Philippines - Data Privacy Guidelines (2024-04)

NPC Advisory No. 2024-04: Guidelines on the Application of the Data Privacy Act to AI Systems Processing Personal Data

Philippines

RAI-PH-NA-NAN2GXX-2024
Effective: December 19, 2024
In Force(In Force)
GuidelineData Protection and PrivacyGovernance and OversightAccountability and Documentation
Export PDF

The National Privacy Commission's Advisory No. 2024-04, issued on December 19, 2024, provides comprehensive guidelines on applying the Data Privacy Act of 2012 to artificial intelligence systems that process personal data. The advisory covers all phases of AI development including training, testing, and deployment, emphasizing principles of transparency, accountability, fairness, and data subject rights protection.

Summary

On December 19, 2024, the Philippine National Privacy Commission (NPC) issued Advisory No. 2024-04 titled 'Guidelines on the Application of Republic Act No. 10173 or the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations, and the Issuances of the Commission to Artificial Intelligence Systems Processing Personal Data.' This landmark advisory provides detailed guidance for personal information controllers (PICs) and processors (PIPs) on ensuring compliance with data privacy laws when developing, training, testing, or deploying AI systems that process personal data. The advisory explicitly clarifies that the DPA and its implementing rules apply throughout the entire AI system lifecycle, from initial development through deployment and ongoing operation. Key principles emphasized include transparency, requiring PICs to clearly inform data subjects about the nature, purpose, extent, and risks of AI-driven data processing; accountability, holding PICs responsible for AI system outcomes and consequences when personal data is involved; fairness, mandating elimination of systemic, human, and statistical biases while ensuring data accuracy; and data minimization, requiring collection and processing of only necessary personal data. The guidelines impose specific obligations on PICs including implementing Privacy-Enhancing Technologies (PETs) to safeguard data subject rights, providing mechanisms for meaningful human intervention by authorized personnel, enabling data subjects to exercise rights to object, rectify, and erase their data even after integration into AI datasets, monitoring and mitigating biases in AI systems, conducting Privacy Impact Assessments for AI systems with significant risks, implementing robust governance frameworks for responsible AI development, ensuring explainability of AI decision-making processes, and maintaining documentation of AI processing activities. The advisory reinforces that automated decision-making with legal or significant effects requires explicit consent and appropriate safeguards including human oversight. For high-risk AI applications, additional scrutiny and protective measures are required. The NPC emphasized that these guidelines align with international best practices and frameworks including UNESCO's Recommendation on the Ethics of AI and OECD AI Principles, while being specifically tailored to the Philippine legal context. Organizations deploying AI systems must now ensure full compliance with both the Data Privacy Act and these new AI-specific guidelines to avoid potential penalties and maintain public trust.

Full article

Read full text ↗

Overview

The NPC Advisory No. 2024-04, released on December 19, 2024, by the Philippine National Privacy Commission represents a significant development in the regulation of artificial intelligence systems in the Philippines. This comprehensive advisory provides clear guidance on how the Data Privacy Act of 2012, its Implementing Rules and Regulations, and various NPC issuances apply to AI systems that process personal data. The advisory emerged in response to the rapid proliferation of AI technologies across sectors and growing concerns about privacy implications, algorithmic bias, and automated decision-making. It explicitly states that all provisions of the DPA apply to AI systems throughout their entire lifecycle—from initial conception and training through testing, deployment, and ongoing operation. The advisory is binding on all personal information controllers and processors engaged in AI-related activities in the Philippines, regardless of where the AI system is physically located if it processes data of Filipino citizens or residents. By issuing these guidelines, the NPC aims to foster responsible AI innovation while safeguarding fundamental privacy rights, ensuring that technological advancement does not come at the expense of individual autonomy and data protection. The advisory aligns Philippine AI governance with international standards while addressing local context and concerns.

