incident response, and other processing activities.

 

The program should also be reviewed and updated as the organization’s operations, technology, and risks change.

 

4. Implement Appropriate Privacy and Security Measures

 

Compliance requires more than written policies. Those policies must be implemented.

 

The DPA requires reasonable and appropriate organizational, physical, and technical measures to protect personal information against unauthorized access, disclosure, alteration, destruction, and other unlawful processing. The appropriate level of security depends on factors such as the nature of the information, the risks involved, the size and complexity of the organization, and available security practices.

 

These measures may include access controls, authentication measures, employee training, secure systems, confidentiality obligations, monitoring, vulnerability assessments, and appropriate contractual safeguards for third-party service providers.

 

5. Regularly Exercise Breach Reporting Procedure

 

Even organizations with strong safeguards cannot assume that a security incident will never happen. What matters is whether the organization is prepared to respond.

 

Organizations should maintain a security incident management policy and procedures for handling personal data breaches. These should include an incident response team, procedures for containing the incident, measures for mitigating the risk arising from the incident, and procedures for complying with breach notification requirements.

 

Not every breach requires notification to the NPC and affected data subjects. Mandatory notification applies when the conditions under the DPA and applicable NPC regulations are met. Where notification is required, the NPC’s rules generally require notification within 72 hours from knowledge of, or reasonable belief that, a reportable personal data breach has occurred.

 

Compliance Is an Ongoing Responsibility

 

Ultimately, data privacy compliance is not a one-time project. It is a continuing process of identifying risks, implementing safeguards, educating personnel, reviewing practices, and responding appropriately when something goes wrong.

 

For organizations operating in the Philippines, the goal should not simply be to comply because the law requires it. A well-designed privacy program helps protect customers, employees, business partners, and the organization itself.

 

Privacy compliance is about responsible handling of information entrusted to an organization. That responsibility begins long before a data breach occurs—and continues long after one has been resolved.

 

Finally, privacy compliance is not just a responsibility of the DPO, the management, or the board of directors of an organization. It is everybody’s responsibility.

 

NARP LAW assists clients in navigating complex legal issues, regulatory requirements, and legal risks structuring operations for compliance and growth. We support organizations in ensuring data privacy compliance and in the assessment of privacy risks.

 

For more information, you may contact us at info@narplaw.com or at +639063731095.

Scroll to Top