Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Philippines · Data Privacy Act (RA 10173)

Security & 72-hour NPC breach notice.

Applies to: Personal information controllers in the Philippines. Built · in force

What the signed record shows

Security records, privacy-principle signals, and breach detail for NPC notification.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: RA 10173 s.11/20/21; IRR Rule IX

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations (NPC, 2016). Provisions addressed:

s. 20
Security of personal information (organisational, physical and technical measures); s. 20(f) is the breach-notification trigger (notify the Commission and affected data subjects).
s. 21
Principle of accountability; designate accountable individual(s) (the statutory root of the Data Protection Officer requirement).
s. 11
General data privacy principles (transparency, legitimate purpose, proportionality; retention limits).
IRR Rule IX
personal-data-breach notification to the National Privacy Commission (NPC) and affected data subjects within 72 hours. RA 10173 approved 2012; the IRR took effect 2016. NPC Circular 16-03 governs breach management.

Taken from the Regulayer entry for this instrument, which is built against the primary text.