Cybersecurity Program Requirements in the Philippines: What the Law Requires
Understand cybersecurity program requirements in the Philippines under the Cybercrime Prevention Act and the DICT Act, including data retention and corporate duties.
The Philippines does not impose a single, standardized cybersecurity program that every organization must file with one agency. Instead, the obligations come mainly from two statutes: Republic Act No. 10175, the Cybercrime Prevention Act of 2012, as implemented by its 2015 DOJ Rules and Regulations, and Republic Act No. 10844, the Department of Information and Communications Technology Act of 2015, as implemented by its 2016 IRR. The state's declared policy is to protect and safeguard the integrity of computer systems, networks, and databases, and the confidentiality, integrity, and availability of the data stored in them, from misuse, abuse, and illegal access.
How Philippine rules define cybersecurity
The DOJ Rules and Regulations implementing the Cybercrime Prevention Act define cybersecurity as the collection of tools, policies, risk management approaches, actions, training, best practices, assurance, and technologies that can be used to protect the cyber environment, and an organization and user's assets.
That definition matters because it shows the law treats cybersecurity as an ongoing effort — not a one-time purchase. A workable program built on this definition typically covers risk assessment, written policies, employee training, technical controls, and continuous assurance.
The same Rules define critical infrastructure as computer systems, networks, programs, data, or traffic data so vital that their incapacity, destruction, or interference would have a debilitating impact on national or economic security, public health and safety, or any combination of these. Organizations that fall in this category face higher stakes under the law.
The government's cybersecurity mandate
Under the 2016 IRR of Republic Act No. 10844, the Department of Information and Communications Technology (DICT) is directed to formulate a national cybersecurity plan consisting of robust and coherent strategies that minimize national security risks and promote a peaceful, secure, open, and cooperative ICT environment.
The DICT is also mandated to extend immediate assistance for the suppression of real-time cybercrime offenses and cyber-attacks against critical infrastructures through a computer emergency response team (CERT), and to provide proactive government countermeasures against incidents affecting Philippine cyberspace.
For private organizations, this means the state's cybersecurity architecture is led by the DICT, with the Cybercrime Investigation and Coordination Center (CICC) chaired by the DICT Secretary. The IRR also provides that all powers and functions related to cybersecurity — including formulation of the National Cybersecurity Plan and establishment of the National CERT — are transferred to the Department.
Data retention: the six-month preservation rule
One of the most concrete operational requirements appears in the DOJ Rules implementing the Cybercrime Prevention Act. Under Section 12 of those Rules, the integrity of traffic data and subscriber information shall be kept, retained, and preserved by a service provider for a minimum period of six (6) months from the date of the transaction.
Content data shall be similarly preserved for six (6) months from the date of receipt of the order from law enforcement authorities requiring its preservation. Law enforcement authorities may order a one-time extension for another six (6) months.
A service provider is defined in the Rules as any public or private entity that provides users of its service with the ability to communicate by means of a computer system, and any other entity that processes or stores computer data on behalf of such communication service or its users. If an organization meets this definition, the retention obligation applies.
The Rules also require that a service provider ordered to preserve computer data keep the order and its compliance with it confidential.
Corporate liability for cyber offenses
The DOJ Rules address what happens when cyber offenses are committed for the benefit of a company. Under Section 6 on Corporate Liability, when a punishable act is knowingly committed on behalf of or for the benefit of a juridical person by a natural person with a leading position — based on power of representation, authority to take decisions, or authority to exercise control — the juridical person shall be held liable for a fine equivalent to at least double the fines imposable, up to a maximum of Ten Million Pesos (P10,000,000.00).
If the offense was made possible by a lack of supervision or control over a person acting under the organization's authority, the juridical person may be held liable for a fine of at least double the imposable fines, up to a maximum of Five Million Pesos (P5,000,000.00).
This is the clearest legal reason to build internal controls: the law can hold the organization itself liable, without prejudice to the criminal liability of the individual who committed the offense.
Non-compliance with law enforcement orders
Section 19 of the DOJ Rules provides that failure to comply with the provisions of Chapter IV of the Act and Rules 7 and 8 of Chapter VII — specifically orders from law enforcement authorities — shall be punished as a violation of Presidential Decree No. 1829, with imprisonment of prision correccional in its maximum period, a fine of One Hundred Thousand Pesos (P100,000.00), or both, for each and every noncompliance.
Compliance with lawful orders is therefore itself a program requirement, not an optional courtesy.
Frequently asked questions
Is there a law requiring companies to have a cybersecurity program in the Philippines? No single statute requires every company to adopt a formally named cybersecurity program. However, Republic Act No. 10175 and its DOJ Rules impose concrete duties — including data preservation, cooperation with law enforcement, and exposure to corporate liability — that in practice require organizations to maintain cybersecurity policies and controls. Republic Act No. 10844 tasks the DICT with national cybersecurity planning and coordination.
How long must a service provider keep traffic data and subscriber information? Under Section 12 of the DOJ Rules implementing the Cybercrime Prevention Act, traffic data and subscriber information must be kept, retained, and preserved for a minimum of six (6) months from the date of the transaction. Content data is preserved for six (6) months from receipt of a law enforcement preservation order.
Can a company be fined for a cybercrime committed by its officer? Yes. Under Section 6 of the DOJ Rules, a juridical person may be held liable for a fine of at least double the imposable fines, up to Ten Million Pesos, when a punishable act is knowingly committed for its benefit by a person in a leading position. A separate fine of up to Five Million Pesos may apply where the offense was made possible by lack of supervision or control.
Practical takeaways
- Build your program around the legal definition of cybersecurity: tools, policies, risk management, training, and assurance — not just technology.
- If your organization qualifies as a service provider, implement a data retention schedule covering traffic data, subscriber information, and content data, with the six-month preservation period as the baseline.
- Treat law enforcement preservation and disclosure orders as priority items; non-compliance carries criminal and financial penalties.
- Reduce corporate exposure by documenting supervision and control over personnel with authority to act for the organization.
- Monitor DICT issuances on the National Cybersecurity Plan and CERT, since national policy shapes the standards expected of covered organizations.
Primary sources
The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.
-
DOJ RULES AND REGULATIONS IMPLEMENTING REPUBLIC ACT NO. 10175, OTHERWISE KNOWN AS THE "CYBERCRIME PREVENTION ACT OF 2012", August 12, 2015
-
IRR RUBPLIC ACT NO. 10844, October 17, 2016
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
This topic sits within our Technology, AI & Digital Economy practice.
Related reading
Product liability in the Philippines holds manufacturers, distributors, and sellers accountable for defective goods under the Consumer Act and the Civil Code.
Employee data retention in the Philippines follows the Data Privacy Act rule that personal data must not be kept longer than necessary for its purpose.
Employee monitoring in the Philippines is governed by the Data Privacy Act of 2012 and its IRR, which require transparency, legitimate purpose, and proportionality.
The Bangsamoro Administrative Code or BAA No. 13 prescribes the structure, powers, and procedures of the BARMM government. Here is what it covers.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.