Law Evolution Timeline

Data Privacy Act

13 events

✏️ Amended by (8)

EO 01, s. 2016 · 2016

National Privacy Commission established

President Rodrigo Duterte issued Executive Order No. 01 reconstituting the National Privacy Commission with independence from DICT supervision. The NPC was granted quasi-judicial powers to enforce the Data Privacy Act and adjudicate complaints.

NPC Circular 16-01 · 2016

Implementing Rules and Regulations adopted

The National Privacy Commission issued the comprehensive Implementing Rules and Regulations of the Data Privacy Act. The IRR clarified key concepts including consent requirements, data subject rights, security measures, and breach notification procedures.

NPC Circular 16-03 · 2016

Security of Personal Data regulations issued

The NPC issued regulations on the security of personal data requiring organizational, physical, and technical measures to protect personal information. This circular mandated risk assessments, encryption standards, and incident response protocols.

NPC Advisory Opinion 2017-01 · 2017

Data breach notification protocols strengthened

Following several high-profile data breaches including the COMELEC voter database leak, the NPC issued binding guidance on breach notification timelines and content requirements. Organizations faced mandatory 72-hour reporting windows and potential penalties for delayed disclosure.

NPC Circular 19-01 · 2019

General Data Privacy Consent Guidelines issued

The NPC issued comprehensive guidelines on obtaining valid consent for data processing, requiring clear, specific, and freely given consent. The circular prohibited pre-ticked boxes and required granular consent for different processing purposes.

NPC Advisory 2020-01 · 2020

COVID-19 data privacy guidelines issued

During the COVID-19 pandemic, the NPC issued guidelines balancing public health data collection with privacy rights. The advisory permitted health data processing for contact tracing while requiring strict security, purpose limitation, and data minimization.

NPC Circular 22-01 · 2022

Guidelines on AI and automated decision-making

The NPC issued pioneering guidelines regulating artificial intelligence and automated decision-making that uses personal data. The circular required transparency, human intervention options, and prohibition of solely automated decisions affecting legal or significant rights.

NPC Circular 23-01 · 2023

Cross-border data transfer guidelines strengthened

The NPC issued updated regulations on international data transfers requiring adequacy assessments and appropriate safeguards. The circular introduced standard contractual clauses and binding corporate rules for compliant cross-border transfers.

2012 · Aug📜 Enactment

RA 10173

Data Privacy Act of 2012 signed into law

President Benigno Aquino III signed the Data Privacy Act into law on August 15, 2012, establishing comprehensive data protection framework for the Philippines. The law aimed to protect personal information in information and communications systems and ensure free flow of information for innovation and growth.

2012 · Sep📜 Enactment

RA 10173

Data Privacy Act effectivity

The Data Privacy Act took effect on September 8, 2012, fifteen days after its publication in the Manila Bulletin and Malaya. This marked the beginning of data protection obligations for personal information controllers and processors in the Philippines.

2016 · Jan✏️ Amendment

EO 01, s. 2016

National Privacy Commission established

President Rodrigo Duterte issued Executive Order No. 01 reconstituting the National Privacy Commission with independence from DICT supervision. The NPC was granted quasi-judicial powers to enforce the Data Privacy Act and adjudicate complaints.

2016 · Sep✏️ Amendment

NPC Circular 16-01

Implementing Rules and Regulations adopted

The National Privacy Commission issued the comprehensive Implementing Rules and Regulations of the Data Privacy Act. The IRR clarified key concepts including consent requirements, data subject rights, security measures, and breach notification procedures.

2016 · Oct✏️ Amendment

NPC Circular 16-03

Security of Personal Data regulations issued

The NPC issued regulations on the security of personal data requiring organizational, physical, and technical measures to protect personal information. This circular mandated risk assessments, encryption standards, and incident response protocols.

2017 · May✏️ Amendment

NPC Advisory Opinion 2017-01

Data breach notification protocols strengthened

Following several high-profile data breaches including the COMELEC voter database leak, the NPC issued binding guidance on breach notification timelines and content requirements. Organizations faced mandatory 72-hour reporting windows and potential penalties for delayed disclosure.

2018 · Feb⚖️ SC Ruling

NPC Case No. 17-007

First major privacy penalty in Re: Nationwide Air Espana

The NPC imposed a PHP 6 million penalty on Nationwide Air Espana for unauthorized processing and disclosure of passenger personal data. This was the first significant administrative penalty demonstrating the NPC's enforcement capability and commitment to sanctions.

2019 · Jan✏️ Amendment

NPC Circular 19-01

General Data Privacy Consent Guidelines issued

The NPC issued comprehensive guidelines on obtaining valid consent for data processing, requiring clear, specific, and freely given consent. The circular prohibited pre-ticked boxes and required granular consent for different processing purposes.

2020 · Apr✏️ Amendment

NPC Advisory 2020-01

COVID-19 data privacy guidelines issued

During the COVID-19 pandemic, the NPC issued guidelines balancing public health data collection with privacy rights. The advisory permitted health data processing for contact tracing while requiring strict security, purpose limitation, and data minimization.

2021 · Mar⚖️ SC Ruling

NPC Case No. 20-D04

NPC sanctions Philippine Health Insurance Corporation for data breach

The NPC found PhilHealth liable for the massive September 2020 data breach exposing sensitive health information of millions of members. The case established that government agencies are equally accountable under the Data Privacy Act.

2022 · May✏️ Amendment

NPC Circular 22-01

Guidelines on AI and automated decision-making

The NPC issued pioneering guidelines regulating artificial intelligence and automated decision-making that uses personal data. The circular required transparency, human intervention options, and prohibition of solely automated decisions affecting legal or significant rights.

2023 · Jun✏️ Amendment

NPC Circular 23-01

Cross-border data transfer guidelines strengthened

The NPC issued updated regulations on international data transfers requiring adequacy assessments and appropriate safeguards. The circular introduced standard contractual clauses and binding corporate rules for compliant cross-border transfers.

2024 · Feb⚖️ SC Ruling

NPC Case No. 23-011

NPC imposes record penalty in Re: Major Telco Data Leak

The NPC imposed a PHP 15 million penalty on a major telecommunications company for inadequate security measures leading to a massive customer data breach. This represented the highest administrative fine in NPC history and signaled escalating enforcement.

20122024 · 13 legislative & jurisprudential events