ISO 27001 · Philippines

ISO 27001 Certification Requirements in the Philippines

The Short Answer

Two statutes apply in the Philippines: the Data Privacy Act of 2012 (RA 10173), which requires ‘reasonable and appropriate’ security measures and 72-hour breach notification to the National Privacy Commission and affected data subjects, and the Cybercrime Prevention Act (RA 10175). Neither names a certificate. An ISO 27001 ISMS is the recognised way to evidence reasonable and appropriate measures in practice.

What the Data Privacy Act requires

The Data Privacy Act of 2012 — Republic Act No. 10173, effective 8 September 2012 — and its 2016 Implementing Rules and Regulations form the core of Philippine data-protection law, enforced by the National Privacy Commission (NPC). Alongside it sits the Cybercrime Prevention Act of 2012 (RA 10175), which defines offences against the confidentiality, integrity and availability of computer systems.

Instrument What it is What it requires
Data Privacy Act (RA 10173) + IRR The data-protection statute, enforced by the NPC “Reasonable and appropriate” organisational, physical and technical security measures
NPC breach-notification rules The DPA’s notification regime Notification to the NPC and affected data subjects within 72 hours for notifiable breaches; full report within 5 days
Cybercrime Prevention Act (RA 10175) The criminal statute for attacks on computer systems Defines the offences — against confidentiality, integrity and availability — that your controls exist to prevent

The breach rule is stricter than most of the region on one axis: within 72 hours of knowledge, or reasonable belief, of a notifiable breach, you notify the NPC and the affected data subjects, inside the same window. Neighbouring regimes stage those two duties. The Philippines requires them together, followed by a full report within 5 days.

“Notifiable” has a definition: breaches involving sensitive personal information, or information that could enable identity fraud, where there is a real risk of serious harm. Establishing that a breach falls on either side of that definition requires evidence.

How an ISO 27001 ISMS maps to the DPA

The DPA’s formulation — reasonable and appropriate organisational, physical and technical measures — maps directly onto how ISO 27001 arranges its 93 Annex A controls. The Cybercrime Prevention Act’s triad of confidentiality, integrity and availability is the triad ISO 27001 uses to define information security, so the Philippine statutes and the standard use the same terms.

Philippine obligation Where the ISMS answers it
“Reasonable and appropriate” measures (DPA + IRR) Risk assessment across all 93 controls, applicability documented in the Statement of Applicability — a written, auditable position on what is reasonable for your processing
72-hour notification to the NPC and data subjects Incident management with detection in front of it: continuous logging and monitoring, plus an assessment step that fits inside the window
Full report within 5 days The records to write it from — logs of what was accessed, when, and what containment ran
The notifiable-breach gate Evidence of what data a breach touched, so the sensitive-information and serious-harm tests can be applied

Certification is not a legal safe harbour. The ISMS has to carry the DPA, the IRR and the NPC’s rules as recorded legal requirements, so the controls are built against Philippine law rather than against the standard alone.

Certification: PAB and scope

The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited by the Philippine Accreditation Bureau (PAB) under the Department of Trade and Industry, and not by Secure60. Audit fees are set by the certification body and vary with the size and scope of the certified system, which makes scope the first decision. Surveillance audits run annually, with full recertification every three years.

Where the Philippine operation is part of a wider group, one ISMS can hold Philippine sites inside a multi-country scope. Secure60 has delivery infrastructure in the Philippines via Rackcorp, with 2 datacentres, so collection and monitoring can run in-country where customers or regulators require it.

A breach can only be ruled non-notifiable with evidence

The notifiable-breach criteria are frequently read as an exemption that removes most incidents from the 72-hour clock.

Concluding that no sensitive data was touched requires knowing what was touched, which requires logging and monitoring that were operating before the incident. Without that evidence, the defensible legal position defaults to notification, and 72-hour dual notification to the NPC and every affected data subject is the outcome the definition exists to avoid. The exemption is earned in advance, through instrumentation.

How Secure60 handles this

Secure60 delivers the certification and operates the security behind it. In the Philippines that means building the ISMS against the DPA and its IRR, then operating what the 72-hour clock tests: logging, monitoring and incident management on one security platform, running on in-country Rackcorp infrastructure where that is required. The certification audit belongs to a PAB-accredited certification body, and we make sure what it samples is operating. Secure60 holds ISO 27001:2022 certification.

Frequently Asked Questions

Is ISO 27001 legally mandatory in the Philippines?

No. The Data Privacy Act and its IRR require ‘reasonable and appropriate’ organisational, physical and technical measures without naming a standard. A certified ISMS is the practical way to establish, for the NPC and for customers, what reasonable and appropriate means for your organisation and that it is operating.

What does the 72-hour breach rule require?

For notifiable breaches, you must notify the National Privacy Commission and the affected data subjects within 72 hours of knowledge or reasonable belief that a breach occurred, with a full report within 5 days. Notifiable covers sensitive personal information, or data that could enable identity fraud, with a real risk of serious harm.

Who performs the ISO 27001 certification audit in the Philippines?

A certification body accredited by the Philippine Accreditation Bureau (PAB), under the Department of Trade and Industry, and not Secure60. Audit fees are set by the certification body and vary with the size and scope of what is being certified.

Does our data have to stay in the Philippines?

The DPA imposes no data-residency requirement. Where data resides is still worth recording, because customers and sector regulators ask, and the ISMS holds that record. Our data residency guide covers the difference between where data lives and where you are certified.

Can Secure60 deliver in the Philippines?

Yes. We have delivery infrastructure in the Philippines via Rackcorp, with 2 datacentres, so log collection and monitoring can run in-country. We have no local offices, and we do not perform the certification audit.

Philippines Data Privacy Act Readiness

A readiness call maps the DPA, its IRR and the NPC's breach rules against the environment and scopes the ISMS engagement.

30 days, every feature switched on. No credit card.