Two statutes shape the Philippines: the Data Privacy Act of 2012 (RA 10173), which requires ‘reasonable and appropriate’ security measures and 72-hour breach notification to the National Privacy Commission and affected data subjects, and the Cybercrime Prevention Act (RA 10175). Neither names a certificate. An ISO 27001 ISMS is the recognised way to evidence ‘reasonable and appropriate’ in practice.
The Data Privacy Act of 2012 — Republic Act No. 10173, effective 8 September 2012 — and its 2016 Implementing Rules and Regulations are the core of Philippine data-protection law, enforced by the National Privacy Commission (NPC). Alongside it sits the Cybercrime Prevention Act of 2012 (RA 10175), which defines offences against the confidentiality, integrity and availability of computer systems.
| Instrument | What it is | What it asks of you |
|---|---|---|
| Data Privacy Act (RA 10173) + IRR | The data-protection statute, enforced by the NPC | “Reasonable and appropriate” organisational, physical and technical security measures |
| NPC breach-notification rules | The DPA’s notification regime | Notify the NPC and affected data subjects within 72 hours for notifiable breaches; full report within 5 days |
| Cybercrime Prevention Act (RA 10175) | The criminal statute for attacks on computer systems | Defines the offences — confidentiality, integrity and availability — your controls exist to prevent |
The breach rule deserves a slow read, because it’s stricter than most of the region on one axis: within 72 hours of knowledge — or reasonable belief — of a notifiable breach, you notify the NPC and the affected data subjects. Both, inside the same window. Neighbouring regimes stage those duties; the Philippines runs them together, then wants a full report within 5 days.
“Notifiable” has a definition: breaches involving sensitive personal information, or information that could enable identity fraud, where there’s a real risk of serious harm. That definition is a gate, and passing through it in either direction requires evidence — a point we’ll come back to.
The DPA’s phrase — reasonable and appropriate organisational, physical and technical measures — maps almost word for word onto how ISO 27001 arranges its 93 Annex A controls. The Cybercrime Prevention Act’s triad of confidentiality, integrity and availability is the same triad ISO 27001 defines information security by. You’re not translating between frameworks; the Philippine statutes and the standard already speak the same language.
| Philippine obligation | Where the ISMS answers it |
|---|---|
| “Reasonable and appropriate” measures (DPA + IRR) | Risk assessment across all 93 controls, applicability documented in the Statement of Applicability — a written, auditable answer to what’s reasonable for your processing |
| 72-hour notification to the NPC and data subjects | Incident management with detection in front of it: continuous logging and monitoring, plus an assessment step that fits inside the window |
| Full report within 5 days | The records to write it from — logs of what was accessed, when, and what containment ran |
| The notifiable-breach gate | Evidence of what data a breach actually touched, so the sensitive-information and serious-harm tests can be run rather than guessed |
One caveat, as everywhere on this hub: certification is not a legal safe harbour. The ISMS must carry the DPA, the IRR and the NPC’s rules as recorded legal requirements so the controls are built against Philippine law, not just against the standard.
The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited by the Philippine Accreditation Bureau (PAB) under the Department of Trade and Industry. Never by Secure60. Audit fees are set by the certification body and vary with the size and scope of the certified system, so settle scope before gathering quotes. Surveillance audits run annually; full recertification every three years.
If your Philippine operation is part of a wider group, one ISMS can hold Philippine sites inside a multi-country scope. Secure60 has delivery infrastructure in the Philippines via Rackcorp, with 2 datacentres, so collection and monitoring can run in-country where customers or regulators expect it.
The notifiable-breach criteria get read as an exemption. Teams see “sensitive personal information” and “real risk of serious harm” and conclude most incidents won’t qualify, so the 72-hour clock feels like someone else’s problem.
Here’s the catch: you can only rule a breach non-notifiable with evidence. Deciding that no sensitive data was touched means knowing exactly what was touched — which requires logging and monitoring that were running before the incident, not assembled after it. Without that evidence, the defensible legal answer defaults to “notify”, and 72-hour dual notification to the NPC and every affected data subject is precisely the outcome the definition was supposed to spare you. The exemption is earned in advance, by instrumentation.
Tools hand you a to-do list. We do the list — and run the security behind it. In the Philippines that means building the ISMS against the DPA and its IRR, then operating the part the 72-hour clock actually tests: logging, monitoring and incident management on one security platform, running on in-country Rackcorp infrastructure where that’s expected. The certification audit belongs to a PAB-accredited certification body; we make sure what it samples is running. We’re ISO 27001:2022 certified ourselves.
Is ISO 27001 legally mandatory in the Philippines?
No. The Data Privacy Act and its IRR require ‘reasonable and appropriate’ organisational, physical and technical measures without naming a standard. A certified ISMS is the practical way to show the NPC — and your customers — what ‘reasonable and appropriate’ means for you and that it’s running.
What does the 72-hour breach rule actually require?
For notifiable breaches, you must notify the National Privacy Commission and the affected data subjects within 72 hours of knowledge or reasonable belief that a breach occurred, with a full report within 5 days. Notifiable means sensitive personal information, or data that could enable identity fraud, with a real risk of serious harm.
Who performs the ISO 27001 certification audit in the Philippines?
A certification body accredited by the Philippine Accreditation Bureau (PAB), under the Department of Trade and Industry — not Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s being certified.
Does our data have to stay in the Philippines?
The DPA imposes no data-residency requirement. Where data lives is still worth writing down — customers and sector regulators ask — and the ISMS records it. Our data residency guide covers the difference between where data lives and where you’re certified.
Can Secure60 deliver in the Philippines?
Yes — we have delivery infrastructure in the Philippines via Rackcorp, with 2 datacentres, so log collection and monitoring can run in-country. We don’t have local offices, and we never perform the certification audit.