·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

Data Privacy Obligations of Philippine Online Sellers Under the Data Privacy Act

Online sellers in the Philippines must follow the Data Privacy Act of 2012 and the Internet Transactions Act when handling customer data. Here is what the law requires.


Online sellers in the Philippines are personal information controllers under the Data Privacy Act of 2012 (Republic Act No. 10173). This means that whenever a seller collects a buyer's name, address, contact number, or payment details, the seller must process that data lawfully, keep it secure, and respect the buyer's rights. The Internet Transactions Act of 2023 (Republic Act No. 11967) reinforces this: e-retailers, online merchants, e-marketplaces, and digital platforms are expressly covered by the Data Privacy Act and must follow National Privacy Commission issuances.

What makes a seller a personal information controller

Under the Implementing Rules and Regulations of the Data Privacy Act, a personal information controller is a person or entity who controls the processing of personal data, or who instructs another to process personal data on its behalf. There is control if the seller decides what information is collected, or the purpose or extent of its processing.

An online seller who decides which customer details to collect, why to collect them, and how long to keep them is exercising control. If the seller hires a courier, payment processor, or marketing service to handle that data, those providers are personal information processors acting on the seller's instructions.

The core privacy principles sellers must follow

The IRR lays down principles that apply to every online seller:

  • Collection must be for a specified and legitimate purpose. A seller should collect customer data for a declared reason — fulfilling orders, delivery, warranty, or customer support — not for vague future use.
  • Personal data must be processed fairly and lawfully. Consent, where used, must be a freely given, specific, and informed indication of will, evidenced by written, electronic, or recorded means.
  • Processing must ensure data quality. Customer records should be accurate and kept up to date.
  • Personal data must not be retained longer than necessary. Old order records, chat logs, and marketing lists should be disposed of once the purpose is served.
  • Further processing must have adequate safeguards. Using customer data for a new purpose, such as a newsletter or profiling, requires appropriate protection.

Transparency, legitimate purpose, and proportionality

The IRR requires sellers to observe the principles of transparency, legitimate purpose, and proportionality. In practice, this means telling customers clearly what data is collected and why, using that data only for a declared and lawful objective, and collecting no more than what the purpose actually requires. A seller who asks for a customer's birth date or government ID number for a simple product delivery is likely collecting more than necessary.

Rights of the buyer that sellers must respect

The Data Privacy Act gives data subjects specific rights that online sellers must be prepared to honor:

  • Right to be informed that their personal data is being processed;
  • Right to object to processing;
  • Right to access the data held about them;
  • Right to correct inaccurate information; and
  • Right to rectification, erasure, or blocking of data.

A seller who ignores a legitimate request to correct or delete customer data risks a complaint before the National Privacy Commission.

Security measures and data breach notification

The IRR requires organizational, physical, and technical security measures appropriate to the nature of the data and the risks of the processing. For an online seller, this can mean limiting staff access to customer records, securing devices and accounts, and protecting databases from unauthorized access.

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. The IRR contains a dedicated rule on data breach notification, including what a notification must contain and the procedure for notifying the Commission and affected data subjects. Sellers should have a written response plan before an incident happens.

What the Internet Transactions Act adds

The Internet Transactions Act of 2023 requires e-marketplaces and other digital platforms to take necessary precautions to protect the data privacy of consumers in accordance with the Data Privacy Act, and to comply with minimum information security standards set by the E-Commerce Bureau, the National Privacy Commission, and other agencies. E-retailers and online merchants carry the same obligation.

The law also requires e-marketplaces to collect and maintain identifying information about their online merchants, and to provide specific information upon a subpoena by competent authority in an investigation based on a sworn complaint. Sellers should expect that platform onboarding and verification requirements exist partly for this reason.

Frequently asked questions

Do online sellers need to register with the National Privacy Commission? The IRR provides for the registration of data processing systems and notification for automated processing operations, with the procedure set by the Commission. Whether registration applies depends on the nature and scale of the processing, so sellers should check the Commission's current registration rules.

What happens if an online seller mishandles customer data? The IRR provides penalties for offenses such as unauthorized processing, accessing personal information through negligence, improper disposal, unauthorized disclosure, and concealment of security breaches. The Commission may also issue compliance or enforcement orders and impose administrative fines.

Can a seller use customer data for marketing? Direct marketing is defined in the IRR as communication of advertising or marketing material directed to particular individuals. Because marketing is a distinct purpose, sellers should disclose it clearly and give customers a way to object.

Practical takeaways

  • Treat customer names, addresses, numbers, and payment details as personal data protected by the Data Privacy Act.
  • Collect only what a declared, legitimate purpose requires, and delete it when that purpose ends.
  • Publish a clear privacy notice and honor requests to access, correct, or erase data.
  • Put basic security measures in place and prepare a breach notification procedure.
  • If selling through a platform, comply with both the platform's requirements and the Internet Transactions Act's data privacy obligations.

Primary sources

The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.

  • NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016

  • IRR OF REPUBLIC ACT NO. 10173 - IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 10173, KNOWN AS THE “DATA PRIVACY ACT OF 2012”

  • REPUBLIC ACT NO. 11967 - AN ACT PROTECTING ONLINE CONSUMERS AND MERCHANTS ENGAGED IN INTERNET TRANSACTIONS, CREATING FOR THIS PURPOSE ELECTRONIC COMMERCE BUREAU, APPROPRIATING FUNDS THEREFOR, AND FOR OTHER PURPOSES

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

This topic sits within our Data Privacy & Cybersecurity practice.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.