Reference · Current as of August 2026
Index of Issuances
Every authority cited in this project, what it does, and why it matters to a DPO. Official texts live at privacy.gov.ph.
The statute
| Reference | Subject |
|---|---|
| RA 10173 | Data Privacy Act of 2012. Took effect 8 September 2012. |
| IRR | Implementing Rules and Regulations, 2016 as amended 2023. Rule XI covers the DPO; Rules VI–VIII cover security measures; Rule IX covers outsourcing. |
| Const. Art. III | Secs. 2 and 3 of the 1987 Constitution — privacy of communication and correspondence, and freedom from unreasonable searches. Worth one sentence if asked where the right comes from. |
← swipe tables sideways
The Act has sections. The IRR has rules. So "Rule XI" is never a section of the Act, and "Sec. 21" is never part of the IRR. Mixing the two is a common tell that someone has only skimmed.
Sections worth citing by number
| Sec. | Subject |
|---|---|
| 3 | Definitions — PI, SPI, privileged, PIC, PIP, processing |
| 4 | Scope, and the information-specific exclusions |
| 6 | Extraterritorial application |
| 7 | Functions of the NPC |
| 11 | Three general data privacy principles |
| 12 | Six lawful bases for personal information |
| 13 | Grounds for sensitive personal and privileged information |
| 14 | Subcontracting |
| 16 | Rights of the data subject |
| 17 | Transmissibility of rights to heirs |
| 18 | Right to data portability |
| 20 | Security of personal information; 20(f) is breach notification |
| 21 | Accountability — the DPO's foundation |
| 25–34 | Criminal offences |
| 35 | Large-scale aggravation — data of 100 or more persons |
| 36 | Offence by a public officer — disqualification |
| 37 | Restitution |
| 44 | Liability of the PIP |
Circulars
Circulars are binding rules. When one applies to your situation, it is not optional guidance.
| Circular | Subject | Why it matters |
|---|---|---|
| 16-03 | Personal Data Breach Management | The 72-hour rule, breach report contents, and the Annual Security Incident Report |
| 20-01 | Processing for loan-related transactions (am. by 2022-02) | Lending sector; the NPC's response to abusive collection apps |
| 20-02 | Rules on Cease and Desist Orders | The procedure behind the NPC's sharpest tool |
| 2020-03 | Data Sharing Agreements | Read alongside Advisory 2025-01, not on its own |
| 2021-01 | NPC Rules of Procedure | How complaints, investigations, and adjudication actually run |
| 2021-02 | Processing during public health emergencies | — |
| 2022-01 | Guidelines on Administrative Fines | The fine tiers and the ₱5M cap. Effective 27 August 2022, prospective only |
| 2022-02 | Amending Circular 20-01 | — |
| 2022-03 | Private security agencies handling customer and visitor information | — |
| 2022-04 | Registration, ADM notification, DPO designation, Seal | Your registration obligations. Verify the Annex thresholds yourself |
| 2023-01 | Schedule of fees and charges | — |
| 2023-05 | Philippine Privacy Mark certification | Voluntary certification; useful to raise as a maturity goal |
| 2024-02 | CCTV systems | Repealed and replaced Advisory 2020-04 |
| 2025-01 | Body-worn cameras | — |
Advisories
Advisories are interpretive guidance. Not binding in the same way as a circular, but they tell you exactly how the regulator reasons — which makes them extremely useful in an interview.
| Advisory | Subject | Why it matters |
|---|---|---|
| 2017-01 | Designation of Data Protection Officers | Independence, conflict of interest, COPs, qualifications — the core of your role |
| 2017-03 | Guidelines on Privacy Impact Assessments | How to actually run a PIA |
| 2024-04 | Application of the DPA to AI systems | Confirms there is no AI carve-out. Cite this the moment AI comes up |
| 2025-01 | Clarification on Circular 2020-03 (DSAs) | DSAs are optional; no NPC approval required; the sharing activity is still reviewable |
| 2025-02 | Privacy Engineering in Systems Life Cycle Processes | The five SDLC phases. Your strongest differentiator for a software role |
| 2026-01 | Data Scraping of Publicly Available Personal Data | Public does not mean free to process |
| 2026-02 | Breach notification via the DBNMS | Postponement, exemption, alternative notification, and extension requests |
NPC–IC Joint Advisory 2025-001 covers privacy-enhancing technologies in insurance — relevant only if the employer is an insurer.
Enforcement worth citing
| Date | Matter | Holding |
|---|---|---|
| 8 Oct 2025 | Cease and desist order against Tools for Humanity (World App), on biometric iris collection | Financially incentivised consent is not freely given consent. The NPC examined the quality of consent, not merely its existence |
You do not need a catalogue. Naming a single recent action, correctly dated, with the point it established, signals that you follow the field rather than only the textbook. Most candidates cannot name any.
If you only have one evening
Read these three, in this order.
- NPC Advisory 2025-02 — short, and it is your edge for anything involving software.
- NPC Circular 2022-01 — the fine structure. Interviewers ask for numbers.
- Secs. 11, 12, 13, 16, 20, and 21 of RA 10173 — the load-bearing provisions. Everything else hangs off them.
The registration thresholds in Circular 2022-04 are the most commonly misquoted numbers in Philippine privacy practice. Check the Annex against the official text before you cite them in an interview.
Current as of August 2026. Issuances land regularly — check privacy.gov.ph for anything published since. This is interview preparation, not legal advice.