Aug 14, 2026cybersecurity law philippinescybercrime prevention actdata privacy actcomplianceincident responsera 10175

Cybersecurity Law in the Philippines: Compliance and Incident Response

Learn Philippine cybersecurity law compliance under the Cybercrime Prevention Act and Data Privacy Act, including penalties and incident response duties.


Philippine cybersecurity law is built on two main pillars: the Cybercrime Prevention Act of 2012 (Republic Act No. 10175) and the Data Privacy Act of 2012 (Republic Act No. 10173). Compliance means understanding the punishable acts under the first law and the data protection duties under the second. For businesses, the practical starting point is to implement security measures that protect computer systems and personal data, and to have a clear incident response plan ready before a breach occurs.

The Two Laws That Govern Cybersecurity in the Philippines

The Cybercrime Prevention Act of 2012 (RA 10175) defines and penalizes offenses committed through computer systems. Its Implementing Rules and Regulations (IRR), adopted on 12 August 2015, detail the punishable acts and the enforcement powers of law enforcement agencies.

The Data Privacy Act of 2012 (RA 10173) protects personal data. Its IRR, issued by the National Privacy Commission (NPC) on 24 August 2016, sets out the obligations of entities that collect, process, or store personal information.

Together, these laws create a compliance framework: secure your systems against cybercrime, and protect the personal data you hold.

Punishable Acts Under the Cybercrime Prevention Act

The IRR of RA 10175 identifies three categories of offenses: cybercrime offenses, computer-related offenses, and content-related offenses. Understanding these helps an organization know what conduct to prevent and detect.

Offenses against confidentiality, integrity, and availability of computer data and systems include:

  • Illegal Access – accessing a computer system without right.
  • Illegal Interception – intercepting non-public transmissions of computer data by technical means without right.
  • Data Interference – intentional or reckless alteration, damaging, deletion, or deterioration of computer data without right, including introducing viruses.
  • System Interference – intentional alteration or reckless hindering of the functioning of a computer or network without right.
  • Misuse of Devices – using, producing, selling, or possessing devices or passwords designed to commit these offenses, unless done for authorized testing of a computer system.

Computer-related offenses include:

  • Computer-related Forgery – inputting, altering, or deleting computer data without right, resulting in inauthentic data intended for legal purposes.
  • Computer-related Fraud – unauthorized input, alteration, or deletion of computer data causing damage with fraudulent intent.
  • Computer-related Identity Theft – intentional acquisition, use, or transfer of identifying information belonging to another without right.

Content-related offenses include child pornography committed through a computer system, with penalties one degree higher than under the Anti-Child Pornography Act of 2009.

The IRR also covers cyber-squatting, cybersex, and online libel, which applies only to the original author of the post.

Penalties and Corporate Liability

Penalties for core cybercrime offenses range from prision mayor or fines starting at PHP 200,000, up to an amount commensurate with the damage incurred. If committed against critical infrastructure, the penalty increases to reclusion temporal or a fine of at least PHP 500,000.

Corporate liability is significant. Under Section 6 of the IRR, if a punishable act is knowingly committed for the benefit of a juridical person by someone in a leading position, the entity faces a fine of at least double the imposable fines, up to PHP 10,000,000. Even if the offense was made possible by a lack of supervision or control, the entity can be fined up to PHP 5,000,000. This criminal liability of the company is separate from the liability of the individual who committed the offense.

Data Privacy Compliance Under RA 10173

The Data Privacy Act IRR requires personal information controllers and processors to implement organizational, physical, and technical security measures to protect personal data. These measures must be appropriate to the nature of the data, the risks presented by processing, the size of the organization, and current data privacy best practices.

Key principles include:

  • Transparency – data subjects must be informed of how their data is processed.
  • Legitimate purpose – processing must be for a specified and legitimate purpose.
  • Proportionality – only data necessary for the purpose should be collected.
  • Retention limitation – personal data shall not be retained longer than necessary.

The NPC has the power to issue compliance orders, impose administrative fines, and recommend prosecution to the Department of Justice for violations.

Incident Response: Data Breach Notification

Under the Data Privacy Act IRR, a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. The IRR requires notification procedures, but the specific timelines and thresholds are governed by NPC issuances.

In practice, an organization that suffers a breach should:

  1. Contain the breach immediately to prevent further damage.
  2. Assess the risk to affected data subjects.
  3. Notify the NPC and affected individuals as required by the rules.
  4. Document the incident and the response for regulatory review.

For cybercrime incidents, the NBI and PNP are the designated law enforcement authorities under Section 9 of the RA 10175 IRR. They conduct investigation, data recovery, and forensic analysis. Service providers are required to preserve traffic data and subscriber information for at least six months from the date of transaction.

Frequently Asked Questions

Is cybersecurity compliance mandatory for small businesses in the Philippines? Yes. The Data Privacy Act applies to any natural or juridical person processing personal data, regardless of size. The security measures required should be proportionate to the organization's size and the risks involved.

What is the penalty for violating the Cybercrime Prevention Act? Penalties include imprisonment (prision mayor) or fines starting at PHP 200,000, or both. If the offense targets critical infrastructure, the penalty increases to reclusion temporal or a fine of at least PHP 500,000.

Who enforces cybersecurity laws in the Philippines? The NBI and PNP handle cybercrime investigation and enforcement, coordinated by the DOJ Office of Cybercrime. The National Privacy Commission enforces the Data Privacy Act.

Practical Takeaways

  • Implement layered security: technical, physical, and organizational measures are all required under the Data Privacy Act IRR.
  • Know the punishable acts: illegal access, data interference, and identity theft are common risk areas for businesses.
  • Prepare an incident response plan: designate a team, document procedures, and know when to notify the NPC.
  • Train employees: most breaches stem from human error or negligence, which can trigger corporate liability.
  • Review vendor agreements: if a third party processes data on your behalf, ensure the contract addresses data protection duties.

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

This article is general information and not legal advice. For your situation, ask ASG Legal AI or book a consultation.