Security Measures for Protection of Personal Data, Data Privacy Law
Responsibility of PICs and PIPs
Section 25. Data Privacy and Security. Personal information controllers and personal information processors shall implement reasonable and appropriate organizational, physical, and technical security measures for the protection of personal data.
The personal information controller and personal information processor shall take steps to ensure that any natural person acting under their authority and who has access to personal data, does not process them except upon their instructions, or as required by law.
The security measures shall aim to maintain the availability, integrity, and confidentiality of personal data and are intended for the protection of personal data against any accidental or unlawful destruction, alteration, and disclosure, as well as against any other unlawful processing. These measures shall be implemented to protect personal data against natural dangers such as accidental loss or destruction, and human dangers such as unlawful access, fraudulent misuse, unlawful destruction, alteration and contamination. (IRR, Rule VI)
Implement security measures
1) For the protection of personal data, Personal Information Controllers (PIC) and Personal Information Processors (PIP) are required to implement reasonable and appropriate:
a) organizational security measures,
b) physical security measures, and
c) technical security measures. (IRR, Section 25, Rule VI)
2) The PIC and PIP shall take steps to ensure that any natural person acting under their authority and who has access to personal data, does not process them except upon their instructions, or as required by law.” (IRR, Section 25, Rule VI)
3) The security measures shall be:
b) Aimed to maintain the availability, integrity, and confidentiality of personal data;
b) Intended for the protection of personal data against any accidental or unlawful destruction, alteration, and disclosure; and
c) Intended against any other unlawful processing. (IRR, Section 25, Rule VI)
2 kinds of dangers
1) These measures shall be implemented to protect personal data against:
a) natural dangers, such as accidental loss or destruction, and
b) human dangers, such as unlawful access, fraudulent misuse, unlawful destruction, alteration and contamination. (IRR, Section 25, Rule VI)
Security Measures
Security measures – refer to appropriate steps taken to protect a personal data.
“Security incident” is an event or occurrence that affects or tends to affect data protection, or may compromise the availability, integrity and confidentiality of personal data. It includes incidents that would result to a personal data breach, if not for safeguards that have been put in place. (IRR, Section 3[s])

Figure 1. Security Measures
Organizational Security
Section 26. Organizational Security Measures. Where appropriate, personal information controllers and personal information processors shall comply with the following guidelines for organizational security:
a. Compliance Officers. Any natural or juridical person or other body involved in the processing of personal data shall designate an individual or individuals who shall function as data protection officer, compliance officer or otherwise be accountable for ensuring compliance with applicable laws and regulations for the protection of data privacy and security.
b. Data Protection Policies. Any natural or juridical person or other body involved in the processing of personal data shall implement appropriate data protection policies that provide for organization, physical, and technical security measures, and, for such purpose, take into account the nature, scope, context and purposes of the processing, as well as the risks posed to the rights and freedoms of data subjects.
1. The policies shall implement data protection principles both at the time of the determination of the means for processing and at the time of the processing itself.
2. The policies shall implement appropriate security measures that, by default, ensure only personal data which is necessary for the specified purpose of the processing are processed. They shall determine the amount of personal data collected, including the extent of processing involved, the period of their storage, and their accessibility.
3. The polices shall provide for documentation, regular review, evaluation, and updating of the privacy and security policies and practices.
c. Records of Processing Activities. Any natural or juridical person or other body involved in the processing of personal data shall maintain records that sufficiently describe its data processing system, and identify the duties and responsibilities of those individuals who will have access to personal data. Records should include:
1. Information about the purpose of the processing of personal data, including any intended future processing or data sharing;
2. A description of all categories of data subjects, personal data, and recipients of such personal data that will be involved in the processing;
3. General information about the data flow within the organization, from the time of collection, processing, and retention, including the time limits for disposal or erasure of personal data;
4. A general description of the organizational, physical, and technical security measures in place;
5. The name and contact details of the personal information controller and, where applicable, the joint controller, the its representative, and the compliance officer or Data Protection Officer, or any other individual or individuals accountable for ensuring compliance with the applicable laws and regulations for the protection of data privacy and security.
d. Management of Human Resources. Any natural or juridical person or other entity involved in the processing of personal data shall be responsible for selecting and supervising its employees, agents, or representatives, particularly those who will have access to personal data.
