How to Conduct a Privacy Impact Assessment in the Philippines
Learn how to conduct a privacy impact assessment in the Philippines under the Data Privacy Act and its IRR, from risk mapping to safeguards.
A privacy impact assessment in the Philippines is the process of mapping how an organization collects and processes personal data, identifying the risks that processing poses to data subjects, and putting safeguards in place. The Data Privacy Act of 2012 and its Implementing Rules and Regulations do not prescribe a single mandatory form, but they require personal information controllers to observe general privacy principles, implement security measures, and uphold the rights of data subjects. A sound assessment documents how each of these duties is met for a given system or activity.
What the law requires before anything else
Under the IRR of the Data Privacy Act, the general principles are transparency, legitimate purpose, and proportionality. Processing must be fair and lawful, limited to a specified and legitimate purpose, and the data must not be retained longer than necessary. Any further processing must have adequate safeguards.
The IRR also requires that collection be for a specified and legitimate purpose, that processing ensure data quality, and that personal data not be kept longer than necessary. These principles are the yardstick against which every risk identified in an assessment is measured.
Rule VI of the IRR governs security measures. It covers organizational security, physical security, and technical security, and requires an appropriate level of security that takes into account the nature of the personal data, the risks presented by the processing, the size of the organization, the complexity of its operations, current data privacy best practices, and the cost of implementation. The IRR also directs the National Privacy Commission to issue guidelines for these security measures.
Step 1: Describe the processing
Start by describing the data processing system: the structure and procedure by which personal data is collected and further processed, including the purpose and intended output of the processing. Identify the categories of personal data involved, whether any of it is sensitive personal information, who the data subjects are, where the data flows, who receives it, and how long it is kept.
The IRR defines sensitive personal information to include data about race, ethnic origin, marital status, age, color, religious, philosophical or political affiliations; health, education, genetic or sexual life; proceedings for an offense; and government-issued identifiers such as social security numbers, health records, licenses, and tax returns. Processing sensitive personal information attracts stricter rules, so it must be flagged early.
Step 2: Identify the lawful basis
Every processing activity must rest on a lawful basis. The IRR devotes Rule V to lawful processing of personal information, and separately to lawful processing of sensitive personal information and privileged information. If consent is the basis, remember that consent must be freely given, specific, and informed, and evidenced by written, electronic, or recorded means. It may be given by a lawful representative or an authorized agent.
Step 3: Assess risks to data subjects
For each processing activity, ask what could go wrong: unauthorized access, accidental loss or alteration, improper disposal, or disclosure beyond the stated purpose. The IRR defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. It also defines a security incident as an event that affects or tends to affect data protection, or may compromise the availability, integrity, and confidentiality of personal data, including incidents that would have been a breach if not for safeguards already in place.
Rate each risk by likelihood and impact, and pay particular attention to sensitive personal information and to processing that affects many individuals.
Step 4: Design safeguards and assign accountability
Map each risk to a control under organizational, physical, and technical security. Document who is accountable, how access is limited, how incidents are detected, and how the controls will be tested. The IRR also addresses outsourcing and subcontracting agreements, so where a personal information processor is engaged, the assessment should cover the written agreement and the processor's duty to process only as instructed.
Step 5: Document, review, and keep it current
Record the assessment, the decisions made, and the reasons for them. Review it whenever the processing changes, a new system is introduced, or a security incident occurs. The IRR requires that personal data not be retained longer than necessary, so retention and disposal should be revisited at each review.
Frequently asked questions
Is a privacy impact assessment mandatory in the Philippines? The Data Privacy Act and its IRR do not prescribe a single mandatory template. What is mandatory is compliance with the general privacy principles, the security measures under Rule VI, and the rights of data subjects. An assessment is the practical way to show that compliance.
What is the difference between a privacy impact assessment and a data breach notification? An assessment is forward-looking: it identifies risks before harm occurs. A data breach notification under Rule IX of the IRR is triggered after a breach of security has occurred.
Do we need an assessment if we only process sensitive personal information occasionally? Yes. The nature of the data affects the appropriate level of security, and sensitive personal information is treated more strictly under the IRR. Occasional processing still requires a lawful basis and adequate safeguards.
Practical takeaways
- Anchor the assessment on the IRR principles: transparency, legitimate purpose, and proportionality.
- Identify sensitive personal information early, because it attracts stricter requirements.
- Match safeguards to the risks, the size of the organization, and the sensitivity of the data under Rule VI.
- Document the lawful basis for every processing activity, including consent where relied upon.
- Review and update the assessment whenever processing changes or an incident occurs.
Primary sources
The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.
-
NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016
-
IRR OF REPUBLIC ACT NO. 10173 - IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 10173, KNOWN AS THE “DATA PRIVACY ACT OF 2012”
-
NPC CIRCULAR NO. 2014-014, April 25, 2014
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
This topic sits within our Data Privacy & Cybersecurity practice.
Related reading
Dark fiber lease in the Philippines sits outside public utility classification, but the agreement still needs the right legal treatment and regulatory checks.
NPC enforcement fines in the Philippines are administrative penalties the National Privacy Commission may impose for violations of the Data Privacy Act of 2012.
Legal process outsourcing in the Philippines lets in-house teams delegate legal work to local providers while Philippine law and professional rules still govern the lawyers involved.
A colocation SLA in the Philippines should cover power, cooling, uptime, security, and support. Here is what to contract for and which rules apply.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.