Interview preparation · Updated August 2026
The Beginner's DPO Reviewer
The Data Privacy Act of 2012, written for someone starting from zero. Every term is defined before it is used.
How to use this guide
If you have never worked in privacy before, this guide is written for you. It assumes you know nothing about the law and builds up from there.
Read it in order the first time. Each section uses words the previous one defined. Skipping ahead is how people end up memorising phrases they cannot explain.
How much time do you have?
| Time | Read this |
|---|---|
| 2 hours | Parts 1, 2, 3, and 9 |
| 1 day | Parts 1–5, then 9 and 10 |
| 1 week | All of it, then drill in the practice app until the Scenarios set retires |
← swipe tables sideways
You do not need to memorise every citation. Knowing what the rule is matters far more than knowing it lives in Section 12. But a few — Sections 11, 12, 13, 16, 20, and 21 — come up so often that they stop feeling like memorisation and start feeling like vocabulary. Those are marked as you go.
The big picture
Before any law, understand the problem it solves.
Organisations collect information about people. Your name, your birthday, your medical records, your salary, your location, what you clicked on last night. That information has value, and it can be used to help you or to hurt you.
The Data Privacy Act exists to say: you can collect and use people's information, but only under conditions, and the person the information is about keeps certain rights over it.
That is the whole law in one sentence. Everything else is detail.
The three things you need to know
1. The law is Republic Act No. 10173, the Data Privacy Act of 2012. People shorten it to "the DPA" or "RA 10173." It has been in force since 2012.
2. The regulator is the National Privacy Commission, the NPC. They are the government body that enforces the law. They write rules, investigate complaints, impose fines, and can order a company to stop processing data entirely. They became operational in 2016.
3. The DPA has an IRR — Implementing Rules and Regulations. The law says what; the IRR says how. When someone cites "Rule XI," they mean a rule in the IRR, not a section of the Act. The IRR came out in 2016 and was amended in 2023.
Where the NPC's rules come from
The NPC publishes two kinds of document you will hear referenced constantly:
- Circulars — binding rules. "NPC Circular 2022-01" sets out how fines are calculated.
- Advisories — guidance on how the NPC interprets the law. Not binding in the same way, but ignore them at your peril; they tell you exactly how the regulator thinks.
Both are numbered by year. 2025-02 means the second issuance of 2025.
The Act is the constitution of Philippine privacy. The IRR is the manual. Circulars and advisories are the regulator explaining itself. All of them matter.
The vocabulary
Privacy has a lot of jargon and it is genuinely the biggest barrier for beginners. Learn these eleven terms and most documents become readable.
Personal Information PI
Information that identifies a person, or from which you could reasonably work out who they are — either on its own, or by combining it with other information you have.
Examples: name, email, phone number, address, employee ID, photo, IP address.
Could someone figure out who this is? If yes, it is personal information.
Sensitive Personal Information SPI
A protected subset of personal information. Getting this wrong hurts people more, so the law guards it harder.
It covers: race, ethnic origin, marital status, age, colour, religious or philosophical or political affiliation; health, education, genetic or sexual life; any legal proceeding for an offence; and government-issued numbers — SSS, GSIS, TIN, PhilHealth, driver's licence, passport.
Processing SPI is prohibited by default. You need one of a short list of specific justifications. Penalties for mishandling it run roughly double.
Privileged Information
Communications that are legally confidential — lawyer and client, doctor and patient, priest and penitent. Defined by the Rules of Court, not by the DPA itself. It comes up rarely; know the name.
Processing
Any single thing you do with personal data. Collecting it, storing it, reading it, updating it, sharing it, deleting it. All of it is processing.
Thinking "processing" means something technical or computational. Writing a name on paper and putting it in a drawer is processing.
Data Subject
The living person the information is about. You are a data subject of your bank, your school, your employer.
Personal Information Controller PIC
The organisation that decides why and how personal data gets used. It is in charge, and it carries the main legal responsibility.
Personal Information Processor PIP
An organisation that handles personal data on behalf of a PIC, following its instructions.
A hospital collects your medical records and decides how they are used — the hospital is the PIC. It hires a cloud company to store them — the cloud company is the PIP. The cloud company cannot decide to do anything else with your records.