Definitions

The advisory adopts key definitions from the Data Privacy Act while providing specific context for AI applications. "Artificial Intelligence (AI) systems" are understood as systems that can process personal data through machine learning, deep learning, natural language processing, computer vision, or other automated technologies to make predictions, recommendations, or decisions. "Personal data processing in AI" encompasses collection, training, testing, deployment, and ongoing operation of AI systems. "Training data" refers to datasets, including personal information, used to develop AI models and algorithms. "Automated decision-making" involves decisions made by AI systems without meaningful human intervention that produce legal effects or similarly significantly affect data subjects. "Profiling" means automated processing to evaluate personal aspects, particularly to analyze or predict behavior, preferences, performance, or personal circumstances. "Bias" includes systemic bias (embedded in data or algorithms), human bias (introduced by developers or users), and statistical bias (skewed or unrepresentative data). "Privacy-Enhancing Technologies (PETs)" are technical measures that minimize personal data use, maximize data security, and empower data subjects. "Explainability" refers to the ability to explain AI system logic, significance, and anticipated consequences of processing. "Human oversight" involves meaningful human intervention by qualified, authorized persons in AI decision-making processes, particularly for high-stakes decisions. These definitions ensure consistent interpretation and application of privacy principles in AI contexts.

Governance and Institutional Framework

The National Privacy Commission serves as the primary regulatory authority for enforcing AI data privacy compliance in the Philippines. The NPC's role includes issuing guidance and advisories (such as this Advisory No. 2024-04), investigating complaints related to AI system privacy violations, conducting compliance audits of organizations deploying AI systems, imposing administrative penalties for non-compliance, and providing capacity-building programs for stakeholders. Personal information controllers must designate Data Protection Officers with specific responsibility for AI governance, ensuring they have adequate technical expertise in AI and data protection. Organizations are required to establish AI Ethics Committees or similar oversight bodies to review high-risk AI applications and ensure alignment with ethical principles and privacy requirements. The advisory mandates implementation of robust governance frameworks including policies and procedures for AI development and deployment, regular risk assessments of AI systems, documentation of AI processing activities and decision-making logic, mechanisms for ongoing monitoring and auditing of AI systems, and incident response plans for AI-related data breaches or failures. The NPC coordinates with sector-specific regulators (such as the Bangko Sentral ng Pilipinas for financial AI, Department of Health for healthcare AI) to provide industry-tailored guidance. International cooperation with data protection authorities in other jurisdictions enhances the NPC's capacity to address cross-border AI challenges and ensure alignment with global best practices.

Key Focus Areas

The advisory identifies several critical focus areas for AI privacy compliance. First, transparency and explainability require PICs to inform data subjects about AI processing including the logic involved, significance, and envisaged consequences; provide clear explanations of how AI systems make decisions affecting individuals; disclose when automated decision-making is being used; and explain data sources used for training AI models. Second, data quality and bias mitigation mandate that PICs ensure training data is accurate, complete, and up-to-date; identify and eliminate systemic, human, and statistical biases; regularly test AI systems for discriminatory outcomes; implement fairness metrics and monitoring; and maintain diverse, representative datasets. Third, data subject rights enforcement requires enabling individuals to exercise rights to access, rectify, erase, or object even after data integration into AI systems; providing effective mechanisms for contesting automated decisions; ensuring portability of personal data used in AI processing; and respecting withdrawal of consent with appropriate system adjustments. Fourth, human oversight and intervention mandate meaningful human involvement in high-stakes AI decisions; qualified personnel authorized to override AI decisions when appropriate; regular human review of AI system outputs; and escalation procedures for problematic cases. Fifth, security and confidentiality require robust technical and organizational measures to protect AI training data and models; protection against unauthorized access, data poisoning, and adversarial attacks; secure data storage and transmission; and regular security assessments and updates. Sixth, accountability and documentation mandate maintaining comprehensive records of AI processing activities, conducting and documenting Privacy Impact Assessments, establishing clear lines of responsibility, and preparing for regulatory audits and investigations.

