·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

Data Processing Outsourcing Agreement in the Philippines: DPA Rules

A data processing outsourcing agreement in the Philippines must meet the Data Privacy Act and NPC IRR requirements. Here is what the law requires.


Outsourcing data processing in the Philippines is governed by the Data Privacy Act of 2012 and its Implementing Rules and Regulations. Under the IRR, a personal information processor is any natural or juridical person to whom a personal information controller may outsource or instruct the processing of personal data. The controller remains accountable to the data subject; the processor acts only on the controller's instructions. The IRR devotes Rule X, titled "Outsourcing and Subcontracting Agreements," to this arrangement. The law does not prescribe a single contract template, but it does require that the engagement be covered by an agreement consistent with the standards set in the IRR.

Who is the controller and who is the processor

The distinction determines each party's obligations. A personal information controller controls the processing of personal data, or instructs another to process personal data on its behalf. The IRR defines control as deciding what information is collected, or the purpose or extent of its processing.

A personal information processor is the outsourced party — the natural or juridical person to whom a controller may outsource or instruct the processing of personal data pertaining to a data subject.

Notably, the IRR excludes from the definition of controller a person or body who performs functions as instructed by another. That is the processor's position: it executes instructions rather than setting the purpose of processing.

Outsourcing is not data sharing

The IRR distinguishes outsourcing from data sharing. Data sharing is the disclosure or transfer of personal data to a third party under the custody of a controller or processor. In the case of a processor, such transfer must be upon the instructions of the controller.

The IRR expressly states that the term data sharing excludes outsourcing — the disclosure or transfer of personal data by a personal information controller to a personal information processor. This matters because the two arrangements are treated differently under the IRR's principles for data sharing. An outsourcing engagement falls under Rule X instead.

What Rule X covers

Rule X of the IRR is titled "Outsourcing and Subcontracting Agreements" and, as listed in the IRR's table of contents, contains three provisions:

  • Subcontract of Personal Data
  • Agreements for Outsourcing
  • Duty of Personal Information Processor

The structure of Rule X confirms that the law contemplates an agreement between the controller and the processor, and that the processor carries duties that survive regardless of the contract terms. The agreement should therefore reflect the processor's legal obligations, not just commercial terms.

The processor's duty

Rule X imposes a duty on the personal information processor. This duty exists by operation of law. A processor cannot contract away its obligations under the Data Privacy Act and the IRR simply because the controller agreed to a different arrangement.

Because the controller remains the party accountable to the data subject, the agreement should clearly define the scope of processing, the instructions the processor must follow, and the safeguards the processor must maintain. The IRR's Rule VI on security measures — covering organizational, physical, and technical security — applies to the protection of personal data, and the appropriate level of security depends on the nature of the data and the risks of processing.

Cross-border outsourcing

The Data Privacy Act and the IRR have extraterritorial reach. Under the IRR's provision on scope, the law applies to processing done outside the Philippines if the person involved is found or established in the Philippines; if the processing relates to personal data about a Philippine citizen or resident; if the processing is done in the Philippines; or if the entity has links to the Philippines.

Links to the Philippines include using equipment located in the country, maintaining an office, branch, or agency here, entering into a contract in the Philippines, or collecting or holding personal data in the Philippines. An offshore service provider handling data of Philippine citizens or residents can therefore be covered.

Frequently asked questions

Is a data processing agreement required under the Data Privacy Act? The IRR's Rule X specifically addresses agreements for outsourcing, which indicates that an outsourcing arrangement must be covered by an agreement consistent with the law. The IRR does not prescribe a single template, but the engagement must comply with the controller's and processor's obligations.

What is the difference between a personal information controller and a personal information processor? The controller decides what information is collected and the purpose or extent of processing, or instructs another to process data on its behalf. The processor performs processing functions as instructed by the controller.

Does the Data Privacy Act apply to an offshore outsourcing provider? It can. The IRR applies the law to processing with links to the Philippines, including processing of data about Philippine citizens or residents and contracts entered in the Philippines.

Practical takeaways

  • Identify each party's role — controller or processor — before drafting, because the IRR defines them separately and assigns different duties.
  • Treat outsourcing as distinct from data sharing; the IRR expressly excludes outsourcing from the definition of data sharing.
  • Build the agreement around Rule X, "Outsourcing and Subcontracting Agreements," and the processor's statutory duty.
  • Address security measures consistent with Rule VI, proportionate to the sensitivity of the data and the risks of processing.
  • Consider the IRR's extraterritorial scope if any part of the processing or the provider is outside the Philippines.

Primary sources

The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.

  • NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016

  • IRR OF REPUBLIC ACT NO. 10173 - IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 10173, KNOWN AS THE “DATA PRIVACY ACT OF 2012”

  • NPC CIRCULAR NO. 2014-014, April 25, 2014

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

This topic sits within our Data Privacy & Cybersecurity practice.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.