And critically: the hospital stays responsible for what happens to your data, even inside the cloud company's systems.
The same organisation can be a PIC for some data and a PIP for other data. A BPO is a PIP for its client's customer data and a PIC for its own employees' data.
Data Protection Officer DPO
The person inside an organisation accountable for privacy compliance. That is the job you are interviewing for. Part 3 covers it fully.
Personal Data Breach
A security incident where personal data is destroyed, lost, altered, disclosed, or accessed without authorisation. Not every incident is a breach; not every breach must be reported. Part 5 covers the difference.
Privacy Impact Assessment PIA
A structured review you run before building or launching something that will handle personal data. It asks: what data, why, who sees it, what could go wrong, how do we reduce that risk?
A risk assessment specifically for privacy. Same idea as checking a building's fire safety before opening it.
Lawful Basis
The legal justification for processing personal data. You must have one before you start. There are six for ordinary personal information. Part 4 covers them.
Consent is only one of the six. Many people assume you always need consent. You do not, and often you should not rely on it.
What a DPO actually does
The job in one line
A DPO makes sure the organisation follows privacy law, and is the person the regulator and the public can talk to.
The five duties, in plain terms
1. Know what data the organisation holds. You cannot protect what you cannot see. This means building and maintaining a record of every system that touches personal data — what it holds, why, who can see it, how long it stays.
2. Check that new things are safe before they launch. This is where PIAs live. A new app, a new vendor, a new marketing campaign — you review it before it goes live.
3. Handle people's requests. Someone asks what data you hold on them, or asks you to correct or delete it. You make sure that happens, properly and on time.
4. Handle breaches. When something goes wrong, you run the response and decide whether the NPC and affected people must be told — within 72 hours. Part 5 covers this.
5. Train everyone else. Most privacy failures are ordinary people making ordinary mistakes. Training is not a box-tick; it is the highest-leverage thing you do.
The part interviewers care about most: independence
The law requires the DPO to be independent. Beginners often nod at this word without understanding it. Here is what it actually means:
- Nobody can tell you what conclusion to reach on a privacy question.
- You cannot be fired or punished for doing the role properly.
- You report to the highest level of management, not to a department head.
- You get budget, access, and time to do the work.
But independence is not veto power. You advise. You flag risk. You put it in writing. Management decides, and management owns the consequences.
The answer is not "I resign" and it is not "I overrule them." It is: put the advice in writing, record the risk and who accepted it, escalate to the top, and keep the record. That document protects you and the organisation both.
Who cannot be the DPO
Anyone who decides how personal data gets used, because they would be checking their own work. That rules out the CEO, Head of IT, Head of HR, and Head of Marketing. This is called a conflict of interest and it is a favourite interview question.
DPO vs COP
A Compliance Officer for Privacy handles a branch or a regional office and reports to the DPO. It is a delegation, not a replacement. Every organisation still needs one DPO. Many fresh graduates enter privacy as a COP or a privacy associate — it is a normal path.
The five pillars — memorise these
The NPC frames compliance as five pillars. This gets asked almost verbatim.
- Appoint a DPO
- Conduct a Privacy Impact Assessment
- Create a Privacy Management Program and privacy manual
- Implement privacy and data protection measures — organisational, physical, technical
- Exercise breach reporting procedures
The law in plain English
Who the law applies to
Anyone processing personal data in the Philippines, government or private.
It also reaches outside the country, if the organisation uses equipment located here, has an office or branch here, or processes Filipinos' data in connection with that presence. This is called extraterritorial reach.
The exclusions in Section 4 are information-specific, not company-wide. A news organisation gets an exclusion for journalistic material. It does not get an exclusion for its employees' payroll records.
The three principles (Sec. 11)
Every processing activity must satisfy all three.
| Principle | What it asks |
|---|---|
| Transparency | Does the person know what you are doing with their data, and why? |
| Legitimate purpose | Is your reason legal and not against public policy? |
| Proportionality | Are you collecting only what you actually need? |
Most real arguments come down to "do you genuinely need all of this?" If the purpose could be achieved with less data, you are collecting too much.
