Enacted at the dawn of the Philippines’ digital boom, Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, stands as a monumental pillar in legislation that establishes the country’s definitive framework for the human right to data privacy while ensuring the free flow of information for innovation and growth (Section 2, Data Privacy Act).
The legislation regulates the processing of personal and sensitive personal information by both the government and private sectors, mandating adherence to the core data principles of transparency, legitimate purpose, and proportionality (Section 11).
For instance, Section 16 explicitly outlines the statutory rights of data subjects—such as the rights to be informed, access, dispute the accuracy, and demand removal of personal information—while imposing strict penalties, including fines and imprisonment, for unauthorized processing, malicious disclosure, or data breaches (Sections 25-37).
Pursuant to the legal mandate to administer and implement the provisions of the DPA and to monitor and ensure compliance of the country with international standards set for data protection, the National Privacy Commission (NPC) promulgated the Implementing Rules and Regulations (IRR).
Based on the IRR, the NPC subsequently issued NPC Circular No. 2022-04, which provides the framework for the registration of Data Processing Systems (DPS) and Data Protection Officers (DPO) in both government and private entities (Section 3).
Data Processing System (DPS)
Under Section 3(e) of the IRR, a Data Processing System (DPS) refers to “the structure and procedure by which personal data is collected and further processed in an information and communications system or relevant filing system, including the purpose and intended output of the processing.”
Accordingly, DPS registration with the NPC may either be mandatory or voluntary. Under Sections 5 and 6 of the Circular:
“SECTION 5. Mandatory Registration. A PIC or PIP that employs two hundred fifty (250) or more persons, or those processing sensitive personal information of one thousand (1,000) or more individuals, or those processing data that will likely pose a risk to the rights and freedoms of data subjects shall register all Data Processing Systems.
SECTION 6. Voluntary Registration. An application for registration by a PIC or PIP whose Data Processing System does not operate under any of the conditions set out in the preceding Section may register voluntarily following the process outlined in this Circular.
A PIC or PIP who does not fall under mandatory registration and does not undertake voluntary registration shall submit a sworn declaration (see Annex 1). The Commission through an Order may require a PIC or PIP to submit supporting documents related to this submission.”
As defined under Section 3(h) of the DPA, a Personal Information Controller (PIC) refers to “a person or organization who controls the collection, holding, processing, or use of personal information, including a person or organization who instructs another person or organization to collect, hold, process, use, transfer, or disclose personal information on his or her behalf.”
On the other hand, a Personal Information Processor (PIP) refers to “any natural or juridical person qualified to act as such under this Act to whom a personal information controller may outsource the processing of personal data pertaining to a data subject” (Section 3(i)).
Data Protection Officer (DPO) and Compliance Officer for Privacy (COP)
Under Section 2(d) of the Circular, a Data Protection Officer (DPO) refers to “an individual designated by the head of agency or organization to ensure its compliance with the Act, its IRR, and other issuances of the Commission: Provided, that, except where allowed otherwise by law or the Commission, the individual must be an organic employee of the government agency or private entity: Provided further, that a government agency or private entity may not have more than one DPO.”
Further, under NPC Advisory No. 2017-0, a Data Protection Officer (DPO) must possess specialized expertise in privacy laws, data protection practices, and the specific information systems and security needs of their organization. Additionally, having a deep understanding of the organization’s internal structure, operational processes, and industry sector is crucial for effectively performing their duties.
On the other hand, a Compliance Officer for Privacy (COP) refers to “an individual that performs the functions or some of the functions of a DPO in a particular region, office, branch, or area of authority” (Section 2(c)).
A DPO or COP must be a full-time, organic employee, ideally holding a regular, permanent position in the private sector or a career/appointive post in government. If the role is bound by an employment contract, the duration must be at least two (2) years to ensure organizational stability.
While a PIC or PIP is permitted to outsource or subcontract its data protection functions, the official DPO or COP must still oversee the third-party service provider’s performance to the extent possible and shall also remain the contact person of the PIC or PIP vis-à-vis the NPC.
DPS and DPO Registrations with the National Privacy Commission (NPC)
Under Section 7 of the Circular, a covered PIC or PIP must register its newly implemented Data Processing System (DPS) within twenty (20) days from the commencement of such a system or the effectivity date of the appointment of a DPO.
To register with the NPC’s official platform, a PIC or PIP must create an account and input the contact details of its Head of Organization, alongside a unique, dedicated email address for its DPO. The entity must then upload the prescribed application form with supporting documents and encode details for all its data processing systems and public-facing online applications. Finally, the submissions will undergo review by the Commission, which grants a downloadable Certificate of Registration (COR) once all requirements are validated or any deficiencies are corrected within five days.
Information Amendments and Registration Renewals
In the event a covered PIC or PIP seeks to apply minor amendments to its existing registration information, which includes updates on an existing Data Processing System, or a change in DPO, the PIC or PIP shall update the system within ten (10) days from the system update or effectivity of the appointment of the new DPO.
The Certificate of Registration (COR) is valid for one (1) year from its date of issuance, unless it is revoked by the NPC for grounds provided under Section 35 of the Circular and after issuance of a Notice of Revocation (Section 14). Thus, the registration must be renewed thirty (30) days before its expiration (Section 18).
Mandatory Display of Seal of Registration
The National Privacy Commission (NPC) Seal of Registration is also issued and is available for download simultaneously with the Certificate of Registration (COR). Under Section 32 of the Circular, it must be displayed at the main entrance of the place of business or office or at the most conspicuous place to ensure visibility to all data subjects and on the main website or at least the webpage specifically pertaining to the Philippines for global websites.
For legal consultations and inquiries regarding the DPS and DPO registrations, renewals, and amendments—and other data privacy compliance requirements in the Philippines, call us at (02) 8928-9535 (landline) or +639171940482 (mobile), or email info@duranschulze.com.







