Compliance with the Data Privacy Act, breach response, and advisory work for personal-data handlers.
What this area covers
Data privacy law governs how organizations collect, use, and protect personal information. Our work covers building compliance into how a business handles data, responding when a breach occurs, and advising the organizations that the law treats as responsible for personal data.
Any organization that processes the personal data of others carries obligations under the law, whatever its size.
Matters we handle
Privacy compliance programs
Privacy notices and consent
Data-sharing and processing agreements
Breach assessment and notification
Matters before the National Privacy Commission
How these matters typically proceed
The governing law is the Data Privacy Act of 2012 (Republic Act No. 10173), administered by the National Privacy Commission (NPC). It places obligations on the personal-information controller — the organization that decides how and why data is processed — and on the processor that handles data on the controller's behalf.
When a personal-data breach occurs that meets the law's criteria, the controller must notify the NPC and the affected individuals within seventy-two hours of knowledge of the breach. Throughout, individuals retain rights over their data — among them the rights to be informed, to access, and to correct — which a compliance program is built to respect.
Related areas
Privacy compliance is closely tied to our Business & Corporate Law practice and to the data provisions we review in Contract Law matters.
