A Firm Built on Principle.

Gorriceta Africa Cauton & Saavedra is a premier Philippine law firm — trusted by institutions, corporations, and investors for over two decades of rigorous, principled legal counsel.

Full-Service Legal Counsel.

Spanning transactional, regulatory, and contentious matters — Gorriceta delivers integrated legal capabilities across the industries and institutions that shape the Philippine economy.

News & Events.

In-depth legal analysis, firm news, and thought leadership — written by Gorriceta lawyers for clients, peers, and the broader business community.

Artificial Intelligence
July 13, 2026

Data Privacy Compliance for AI-Driven Businesses in the Philippines

ABOUT THIS STORY

July 13, 2026
Artificial Intelligence, Compliance, Cybersecurity, Data Privacy

Interested in our Capital Markets practice?

Our Banking & Finance team advises on the full spectrum of capital markets transactions in the Philippines.

As Philippine companies increasingly adopt AI tools for operations and customer engagement, understanding the intersection between the Data Privacy Act and emerging AI governance expectations has become a critical compliance priority.

Data Privacy Compliance for AI-Driven Businesses in the Philippines

Artificial intelligence adoption is accelerating across Philippine businesses — from customer service chatbots to AI-powered analytics and automated decision-making tools. But every AI system that touches personal data also touches the Data Privacy Act of 2012 (RA 10173). Here’s what businesses building or deploying AI need to know to stay compliant.

The Legal Backbone: RA 10173 and the NPC

The Data Privacy Act of 2012, enforced by the National Privacy Commission (NPC), remains the primary law governing how personal data is collected, processed, stored, and disposed of in the Philippines. Its reach is extraterritorial, meaning foreign companies processing the data of Philippine data subjects can also fall under its scope.

“Public availability does not constitute consent.”

That line, drawn from a recent NPC advisory, captures a key theme running through the regulator’s recent guidance: just because data is accessible online doesn’t mean an AI system is free to collect, train on, or process it.

The NPC’s AI-Specific Guidance

In December 2024, the NPC issued Advisory Guidelines on the Application of the Data Privacy Act to AI Systems Processing Personal Data. This advisory applies data protection principles across the entire AI lifecycle — from initial data collection and model training, to testing and final deployment. Key obligations include:

  • Lawful basis for processing. Businesses must identify and document an appropriate lawful basis under Sections 12 and 13 of the DPA before using personal data to train or run an AI system — including data drawn from publicly available sources.
  • Transparency. Data subjects must be clearly informed when AI is being used to process their personal data, including the scope and consequences of that processing.
  • Privacy Impact Assessments (PIAs). PIAs are required before deployment to identify and mitigate risks tied to the AI system.
  • Privacy-by-design and Privacy-Enhancing Technologies (PETs). Businesses are expected to build safeguards into the system architecture itself, not bolt them on afterward.
  • Human intervention. Where an AI system makes automated decisions with significant effects on a person’s rights, the business must allow meaningful human review and give data subjects a way to contest the outcome.
  • Documented governance. Policies and procedures addressing AI-specific processing must be written down, not just practiced informally.

Data Scraping: A New Compliance Flashpoint

If your AI strategy involves scraping publicly available data — for training sets, enrichment, or profiling — pay close attention to NPC Advisory No. 2026-01, issued in April 2026. It confirms that scraped personal data is still fully covered by the DPA, and introduces specific expectations:

  • Data scraping must be backed by a valid lawful basis; public availability alone is not enough.
  • Businesses must conduct PIAs specifically covering scraping activities, including where third-party processors are involved.
  • Large-scale scraping, profiling, and data aggregation are subject to heightened regulatory scrutiny.
  • Organizations that host publicly available personal data now carry their own transparency and security obligations — including disclosing that hosted data may be scraped, and giving individuals a way to object.
  • Any downstream use of scraped data beyond its originally declared purpose needs a fresh lawful basis, an updated privacy notice, and a new PIA.
  • Businesses must build in mechanisms to identify and limit bias or discriminatory treatment that could arise from how scraped data is used or interpreted.

Practical Steps for AI-Driven Businesses

  1. Map your data flows. Know exactly what personal data feeds into your AI systems, where it comes from, and how it’s used at each stage.
  2. Establish and document a lawful basis for every category of personal data used in AI training or operation — don’t assume public data is automatically fair game.
  3. Run PIAs before deployment, and refresh them whenever the system’s purpose, scope, or data sources change.
  4. Update privacy notices to clearly disclose AI-based processing and any use of publicly sourced data.
  5. Build in human review for AI outputs that carry legal or significant effects on individuals, and create a clear channel for people to question or contest those outputs.
  6. Monitor for bias. Put mechanisms in place to catch discriminatory patterns in AI outputs, especially where scraped or aggregated data is involved.
  7. Review third-party arrangements. If a vendor or processor handles data scraping, training, or model hosting on your behalf, make sure your contracts reflect DPA-compliant obligations.

Why This Matters

The NPC has real enforcement teeth — including compliance orders, cease-and-desist orders, administrative fines of up to PHP 5,000,000 per act, and the power to temporarily or permanently ban data processing altogether. For AI-driven businesses, the message from recent NPC guidance is clear: innovation is welcome, but it has to be built on a foundation of lawful, transparent, and accountable data processing.


This article is for general informational purposes only and does not constitute legal advice. Businesses should consult qualified legal counsel to assess their specific data privacy obligations under Philippine law.

MORE NEWS
July 13, 2026
Capital Markets
Understanding ESG Disclosure Obligations for Publicly Listed Companies
July 13, 2026
Compliance
Key Amendments to the Corporate Recovery and Insolvency Rules
July 13, 2026
Compliance
Navigating BIR’s New Transfer Pricing Documentation Requirements