Philippines

Philippines Data Privacy Act

51 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

51 controls 0 frameworks share controls with it Philippines verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
PHILDPA-1Scope, Lawful Basis, General Principles, Sensitive Personal Info0
PHILDPA-2Data Subject Rights, Notice, Direct Marketing, Cookies0
PHILDPA-3Children's Data, PIA, Privacy by Design, Sensitive Categories0
PHILDPA-4Security of Personal Data, Access Logs, Encryption0
PHILDPA-5Cross-Border Transfer and Processor Agreements0
PHILDPA-6DPO, NPC Registration, Records, Privacy Management Program, Training0
PHILDPA-7Personal Data Breach Notification and Breach Management0
PHILDPA-8NPC Cooperation, Compliance, Enforcement, Sectoral Considerations0
1-3Title, declaration of policy and definitions0
11General data privacy principles: transparency, legitimate purpose, proportionality0
12Criteria for lawful processing of personal information0
13Sensitive personal information and privileged information0
14Subcontract of personal information0
15Extension of privileged communication0
16Rights of the data subject (section 16)0
16(a)-(b)Right to be informed and the information to be furnished before processing0
16(c)Right to reasonable access0
16(d)Right to dispute inaccuracy and have it corrected0
16(e)Right to suspend, withdraw, block, remove or destroy personal information0
16(f)Right to be indemnified for damages0
17Transmissibility of the data subject's rights0
18Right to data portability0
19Non-applicability of the rights chapter0
20Security of personal information (section 20)0
20(a)-(c)Reasonable and appropriate organizational, physical and technical security measures0
20(d)Security measures by third-party processors0
20(e)Confidentiality of personnel processing personal information0
20(f)Notification of the Commission and affected data subjects of a personal data breach0
21Principle of accountability (section 21)0
21(a)Accountability for transferred personal information: comparable protection0
21(b)Designated individual accountable for compliance (Data Protection Officer)0
22Responsibility of heads of government agencies for sensitive personal information0
23Access by agency personnel to sensitive personal information: on-site, online and off-site0
24Applicability to government contractors0
25-32Chapter VIII: penalties0
33-37Combination of acts, extent of liability, large scale, public officers, restitution0
38-45Chapter IX: interpretation, IRR, reports, appropriations, transitory period and repeal0
5Protection afforded to journalists and their sources0
6Extraterritorial application0
7-10The National Privacy Commission0
IRRImplementing Rules and Regulations of RA 10173 (NPC, 24 August 2016)0
R.19IRR section 19: consent, collection, data quality, retention and secure disposal0
R.20IRR section 20: data sharing and data sharing agreements0
R.26IRR section 26: organizational security measures0
R.27IRR section 27: physical security measures0
R.28IRR section 28: technical security measures0
R.34IRR section 34(b): right to object0
R.41IRR section 41: breach report to the Commission, documentation of all incidents and the annual summary0
R.44IRR section 44: contents of agreements for outsourcing to a personal information processor0
R.47IRR section 47: registration of personal data processing systems0
R.48IRR section 48: notification of automated processing operations and decisions based solely on them0

Tell me when Philippines Data Privacy Act files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for Philippines Data Privacy Act, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition