The Philippine Privacy Impact Assessment Revolution: What the 2026 Draft Circular Means for Foreign Companies
The National Privacy Commission's August 2026 draft circular on Privacy Impact Assessments — designated NPC Circular No. 2026 [number to be assigned] — represents the most consequential structural reform to Philippine data privacy compliance since the Implementing Rules and Regulations of Republic Act No. 10173 took effect on August 24, 2016. The draft, currently open for public consultation until August 14, 2026, would supersede NPC Advisory No. 2017-03 in its entirety. For foreign companies processing the personal data of individuals in the Philippines — whether through a Philippine subsidiary, a BPO engagement, an e-commerce platform, or any digital service accessible to Filipino users — the shift from the 2017 advisory's blanket PIA requirement to the 2026 draft's threshold-based framework demands a fresh look at your compliance posture.
This guide provides a comprehensive analysis of the draft circular, the eight categories that would trigger mandatory PIA obligations, the enforcement context in which the reform arrives, and the practical steps foreign companies should take in the transition period before the circular takes effect.
Background: Why the 2017 Advisory Could Not Last
NPC Advisory No. 2017-03 was issued on July 31, 2017 — two years before the commercial deployment of large language models, four years before the NPC's first AI-specific guidance, and before the Philippine government had issued any detailed framework on cross-border data transfers. The advisory told organizations to map their data flows, assess risks, and document controls. It applied equally to a five-person startup running basic customer databases and a multinational bank operating facial recognition systems at scale.
That generalized approach made sense as an initial framework for a law that was barely five years old. But the regulatory landscape has changed dramatically. The NPC has since issued a cascade of supplemental advisories that layered new PIA obligations onto the 2017 baseline:
- NPC Advisory No. 2024-01 — Model Contractual Clauses for Cross-Border Transfers of Personal Data, published May 30, 2024
- NPC Advisory No. 2024-04 — Guidelines on the Application of the Data Privacy Act to AI Systems Processing Personal Data, published November 2024
- NPC Circular No. 2025-01 — Guidelines on Body-Worn Cameras for Law Enforcement and Other Authorized Entities, published January 2025
- NPC Advisory No. 2025-02 — Privacy Engineering in Software Development Lifecycles, published mid-2025
- NPC Advisory No. 2026-01 — Guidelines on Data Scraping of Publicly Available Personal Data, published April 13, 2026
Each issuance added PIA obligations without systematically updating the 2017 framework. The August 2026 draft circular is the NPC's response: a consolidated, modernized PIA framework that accounts for the technological and regulatory developments of the intervening nine years.
The Structural Shift: From Blanket Obligation to Threshold Analysis
The most fundamental change in the draft circular is architectural. Rather than requiring every Personal Information Controller (PIC) — or every Personal Information Processor (PIP) — to conduct a Privacy Impact Assessment, the draft confines mandatory PIA obligations to processing that falls into one of eight defined trigger categories. Processing that falls outside all eight categories is explicitly exempt from the mandatory assessment obligation, though organizations may still conduct one voluntarily.
This risk-tiered approach mirrors the EU General Data Protection Regulation's Article 35 framework, which the draft circular explicitly cites as a recognized reference point. The EU GDPR's approach — mandatory DPIA only for processing likely to result in high risk — has become the international standard for mature data protection regimes. The NPC's adoption of a similar structure signals an intent to align Philippine data privacy practice with global norms.
For foreign companies, the practical implication is significant: if your Philippine data processing is limited to routine, low-risk activities — basic employee records administration, standard customer contact information — you may no longer face a mandatory PIA obligation once the circular takes effect. If, on the other hand, your processing involves any of the eight trigger categories, your obligations become more demanding rather than less.
The Eight Mandatory PIA Trigger Categories
The draft circular identifies eight categories of processing that trigger mandatory PIA obligations. Understanding each category is essential for determining whether your company's Philippine operations require an assessment.
