AI Governance in the Philippines: What Organizations Must Put in Place
Building AI governance in the Philippines starts with Data Privacy Act compliance, NPC registration, and security measures for automated processing.
The Philippines has no single AI law. AI governance in the Philippines is built from existing rules — chiefly the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, which already govern automated processing of personal data. Any organization using AI on data about people must comply with the same duties that apply to ordinary data processing: lawful basis, transparency, security, accountability, and respect for data subject rights. The National Privacy Commission (NPC) administers and enforces these rules.
What "AI governance" means under Philippine law
The NPC's IRR does not use the term "artificial intelligence," but it directly regulates the activities AI systems perform. Processing is defined broadly to include the collection, recording, organization, storage, updating, retrieval, consultation, use, consolidation, blocking, erasure, or destruction of data — whether by automated means or manual processing where data are contained in a filing system.
The IRR also defines profiling as any form of automated processing of personal data used to evaluate personal aspects of a natural person — analyzing or predicting performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements. If an AI system scores, ranks, or predicts things about people, it is profiling under these Rules.
Who is covered
The Data Privacy Act and its IRR apply to the processing of personal data by any natural or juridical person in the government or private sector. Coverage extends to acts done or practices engaged in outside the Philippines where the entity is found or established in the Philippines, the processing relates to a Philippine citizen or resident, the processing is done in the Philippines, or the entity has links to the Philippines — such as maintaining an office or branch here, entering into a contract here, or collecting or holding personal data in the country.
This matters for AI: a foreign-hosted model or offshore vendor does not remove the organization from Philippine jurisdiction.
The roles: controller and processor
Under the IRR, a personal information controller is the person or body who controls the processing of personal data, or instructs another to process it on its behalf. There is control if the entity decides what information is collected, or the purpose or extent of its processing. A personal information processor is the person or body to whom a controller may outsource or instruct the processing of personal data.
In practice, the organization deploying an AI tool is typically the controller and must answer for it. An AI vendor acting on instructions is typically a processor. The IRR requires that outsourcing arrangements be governed by agreements, and imposes a duty on personal information processors.
Core obligations to put in place
Lawful basis and principles. Processing must rest on a lawful basis, and the IRR sets out principles of transparency, legitimate purpose, and proportionality, along with principles for collection, processing, and retention. Collection must be for a specified and legitimate purpose; processing must be fair and lawful; data quality must be ensured; personal data must not be retained longer than necessary; and any authorized further processing must carry adequate safeguards.
Security measures. The IRR requires organizational, physical, and technical security measures appropriate to the nature of the data, the risks of processing, the size and complexity of the organization, current best practices, and cost. For AI, this means access controls, logging, vendor oversight, and safeguards against unauthorized use of training data.
Data subject rights. The IRR enumerates the rights of data subjects — to be informed, to object, to access, to correct, and to rectification, erasure, or blocking — plus the right to data portability. An AI system that cannot answer an access request, correct an erroneous record, or stop processing upon a valid objection is not compliant.
Breach response. A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. The IRR requires breach notification and specifies its contents, with procedures for notification and breach reports. A security incident — an event that affects or tends to affect data protection or may compromise availability, integrity, and confidentiality — also triggers internal handling even if no breach results.
Registration and accountability. The IRR provides for registration of data processing systems and notification for automated processing operations, and sets rules on accountability for transfers of personal information and for violations of the Act and Rules.
Penalties. The IRR lists offenses including unauthorized processing, accessing personal data through negligence, improper disposal, processing for unauthorized purposes, unauthorized access or intentional breach, concealment of security breaches involving sensitive personal information, malicious disclosure, and unauthorized disclosure, with fines and penalties.
If the organization is an online platform or merchant
The Internet Transactions Act of 2023 (Republic Act No. 11967) adds duties for digital platforms, e-marketplaces, e-retailers, and online merchants. They must take necessary precautions to protect consumer data privacy in accordance with the Data Privacy Act and comply with minimum information security standards set by the E-Commerce Bureau, the NPC, and other agencies. E-marketplaces must also maintain updated lists of online merchants and provide information upon subpoena in investigations based on sworn complaints.
A practical sequence
- Map every AI system that touches personal data, and classify the data involved.
- Confirm a lawful basis and document purpose, proportionality, and retention limits.
- Execute written agreements with vendors, assigning controller and processor roles.
- Adopt organizational, physical, and technical security measures proportionate to risk.
- Build workflows for access, correction, objection, erasure, and portability requests.
- Prepare breach detection, notification, and reporting procedures.
- Register or notify data processing systems as required, and keep accountability records.
Frequently asked questions
Is there an AI law in the Philippines? No single AI statute exists. AI is governed mainly by the Data Privacy Act of 2012 and its IRR, which regulate automated processing and profiling, alongside sector rules such as the Internet Transactions Act of 2023 for online platforms.
Does the Data Privacy Act cover AI profiling? Yes. The IRR defines profiling as automated processing used to evaluate personal aspects of a person, such as behavior, reliability, or performance at work, and applies the general data privacy principles to it.
What must a company do before deploying an AI tool on customer data? Establish a lawful basis, apply transparency, legitimate purpose, and proportionality, put security measures in place, honor data subject rights, and govern any vendor through a written outsourcing agreement.
Practical takeaways
- There is no standalone AI statute; compliance runs through the Data Privacy Act and its IRR.
- Automated profiling is expressly defined and regulated, so AI scoring and prediction tools are covered.
- Controller and processor roles must be documented in vendor agreements.
- Security measures must be proportionate to risk, data type, and organizational complexity.
- Breach notification and data subject rights must be operational, not just policy statements.
Primary sources
The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.
-
NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016
-
REPUBLIC ACT NO. 11967 - AN ACT PROTECTING ONLINE CONSUMERS AND MERCHANTS ENGAGED IN INTERNET TRANSACTIONS, CREATING FOR THIS PURPOSE ELECTRONIC COMMERCE BUREAU, APPROPRIATING FUNDS THEREFOR, AND FOR OTHER PURPOSES
-
IRR RUBPLIC ACT NO. 10844, October 17, 2016
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
This topic sits within our Tax Law & Compliance practice.
Related reading
Dark fiber lease in the Philippines sits outside public utility classification, but the agreement still needs the right legal treatment and regulatory checks.
NPC enforcement fines in the Philippines are administrative penalties the National Privacy Commission may impose for violations of the Data Privacy Act of 2012.
Legal process outsourcing in the Philippines lets in-house teams delegate legal work to local providers while Philippine law and professional rules still govern the lawyers involved.
A colocation SLA in the Philippines should cover power, cooling, uptime, security, and support. Here is what to contract for and which rules apply.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.