The six lawful bases (Sec. 12)
You need at least one before processing ordinary personal information.
- Consent — the person agreed.
- Contract — you need the data to deliver something they asked for. An online store needs your address to ship your order.
- Legal obligation — a law requires you to hold it. Employers must keep tax records.
- Vital interests — to protect someone's life or health.
- Public authority or national emergency — government mandate, public order and safety.
- Legitimate interests — a genuine business reason that does not override the person's rights. Fraud detection is the classic example.
Consent is often the weakest basis, not the strongest.
Consent must be freely given. If the person cannot realistically say no — an employee, or someone who needs the service — the consent is not real. And if you would carry on processing after they withdrew consent, then consent was never your actual basis. Say this in the interview and you will sound like someone who has thought about it.
Sensitive personal information (Sec. 13)
Start your answer with the framing: processing SPI is prohibited by default. Then give the exceptions:
- Consent, given before processing. For privileged information, all parties must consent.
- A law provides for it, with safeguards.
- Life and health, where the person cannot consent themselves.
- Non-commercial purposes of public organisations, limited to members, no onward sharing.
- Medical treatment by a practitioner or institution with safeguards.
- Legal claims — establishing, exercising, or defending them.
The rights of a data subject (Sec. 16)
People hold rights over their own data. In plain terms:
| Right | What the person can do |
|---|---|
| To be informed | Know you are collecting their data, and why — before you do it |
| To object | Say no, including to marketing and to profiling |
| To access | Ask for a copy, plus who you shared it with and why |
| To rectification | Have wrong information corrected |
| To erasure or blocking | Have data deleted or its use suspended, in defined circumstances |
| To damages | Be compensated for harm from mishandled data |
| To data portability | Get their data in a usable electronic format (Sec. 18) |
| To complain | Take it to the NPC |
Rights pass to lawful heirs if the person dies or becomes incapacitated.
A deletion request loses to a legal retention obligation. If the BIR requires you to keep transaction records, you keep them — but you delete everything else about that person, and you stop using the retained records for anything but the legal purpose. That balanced answer scores far better than "we must always delete."
Keeping data secure (Sec. 20)
The law asks for reasonable and appropriate measures in three categories:
- Organisational — policies, a DPO, training, access rules, contracts with vendors.
- Physical — locked rooms, controlled office access, secure disposal of paper and drives.
- Technical — encryption, access controls, logging, backups, patching.
"Reasonable and appropriate" scales with the sensitivity of the data, the size of the organisation, and the cost. A hospital and a sari-sari store are not held to the same standard.
Accountability (Sec. 21)
The PIC stays responsible for personal data it holds or transfers to someone else, including overseas.
You cannot outsource responsibility. If your payroll vendor is breached, it is still your problem, your notification duty, your data subjects.
The DPA has no adequacy or standard-clause system for international transfers. Accountability under Section 21 is the control, managed through contracts and due diligence. Do not import GDPR mechanics into a Philippine answer.
When things go wrong
What counts as a breach
A security incident is anything that threatens data. A personal data breach is narrower: personal data was actually destroyed, lost, altered, disclosed, or accessed without authorisation.
The 72-hour rule (Sec. 20(f))
You must notify the NPC and the affected people within 72 hours — but only when all three of these are true:
- Sensitive personal information, or information that could enable identity fraud, is involved.
- There is reasonable belief it was acquired by someone unauthorised.
- The breach is likely to give rise to a real risk of serious harm.
Two details beginners get wrong:
- The clock starts on knowledge or reasonable belief, not on confirmation. You do not get to run a three-week investigation first. File an initial notification and supplement it later.
- The clock starts when you find out, not when the incident happened. Discovering a leak that began eight months ago does not forfeit the duty — and the duration will make the harm assessment worse.
Concealing a breach is its own crime (Sec. 30) — roughly 18 months to 5 years imprisonment.
So when you are genuinely unsure whether to report: report. Over-reporting costs you paperwork. Under-reporting is a criminal offence.
Ongoing reporting
- Annual Security Incident Report (ASIR) — due 31 March each year, covering the previous year. It includes all incidents, even those that never met the notification threshold.