1. Processing of Sensitive Personal Information
The first trigger covers the processing of sensitive personal information as defined under Section 3(l) of RA 10173. This category includes personal data concerning:
- Race, ethnic origin, marital status, age, color, and religious or philosophical affiliations
- Political opinions and affiliations
- Health, education, genetic or sexual life of an individual
- Government-issued identifiers such as SSS numbers, tax identification numbers, passport numbers, and driver's license numbers
- Any information specifically ordered by a court to be kept confidential
For foreign companies, this category frequently applies. Employee records in the Philippines routinely include government-issued identification numbers (TIN, SSS, PhilHealth). Payroll processing necessarily involves sensitive personal information. If your company operates a defined contribution retirement plan for Philippine employees, the plan administrator handles sensitive financial and health-related data. The breadth of this category means that most established foreign companies operating in the Philippines will find at least some processing captured here, even if their core business is not data-intensive.
2. Processing of High-Risk Data Categories
The second trigger introduces a concept not explicitly defined in the 2017 advisory: high-risk data. The draft classifies the following as high-risk data categories:
- Financial information — bank account details, credit card numbers, tax records, loan applications, insurance claims, investment portfolios, credit scores, and transaction histories
- Biometric data — fingerprints, facial geometry, iris scans, voiceprints, and any other unique biological identifiers used for authentication or identification purposes
- Personal data relating to children — any data identifying or purporting to identify an individual under 18 years of age
Foreign companies operating fintech platforms, e-commerce marketplaces, or digital lending services in the Philippines will almost certainly process financial information as a core business function. Companies using biometric timekeeping systems for their Philippine workforce — common in manufacturing, logistics, and retail operations — are processing biometric data. Any company whose Philippine customer base includes minors faces the children-related subcategory.
3. Large-Scale Processing
The third trigger is new to Philippine law and addresses the ambiguity that plagued the 2017 advisory's application of the term "large-scale." The draft circular provides the first quantitative threshold, defining large-scale processing as processing involving:
- 250 or more employees, or
- The sensitive personal information of 1,000 or more individuals
The 250-employee threshold mirrors the NPC's existing registration requirement under NPC Circular No. 2022-04, which mandates NPC registration for PICs and PIPs that employ 250 or more persons or that process the sensitive personal information of 1,000 or more individuals. This consistency is deliberate — the NPC is aligning the PIA threshold with the existing registration threshold, creating a coherent compliance framework.
For a foreign company with a substantial Philippine workforce — a BPO operator with thousands of agents, a logistics company with a large delivery fleet, a retail chain with hundreds of store employees — this threshold is almost certainly exceeded. The same applies to any company whose Philippine customer database contains the records of 1,000 or more individuals.
4. Processing Involving Vulnerable Groups
The fourth trigger covers processing that involves or affects vulnerable groups, including:
- Minors (children under 18)
- Senior citizens (elderly persons)
- Persons with disabilities (PWDs)
- Economically or socially marginalized populations
Foreign companies operating in sectors that serve vulnerable populations — healthcare providers, educational institutions, microfinance lenders, social services organizations, or government contractors — will need to assess whether their data processing falls within this trigger. The inclusion of "economically or socially marginalized populations" is notably broad and could, in theory, capture processing of data relating to beneficiaries of conditional cash transfer programs, overseas Filipino worker families, or informal sector workers.
5. Automated Decision-Making or Profiling with Legal or Significant Effects
The fifth trigger addresses processing that involves automated decision-making — a category that has become critically important with the proliferation of AI-driven systems. The draft covers:
- Automated decisions that produce legal effects — such as automated credit approval or rejection, algorithmic hiring decisions, or systems that determine access to services or benefits
- Automated profiling that produces significant effects — behavioral scoring systems, algorithmic risk classification, and similar processes that materially influence an individual's circumstances
This trigger directly reflects the concerns addressed in NPC Advisory No. 2024-04 on AI systems. If your company uses an AI-driven recruitment platform that筛 shortlists candidates without human intervention, an automated credit scoring system that approves or declines loan applications, or a behavioral analytics engine that segments customers for differential pricing — each of these likely constitutes automated decision-making that triggers mandatory PIA obligations.
