data privacy act rights
Your Data Was Leaked. Here's Exactly What the Data Privacy Act Lets You Do

Key Takeaway

  • ⚖️ The data privacy act rights in RA 10173 give every Filipino 7 enforceable powers over their personal data — informed, object, access, rectify, erase, damages, portability.
  • 🩸 A leak is not the end: your data being breached triggers real legal duties on the company and real options for you, starting with the right to be told.
  • 📝 The NPC complaint path is concrete: download the Complaint Affidavit form, notarize it, submit in person, by courier, or by email — fees are published under NPC Circular 2023-01.
  • 🏢 Companies must notify NPC and affected individuals within 72 hours of qualifying breaches; if nobody told you, that silence is itself actionable.
  • 🛡️ The rights work best in order — demand information first, correction second, damages last — and document every request in writing.
data privacy act rights

Southeast Asian data breach costs jumped again this year, and the Philippines sits in the region’s blast radius — telcos, hospitals, government portals, and e-commerce platforms all shipped leaks in recent memory. Most victims assume a breach means accepting spam texts forever. It does not. The data privacy act rights enshrined in RA 10173 hand every Filipino seven enforceable powers over their personal data, a regulator with real teeth, and a complaint procedure you can complete in an afternoon. This guide turns the law into a working playbook: what each right actually lets you do, what companies owe you when your data leaks, and the exact steps to make the National Privacy Commission move.

The Law in One Paragraph

Republic Act 10173, the Data Privacy Act of 2012, regulates anyone who collects and processes personal data in the Philippines — companies, schools, hospitals, government offices, and yes, app developers serving Filipino users. It created the National Privacy Commission (NPC) as enforcement body, defined personal and sensitive personal information, and — the part most people never learn — codified the data privacy act rights of the data subject: you. Those data privacy act rights are not polite suggestions. They are enforceable claims with a regulator standing behind them, and 2026 has been a year of the NPC sharpening its instruments, from clarified breach-notification procedure under NPC guidance documented by Baker McKenzie to tightened rules on emerging practices like data scraping.

Right 1: To Be Informed — the Door to Everything Else

Every other right depends on this one. The law entitles you to know whether personal data about you is being, has been, or will be processed, and the details: what data, for what purpose, on what legal basis, who receives it, how long it is kept, and who the controller actually is. Before you hand over details to any app or establishment, this right is the question checklist: “What will you do with this? Who else sees it? How long do you keep it?” A company that cannot answer has already violated the right to be informed — and your documentation of that refusal becomes evidence later.

Right 2: To Object — Saying No to Processing

You may object to processing of your personal data, including the automated-decision and direct-marketing flavors. This is one of the data privacy act rights that powers the “stop sending me promotional texts” demand — and under the law it is not a favor the company grants; it is a claim you enforce. The practical form: a written objection naming the data, the processing you refuse, and a request for confirmation that processing stopped. Direct-marketing objections are the most commonly honored because the law treats marketing consent as withdrawable at any time.

Right 3: To Access — Your File, Their Obligations

You can demand a copy of the personal data an organization holds about you — the access right that makes data privacy act rights real in practice, plus what they have done with it: processing purposes, recipients, and sources. This is the right that turns vague suspicion into facts — “what exactly does this lending app have on me, and who did they sell it to?” Organizations must respond within reasonable time; failure to provide access is a violation in itself. Written requests win again: email creates the timestamp that later proves refusal.

Right 4: To Rectification — Fixing the Record

Wrong data ruins real lives — a misspelled name on a credit record, an outdated number linked to someone else’s debt. The right to rectification among the data privacy act rights obliges the controller to correct inaccurate or incomplete data “in a manner that is fair and accurate,” and to notify third parties who received the erroneous version. For OFWs whose bank records, deployment documents, and credit files circulate between countries, this right is operational hygiene: fix the record at the source, demand the fix propagate downstream.

Right 5: To Erasure or Blocking — the Disappear Option

You can demand deletion or blocking of your personal data when processing is unlawful, when the purpose has expired, or when you withdraw consent on which the processing was built. This is the legal muscle behind “delete my account and my data” — the strongest of the data privacy act rights for cleanup cases — and the distinction matters: erasure destroys, blocking suspends use while data remains. The right has boundaries (legal retention duties, fraud-prevention records survive), but marketing databases and stale app profiles have no such shield. Follow the erasure demand with our breach hygiene workflow to clean up the exposure the deleted database may already have caused.

Right 6: To Damages — When the Harm Is Real

When improper processing causes you actual damage, the data privacy act rights let you claim compensable damages — identity theft losses, a loan taken in your name, reputational harm from a leaked record — the law lets you claim compensable damages. This is the right that makes the others expensive to ignore: a company that sat on your correction request or leaked your sensitive data and left you with the fallout can face liability. Pair the claim with the paper trail from Rights 1-5: refused access, ignored objection, unnotified breach. The trail is what turns a complaint into an award.

