Data Processing Agreement in the Philippines: What the DPA and Its IRR Require
A data processing agreement in the Philippines is governed by the Data Privacy Act and its IRR, which require written outsourcing terms and impose duties on processors.
A data processing agreement in the Philippines is the contract that governs the relationship between a personal information controller (PIC) — the entity that decides what personal data is collected and why — and a personal information processor (PIP), the entity it instructs or outsources processing to. The Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations (IRR) require this relationship to be documented, and the IRR devotes an entire rule — Rule X on Outsourcing and Subcontracting Agreements — to it. The PIC remains accountable for the data; the processor acts only on the controller's instructions.
Who is a personal information processor under the DPA?
Under Section 3 of the IRR, a personal information processor is any natural or juridical person, or any other body, to whom a personal information controller may outsource or instruct the processing of personal data pertaining to a data subject.
The same section defines a personal information controller as the person or body who controls the processing of personal data, or instructs another to process personal data on its behalf. There is control when the entity decides what information is collected, or the purpose or extent of its processing.
The distinction matters. A person who merely performs functions as instructed by another is excluded from the definition of a controller. That is the classic processor role: a payroll provider, a cloud storage vendor, a third-party call center, or an IT support contractor handling personal data on someone else's instructions.
Is a data processing agreement required?
Yes. Rule X of the IRR — covering subcontracts of personal data, agreements for outsourcing, and the duty of the personal information processor — governs this relationship. The rule exists because outsourcing does not transfer accountability: the controller remains responsible for personal data even when a processor handles it.
Note also the IRR's definition of data sharing, which expressly excludes outsourcing — the disclosure or transfer of personal data by a controller to a processor. That means an outsourcing arrangement is not treated as data sharing; it is governed by the outsourcing and subcontracting rules instead. Parties sometimes mislabel a processing arrangement as "data sharing," which can lead to the wrong compliance measures.
What should the agreement cover?
The IRR does not prescribe a single template, but Rule X read with the rest of the Rules points to the terms a sound agreement should contain:
- Instructions and scope. The processor acts only upon the instructions of the controller. The agreement should define what data is processed, for what purpose, and for how long.
- Confidentiality. Personnel of the processor who access personal data should be bound to confidentiality.
- Security measures. Under Rule VI, the controller and processor must implement organizational, physical, and technical security measures appropriate to the nature of the data and the risks of processing. Section 29 of the IRR speaks of the appropriate level of security.
- Breach cooperation. Rule IX requires data breach notification, and the processor must be able to notify the controller promptly so the controller can comply.
- Rights of data subjects. Section 6 of the IRR provides that controllers and processors must uphold the rights of data subjects and adhere to general data privacy principles.
- Sub-subcontracting. If the processor engages another processor, the arrangement should be covered by a similar written agreement.
- Return or disposal of data. The agreement should state what happens to the data at the end of the engagement.
What are the duties of the processor?
Rule X of the IRR includes a provision on the duty of the personal information processor. Read with the rest of the Rules, the processor's core obligations are to process personal data only on the documented instructions of the controller, to implement the required security measures, to assist the controller in responding to data subject requests and breaches, and to keep the processing confidential.
The processor does not become the controller simply by handling the data. But it can be held accountable: Rule XII of the IRR addresses accountability for transfer of personal information and accountability for violation of the Act, these Rules and other issuances. Rule XIII sets out penalties, including for unauthorized processing and unauthorized disclosure.
What about transfers and offshore processors?
Section 4 of the IRR gives the law extraterritorial reach. It applies to processing by any natural or juridical person in the government or private sector, including acts done outside the Philippines where the entity is found or established in the country, where the processing relates to a Philippine citizen or resident, where the processing is done in the Philippines, or where the entity has links to the Philippines — for example, use of equipment located in the country, a contract entered in the Philippines, or an office, branch, or agency here.
For a Philippine company engaging an offshore processor, this means the DPA and IRR can follow the data. The agreement should therefore address where data will be stored and processed and what safeguards apply.
Frequently asked questions
Is a data processing agreement required under the Data Privacy Act? Yes. The IRR's Rule X on Outsourcing and Subcontracting Agreements governs the outsourcing relationship, and the controller must be able to show it instructed the processor and that appropriate safeguards are in place.
What is the difference between a personal information controller and a personal information processor? The controller decides what personal data is collected and the purpose or extent of processing. The processor processes personal data on the controller's instructions. The controller retains accountability.
Does a data processing agreement remove the company's liability? No. Outsourcing does not transfer accountability. The controller remains responsible for compliance, and both controllers and processors can be held liable under Rule XII and Rule XIII of the IRR.
Practical takeaways
- A data processing agreement documents an outsourcing relationship between a personal information controller and a personal information processor, governed by Rule X of the DPA IRR.
- Outsourcing is expressly excluded from the IRR's definition of data sharing — do not confuse the two when drafting.
- The agreement should cover instructions and scope, confidentiality, security measures, breach cooperation, data subject rights, sub-processing, and return or disposal of data.
- The controller stays accountable for the data; the processor must act only on instructions and can itself be penalized under Rule XIII.
- The DPA has extraterritorial reach under Section 4 of the IRR, so offshore processing arrangements still need safeguards.
Primary sources
The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.
-
NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016
-
IRR OF REPUBLIC ACT NO. 10173 - IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 10173, KNOWN AS THE “DATA PRIVACY ACT OF 2012”
-
NPC CIRCULAR NO. 2014-014, April 25, 2014
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
This topic sits within our Technology, AI & Digital Economy practice.
Related reading
Dark fiber lease in the Philippines sits outside public utility classification, but the agreement still needs the right legal treatment and regulatory checks.
NPC enforcement fines in the Philippines are administrative penalties the National Privacy Commission may impose for violations of the Data Privacy Act of 2012.
Legal process outsourcing in the Philippines lets in-house teams delegate legal work to local providers while Philippine law and professional rules still govern the lawyers involved.
A colocation SLA in the Philippines should cover power, cooling, uptime, security, and support. Here is what to contract for and which rules apply.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.