6. Novel or High-Risk Technologies
The sixth trigger covers the use of technologies that the NPC considers to carry elevated privacy risk, including:
- Artificial intelligence and machine learning systems
- Facial recognition and biometric identification systems
- Behavioral analytics platforms
- Any other novel or emerging technology that processes personal data in ways that present heightened privacy risks
The scope of this category is capacious. Virtually any company that has deployed machine learning models in production — customer service chatbots, recommendation engines, fraud detection systems, demand forecasting tools — is operating an AI system that processes personal data. Foreign companies that have introduced AI tools as part of their Philippine operations in the past two years should carefully assess whether those tools trigger this category.
The enforcement action against Tools for Humanity — the company behind the Worldcoin iris-scanning program — provides concrete context. In October 2025, the NPC issued a cease and desist order against the company, ruling that compensation-induced consent for biometric data collection did not constitute freely given consent under RA 10173. The Deputy Privacy Commissioner stated explicitly that when consent is compromised by financial inducement, it ceases to be a genuine expression of choice. The case illustrates the NPC's willingness to intervene aggressively when novel biometric technologies are deployed without adequate safeguards.
7. Targeted Advertising and Behavioral Tracking
The seventh trigger covers processing activities associated with digital marketing, specifically:
- Targeted advertising based on preference or behavioral analytics
- Behavioral tracking of individuals across websites, applications, or platforms
Foreign companies that operate consumer-facing digital platforms in the Philippines — e-commerce sites, mobile applications, digital media services — and that use third-party advertising technologies, cookies, pixel tags, or similar tracking mechanisms to build user profiles and deliver personalized advertising will likely fall within this trigger. The growing sophistication of digital marketing technology means that many companies are conducting behavioral tracking without fully appreciating its data privacy implications.
8. Cross-Border Data Transfers to Jurisdictions with Insufficient Safeguards
The eighth trigger completes the framework by addressing international data transfers. Processing that involves the transfer of personal data outside the Philippines to jurisdictions that do not provide an adequate level of protection as defined under RA 10173 triggers mandatory PIA obligations.
For foreign companies, this trigger is almost automatically activated. When a Philippine subsidiary transfers employee records, customer data, or business information to a foreign parent company, affiliate, or third-party service provider located outside the Philippines — whether in the United States, Europe, Asia, or elsewhere — that transfer constitutes cross-border processing. The question is whether the destination jurisdiction provides "adequate protection" under Philippine standards.
The NPC's position, articulated in Advisory No. 2024-01 and subsequent guidance, is that cross-border transfers require appropriate safeguards. The use of NPC-approved Model Contractual Clauses — modeled on the EU Standard Contractual Clauses — or the ASEAN Model Contractual Clauses provides one pathway. Binding Corporate Rules, applicable within multinational corporate groups, provide another. If neither mechanism is in place, and the destination country does not have an adequacy determination from the NPC, the transfer falls into a compliance gap that the mandatory PIA is designed to illuminate and address.
Enhanced Obligations for Mandatory PIA Processing
The draft circular does not merely define new thresholds — it also imposes more rigorous requirements on processing that falls within the trigger categories. Under the draft, a mandatory PIA must include:
- A risk scoring matrix — a structured assessment of the likelihood and severity of privacy harms arising from the processing
- Annual review mandates — the PIA must be refreshed at least once per year, or sooner if there is a material change in the processing activity
- DPO sign-off — the Data Protection Officer must review and approve the PIA before it is finalized
- Timestamped, version-controlled documentation — the PIA must be maintained as a living document with a clear audit trail of changes
- Availability for NPC inspection — the documentation must be accessible to the NPC upon request
These requirements represent a meaningful step up from the documentation practices that many companies have adopted under the 2017 advisory. A static PIA document completed at project inception and filed away is no longer sufficient. Companies must implement processes for ongoing monitoring and annual reassessment.
Exempt Processing: What No Longer Triggers a Mandatory PIA
The threshold-based approach explicitly exempts processing that falls outside all eight trigger categories. Under the 2017 advisory, even the most routine processing activities — processing employee contact details, maintaining basic customer records, sending promotional email newsletters — technically required a PIA. The draft circular eliminates that requirement for low-risk processing.
