Aug 14, 2026ai governancedata privacy actinternet transactions actnational privacy commissionphilippines ai lawartificial intelligence regulation

AI Governance in the Philippines: What the Law Requires Today

AI governance in the Philippines today relies on the Data Privacy Act of 2012 and the Internet Transactions Act of 2023. Learn the key compliance rules.


AI governance in the Philippines has no single, comprehensive law dedicated solely to artificial intelligence. Instead, existing statutes regulate AI systems indirectly through their impact on personal data and online transactions. The two principal laws are Republic Act No. 10173, the Data Privacy Act of 2012, and the Internet Transactions Act of 2023. Any organization deploying AI in the Philippines must comply with both, particularly where AI processes personal data or facilitates e-commerce.

The Data Privacy Act of 2012 as the Core AI Governance Framework

The Data Privacy Act of 2012, implemented through its Implementing Rules and Regulations (IRR), governs how AI systems handle personal data. The National Privacy Commission (NPC) administers and implements the Act and monitors compliance with international data protection standards.

Under the IRR, "processing" includes any operation performed on personal data, including collection, recording, organization, storage, updating, retrieval, consultation, use, consolidation, blocking, erasure, or destruction. This definition covers automated means, which means AI-driven data processing falls squarely within the law's scope.

The law applies to any natural or juridical person in the government or private sector that processes personal data. Importantly, it has extraterritorial reach: it applies to acts done outside the Philippines if the person involved is found or established in the Philippines, the processing relates to personal data about a Philippine citizen or resident, the processing is done in the Philippines, or the entity has links to the Philippines such as using equipment located in the country or maintaining an office, branch, or agency here.

Key Definitions Every AI Developer Must Know

The IRR provides definitions critical to understanding AI compliance obligations:

  • Personal information refers to any information from which the identity of an individual is apparent or can be reasonably and directly ascertained, or when put together with other information would directly and certainly identify an individual.
  • Sensitive personal information includes data about an individual's race, ethnic origin, marital status, age, color, and religious, philosophical, or political affiliations; health, education, genetic or sexual life; government-issued identifiers like social security numbers and tax returns; and information specifically established by law to be kept classified.
  • Profiling refers to any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, particularly to analyze or predict aspects concerning performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
  • Personal information controller controls the processing of personal data or instructs another to process it on its behalf.
  • Personal information processor is any person to whom a controller outsources or instructs the processing of personal data.

AI systems that engage in profiling must therefore comply with the Data Privacy Act's requirements, including the principles of transparency, legitimate purpose, and proportionality.

Data Privacy Principles for AI Systems

The IRR establishes three general principles that AI systems must observe:

  1. Transparency — the data subject must be informed of the purpose of processing.
  2. Legitimate purpose — processing must be for a declared, specified, and legitimate purpose.
  3. Proportionality — processing must be adequate, relevant, suitable, and not excessive.

Additionally, collection must be for a specified and legitimate purpose, personal data must be processed fairly and lawfully, processing should ensure data quality, and personal data shall not be retained longer than necessary. Any authorized further processing must have adequate safeguards.

Lawful Processing Requirements

AI systems may only process personal information if the processing falls under one of the lawful bases recognized by the IRR. These include consent of the data subject, which is defined as any freely given, specific, and informed indication of will, evidenced by written, electronic, or recorded means.

For sensitive personal information, stricter requirements apply. The IRR specifies separate conditions for lawful processing of sensitive personal information and privileged information.

Security Measures for AI Data Processing

The IRR requires organizational, physical, and technical security measures to protect personal data. The appropriate level of security depends on the nature of the personal data, the risks presented by the processing, the size of the organization, and the complexity of operations.

For AI systems, this means implementing technical safeguards such as access controls, encryption where appropriate, and audit trails. The NPC has the function of issuing guidelines for these security measures, taking into account current data privacy best practices and the most appropriate standard recognized by the information and communications technology industry.

The Internet Transactions Act of 2023 and AI in E-Commerce

The Internet Transactions Act of 2023 regulates e-commerce and directly addresses data privacy obligations for digital platforms. The Act declares a policy to guarantee effective regulation of e-commerce to protect consumer rights and data privacy.

Digital platforms, e-marketplaces, and e-retailers must take necessary precautions to protect the data privacy of consumers at all times in accordance with the Data Privacy Act of 2012. The Act explicitly states that digital platforms and e-marketplaces shall be covered by the provisions of Republic Act No. 10173 and issuances by the NPC.

The Act also has extraterritorial application: a person who engages in e-commerce and avails of the Philippine market to the extent of establishing minimum contacts shall be subject to applicable Philippine laws despite lack of legal presence in the country.

Compliance Obligations for AI-Driven Businesses

Organizations using AI in the Philippines should take the following steps:

  • Conduct a data inventory — identify what personal data AI systems collect, process, and store.
  • Establish lawful bases — ensure every processing activity has a valid basis under the Data Privacy Act.
  • Implement security measures — put in place organizational, physical, and technical safeguards appropriate to the risks.
  • Prepare for data breach notification — the IRR requires notification procedures for personal data breaches.
  • Review e-commerce obligations — if AI powers an online platform, comply with the Internet Transactions Act's requirements on transparency, merchant verification, and data privacy.

Frequently asked questions

Is there a specific AI law in the Philippines? No. The Philippines currently regulates AI through existing laws, primarily the Data Privacy Act of 2012 and the Internet Transactions Act of 2023.

Does the Data Privacy Act apply to AI systems that process data of Filipinos from abroad? Yes. The IRR provides that the Act applies to processing done outside the Philippines if it relates to personal data about a Philippine citizen or resident, or if the entity has links to the Philippines.

What is profiling under Philippine data privacy law? Profiling is any form of automated processing of personal data used to evaluate personal aspects of a natural person, including analyzing or predicting performance at work, economic situation, health, preferences, interests, reliability, behavior, location, or movements.

Practical takeaways

  • AI governance in the Philippines is currently anchored on the Data Privacy Act of 2012 and the Internet Transactions Act of 2023; no standalone AI statute exists yet.
  • Any AI system that processes personal data must comply with the principles of transparency, legitimate purpose, and proportionality under the NPC's IRR.
  • AI-driven profiling activities are expressly within the scope of the Data Privacy Act and require lawful bases for processing.
  • Digital platforms using AI must comply with both the Data Privacy Act and the Internet Transactions Act, including obligations to protect consumer data privacy.
  • The NPC has broad enforcement powers, including issuing compliance orders, imposing administrative fines, and recommending prosecution of crimes under the Act.

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

This article is general information and not legal advice. For your situation, ask ASG Legal AI or book a consultation.