The said employees, agents, or representatives shall operate and hold personal data under strict confidentiality if the personal data are not intended for public disclosure. This obligation shall continue even after leaving the public service, transferring to another position, or upon terminating their employment or contractual relations. There shall be capacity building, orientation or training programs for such employees, agents or representatives, regarding privacy or security policies.
e. Processing of Personal Data. Any natural or juridical person or other body involved in the processing of personal data shall develop, implement and review:
1. A procedure for the collection of personal data, including procedures for obtaining consent, when applicable;
2. Procedures that limit the processing of data, to ensure that it is only to the extent necessary for the declared, specified, and legitimate purpose;
3. Policies for access management, system monitoring, and protocols to follow during security incidents or technical problems;
4. Policies and procedures for data subjects to exercise their rights under the Act;
5. Data retention schedule, including timeline or conditions for erasure or disposal of records.
f. Contracts with Personal Information Processors. The personal information controller, through appropriate contractual agreements, shall ensure that its personal information processors, where applicable, shall also implement the security measures required by the Act and these Rules. It shall only engage those personal information processors that provide sufficient guarantees to implement appropriate security measures specified in the Act and these Rules, and ensure the protection of the rights of the data subject. (IRR, Rule VI)
Guidelines for organizational security
For organizational security, the Data Privacy Law provides for the following guidelines which PICs and PIPs are required to comply where appropriate:
1) Compliance Officers,
2) Data Protection Policies,
3) Records of Processing Activities,
4) Management of Human Resources,
5) Processing of Personal Data, and
6) Contracts with Personal Information Processors.

Figure 2. Guidelines for Organizational Security Measures
Compliance Officers
1) Any natural or juridical person or other body involved in the processing of personal data shall designate an individual or individuals who shall function as:
a) data protection officer,
b) compliance officer, or
c) otherwise be accountable for ensuring compliance with applicable laws and regulations for the protection of data privacy and security. (IRR, Section 26[a], Rule VI)
2) “Data Protection Officer” or “DPO” refers to an individual designated by the head of agency or organization to ensure its compliance with the Act, its IRR, and other issuances of the Commission: Provided, that, except where allowed otherwise by law or the Commission, the individual must be an organic employee of the government agency or private entity: Provided further, that a government agency or private entity may not have more than one DPO. (NPC Circular No. 4, Series of 2022, Section 2[D]; underscoring supplied)
NB: The DPO cannot anymore be outsourced or subcontracted as was previously provided under NPC Advisory No. 01, Series of 2017.
Data Protection Policies
1) Any natural or juridical person or other body involved in the processing of personal data shall implement appropriate data protection policies that provide for organization, physical, and technical security measures, and, for such purpose, take into account the nature, scope, context and purposes of the processing, as well as the risks posed to the rights and freedoms of data subjects. (IRR, Section 26[b], Rule VI; underscoring supplied)
1) The policies shall implement data protection principles both at the time of the determination of the means for processing and at the time of the processing itself. (IRR, Section 26[b][1], Rule VI; underscoring supplied)
2) The policies shall implement appropriate security measures that, by default, ensure only personal data which is necessary for the specified purpose of the processing are processed. They shall determine the amount of personal data collected, including the extent of processing involved, the period of their storage, and their accessibility. (IRR, Section 26[b][2], Rule VI; underscoring supplied)
3) The polices shall provide for documentation, regular review, evaluation, and updating of the privacy and security policies and practices. (IRR, Section 26[b][3], Rule VI; underscoring supplied)
Records of Processing Activities
1) Any natural or juridical person or other body involved in the processing of personal data shall maintain records that sufficiently describe its data processing system, and identify the duties and responsibilities of those individuals who will have access to personal data. (IRR, Section 26[c], Rule VI)
“Data processing systems” refers to the structure and procedure by which personal data is collected and further processed in an information and communications system or relevant filing system, including the purpose and intended output of the processing. (IRR, Section 3[e], Rule I)
2) Records should include:
a) Information about the purpose of the processing of personal data, including any intended future processing or data sharing;
b) A description of all categories of data subjects, personal data, and recipients of such personal data that will be involved in the processing;
c) General information about the data flow within the organization, from the time of collection, processing, and retention, including the time limits for disposal or erasure of personal data;
d) A general description of the organizational, physical, and technical security measures in place;
e) The name and contact details of the personal information controller and, where applicable, the joint controller, the its representative, and the compliance officer or Data Protection Officer, or any other individual or individuals accountable for ensuring compliance with the applicable laws and regulations for the protection of data privacy and security. (IRR, Section 26[c], Rule VI)