Specifically, the following categories of processing would no longer trigger a mandatory PIA:
- Basic employee records administration (contact information, attendance, standard payroll data) for companies below the 250-employee threshold
- Standard customer relationship management records without sensitive personal information
- Internal administrative processing with no external transfer component
- Manual, human-reviewed processing that does not involve automated decision-making
This narrowing is a genuine compliance benefit for smaller foreign companies operating in the Philippines. It eliminates a source of unnecessary burden for processing that experience has shown poses minimal privacy risk. However, the NPC has made clear that organizations may still conduct a voluntary PIA for any processing activity — and that doing so is considered best practice even when not mandatory.
Foreign Company Implications: What Changes and What Does Not
Data Scraping and Publicly Available Personal Data
NPC Advisory No. 2026-01, published April 13, 2026, explicitly requires PIAs for data scraping activities. The Advisory confirms that the scraping of publicly available personal data remains fully subject to RA 10173, regardless of the public availability of the data. This means that any foreign company that uses data scraping as part of its market research, lead generation, competitive intelligence, or training data collection — whether conducted from abroad or through a Philippine subsidiary — must conduct a PIA before initiating such activities.
The Advisory also requires that data scraping be conducted in compliance with the requirements of RA 10173, its IRR, and NPC issuances, including that the personal data under the scraping arrangement was obtained in compliance with all applicable requirements. For foreign companies that have been conducting data scraping without a PIA — a practice that was arguably non-compliant with the 2017 advisory — the Advisory 2026-01 creates an urgent compliance gap that must be addressed.
Cross-Border Data Transfers
For foreign companies with Philippine subsidiaries, cross-border data flows are a fact of corporate life. Employee records go to HR headquarters abroad. Customer data feeds into global analytics platforms. Business performance data consolidates into regional or global reporting systems.
The eighth trigger — cross-border transfers to jurisdictions without adequate safeguards — means that most foreign companies must conduct a PIA for their transfer activities unless they have implemented appropriate safeguards. The good news is that NPC Advisory No. 2024-01 provides a clear pathway: the NPC's Model Contractual Clauses or the ASEAN Model Contractual Clauses offer a recommended (though not yet mandatory) mechanism for legitimizing cross-border transfers.
Foreign companies that have not yet adopted Model Contractual Clauses for their Philippine-to-parent transfers should treat this as a priority action item. The adoption of these clauses does not eliminate the PIA requirement for cross-border transfers — but it does provide a recognized framework for managing the associated risks and demonstrates good-faith compliance to the NPC.
AI Systems and Automated Decision-Making
NPC Advisory No. 2024-04 — Guidelines on the Application of the Data Privacy Act to AI Systems Processing Personal Data — establishes that all provisions of RA 10173 apply to AI systems throughout their entire lifecycle, from initial conception and training through testing, deployment, and ongoing operation. The Advisory explicitly holds PICs accountable for the outcomes of their AI systems, regardless of whether the actual processing was performed by a third-party AI provider.
For foreign companies deploying AI systems in the Philippines — whether through a Philippine subsidiary or by providing AI-powered services to Philippine users — the combination of Advisory 2024-04 and the draft circular's mandatory PIA triggers means that AI deployment is among the highest-priority compliance items. The PIA must address the specific AI system's data processing activities, the risks associated with its outputs, and the measures in place to ensure compliance with RA 10173 throughout the system's lifecycle.
Philippine BPO and Outsourcing Engagements
Foreign companies that engage Philippine BPO providers to process personal data on their behalf face a layered compliance picture. The foreign company is typically the PIC — it determines the purpose and means of the processing. The BPO provider is the PIP. Both bear obligations under RA 10173, though their specific responsibilities differ.
The engagement of a BPO provider typically involves the cross-border transfer of personal data to the BPO's systems, which may be located in the Philippines or abroad. If the BPO operates in multiple jurisdictions — as most large Philippine BPOs do — the personal data of the foreign company's customers or employees may transit through multiple countries. The eighth trigger's application to cross-border transfers means that the foreign company's data transfer arrangements with its BPO providers require scrutiny.
