·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

Data Sharing Agreements in the Philippines: Rules Under the Data Privacy Act

A data sharing agreement in the Philippines must follow the Data Privacy Act and its IRR. Learn what counts as data sharing and the rules that apply.


A data sharing agreement in the Philippines is a contract between a personal information controller (or processor) and a third party covering the disclosure or transfer of personal data. The National Privacy Commission's Implementing Rules and Regulations of the Data Privacy Act of 2012 define data sharing as the disclosure or transfer to a third party of personal data under the custody of a personal information controller or personal information processor. Where a processor shares data, the transfer must be upon the instructions of the controller. Outsourcing — a controller transferring data to a personal information processor — is expressly excluded from the definition. The IRR also devotes a specific section to the Principles for Data Sharing.

What counts as data sharing under the Data Privacy Act

The IRR's definition of data sharing has three elements: (1) a disclosure or transfer of personal data, (2) to a third party, and (3) the data is under the custody of a personal information controller or personal information processor.

If the disclosing party is a personal information processor, the disclosure or transfer must have been upon the instructions of the personal information controller concerned.

Data sharing vs. outsourcing: why the distinction matters

The definition excludes outsourcing, or the disclosure or transfer of personal data by a personal information controller to a personal information processor. Outsourcing is governed separately by the IRR's Rule X on Outsourcing and Subcontracting Agreements.

The distinction affects which rules apply and who remains accountable. A personal information controller is the person or body who controls the processing of personal data, or instructs another to process personal data on its behalf. Control exists if the entity decides on what information is collected, or the purpose or extent of its processing. A personal information processor, by contrast, is a person or body to whom a controller may outsource or instruct the processing of personal data.

The principles that govern data sharing

The IRR addresses data sharing under Rule IV, Data Privacy Principles, which includes Section 20, Principles for Data Sharing. This places data sharing within the same framework as the general principles of transparency, legitimate purpose, and proportionality, and the principles in collection, processing, and retention.

Those principles require that collection be for a specified and legitimate purpose; that personal data be processed fairly and lawfully; that processing ensure data quality; that personal data not be retained longer than necessary; and that any authorized further processing have adequate safeguards.

What a data sharing agreement should cover

A well-drafted agreement should reflect the IRR's principles. In practice, this means the parties should:

  • Identify the purpose. State the specified and legitimate purpose of the sharing, consistent with the principle that collection must be for a specified and legitimate purpose.
  • Define the data. Describe the personal data covered and confirm its quality, consistent with the principle that processing should ensure data quality.
  • Set retention rules. Provide that personal data shall not be retained longer than necessary.
  • Address further processing. Confirm that any authorized further processing shall have adequate safeguards.
  • Assign accountability. Clarify which party acts as personal information controller and which acts as personal information processor, since the IRR's Rule XII provides for accountability for transfer of personal information.

When the Data Privacy Act does not apply

The IRR's Section 5 on Special Cases lists information to which the Act and the Rules do not apply, only to the minimum extent necessary for the purpose, function, or activity concerned. These include information processed to allow public access to matters of public concern, personal information processed for journalistic, artistic, or literary purpose, and personal information processed for research intended for a public benefit, among others.

Even where an exemption is claimed, the burden of proving that the Act and the Rules are not applicable falls on those involved in the processing or the party claiming the non-applicability. The determination of any exemption shall be liberally interpreted in favor of the rights and interests of the data subject.

Frequently asked questions

Is a data sharing agreement required under the Data Privacy Act? The IRR defines data sharing and sets out Principles for Data Sharing, but the requirement to put an arrangement in writing flows from the general principles of transparency, legitimate purpose, and proportionality, and from the parties' accountability for the transfer of personal information.

What is the difference between data sharing and outsourcing? Data sharing is the disclosure or transfer of personal data to a third party. The IRR expressly excludes outsourcing — the disclosure or transfer of personal data by a personal information controller to a personal information processor — from the definition of data sharing.

Who is accountable when personal data is shared? Accountability follows the roles in the IRR. The personal information controller decides what information is collected and the purpose or extent of its processing, while a personal information processor acts on the controller's instructions. The IRR's Rule XII addresses accountability for transfer of personal information.

Practical takeaways

  • The IRR defines data sharing as the disclosure or transfer of personal data to a third party, and expressly excludes outsourcing.
  • Where a personal information processor shares data, it must be upon the instructions of the personal information controller.
  • Data sharing is governed by the IRR's Principles for Data Sharing under Rule IV, alongside the general data privacy principles.
  • Agreements should reflect the principles of specified and legitimate purpose, data quality, limited retention, and adequate safeguards for further processing.
  • Exemptions under Section 5 are narrow, and the burden of proving non-applicability falls on the party claiming it.

Primary sources

The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.

  • NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016

  • IRR OF REPUBLIC ACT NO. 10173 - IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 10173, KNOWN AS THE “DATA PRIVACY ACT OF 2012”

  • NPC CIRCULAR NO. 2014-014, April 25, 2014

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.