Skip to content

Evidence request lists

Philippines Data Privacy Act

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach Response

PHILDPA-7
Personal Data Breach Notification and Breach Management

Per RA 10173 + NPC Circular 16-03: breach notification. Requirements include (a) maintain Breach Management Team and Procedures per NPC Circular 16-03 + (b) implement Personal Data Breach Notification to NPC within 72 hours of knowledge of breach involving sensitive personal information or threatening to cause harm + notify affected data subjects per NPC requirements + (c) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (d) maintain breach log + breach management team + tabletop exercises + (e) integrate with broader incident management + (f) maintain documentation supporting NPC reporting.

Artefacts an auditor will ask for
  • Philippines DPA evidence for PHILDPA-7
Where this commonly fails
  • DPO + NPC registration + privacy manual partial

Enforcement and Sectoral

PHILDPA-8
NPC Cooperation, Compliance, Enforcement, Sectoral Considerations

Per RA 10173 + NPC Issuances: enforcement + sectoral. Requirements include (a) cooperate with NPC including responding to inquiries + facilitating audits + complying with directives + (b) maintain compliance monitoring + auditing + reporting + (c) understand enforcement + penalties including administrative fines + criminal penalties + civil liability + (d) implement sectoral considerations including BPO and KPO Sector Compliance + Government Agencies Specific Obligations + Health Sector + Employee + Research Exemption Conditions where applicable + (e) maintain Research Exemption Conditions documentation where research exemption is relied upon + (f) maintain broader compliance + governance.

Artefacts an auditor will ask for
  • Philippines DPA evidence for PHILDPA-8
Where this commonly fails
  • DPO + NPC registration + privacy manual partial

Governance and Accountability

PHILDPA-6
DPO, NPC Registration, Records, Privacy Management Program, Training

Per RA 10173 + NPC Circular 16-01 + Privacy Manual: governance + accountability. Requirements include (a) Mandatory Designation of Data Protection Officer (DPO) per NPC Circular 16-01 with defined responsibilities + (b) Registration of Data Processing Systems with NPC per NPC Circular 17-01 + (c) maintain Privacy Management Program and Manual per IRR Section 26 documenting roles + processes + controls + (d) maintain Data Retention and Disposal per IRR Section 37 + (e) deliver Employee Privacy Training including role-based content + (f) maintain governance + accountability framework demonstrating compliance.

Artefacts an auditor will ask for
  • Philippines DPA evidence for PHILDPA-6
Where this commonly fails
  • DPO + NPC registration + privacy manual partial

High-Risk Processing

PHILDPA-3
Children's Data, PIA, Privacy by Design, Sensitive Categories

Per RA 10173 IRR + NPC Advisory Opinions: heightened safeguards. Requirements include (a) implement Children's Personal Data protections per IRR Section 25 requiring parental consent + heightened safeguards for minors + (b) conduct Privacy Impact Assessment (PIA) per NPC Circular 18-02 for processing of personal data with risk to data subjects + (c) implement Privacy by Design and Default + (d) implement sectoral safeguards for Health Sector + Employee Personal Data + Research + Government Agencies + (e) maintain documented safeguards + PIAs + (f) integrate with broader privacy programme.

Artefacts an auditor will ask for
  • Philippines DPA evidence for PHILDPA-3
Where this commonly fails
  • DPO + NPC registration + privacy manual partial

Rights and Transparency

PHILDPA-2
Data Subject Rights, Notice, Direct Marketing, Cookies

Per RA 10173 Section 16 + NPC Circulars: data subject rights + notice + marketing. Requirements include (a) implement Data Subject Rights including Right to be Informed + Access + Object + Rectify + Erasure + Block + Data Portability + Damages + (b) provide Privacy Notices and Transparency including identity of controller + purposes + recipients + retention + rights + transfer + (c) implement Direct Marketing Restrictions including consent + opt-out + suppression lists + (d) implement Cookies and Online Tracking notice and consent + (e) maintain mechanism for rights handling within statutory timelines + (f) maintain records of requests + responses.

Artefacts an auditor will ask for
  • Philippines DPA evidence for PHILDPA-2
Where this commonly fails
  • DPO + NPC registration + privacy manual partial

Scope and Principles

PHILDPA-1
Scope, Lawful Basis, General Principles, Sensitive Personal Info

Per Philippines Data Privacy Act of 2012 (RA 10173) + Implementing Rules and Regulations (IRR) + NPC Issuances: scope + lawful basis + principles. Requirements include (a) determine scope including extraterritorial application + sectoral coverage (BPO + KPO + government agencies + health + research) + (b) apply General Data Privacy Principles - transparency + legitimate purpose + proportionality per Section 11 RA 10173 + (c) establish Criteria for Lawful Processing of Personal Information per Section 12 + (d) implement Sensitive Personal Information and Privileged Information stricter handling per Section 13 + (e) document applicability assessment + lawful basis + (f) maintain alignment with National Privacy Commission (NPC) issuances.

Artefacts an auditor will ask for
  • Philippines DPA evidence for PHILDPA-1
Where this commonly fails
  • DPO + NPC registration + privacy manual partial

Security

PHILDPA-4
Security of Personal Data, Access Logs, Encryption

Per RA 10173 + IRR + NPC Security Circulars: security of processing. Requirements include (a) implement Security of Personal Data including organisational + physical + technical security measures appropriate to risk per IRR + NPC guidance + (b) maintain Access and Activity Logging per IRR Section 38 + (c) implement encryption at rest + in transit appropriate to classification + (d) conduct regular security testing + assessment + (e) integrate with broader information security programme aligned to NPC guidance + (f) maintain documented security baseline + improvement.

Artefacts an auditor will ask for
  • Philippines DPA evidence for PHILDPA-4
Where this commonly fails
  • DPO + NPC registration + privacy manual partial

Transfer and Processor Management

PHILDPA-5
Cross-Border Transfer and Processor Agreements

Per RA 10173 + IRR + NPC: cross-border + processor + outsourcing. Requirements include (a) implement Cross-Border Transfer Controls including accountability for personal information transferred abroad + (b) maintain Personal Information Processors Contracts per IRR Section 26 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (c) implement Outsourcing and Subcontracting Agreements per NPC Circulars including specific BPO sector safeguards + (d) maintain inventory of cross-border data flows + recipients + safeguards + (e) implement supplier + processor + sub-processor due diligence.

Artefacts an auditor will ask for
  • Philippines DPA evidence for PHILDPA-5
Where this commonly fails
  • DPO + NPC registration + privacy manual partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.