Additionally, many BPO engagements involve the processing of high-risk data categories — financial information, biometric data (voiceprints for customer service calls), or personal data of children (in education or child-focused service engagements). These subcategories of the second trigger require careful mapping.
Enforcement Context: Why Compliance Cannot Wait
The draft circular arrives against a backdrop of escalating enforcement activity and alarming breach statistics. In 2025, Philippine data breaches exposed over 228 million credentials and approximately 1,382 gigabytes of data across 266 documented incidents, according to Philippine Security Summit threat analysis. A Surfshark report estimated that approximately 1.3 million Philippine accounts were compromised in 2025 alone — roughly three per minute.
The NPC has demonstrated its willingness to use aggressive enforcement tools. The October 2025 cease and desist order against Tools for Humanity — issued despite the company's arguments that its Worldcoin project operated globally and that iris scanning constituted a novel technology — sent a clear message: novel or high-risk technologies do not receive regulatory leniency, and financial inducements do not constitute valid consent under RA 10173.
Under RA 10173, the penalties for unauthorized processing of personal information are severe:
- Imprisonment of one to three years and a fine of PHP 500,000 to PHP 2,000,000 for unauthorized processing of personal information
- Imprisonment of three to six years and a fine of PHP 500,000 to PHP 4,000,000 for unauthorized processing of sensitive personal information or classified personal information
- Imprisonment of six to eight years and a fine of PHP 500,000 to PHP 8,000,000 for unauthorized processing that results in an aggravated breach or is undertaken for purposes of gaining access to sensitive personal information
These are criminal penalties — not merely administrative fines. Individual officers of a company can face personal criminal liability. For foreign companies with Philippine operations, this means that data privacy compliance is not merely a regulatory obligation — it is a personal risk exposure for the executives overseeing Philippine operations.
Compliance Roadmap: Steps for Foreign Companies
Pending the finalization and effective date of the NPC circular, foreign companies operating in or serving the Philippine market should take the following steps to align their compliance posture with the direction of the draft framework.
Step 1: Conduct a Data Processing Inventory
Map every data processing activity your company conducts in connection with Philippine individuals — employees, customers, contractors, or platform users. For each activity, identify:
- The categories of personal data involved (ordinary personal information, sensitive personal information, high-risk data)
- The volume of data and number of individuals affected
- Whether the processing involves automated decision-making or profiling
- Whether AI systems are used in the processing
- Whether cross-border transfers are involved
- Whether the processing affects vulnerable groups
Step 2: Assess Against the Eight Trigger Categories
For each identified processing activity, determine whether it falls within any of the eight mandatory PIA trigger categories. This assessment should be documented and revisited annually. Many companies will find that multiple triggers apply to different processing activities — a single company might conduct routine payroll processing (triggers 1 and potentially 3), operate an AI-powered customer analytics platform (triggers 2, 5, and 6), and transfer customer data to a foreign parent company (trigger 8).
Step 3: Appoint or Review Your Data Protection Officer
Under RA 10173 and the IRR, PICs are required to appoint a Data Protection Officer. The DPO must review and approve any mandatory PIA under the draft circular. Foreign companies with Philippine subsidiaries must ensure that their DPO appointment is properly constituted — the DPO can be an employee or an outsourced contractor, but must be independent and must have the authority to perform the required functions.
Step 4: Implement Cross-Border Transfer Safeguards
For cross-border data transfers, adopt the NPC's Model Contractual Clauses (per Advisory No. 2024-01) or the ASEAN Model Contractual Clauses. Ensure that Data Processing Agreements are in place between your Philippine subsidiary and any foreign affiliates or third-party processors that receive personal data from the Philippines. This is particularly urgent for companies that transfer employee records or customer data to parent companies or regional hubs abroad.
Step 5: Assess AI System Compliance
Inventory all AI systems used in connection with Philippine individuals, whether deployed by the Philippine subsidiary directly or provided as services to Philippine users by the foreign parent or affiliate. For each AI system, assess whether it involves automated decision-making, profiling, or the processing of high-risk data. If so, the mandatory PIA must specifically address the AI system's data processing lifecycle, the risks of automated decision-making, and the safeguards in place.