Right 7: To Data Portability — Take Your Data With You

Where processing runs on your consent or a contract and uses automated means, you can demand your data in a structured, commonly-used format and move it to another service. For users, this is the anti-lock-in right — the newest of the data privacy act rights: your transaction history, health records, or telecom data should travel when you switch providers. For the data economy, it is a quiet revolution — the law says your data belongs to you, not to the platform that collected it.

What the Company Owes You After a Breach

The data privacy act rights above run alongside hard duties on the company side. When a breach meets the NPC’s notification criteria — sensitive personal data, or risk of serious harm — the organization must notify the Commission and affected data subjects within 72 hours of learning of it. The notification must describe the data involved, the likely effects, and the measures taken. If your data was in a leak and no one told you, the silence is itself a violation worth reporting. Check whether your credentials surfaced in known leaks first with our data breach checker guide, then let the notification duty carry the legal weight.

How to File the NPC Complaint, Step by Step

The NPC’s official complaint procedure is refreshingly concrete:

  1. Download the Complaint Affidavit form from privacy.gov.ph — the 2026-formatted Complaint Affidavit with Questionnaire.
  2. Fill it out completely: your identity, the respondent (the company/agency), the facts in timeline form, the violation you allege, and the evidence attached — screenshots, ignored request emails, the breach notice.
  3. Notarize the affidavit.
  4. Submit by any of three channels: in person at the NPC, by courier, or scanned and emailed to the Commission’s complaints address.
  5. Check the fee schedule under NPC Circular 2023-01 — fees are published, and indigent filers can request waiver.

Before the formal complaint, the law expects you to have tried the direct route: a written request to the company’s Data Protection Officer (every covered organization must have one, and their contact details must be public). The DPO’s non-response within the reasonable window is precisely what makes your NPC complaint strong.

Frequently Asked Questions

What are the data privacy act rights in the Philippines?

RA 10173 grants seven rights: to be informed, to object, to access, to rectification, to erasure or blocking, to damages, and to data portability. Together they cover the full lifecycle — knowing what data is held, refusing unwanted processing, seeing and correcting your file, demanding deletion, claiming compensation for harm, and taking your data with you when you switch services.

Can I sue a company that leaked my personal data?

You can claim damages under the Data Privacy Act when improper processing causes you actual harm — identity-theft losses, financial fraud, reputational damage. The practical path runs through the NPC complaint first: the Commission can investigate, order corrective action, and impose penalties, and its findings anchor a civil damages claim. Document everything: the leak, your notifications, the harm, and every ignored request.

How long does a company have to notify me of a data breach?

Qualifying breaches must be reported to the NPC and affected data subjects within 72 hours of the company learning of them. The notice must cover what data was involved, probable effects, and remedial measures. If your data was breached and the company never told you, that failure is independently reportable to the NPC.

How do I file a complaint with the National Privacy Commission?

Download the Complaint Affidavit form from privacy.gov.ph, complete it with your identity, the respondent, a fact timeline, and evidence; have it notarized; then submit in person, by courier, or by scanned email to the NPC. Check the published fee schedule under NPC Circular 2023-01. Before filing, send a written request to the company’s Data Protection Officer — their non-response strengthens your complaint.

Can I demand that an app delete my data?

Yes — the right to erasure or blocking applies when processing lacks legal basis, the purpose expired, or consent was withdrawn. Write to the app’s Data Protection Officer demanding deletion and written confirmation. Legal retention duties (fraud records, statutory books) survive, but marketing profiles and stale app data do not. Refusal or silence goes straight into your NPC complaint.

Does the Data Privacy Act cover government agencies?

Yes — national government agencies, LGUs, and GOCCs are personal information controllers under RA 10173, subject to NPC oversight. Your rights to access, correction, and complaint apply to your records in government systems, from SSS and PhilHealth files to LGU registries, with the same complaint path through the Commission.

Final Word: The Law Only Works for People Who Use It

The data privacy act rights were written for the moment you are living through — breaches as routine, data traded in bulk, spam texts knowing your name. Seven data privacy act rights, one regulator, and a complaint form that costs less than a family dinner: the machinery works, but only when data subjects pull the levers. Demand information, object in writing, document every refusal, and file the NPC complaint when the answers never come. Your data has legal protection; the protection becomes real the day you invoke it.

Editorial Transparency Note:WorldNgayon uses AI-assisted tools in parts of its editorial workflow. For our editorial standards, sourcing practices and use of AI, see worldngayon.com/about/. Article bylines and source credits identify the stated authorship; this general note does not certify how an individual archive article was originally produced. Report factual errors through worldngayon.com/contact-us/.

Leave a Reply