What Is Data Privacy Act of 2012 (Republic Act No. 10173)?
The Philippines' principal comprehensive privacy statute is Republic Act No. 10173, the Data Privacy Act of 2012. The official National Privacy Commission (NPC) text covers processing of all types of personal information by natural and juridical persons, including some controllers and processors outside the Philippines that use equipment in the country or maintain a Philippine office, branch, or agency. Section 6 also describes specific links that can give the Act extraterritorial application to processing involving Philippine citizens or residents. The Act requires transparency, legitimate purpose, and proportionality, and permits processing only when a statutory lawful-processing condition applies. The NPC's Implementing Rules and Regulations (IRR) explain accountability for transfers and describe rights relating to notice, objection, access, rectification, erasure or blocking, portability, and damages. The NPC receives privacy complaints and publishes formal complaint instructions. This page is a source-backed orientation, not legal advice. The official sources do not establish one universal data-broker request form or one set of fields for every controller. A broker's current privacy notice, controller identity, response process, and any applicable exception should be checked separately before sending a request.
At a glance
- Full name
- Data Privacy Act of 2012 (Republic Act No. 10173)
- Short code
- RA 10173
- Jurisdiction
- Philippines
- Enacted
- 2012
- Regulator
- National Privacy Commission (NPC)
- Private right of action
- Limited
- Statutory citation
- Republic Act No. 10173 — Data Privacy Act of 2012
Scope, who RA 10173 covers
Protected data
Data subject rights
Right to be informed about whether personal information is processed and the purposes, scope, recipients, controller, storage period, and rights involved
Right to reasonable access to the contents and sources of personal information, recipients, processing details, automated processes, and controller identity
Right to dispute inaccuracies and have personal information corrected, subject to the Act and reasonable-request limits
Right to object, including to direct marketing, automated processing, or profiling, subject to statutory exceptions
Right to suspend, withdraw, block, remove, or destroy personal information when the statutory conditions and proof requirements are met
Right to data portability for qualifying electronic processing
Right to file a complaint with the National Privacy Commission
Right to indemnification for qualifying damages caused by inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal data
Notable features
The framework expressly addresses direct marketing, automated processing, profiling, data portability, transmissibility of rights, and accountability for domestic or international transfers. The NPC is both the supervisory authority and a published complaint route, but controller-specific procedures remain separate from the regulator route.
Enforcement & penalties
Regulator: National Privacy Commission (NPC)
Penalties: The Act contains criminal offenses for conduct such as unauthorized processing, negligent access, improper disposal, and unauthorized disclosure, with offense-specific imprisonment and fines. It also provides for restitution, while the NPC IRR describes administrative and enforcement powers. Penalties and remedies depend on the offense, facts, affected data, and current procedural requirements; this page does not convert statutory maximums into a prediction about a particular case.
Private right of action: The Act and NPC IRR recognize damages or indemnification rights and the Act provides that restitution for an aggrieved party is governed by the New Civil Code. The NPC can receive complaints, investigate, adjudicate, and award indemnity in matters affecting personal data. These routes do not guarantee compensation or replace a case-specific assessment of civil, administrative, or criminal procedure.
Relevance to data brokers
A data broker may be a personal information controller or processor depending on its role and facts. The Act and IRR support requests for access, correction, objection, or erasure or blocking when the statutory requirements apply, but they do not prove that every public-record or people-search listing must be removed on demand. Identify the controller, state the right and factual basis being invoked, request the broker’s applicable process, preserve delivery evidence, and use the NPC complaint route if a privacy violation or breach remains unresolved.
Exercise your rights
Review removal workflows for 1009 US/global profiles for $9
OfflistMe helps draft opt-out requests using the details you choose. Review the provider route and legal basis, then send from your own inbox. The tool is not legal advice and does not guarantee a broker's response.
Request Removal NowFAQ
What is the main privacy law in the Philippines?+
Republic Act No. 10173, the Data Privacy Act of 2012, is the principal statute described in the National Privacy Commission’s official text. Its framework covers personal-information processing by public and private actors, subject to statutory scope and exceptions.
Can the Philippines Data Privacy Act apply to a foreign data broker?+
Sometimes. The Act covers certain foreign controllers or processors that use equipment in the Philippines or maintain a Philippine office, branch, or agency, and Section 6 lists additional links involving Philippine citizens or residents and Philippine business or management connections. Applicability is fact-specific and is not established merely by a person finding a listing online.
Can I ask a broker to delete or block my personal information?+
You may invoke the right to erasure or blocking when the Act’s conditions are met, such as incomplete, outdated, false, unlawfully obtained, unauthorized, no-longer-necessary, or otherwise unlawful processing, or a violation of data-subject rights. The NPC IRR refers to substantial proof and recognizes exceptions, so deletion is not an automatic result for every request.
Can I object to direct marketing or profiling?+
Yes, the NPC IRR describes a right to object to processing including direct marketing, automated processing, or profiling. The controller may still rely on specified statutory exceptions, so the request should identify the processing and the right being exercised.
What information can I request from a controller?+
The Act and IRR describe reasonable access to the contents and sources of personal data, recipients, processing methods, disclosure reasons, certain automated processes, access or modification dates, and the controller’s identity and address. A controller’s published privacy notice may provide the current submission route and any identity checks.
How do I complain to the National Privacy Commission?+
The NPC publishes a complaint route for privacy violations and personal-data breaches. Its current formal-complaint page instructs complainants to download, print, fill out, notarize, and submit the form through one of the listed channels; check the official page for current instructions before filing.
Official sources & citations
Other international privacy regimes
RA 10173 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
