Philippine data privacy

Protect personal data with practical accountability.

Build a workable privacy programme around your data, people and operating risks, rather than treating compliance as a one-off document exercise.

Discuss NPC / Data Privacy Act

Designed for your context

The right support
for the decision ahead.

For Philippine government and private-sector organisations processing personal information.

What we deliver

Scope tailored to your organisation

DPA readiness review

Assess practices against applicable RA 10173 and NPC requirements.

Privacy impact assessments

Evaluate processing activities and systems, documenting risk and treatment priorities.

DPO advisory & support

Scope Data Protection Officer advisory or service support around the organisation’s needs and accountability.

Privacy documentation

Develop a usable privacy manual, policies and operating procedures.

Registration assistance

Assess applicability and assist with NPC registration requirements.

Breach response planning

Develop escalation, investigation, decision and notification procedures for applicable breach scenarios.

Vendor privacy review

Assess third-party data handling, responsibilities and contractual controls.

Security & assurance readiness

Support relevant NPC security controls and assess Philippine Privacy Mark readiness where appropriate.

Tangible outputs

Leave with more
than recommendations.

  • Privacy readiness assessment
  • PIAs and treatment actions
  • Privacy manual and responsibilities
  • Breach response plan
  • Registration and vendor review support

A clear path to progress

  1. 01

    Understand processing and obligations

  2. 02

    Assess privacy risk

  3. 03

    Implement controls and documentation

  4. 04

    Exercise, review and maintain

Philippine context & engagement boundaries

Registration, notification and other obligations depend on the circumstances and current NPC issuances. Notification criteria, timelines and legal interpretations should be confirmed with the DPO and legal advisers; no blanket compliance guarantee is made.

Questions worth asking

How is the engagement scoped?

We start with your priorities, operating context and current capabilities. The proposal sets out deliverables, responsibilities, dependencies and acceptance criteria.

Can this connect with other Gardoce services?

Yes. Related advisory, security, architecture and implementation work can be coordinated, with each workstream’s scope and ownership made explicit.

Every engagement starts with a clear scope, agreed responsibilities and practical outcomes.

Start with a conversation

What needs to move
forward in your organisation?

Tell us the decision, risk or operational challenge you are facing. We will help define a sensible next step.

Discuss your priorities