- Registration with the NPC — the certificate lasts one year and needs renewal.
What the NPC can actually do to you
| Power | In practice |
|---|---|
| Investigate and adjudicate | On a complaint, or on its own initiative |
| Compliance orders | Do this, by this date |
| Cease and desist orders | Stop immediately |
| Ban processing | Temporarily or permanently |
| Administrative fines | See below |
| Refer for prosecution | To the DOJ — the NPC does not prosecute criminal cases itself |
The fines (NPC Circular 2022-01)
| Tier | Amount |
|---|---|
| Grave infractions | 0.5% to 3% of annual gross income |
| Major infractions | 0.25% to 2% of annual gross income |
| Cap | ₱5,000,000 per single act |
Note the base is gross income, not profit. A company losing money still pays.
The criminal side
Roughly 6 months to 7 years imprisonment and ₱100,000 to ₱5,000,000 in fines, depending on the offence.
Three aggravators worth knowing:
- Responsible officers are personally liable (Sec. 34) — the company being fined does not shield the individuals.
- Data of 100 or more people draws the maximum penalty (Sec. 35).
- Public officers face disqualification from office (Sec. 36).
Administrative and criminal proceedings run in parallel. Paying a fine does not close criminal exposure.
A real case to cite
In October 2025 the NPC issued a cease and desist order against Tools for Humanity, operator of World App, over collection of biometric iris data.
The point it established: paying people for their data does not produce valid consent. Consent obtained through financial incentive is not freely given. The NPC looked at the quality of the consent, not merely whether a box had been ticked.
Naming one current enforcement action signals that you follow the field, not just the textbook. This one is easy to remember and makes a real doctrinal point.
Privacy in software development
If the employer builds software, this section is where you can outshine candidates with more years than you. Most of them stopped reading at the 2012 Act.
The key document: NPC Advisory 2025-02
In 2025 the NPC published Guidelines on Privacy Engineering in Systems Life Cycle Processes. It maps privacy duties onto the five phases of building software, and applies to systems at any stage — new builds, live systems, and updates alike.
Two concepts anchor it:
- Privacy by design — privacy is built into the architecture from the start, not added before launch.
- Privacy by default — the out-of-the-box setting is the most private one. The user opts in to more sharing, never has to opt out.
Location off until switched on. Profile private until made public. Analytics off until consented.
The five phases
1. Planning and requirements. Decide the lawful basis before anything is built. Run the PIA here. Write privacy requirements into the acceptance criteria. Push back on collecting fields nobody can justify — this is the cheapest moment to say no.
2. Design and development. Encryption in transit and at rest. Role-based access so people see only what their job needs. Pseudonymisation and other privacy-enhancing technologies. Secure coding. Private defaults. No dark patterns.
3. Testing. Do not use real production data to test. Test systems rarely have production-grade access control or logging, so copying real customer data into them multiplies your exposure. Use synthetic or properly anonymised data. And test the privacy features themselves — does the consent withdrawal actually work? Does the deletion job actually delete?
4. Deployment. Check the configuration before go-live. Assess every third-party SDK and vendor. Update your records and NPC registration. Notify the NPC if the system does automated decision-making or profiling.
5. Operation and maintenance. Audit logging. Patching. Automated deletion when retention periods expire. Periodic reassessment. Monitoring good enough to detect a breach inside the 72-hour window.
Dark patterns
A dark pattern is an interface designed to push someone toward a choice they would not freely make.
Examples you can name:
- "Accept all" as a bright button, "Reject" as grey text
- Pre-ticked marketing checkboxes
- One click to sign up, five clicks to delete your account
- Guilt-tripping copy: "No thanks, I like paying more"
Is saying no as easy, as visible, and as few clicks as saying yes? If not, it is a dark pattern. The NPC treats these as an enforcement matter, not a design opinion.
AI features
The NPC confirmed in Advisory 2024-04 that the DPA applies fully to AI systems — there is no AI exemption. You still need a lawful basis for training data and for inference, and they may be different. Transparency still applies. And "the model performs better with more data" is not a lawful basis — proportionality still bites.