Management of Human Resources
1) Any natural or juridical person or other entity involved in the processing of personal data shall be responsible for selecting and supervising its employees, agents, or representatives, particularly those who will have access to personal data. (IRR, Section 26[d], Rule VI)
2) The said employees, agents, or representatives shall operate and hold personal data under strict confidentiality if the personal data are not intended for public disclosure. This obligation shall continue even after leaving the public service, transferring to another position, or upon terminating their employment or contractual relations. (IRR, Paragraph 2, Section 26[d], Rule VI)
There shall be capacity building, orientation or training programs for such employees, agents or representatives, regarding privacy or security policies. (IRR, Paragraph 2, Section 26[d], Rule VI)
Processing of Personal Data
Any natural or juridical person or other body involved in the processing of personal data shall develop, implement and review:
1) A procedure for the collection of personal data, including procedures for obtaining consent, when applicable;
2) Procedures that limit the processing of data, to ensure that it is only to the extent necessary for the declared, specified, and legitimate purpose;
3) Policies for access management, system monitoring, and protocols to follow during security incidents or technical problems;
4) Policies and procedures for data subjects to exercise their rights under the Act;
5) Data retention schedule, including timeline or conditions for erasure or disposal of records. (IRR, Section 26[e], Rule VI)
Contracts with Personal Information Processors
1) The personal information controller, through appropriate contractual agreements, shall ensure that its personal information processors, where applicable, shall also implement the security measures required by the Act and these Rules. (IRR, Section 26[f], Rule VI)
2) [The PIC] shall only engage those personal information processors that provide sufficient guarantees to implement appropriate security measures specified in the Act and these Rules, and ensure the protection of the rights of the data subject. (IRR, Section 26[f], Rule VI)
Physical Security
Section 27. Physical Security Measures. Where appropriate, personal information controllers and personal information processors shall comply with the following guidelines for physical security:
a. Policies and procedures shall be implemented to monitor and limit access to and activities in the room, workstation or facility, including guidelines that specify the proper use of and access to electronic media;
b. Design of office space and work stations, including the physical arrangement of furniture and equipment, shall provide privacy to anyone processing personal data, taking into consideration the environment and accessibility to the public;
c. The duties, responsibilities and schedule of individuals involved in the processing of personal data shall be clearly defined to ensure that only the individuals actually performing official duties shall be in the room or work station, at any given time;
d. Any natural or juridical person or other body involved in the processing of personal data shall implement Policies and procedures regarding the transfer, removal, disposal, and re-use of electronic media, to ensure appropriate protection of personal data;
e. Policies and procedures that prevent the mechanical destruction of files and equipment shall be established. The room and workstation used in the processing of personal data shall, as far as practicable, be secured against natural disasters, power disturbances, external access, and other similar threats. (IRR, Rule VI)
Guidelines for physical security
For physical security, the Data Privacy Law provides for the following guidelines which PICs and PIPs are required to comply where appropriate:
1) Policies and procedures on monitoring and limiting access;
2) Design office space and workstations to provide privacy to person responsible for processing personal data;
3) Duties, responsibilities, and schedules of persons responsible for processing personal data;
4) Policies and procedures on transfer, removal, disposal, and re-use of electronic media; and
5) Policies and procedures on preventing the mechanical destruction of files and equipment.
Policies and procedures on monitoring and limiting access,
PICs and PIPs should:
• Implement policies and procedures to monitor and limit access to and activities in the room, workstation or facility, including guidelines that specify the proper use of and access to electronic media. (IRR, Section 27[a], Rule VI)
2) Design office space and workstations to provide privacy to person responsible for processing personal data,
PICs and PIPs should:
• Ensure that the design of office space and work stations, including the physical arrangement of furniture and equipment, shall provide privacy to anyone processing personal data, taking into consideration the environment and accessibility to the public. (IRR, Section 27[b], Rule VI)
3) Duties, responsibilities, and schedules of persons responsible for processing personal data,
PICs and PIPs should:
• Clearly defined the duties, responsibilities and schedule of individuals involved in the processing of personal data, to ensure that only the individuals actually performing official duties shall be in the room or work station, at any given time. (IRR, Section 27[c], Rule VI)
4) Policies and procedures on transfer, removal, disposal, and re-use of electronic media, and
PICs and PIPs should:
• Implement policies and procedures regarding the transfer, removal, disposal, and re-use of electronic media, to ensure appropriate protection of personal data. (IRR, Section 27[d], Rule VI)
5) Policies and procedures on preventing the mechanical destruction of files and equipment.
