·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

DICT Data Center Regulations in the Philippines: What R.A. 10844 Says

What DICT rules apply to data centers and cloud infrastructure in the Philippines? Learn the DICT's mandate over ICT infrastructure and critical systems.


The Department of Information and Communications Technology (DICT) is the primary policy, planning, coordinating, implementing, and administrative entity of the Executive Branch for the national ICT development agenda. Republic Act No. 10844, the DICT Act of 2015, and its 2016 Implementing Rules and Regulations (IRR) give the DICT the powers that shape how data centers and cloud infrastructure are built and operated in the Philippines. There is no single "data center license" issued by the DICT under these laws. Instead, the DICT's authority over data centers and cloud services flows from its general mandate over ICT infrastructure, critical infrastructure security, and consumer protection.

What the DICT Act says about ICT infrastructure

Section 6(d) of R.A. No. 10844 gives the DICT the power to prescribe rules and regulations for the establishment, operation and maintenance of ICT infrastructures in unserved and underserved areas, in consultation with local government units, civil society organizations, the private sector, and the academe.

Data centers and cloud facilities are ICT infrastructure in the sense defined by the law. Section 3(a) of R.A. No. 10844 defines ICT as the totality of electronic means to access, create, collect, store, process, receive, transmit, present and disseminate information. A facility built to store and process data falls squarely within that definition.

The DICT also has the power under Section 6(g) to ensure the development and protection of integrated government ICT infrastructures and designs. This covers the government's own data hosting arrangements, not private commercial data centers as such.

Critical infrastructure security and cybersecurity

Section 2(m) of R.A. No. 10844 declares it State policy to ensure the security of critical ICT infrastructures including information assets of the government, individuals and businesses.

To carry this out, Section 15(b) of R.A. No. 10844 transfers to the DICT all powers and functions related to cybersecurity, including the formulation of the National Cybersecurity Plan, the establishment of the National Computer Emergency Response Team (CERT), and the facilitation of international cooperation on intelligence regarding cybersecurity matters.

The same provision attaches the National Telecommunications Commission (NTC), the National Privacy Commission (NPC), and the Cybercrime Investigation and Coordination Center (CICC) to the DICT for policy and program coordination. The CICC is chaired by the DICT Secretary.

For data center and cloud operators, this means the DICT is the lead agency for national cybersecurity policy and incident response — a key point of contact when a facility is hit by a cyber-attack or when it forms part of infrastructure the State considers critical.

Consumer protection and data privacy

Section 6(n) of R.A. No. 10844 directs the DICT to ensure and protect the rights and welfare of consumers and business users to privacy, security and confidentiality in matters relating to ICT, in coordination with concerned agencies, the private sector, and relevant international bodies.

Section 2(l) separately declares the policy to ensure the rights of individuals to privacy and confidentiality of their personal information.

These provisions sit alongside the Data Privacy Act of 2012 (R.A. No. 10173), which the National Privacy Commission administers. Data centers and cloud providers that process personal data of Filipinos remain subject to NPC rules on data privacy and security. The DICT's role under R.A. No. 10844 is complementary: it sets the broader ICT policy environment while the NPC enforces data privacy compliance.

Investment promotion and private-sector partnerships

Section 6(o) of R.A. No. 10844 authorizes the DICT to support the promotion of trade and investment opportunities in the ICT and ICT-ES sectors, in coordination with the Department of Trade and Industry and other relevant agencies.

Section 6(p) empowers the DICT to establish guidelines for public-private partnerships in the implementation of ICT projects for government agencies.

The law also directs the DICT under Section 6(aa) to formulate policies, in consultation with local government units and other stakeholders, for ICT-related strategies that improve the competitiveness of provincial locations for the ICT and ICT-enabled services industry. This is the legal basis for DICT programs that encourage data center and digital infrastructure investment outside Metro Manila.

Where the Internet Transactions Act fits in

The Internet Transactions Act of 2023 (R.A. No. 11967) regulates e-commerce, not data centers directly. But it is relevant to cloud-hosted platforms. Section 12 of R.A. No. 11967 provides that the regulatory authority of the DTI over internet commerce is ancillary to any duly constituted regulatory jurisdiction granted to an agency by existing laws such as, but not limited to, the DICT, BSP, and NPC.

Section 21(d) of R.A. No. 11967 requires e-marketplaces to take precautions to protect consumer data privacy in accordance with R.A. No. 10173 and to comply with minimum information security standards set by the Bureau, NPC, and other issuances of relevant government agencies. Cloud and data center providers hosting e-commerce platforms therefore operate within a layered regulatory environment in which the DICT remains a named authority.

Frequently asked questions

Does the DICT require a license to operate a data center in the Philippines?

R.A. No. 10844 and its IRR do not establish a DICT-issued license for data centers. The DICT's authority under Section 6(d) covers prescribing rules for ICT infrastructure in unserved and underserved areas, and its broader mandate covers ICT policy and critical infrastructure security. Other registrations, such as with the SEC for the corporate entity, may still apply.

Are cloud service providers regulated by the DICT?

The DICT's powers under R.A. No. 10844 reach ICT infrastructure and cybersecurity policy generally. Cloud providers that process personal data are also covered by the Data Privacy Act of 2012 and NPC issuances. The DICT coordinates with the NPC, which is attached to it for policy and program coordination under Section 15(b).

What DICT office handles cybersecurity incidents affecting data centers?

Under Section 15(b) of R.A. No. 10844, all cybersecurity powers and functions — including the National Cybersecurity Plan and the National CERT — are transferred to the DICT. The CICC, chaired by the DICT Secretary, is attached to the Department.

Practical takeaways

  • R.A. No. 10844 and its 2016 IRR do not create a standalone DICT licensing regime for data centers; the DICT's authority is rooted in its general mandate over ICT infrastructure and policy.
  • Section 6(d) of R.A. No. 10844 lets the DICT prescribe rules for ICT infrastructure in unserved and underserved areas, in consultation with LGUs and the private sector.
  • Cybersecurity powers, including the National CERT and the National Cybersecurity Plan, are consolidated in the DICT under Section 15(b).
  • Data privacy compliance for cloud and data center operators runs through the Data Privacy Act of 2012 and the NPC, which is attached to the DICT for coordination.
  • The Internet Transactions Act of 2023 treats DTI jurisdiction over e-commerce as ancillary to the DICT's and other agencies' existing regulatory authority.

Primary sources

The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.

  • REPUBLIC ACT NO. 11967 - AN ACT PROTECTING ONLINE CONSUMERS AND MERCHANTS ENGAGED IN INTERNET TRANSACTIONS, CREATING FOR THIS PURPOSE ELECTRONIC COMMERCE BUREAU, APPROPRIATING FUNDS THEREFOR, AND FOR OTHER PURPOSES

  • IRR RUBPLIC ACT NO. 10844, October 17, 2016

  • REPUBLIC ACT NO. 10844 - AN ACT CREATING THE DEPARTMENT OF INFORMATION AND COMMUNICATIONS TECHNOLOGY, DEFINING ITS POWERS AND FUNCTIONS APPROPRIATING FUNDS THEREFOR, AND FOR OTHER PURPOSES

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

This topic sits within our Data Centers & Digital Infrastructure practice.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.