Implementation Framework

PICs must implement a structured approach to AI privacy compliance. Initial steps include conducting comprehensive Privacy Impact Assessments (PIAs) for all AI systems processing personal data, particularly those with high-risk characteristics; mapping all personal data flows throughout the AI lifecycle from collection through training, testing, deployment, and disposal; identifying all stakeholders in the AI ecosystem including data subjects, data providers, developers, deployers, and users; and assessing potential risks to individual rights and freedoms. Organizations must then develop and implement AI-specific privacy policies and procedures covering data collection limitations, purpose specification and use limitation, data quality and accuracy standards, transparency and disclosure requirements, security safeguards, and data subject rights mechanisms. Technical implementation requires deploying Privacy-Enhancing Technologies such as differential privacy to protect individual data in training sets, federated learning to train models without centralizing sensitive data, homomorphic encryption for processing encrypted data, synthetic data generation to reduce reliance on real personal data, and anonymization and pseudonymization techniques. Organizations must establish monitoring and auditing systems including regular bias testing and fairness audits, performance monitoring for accuracy and reliability, incident detection and response capabilities, and compliance verification procedures. Training and capacity building are essential, including educating AI developers, data scientists, and engineers on privacy requirements; training business users on responsible AI deployment; raising awareness among data subjects about AI processing; and continuous professional development on emerging AI privacy issues. Documentation requirements include maintaining AI system inventories, recording processing purposes and legal bases, documenting algorithmic logic and decision-making processes, keeping training data lineage and provenance records, and preserving evidence of bias mitigation efforts.

Monitoring and Evaluation

The NPC employs multiple mechanisms to monitor compliance with AI privacy requirements. Organizations must implement continuous monitoring systems tracking AI system performance metrics, data quality indicators, bias and fairness measures, security incident alerts, and data subject rights request volumes and response times. Regular auditing includes internal audits by Data Protection Officers or compliance teams, external audits by independent assessors for high-risk systems, NPC-initiated compliance reviews, and sector-specific regulatory examinations. Performance evaluation involves assessing effectiveness of bias mitigation measures, accuracy and reliability of AI predictions and decisions, adequacy of transparency and explainability provisions, responsiveness to data subject rights requests, and overall privacy program maturity. The NPC requires periodic reporting for high-risk AI systems including annual compliance certifications, data breach notifications within prescribed timeframes, significant algorithm changes or updates, and adverse impact incidents affecting data subjects. Evaluation criteria include adherence to data minimization principles, proportionality of data collection to stated purposes, effectiveness of consent mechanisms, robustness of security measures, and alignment with international AI ethics frameworks. Organizations must maintain audit trails and evidence of compliance including technical documentation, policy documents, training records, impact assessments, and incident response logs. Continuous improvement processes require regular review and updates of AI systems based on monitoring results, stakeholder feedback incorporation, adoption of emerging best practices and technologies, and adaptation to evolving regulatory requirements.

Penalties, Liability, and Appeals

Violations of the advisory's requirements constitute violations of the Data Privacy Act and are subject to the full range of DPA penalties. Criminal penalties may apply including imprisonment and fines as prescribed in the DPA for unauthorized processing, improper disclosure, or other serious violations. Administrative penalties that the NPC may impose include cease and desist orders halting AI system operations until compliance is achieved, administrative fines ranging from PHP 500,000 to PHP 5,000,000 depending on violation severity, temporary or permanent bans on specific AI processing activities, and mandatory corrective actions such as algorithm retraining or system redesign. Liability considerations include direct liability of PICs for AI system outcomes and impacts on data subjects, vicarious liability for actions of personal information processors and third-party AI vendors, joint and several liability when multiple entities share control over AI processing, and potential civil liability for damages suffered by affected individuals. Aggravating factors in penalty determination include intentional or reckless violations, large scale of affected individuals, sensitive nature of data involved, harm suffered by data subjects, failure to implement required safeguards, and repeat violations or patterns of non-compliance. Mitigating factors may include good faith compliance efforts, self-reporting of violations, cooperation with investigations, prompt remediation, and implementation of enhanced controls. Appeals process allows organizations to contest NPC decisions through filing motions for reconsideration with the Commission, appealing to the Court of Appeals within prescribed timeframes, and ultimately seeking Supreme Court review if necessary. Data subjects harmed by AI privacy violations may pursue private rights of action seeking injunctive relief, compensatory damages, and other remedies. The advisory emphasizes that accountability for AI systems requires proactive compliance rather than reactive responses to enforcement actions.