Step 6: Implement Ongoing PIA Processes
The draft circular's requirement for annual PIA reviews and timestamped, version-controlled documentation means that static, point-in-time assessments are no longer adequate. Companies must build internal processes for monitoring changes in their data processing activities, updating their PIA documentation, and ensuring DPO sign-off on an ongoing basis. This requires dedicated resources — either internal compliance staff or an external data privacy consultant who can maintain the PIA program throughout the year.
Step 7: Address Data Scraping Compliance
If your company engages in data scraping of publicly available personal data — including for market research, competitive intelligence, or AI training purposes — you must conduct a PIA for those activities under Advisory No. 2026-01. Ensure that any scraped data was obtained in compliance with RA 10173 and that your scraping practices respect the data privacy rights of the individuals whose data is being collected.
Conclusion
The NPC's August 2026 draft circular represents a maturation of Philippine data privacy law — a shift from a blunt, one-size-fits-all framework to a risk-tiered system that concentrates compliance resources on the processing activities that genuinely pose elevated privacy risks. For foreign companies, this shift brings both relief and new obligations.
The relief comes in the form of explicit exemptions for routine, low-risk processing. The burden of conducting a PIA for basic employee records or standard customer contact information — where no sensitive personal information, no cross-border transfers, and no AI systems are involved — would be lifted under the new framework. Foreign companies with lean Philippine operations and straightforward data processing needs may find their compliance burden genuinely reduced.
The new obligations, however, are substantial. AI systems, biometric technologies, targeted advertising, behavioral tracking, cross-border transfers, and processing involving vulnerable populations each trigger mandatory PIA obligations with enhanced documentation requirements. The 228 million credentials exposed in 2025 breaches, the NPC's aggressive enforcement posture against novel technologies, and the criminal penalties under RA 10173 together make the case for rigorous compliance irrefutable.
Foreign companies that act now — conducting a comprehensive data processing inventory, assessing their exposure against the eight trigger categories, implementing cross-border transfer safeguards, and building ongoing PIA review processes — will be well-positioned when the circular takes effect. Those that wait risk not only non-compliance with the new framework, but exposure to enforcement action under the existing 2017 advisory, which remains in force until the new circular is finalized and published.
The National Privacy Commission's public consultation on the draft circular closed on August 14, 2026. Organizations should monitor the NPC's website at privacy.gov.ph for the final circular and its effective date. In the interim, the compliance steps outlined in this guide represent sound practice under the existing framework and will position your company for a smooth transition to the new PIA regime.
Related Articles
The Philippine Dual-Regulatory Framework for Cryptocurrency and Virtual Assets: A Comprehensive Guide for Foreign Investors in 2026
With the BSP's Circular No. 1108 and the SEC's CASP Rules (MC Nos. 04 and 05 of 2025) now both in force, foreign investors entering the Philippine virtual asset space face a bifurcated regulatory landscape that did not exist three years ago. This guide maps the jurisdictional boundaries between the Bangko Sentral ng Pilipinas and the Securities and Exchange Commission, explains the licensing pathways, capitalization requirements, AML/CTF obligations, the BSP's continued VASP license moratorium, and the practical steps a foreign investor must take to operate lawfully in the Philippines' digital asset market.
The Philippine E-Invoicing Mandate: A Comprehensive Compliance Guide for Foreign Companies in 2026
With the December 31, 2026 deadline for mandatory e-invoicing under BIR Revenue Regulations No. 11-2025 fast approaching, foreign companies operating in the Philippines face an urgent compliance obligation that cannot be deferred. This guide provides a complete analysis of who must comply, what constitutes a compliant electronic invoice, the step-by-step implementation process, tax deduction opportunities under the CREATE MORE Act, and the penalties for non-compliance — with every legal citation verified against primary sources.
BIR RMC No. 24-2026: The Definitive Guide to Cross-Border Services Taxation for Foreign Investors in the Philippines
Revenue Memorandum Circular No. 24-2026 resolves years of confusion over when Philippine income tax applies to cross-border services. This guide explains every key provision, the essential elements test, documentary requirements, treaty implications, and the step-by-step compliance roadmap for foreign investors and their Philippine counsel.