Scraping public data
Advisory 2026-01 deals with scraping publicly available personal data. The headline: public does not mean free to process. Data being visible on the internet is not one of the six lawful bases. Purpose limitation carries over — information posted for one context cannot simply be repurposed.
Anonymised vs pseudonymised
Beginners mix these up constantly, and interviewers know it.
- Anonymised — identity cannot be recovered by anyone, ever. Falls outside the DPA.
- Pseudonymised — identifiers replaced with codes, but a key exists somewhere that could reverse it. Still personal data. Still fully covered.
If anyone in your organisation can reverse it, it is pseudonymisation, not anonymisation.
Answering as a fresh graduate
This section is the one nobody writes for you. Read it twice.
The honest situation
You will likely be asked, in some form: "You don't have experience. Why should we hire you?"
It is a fair question and it is not hostile. They already know your background — they read your CV and invited you anyway. They are testing how you handle it, not whether it is true.
What does not work
- Pretending. Claiming experience you do not have collapses on the second follow-up question, and it ends the interview.
- Apologising. "I know I'm just a fresh grad, sorry…" tells them to doubt you.
- Deflecting into unrelated achievements.
What works
Acknowledge it plainly, then pivot to what you did instead.
"You're right that I haven't run a privacy programme yet. What I have done is go deep on the current framework — I've read the Act, the IRR, and the NPC circulars, including Advisory 2025-02 on privacy engineering, which I think is the most relevant one for a company that builds software. I'd rather be honest that my first ninety days would involve a lot of learning, and tell you specifically what I'd be learning."
That answer does three things: it is honest, it proves initiative with a specific citation, and it shows self-awareness. All three are things they are actually screening for.
Your real advantages — name them
You are current. Someone who trained in 2018 may not have read the 2025 privacy engineering advisory or the 2026 scraping guidance. You have. That is a genuine edge, not a consolation prize.
You have no bad habits. You have not spent years at an organisation that treated privacy as paperwork.
You are cheaper and you will stay. Nobody says this out loud, but it is real. Signalling that you want to grow into the role matters.
You know how software gets built. If you have any coding, IT, or systems background, that is unusually valuable here — most privacy people do not, and they struggle to talk to engineers.
Have these three things ready
1. A 90-day plan. Even a rough one. It shows you can think in structure rather than tasks.
Days 1–30: map what data the organisation holds and check the NPC registration status. Days 31–60: gap assessment against the five pillars, and build a breach runbook with a named owner for the 72-hour clock. Days 61–90: start the PIA process, run training, report metrics to management.
2. Two things you would ask a senior person in week one. Naming what you do not know, specifically, is more convincing than claiming you know everything. Good candidates: "I'd want to sit with whoever handles vendor contracts, because PIP agreements are where accountability actually gets lost."
3. Questions for them. Part 10 has a list. Asking nothing reads as low interest.
On saying "I don't know"
You will hit a question you cannot answer. Everyone does. The strong version:
"I don't know that one. My instinct is that it falls under Section 13, since it involves health data — but I wouldn't want to guess. I'd check the IRR and the relevant circular before advising anyone on it."
That is a good answer, not a failure. A DPO who guesses is genuinely dangerous, and interviewers know it. Showing that you know where to look beats bluffing every time.
Practice questions
Work through these out loud. Full sets are in the practice app.
What is the Data Privacy Act, in your own words?
A law that lets organisations use people's personal information, but only under conditions — and it gives people rights over their own data. It is enforced by the National Privacy Commission.
What is the difference between a PIC and a PIP?
The PIC decides why and how data is used and carries the main responsibility. The PIP handles data on the PIC's behalf, following instructions. A hospital is a PIC; the cloud provider storing its records is a PIP. Crucially, the PIC stays responsible even for what happens at the PIP.
Is consent always required?
No — it is one of six lawful bases under Section 12. Contract, legal obligation, vital interests, public authority, and legitimate interests are the others. Consent is often the weakest, because it must be freely given, and in situations like employment the person cannot realistically refuse.
What would you do if there is a data breach?
Contain it first — stop the exposure and preserve the logs. Then assess it against the three-part test: sensitive or identity-fraud-enabling data, reasonable belief of unauthorised acquisition, and likely real risk of serious harm. If all three are met, notify the NPC and the affected people within 72 hours from when we knew. Document everything, then fix the root cause. And if it is a close call, I would notify — concealment is a separate crime under Section 30.
