Outsourcing Contracts in the Philippines: BPO Risk Allocation Guide
Learn how Philippine law allocates risk in BPO and outsourcing contracts, from data privacy rules on subcontracting to electronic contract validity.
Outsourcing contracts in the Philippines allocate risk through three main legal layers. First, the Data Privacy Act of 2012 and its Implementing Rules and Regulations govern how personal data may be subcontracted, requiring written agreements and imposing duties on personal information processors. Second, the Electronic Commerce Act validates electronic contracts, signatures, and records, which matters because most BPO engagements are executed and performed digitally. Third, the Revised Corporation Code fixes the corporate framework — capacity, authority, and perpetual term — behind every Philippine service provider. This article explains each layer and how risk is distributed between client and vendor.
Who controls the data: the privacy layer
Under the Data Privacy Act of 2012 and its IRR, the party that decides what personal data is collected and why is the personal information controller. The party it engages to process data on its behalf is the personal information processor. In a typical BPO arrangement, the client is the controller and the Philippine service provider is the processor.
The IRR defines "personal information processor" as any natural or juridical person to whom a controller may outsource or instruct the processing of personal data. Critically, the IRR treats outsourcing as distinct from data sharing: data sharing is disclosure to a third party under the controller's custody, while outsourcing is disclosure or transfer by a controller to a processor. The distinction matters because each triggers different documentation and accountability rules.
Rule X of the IRR is devoted to Outsourcing and Subcontracting Agreements. It addresses the subcontract of personal data, agreements for outsourcing, and the duty of the personal information processor. The practical consequence: risk does not disappear when work is outsourced. The controller remains accountable, and the processor carries its own statutory duties. Any further subcontracting by the processor should be addressed expressly in the contract, consistent with the IRR's treatment of subcontracting.
Electronic contracts and signatures
The Electronic Commerce Act (Republic Act No. 8792) confirms that an offer, acceptance, and the other elements of a contract may be expressed and proved by electronic data messages or electronic documents. Under Section 16, no contract shall be denied validity or enforceability solely because it is in electronic form.
Two provisions carry direct risk-allocation weight:
- Section 18 (Attribution). An electronic message is deemed that of the originator if sent by the originator, by a person with authority to act on its behalf, or by an information system programmed to operate automatically. An addressee may act on that assumption if it applied an agreed procedure. This is why authentication protocols in outsourcing contracts are not mere formalities — they determine who bears the loss when a message is disputed.
- Section 20 (Acknowledgment of Receipt). Where receipt is made a condition of effect, the message is treated as never sent until acknowledged. Where it is not, the originator may give notice and, if no acknowledgment follows, treat the message as never sent.
Section 22 fixes when receipt occurs — generally when the message enters the addressee's designated information system. Section 23 deems messages dispatched and received at the parties' places of business, and expressly applies this rule to determine tax situs. For cross-border BPO work, that single sentence can shape tax exposure.
Evidence, retention, and audit risk
Outsourcing disputes are usually evidence disputes. The Electronic Commerce Act provides that electronic documents are the functional equivalent of written documents for evidentiary purposes, and that a compliant electronic document is the best evidence of the agreement and transaction contained in it (Section 12). Admissibility cannot be denied solely because a record is electronic.
The person introducing an electronic document bears the burden of proving authenticity (Section 11). However, the integrity of the information and communications system may be established in the absence of contrary evidence — for instance, by showing the system operated without affecting integrity, or that the record was stored in the usual and ordinary course of business by a person not under the using party's control.
Section 13 allows legal retention requirements to be satisfied electronically if the record remains accessible, is retained in its generated format or an accurate representation, and permits identification of originator, addressee, date, and time. Service-level, audit, and record-retention clauses should be drafted to satisfy these conditions.
Corporate capacity and authority
Every Philippine outsourcing counterparty is a corporation governed by the Revised Corporation Code (Republic Act No. 11232). Under Section 2, a corporation is an artificial being created by operation of law with the right of succession and only those powers expressly authorized by law or incidental to its existence. Section 22 vests corporate powers, business conduct, and control of property in the board of directors or trustees.
Two diligence points follow. First, verify that the signatory is authorized by board resolution — the corporation's capacity is exercised through its board. Second, Section 11 gives corporations perpetual existence unless the articles of incorporation provide otherwise, so a counterparty's corporate term should still be confirmed rather than assumed.
Frequently asked questions
Is an outsourcing contract signed electronically valid in the Philippines? Yes. Under Section 16 of the Electronic Commerce Act, a contract is not denied validity or enforceability solely because it is in electronic form, provided the requirements for electronic signatures and documents are met.
Can a BPO provider subcontract personal data processing? The IRR's Rule X expressly addresses subcontracting of personal data and outsourcing agreements, and imposes duties on the personal information processor. The scope and conditions of any subcontract should be set out in the contract.
Who is liable for a data breach in an outsourcing arrangement? The controller remains accountable under the Data Privacy Act framework, while the processor bears its own statutory duties. Liability allocation between them is a matter of the contract and the IRR's accountability rules.
Practical takeaways
- Identify in writing which party is the personal information controller and which is the personal information processor, and address subcontracting expressly.
- Treat authentication and acknowledgment procedures as risk-allocation terms, not administrative details, given Sections 18 and 20 of the Electronic Commerce Act.
- Confirm the counterparty's corporate existence, term, and signatory authority under the Revised Corporation Code before signing.
- Design retention and audit clauses so electronic records satisfy Section 13 and remain usable as best evidence.
- Note that Section 23 deems electronic messages received at the place of business and applies that rule to tax situs — relevant to cross-border engagements.
Primary sources
The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.
-
REPUBLIC ACT NO. 11232 - AN ACT PROVIDING FOR THE REVISED CORPORATION CODE OF THE PHILIPPINES
-
REPUBLIC ACT NO. 8792 - AN ACT PROVIDING FOR THE RECOGNITION AND USE OF ELECTRONIC COMMERCIAL AND NON-COMMERCIAL TRANSACTIONS, PENALTIES FOR UNLAWFUL USE THEREOF, AND OTHER PURPOSES
-
NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
Related reading
NPC enforcement fines in the Philippines are administrative penalties the National Privacy Commission may impose for violations of the Data Privacy Act of 2012.
Employee data retention in the Philippines follows the Data Privacy Act rule that personal data must not be kept longer than necessary for its purpose.
Employee monitoring in the Philippines is governed by the Data Privacy Act of 2012 and its IRR, which require transparency, legitimate purpose, and proportionality.
Learn how the Data Privacy Act of 2012 protects employee data in the Philippines and what employers must do to comply.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.