Relationship to Other Instruments

The advisory operates within the broader framework of the Data Privacy Act of 2012 and its Implementing Rules and Regulations, serving as interpretive guidance rather than creating new legal obligations. It complements other NPC issuances including NPC Circular 16-03 on Security of Personal Data, which applies to AI system security; NPC Circular 20-01 on Administrative Fines, which governs penalty determination; and various Advisory Opinions addressing specific privacy questions. The advisory relates to sector-specific regulations such as Bangko Sentral ng Pilipinas guidelines on AI in financial services, Department of Health regulations on AI in healthcare, Securities and Exchange Commission rules on AI in investment advice and fintech, and Department of Trade and Industry consumer protection standards. It aligns with the National AI Strategy Roadmap 2.0 and National AI Strategy for the Philippines (NAIS-PH), which emphasize ethical AI development. The advisory references international frameworks including the UNESCO Recommendation on the Ethics of Artificial Intelligence, adopted by the Philippines in 2021; OECD AI Principles, which inform the NPC's approach; and the Bletchley Declaration on AI Safety, which the Philippines joined in 2023. The advisory also considers emerging AI regulations globally including the EU AI Act's risk-based approach, though not directly applicable in the Philippines. Future regulations such as proposed House Bills on AI governance will build upon the foundation established by this advisory.

International Alignment

The advisory demonstrates strong alignment with international AI governance frameworks and best practices. It incorporates principles from the UNESCO Recommendation on the Ethics of AI including proportionality and do no harm, safety and security, fairness and non-discrimination, sustainability, right to privacy and data protection, human oversight and determination, transparency and explainability, responsibility and accountability, awareness and literacy, and multi-stakeholder and adaptive governance. The advisory reflects OECD AI Principles including inclusive growth and sustainable development, human-centered values and fairness, transparency and explainability, robustness, security and safety, and accountability. Risk-based approach elements from the EU AI Act inform the advisory's categorization of AI systems by risk level (minimal, limited, high, unacceptable) and corresponding regulatory requirements. The advisory aligns with the Council of Europe's Framework Convention on AI, Human Rights, Democracy and the Rule of Law principles. Regional coordination occurs through ASEAN AI Governance and Ethics Guidelines, participation in Asia-Pacific Privacy Authorities (APPA), and collaboration with data protection authorities in Singapore, Malaysia, Thailand, and other Southeast Asian nations. The NPC's approach balances innovation enablement with rights protection, recognizing the Philippines' position as both an AI adopter and developer. International cooperation mechanisms include information sharing on AI enforcement cases, joint investigations of cross-border AI privacy violations, harmonization of AI privacy standards, and capacity building initiatives. The advisory positions the Philippines as a regional leader in AI governance, providing a model that other developing countries in Southeast Asia and beyond may reference when formulating their own AI privacy frameworks.

Implementation Timeline

DateMilestone
December 19, 2024NPC Advisory No. 2024-04 issued and took immediate effect
January-March 2025Grace period for organizations to review and assess current AI systems
April 2025NPC begins targeted compliance guidance and stakeholder consultations
July 2025Expected start of proactive compliance audits of high-risk AI systems
OngoingContinuous monitoring, enforcement, and guidance updates as AI technology evolves

Sources and References

SourceType
NPC Advisory No. 2024-04 (Official PDF)Primary Source
National Privacy Commission Official WebsiteRegulatory Authority
NPC Advisories and CircularsRelated Guidance
Data Privacy Act of 2012Foundational Law

Requirements for a company

What an organisation has to do under Philippines - Data Privacy Guidelines (2024-04), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

