Law Evolution Timeline
Data Privacy Act
✏️ Amended by (8)
EO 01, s. 2016 · 2016
National Privacy Commission established
President Rodrigo Duterte issued Executive Order No. 01 reconstituting the National Privacy Commission with independence from DICT supervision. The NPC was granted quasi-judicial powers to enforce the Data Privacy Act and adjudicate complaints.
NPC Circular 16-01 · 2016
Implementing Rules and Regulations adopted
The National Privacy Commission issued the comprehensive Implementing Rules and Regulations of the Data Privacy Act. The IRR clarified key concepts including consent requirements, data subject rights, security measures, and breach notification procedures.
NPC Circular 16-03 · 2016
Security of Personal Data regulations issued
The NPC issued regulations on the security of personal data requiring organizational, physical, and technical measures to protect personal information. This circular mandated risk assessments, encryption standards, and incident response protocols.
NPC Advisory Opinion 2017-01 · 2017
Data breach notification protocols strengthened
Following several high-profile data breaches including the COMELEC voter database leak, the NPC issued binding guidance on breach notification timelines and content requirements. Organizations faced mandatory 72-hour reporting windows and potential penalties for delayed disclosure.
NPC Circular 19-01 · 2019
General Data Privacy Consent Guidelines issued
The NPC issued comprehensive guidelines on obtaining valid consent for data processing, requiring clear, specific, and freely given consent. The circular prohibited pre-ticked boxes and required granular consent for different processing purposes.
NPC Advisory 2020-01 · 2020
COVID-19 data privacy guidelines issued
During the COVID-19 pandemic, the NPC issued guidelines balancing public health data collection with privacy rights. The advisory permitted health data processing for contact tracing while requiring strict security, purpose limitation, and data minimization.
NPC Circular 22-01 · 2022
Guidelines on AI and automated decision-making
The NPC issued pioneering guidelines regulating artificial intelligence and automated decision-making that uses personal data. The circular required transparency, human intervention options, and prohibition of solely automated decisions affecting legal or significant rights.
NPC Circular 23-01 · 2023
Cross-border data transfer guidelines strengthened
The NPC issued updated regulations on international data transfers requiring adequacy assessments and appropriate safeguards. The circular introduced standard contractual clauses and binding corporate rules for compliant cross-border transfers.
RA 10173
Data Privacy Act of 2012 signed into law
President Benigno Aquino III signed the Data Privacy Act into law on August 15, 2012, establishing comprehensive data protection framework for the Philippines. The law aimed to protect personal information in information and communications systems and ensure free flow of information for innovation and growth.
RA 10173
Data Privacy Act effectivity
The Data Privacy Act took effect on September 8, 2012, fifteen days after its publication in the Manila Bulletin and Malaya. This marked the beginning of data protection obligations for personal information controllers and processors in the Philippines.
EO 01, s. 2016
National Privacy Commission established
President Rodrigo Duterte issued Executive Order No. 01 reconstituting the National Privacy Commission with independence from DICT supervision. The NPC was granted quasi-judicial powers to enforce the Data Privacy Act and adjudicate complaints.
NPC Circular 16-01
Implementing Rules and Regulations adopted
The National Privacy Commission issued the comprehensive Implementing Rules and Regulations of the Data Privacy Act. The IRR clarified key concepts including consent requirements, data subject rights, security measures, and breach notification procedures.
NPC Circular 16-03
Security of Personal Data regulations issued
The NPC issued regulations on the security of personal data requiring organizational, physical, and technical measures to protect personal information. This circular mandated risk assessments, encryption standards, and incident response protocols.
NPC Advisory Opinion 2017-01
Data breach notification protocols strengthened
Following several high-profile data breaches including the COMELEC voter database leak, the NPC issued binding guidance on breach notification timelines and content requirements. Organizations faced mandatory 72-hour reporting windows and potential penalties for delayed disclosure.
NPC Case No. 17-007
First major privacy penalty in Re: Nationwide Air Espana
The NPC imposed a PHP 6 million penalty on Nationwide Air Espana for unauthorized processing and disclosure of passenger personal data. This was the first significant administrative penalty demonstrating the NPC's enforcement capability and commitment to sanctions.
NPC Circular 19-01
General Data Privacy Consent Guidelines issued
The NPC issued comprehensive guidelines on obtaining valid consent for data processing, requiring clear, specific, and freely given consent. The circular prohibited pre-ticked boxes and required granular consent for different processing purposes.
NPC Advisory 2020-01
COVID-19 data privacy guidelines issued
During the COVID-19 pandemic, the NPC issued guidelines balancing public health data collection with privacy rights. The advisory permitted health data processing for contact tracing while requiring strict security, purpose limitation, and data minimization.
NPC Case No. 20-D04
NPC sanctions Philippine Health Insurance Corporation for data breach
The NPC found PhilHealth liable for the massive September 2020 data breach exposing sensitive health information of millions of members. The case established that government agencies are equally accountable under the Data Privacy Act.
NPC Circular 22-01
Guidelines on AI and automated decision-making
The NPC issued pioneering guidelines regulating artificial intelligence and automated decision-making that uses personal data. The circular required transparency, human intervention options, and prohibition of solely automated decisions affecting legal or significant rights.
NPC Circular 23-01
Cross-border data transfer guidelines strengthened
The NPC issued updated regulations on international data transfers requiring adequacy assessments and appropriate safeguards. The circular introduced standard contractual clauses and binding corporate rules for compliant cross-border transfers.
NPC Case No. 23-011
NPC imposes record penalty in Re: Major Telco Data Leak
The NPC imposed a PHP 15 million penalty on a major telecommunications company for inadequate security measures leading to a massive customer data breach. This represented the highest administrative fine in NPC history and signaled escalating enforcement.
2012–2024 · 13 legislative & jurisprudential events