How would you handle privacy in software development?
Follow the five phases from NPC Advisory 2025-02. Establish the lawful basis and run the PIA at planning. Build in encryption, access control, and private defaults during design. Use synthetic rather than production data in testing. Review configuration and vendors at deployment. Then logging, patching, and automated retention in operations.
Can our Head of IT be the DPO?
No — that is a conflict of interest. IT decides how data gets processed, so they would be checking their own work. The DPO has to be independent of the people making processing decisions.
Someone asks us to delete all their data, but we need their invoices for tax records. What do you do?
The right to erasure is not absolute; it yields to a legal retention obligation. So I would delete everything not legally required — marketing profile, preferences, behavioural data — and retain only the minimum the tax rules require, for only as long as required. Those retained records get blocked from any other use. Then I would explain the split to the person in plain terms and log the decision.
Where would you look if you didn't know the answer to a privacy question?
The Act and the IRR first, then the NPC's circulars and advisories on privacy.gov.ph. If it is sector-specific, the relevant regulator too — BSP for banking, DOH for health. And I would escalate rather than guess if someone needed an answer to act on.
Cheat sheet
| Thing | Answer |
|---|---|
| The law | RA 10173, Data Privacy Act of 2012 |
| The regulator | National Privacy Commission (NPC), operational 2016 |
| Breach notification | 72 hours from knowledge or reasonable belief |
| Breach test | 3 conditions, all must be met |
| ASIR deadline | 31 March |
| Lawful bases (ordinary PI) | 6 — Sec. 12 |
| SPI grounds | 6 exceptions — Sec. 13, prohibited by default |
| Data subject rights | 8, plus transmissibility to heirs |
| General principles | 3 — transparency, legitimate purpose, proportionality |
| Pillars of compliance | 5 |
| SDLC phases | 5 — Advisory 2025-02 |
| Fines, grave | 0.5%–3% of annual gross income |
| Fines, major | 0.25%–2% of annual gross income |
| Fine cap | ₱5,000,000 per single act |
| Criminal range | ~6 months–7 years; ₱100,000–₱5,000,000 |
| Large-scale trigger | Data of 100+ people → maximum penalty |
| Registration validity | 1 year |
The six sections worth memorising
| Sec. | What it holds |
|---|---|
| 11 | Three principles |
| 12 | Six lawful bases |
| 13 | Sensitive personal information |
| 16 | Data subject rights |
| 20 | Security measures; 20(f) is breach notification |
| 21 | Accountability |
The scenario skeleton
Every situational question follows the same shape. Memorise the sequence, not the answers:
Before the interview
Checklist
Questions to ask them
Asking good questions is the cheapest way to look senior. Pick three:
- Is the DPO role full-time, and who does it report to?
- Are you currently registered with the NPC?
- Has a Privacy Impact Assessment been done, and on which systems?
- Is there a privacy manual and a breach response plan already?
- Have you had a reportable breach or an NPC inquiry before?
- How many vendors process personal data on your behalf?
- Does engineering have a privacy checkpoint today, or would I be building that?
- Who would I learn from — is there a senior privacy person or external counsel?
It is a genuinely strong question from a fresh graduate. It signals you expect to be trained rather than assuming you already know everything.
A last word
You do not need to know everything. Nobody does — privacy professionals look things up constantly, because the rules change every year.
What an interviewer is actually testing is narrower than you fear: do you understand the shape of the law, do you know where to look, and will you tell the truth when you are unsure?
Get those three right and the gaps in your knowledge stop being disqualifying. They become the reason they are hiring someone junior in the first place.
Good luck.
Based on RA 10173 and its IRR; NPC Circulars 16-03, 20-02, 2020-03, 2021-01, 2022-01, 2022-04, 2023-05, 2024-02, 2025-01; NPC Advisories 2017-01, 2017-03, 2024-04, 2025-01, 2025-02, 2026-01, 2026-02. Always confirm against the official text at privacy.gov.ph. This is interview preparation, not legal advice.