15
  • Conduct a Privacy Impact Assessment for all AI systems processing personal data.Personal Information Controllers and Processors using AI.
  • Implement a robust governance framework, including policies, procedures, and oversight bodies for AI.Personal Information Controllers and Processors using AI.
  • Designate a Data Protection Officer with specific responsibility for AI governance.Personal Information Controllers using AI.
  • Inform data subjects about AI processing, its logic, and anticipated consequences.Personal Information Controllers and Processors using AI.
  • Provide clear explanations of AI system logic, significance, and anticipated consequences to data subjects.Personal Information Controllers and Processors using AI.
  • Ensure training and operational data is accurate, complete, and up-to-date.Personal Information Controllers and Processors using AI.
  • +9 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Philippines - Data Privacy Guidelines (2024-04), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Personal Information Controllers and Processors using AI.Conduct a Privacy Impact Assessment for all AI systems processing personal data.
conducting comprehensive Privacy Impact Assessments (PIAs) for all AI systems processing personal data
Mar 31, 2025Implementation FrameworkCritical
2Personal Information Controllers and Processors using AI.Implement a robust governance framework, including policies, procedures, and oversight bodies for AI.
mandates implementation of robust governance frameworks including policies and procedures for AI development and deployment
Mar 31, 2025Governance and Institutional FrameworkCritical
3Personal Information Controllers using AI.Designate a Data Protection Officer with specific responsibility for AI governance.
Personal information controllers must designate Data Protection Officers with specific responsibility for AI governance
Mar 31, 2025Governance and Institutional FrameworkCritical
4Personal Information Controllers and Processors using AI.Inform data subjects about AI processing, its logic, and anticipated consequences.
transparency and explainability require PICs to inform data subjects about AI processing including the logic involved
OngoingKey Focus AreasCritical
5Personal Information Controllers and Processors using AI.Provide clear explanations of AI system logic, significance, and anticipated consequences to data subjects.
provide clear explanations of how AI systems make decisions affecting individuals
OngoingKey Focus AreasCritical
6Personal Information Controllers and Processors using AI.Ensure training and operational data is accurate, complete, and up-to-date.
data quality and bias mitigation mandate that PICs ensure training data is accurate, complete, and up-to-date
OngoingKey Focus AreasCritical
7Personal Information Controllers and Processors using AI.Identify and eliminate systemic, human, and statistical biases in AI systems.
identify and eliminate systemic, human, and statistical biases; regularly test AI systems for discriminatory outcomes
OngoingKey Focus AreasCritical
8Personal Information Controllers and Processors using AI.Provide mechanisms for data subjects to exercise their rights, including after data integration into AI systems.
data subject rights enforcement requires enabling individuals to exercise rights to access, rectify, erase, or object
OngoingKey Focus AreasCritical
9Personal Information Controllers and Processors using AI.Ensure meaningful human intervention in high-stakes AI decision-making processes.
human oversight and intervention mandate meaningful human involvement in high-stakes AI decisions
OngoingKey Focus AreasCritical
10Personal Information Controllers and Processors using AI.Implement robust technical and organizational measures to protect AI systems and data.
security and confidentiality require robust technical and organizational measures to protect AI training data and models
OngoingKey Focus AreasCritical
11Personal Information Controllers and Processors using AI.Conduct regular security assessments and updates for AI systems and their data.
protection against unauthorized access, data poisoning, and adversarial attacks; secure data storage and transmission; and regular security assessments and updates.
OngoingKey Focus AreasCritical
12Personal Information Controllers and Processors using AI.Maintain comprehensive records of AI processing activities throughout the entire lifecycle.
accountability and documentation mandate maintaining comprehensive records of AI processing activities
OngoingKey Focus AreasCritical
13Personal Information Controllers and Processors using AI.Implement continuous monitoring and regular auditing of AI systems for performance, fairness, and compliance.
Organizations must implement continuous monitoring systems tracking AI system performance metrics, data quality indicators, bias and fairness measures
OngoingMonitoring and EvaluationCritical
14Personal Information Controllers and Processors using AI.Deploy Privacy-Enhancing Technologies (PETs) to protect personal data in AI systems.
Technical implementation requires deploying Privacy-Enhancing Technologies such as differential privacy to protect individual data
OngoingImplementation FrameworkImportant
15Personal Information Controllers and Processors using AI.Educate AI developers, data scientists, and business users on AI privacy requirements.
Training and capacity building are essential, including educating AI developers, data scientists, and engineers on privacy requirements
OngoingImplementation FrameworkImportant

© Regulations.AI · updated on 06-Jan-2026