1) PICs and PIPs should:
• Implement policies and procedures that prevent the mechanical destruction of files and equipment shall be established. (IRR, Section 27[e], Rule VI)
2) The room and workstation used in the processing of personal data shall, as far as practicable, be secured against natural disasters, power disturbances, external access, and other similar threats. (IRR, Section 27[e], Rule VI)

Figure 3. Guidelines for Physical Security Measures
Technical Security
Section 28. Guidelines for Technical Security Measures. Where appropriate, personal information controllers and personal information processors shall adopt and establish the following technical security measures:
a. A security policy with respect to the processing of personal data;
b. Safeguards to protect their computer network against accidental, unlawful or unauthorized usage, any interference which will affect data integrity or hinder the functioning or availability of the system, and unauthorized access through an electronic network;
c. The ability to ensure and maintain the confidentiality, integrity, availability, and resilience of their processing systems and services;
d. Regular monitoring for security breaches, and a process both for identifying and accessing reasonably foreseeable vulnerabilities in their computer networks, and for taking preventive, corrective, and mitigating action against security incidents that can lead to a personal data breach;
e. The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
f. A process for regularly testing, assessing, and evaluating the effectiveness of security measures;
g. Encryption of personal data during storage and while in transit, authentication process, and other technical security measures that control and limit access. (IRR, Rule VI)
Guidelines for technical security
For technical security, the Data Privacy Law provides for the following guidelines which PICs and PIPs are required to adopt and establish the following where appropriate:
1) Security policy;
2) Safeguards to protect their computer network;
3) Maintain confidentiality, integrity, availability, and resilience of processing systems and services;
4) Regular monitoring for security breaches;
5) Ability to restore the availability and access to personal data;
6) Regular testing, assessing, and evaluating effectiveness of security measures;
7) Encryption of personal data. (IRR, Section 28, Rule VI)
1) Security policy
PICs and PIPs should adopt and establish:
• A security policy with respect to the processing of personal data. (IRR, Section 28[a], Rule VI)
2) Safeguards to protect their computer network
PICs and PIPs should adopt and establish:
• Safeguards to protect their computer network against accidental, unlawful or unauthorized usage, any interference which will affect data integrity or hinder the functioning or availability of the system, and unauthorized access through an electronic network. (IRR, Section 28[b], Rule VI)
3) Maintain confidentiality, integrity, availability, and resilience of processing systems and services
PICs and PIPs should adopt and establish:
• The ability to ensure and maintain the confidentiality, integrity, availability, and resilience of their processing systems and services. (IRR, Section 28[c], Rule VI)
4) Regular monitoring for security breaches
PICs and PIPs should adopt and establish:
• Regular monitoring for security breaches, and a process both for identifying and accessing reasonably foreseeable vulnerabilities in their computer networks, and for taking preventive, corrective, and mitigating action against security incidents that can lead to a personal data breach. (IRR, Section 28[d], Rule VI)
5) Ability to restore the availability and access to personal data
PICs and PIPs should adopt and establish:
• The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident. (IRR, Section 28[e], Rule VI)
6) Regular testing, assessing, and evaluating effectiveness of security measures
PICs and PIPs should adopt and establish:
• A process for regularly testing, assessing, and evaluating the effectiveness of security measures. (IRR, Section 28[f], Rule VI)
7) Encryption of personal data
PICs and PIPs should adopt and establish:
• Encryption of personal data during storage and while in transit, authentication process, and other technical security measures that control and limit access. (IRR, Section 28[g], Rule VI)

Figure 4. Guidelines for Technical Security Measures
NPC Monitoring on Security Measures
Section 29. Appropriate Level of Security. The Commission shall monitor the compliance of natural or juridical person or other body involved in the processing of personal data, specifically their security measures, with the guidelines provided in these Rules and subsequent issuances of the Commission. In determining the level of security appropriate for a particular personal information controller or personal information processor, the Commission shall take into account the nature of the personal data that requires protection, the risks posed by the processing, the size of the organization and complexity of its operations, current data privacy best practices, and the cost of security implementation. The security measures provided herein shall be subject to regular review and evaluation, and may be updated as necessary by the Commission in separate issuances, taking into account the most appropriate standard recognized by the information and communications technology industry and data privacy best practices. (IRR, Rule VI)
NPC’s Duty to monitor
The [NPC] shall monitor the compliance of natural or juridical person or other body involved in the processing of personal data, specifically their security measures, with the guidelines provided in these Rules and subsequent issuances of the Commission.
Factors to consider for appropriate security measures
In determining the level of security appropriate for a particular personal information controller or personal information processor, the [NPC] shall take into account:
1) the nature of the personal data that requires protection,
2) the risks posed by the processing,
3) the size of the organization and complexity of its operations,
4) current data privacy best practices, and
5) the cost of security implementation.
Regular review and evaluation
The security measures provided herein shall be subject to regular review and evaluation, and may be updated as necessary by the [NPC] in separate issuances, taking into account the most appropriate standard recognized by the information and communications technology industry and data privacy best practices. (IRR, Section 29, Rule VI)
REFERENCES
National Privacy Commission. (n.d.) Implementing Rules and Regulations or Republic Act No. 10173, also known as the “Data Privacy Act of 2012”. https://privacy.gov.ph/implementing-rules-regulations-data-privacy-act-2012/
National Privacy Commission. (n.d.). Powers & Functions. https://privacy.gov.ph/powers-functions/
Republic Act No. 10173. (2012). Data Privacy Act of 2012. https://privacy.gov.ph/data-privacy-act/
