The Philippines Data Privacy Regime
The Philippines’ first comprehensive data protection law, the Data Privacy Act of 2012 (the “Act“), took effect on 8 September 2012. The Act mandated the creation of a National Privacy Commission (“NPC“) to implement, enforce and monitor compliance with the Act, with one of its duties to promulgate rules and regulations to effectively implement the provisions of the Act. It was not until March 2016 that the NPC was officially formed, and soon after issued draft implementing rules and regulations of the Act (“IRRs“). Following a period of public consultation, the IRRs were finalised and formally promulgated on 24 August 2016 and will come into effect today, 9 September 2016.
The IRRs and their Impact
The IRRs will have a significant impact on business in the Philippines generally and on the Philippines’ IT and business process outsourcing (“IT/BPO“) industry – an industry reportedly worth over USD 20 billion in the Philippines and the largest contributor to the country’s GDP.
Indeed, one of the main drivers behind the Act was to bring the Philippines in line with international data protection standards to encourage investment and maintain the country’s position as a leading IT/BPO outsourcing destination. Importantly, the IRRs apply to both “personal information controllers” – those who control the processing of personal data, and “personal information processors” – those engaged by personal information controllers to process personal data on their behalf. This means that both customers that use data processing facilities in the Philippines and IT/BPO vendors themselves will need to comply. Personal information does not need to relate to Philippine residents in order to warrant protection.