Data Privacy & Cybersecurity
We help organizations comply with R.A. 10173 (Data Privacy Act) — NPC registration, privacy impact assessments, breach management — and stand up cyber-resilient programs that satisfy regulators, partners, and customers.
What we handle
- NPC registration and compliance programs
- Privacy policies and consent mechanisms
- Data breach response and notification
- Cybersecurity and incident handling
- Cross-border data transfers and DPO support
Insights on data privacy & cybersecurity
NPC enforcement fines in the Philippines are administrative penalties the National Privacy Commission may impose for violations of the Data Privacy Act of 2012.
Employee data retention in the Philippines follows the Data Privacy Act rule that personal data must not be kept longer than necessary for its purpose.
Learn how the Data Privacy Act of 2012 protects employee data in the Philippines and what employers must do to comply.
Learn how to conduct a privacy impact assessment in the Philippines under the Data Privacy Act and its IRR, from risk mapping to safeguards.
Learn when a Privacy Impact Assessment (PIA) is required in the Philippines under the Data Privacy Act of 2012 and its IRR.
A cybersecurity incident in the Philippines triggers legal duties under the Data Privacy Act — from containment to breach notification to the National Privacy Commission.