If your company collects, stores, or processes personal data in the Philippines, you may be required to register with the National Privacy Commission. The requirement comes from the Data Privacy Act of 2012, and it applies to local and foreign-owned companies alike.
However, not every business has to register. It depends on how many people you employ, how much sensitive data you hold, and what your systems do with it.
This guide covers who has to register, how the process works, and what registration commits you to afterwards.
What Is NPC Registration?
The National Privacy Commission administers the Data Privacy Act of 2012 (Republic Act No. 10173). Registration is governed by NPC Circular No. 2022-04, issued on 5 December 2022 and effective from 11 January 2023, which replaced the earlier 2017 framework.
NPC registration has two parts:
- Your Data Protection Officer: The person accountable for your compliance with the Data Privacy Act. You record their appointment with the NPC, along with their official contact details, which become the channel for privacy-related correspondence and for data subjects raising complaints.
- Your Data Processing Systems: Every system you use to handle personal data, from your HR platform and CRM to your CCTV and visitor logs. For each one, you describe what data it holds, why you process it, who receives the data, whether any of it leaves the Philippines, and how it is secured.
Your company itself is recorded through the same submission, so there is no separate registration for the organization. Once the NPC validates both parts and your fees are paid, you receive a Certificate of Registration and a downloadable NPC Seal of Registration, each valid for one year.
However, registering does not by itself make you compliant with the Data Privacy Act. It records who is responsible and what systems you run.
Separately, the Act requires you to carry out privacy impact assessments, maintain a privacy management program, put security measures in place, and be able to report breaches within the required timeframe.
Who Is Required to Register?
Before checking the thresholds, identify which role your organisation holds, since both can be required to register.
- Personal Information Controller (PIC): You decide how and why personal data is processed. A hospital holding patient records and a bank processing account data are both PICs.
- Personal Information Processor (PIP): You process data on behalf of a PIC under a contract. A BPO handling customer support for a client and a payroll provider running employee payroll are both PIPs.
Many companies are both at once. You are a PIC for your own employee and customer records, and a PIP for whatever client data you handle on their behalf.
NPC Registration is mandatory for a PIC or PIP in any of the following situations:
- You employ 250 or more people
- You process sensitive personal information of 1,000 or more individuals, meaning data such as health records, government ID numbers, or information about race, religion, or political affiliation
- Your processing is likely to pose a risk to the rights and freedoms of data subjects
- Your system involves automated decision-making or profiling, which must be registered in all instances, whatever your headcount or data volume
- You are a government branch, agency, or instrumentality, regardless of size
In our experience, the fourth condition is where companies most often get this wrong. Lending platforms, insurance underwriting, credit scoring, and HR technology all involve automated decisions about individuals. A company running any of them has to register even with a handful of employees and a modest client list.
Foreign companies
The rules apply to organizations operating in the Philippines, and that includes companies not established here but using equipment located in the country, or maintaining an office, branch, or agency here. Multinationals typically register their Philippine entity as the PIC or PIP along with its DPO, and cover cross-border data flows through contractual safeguards.
Companies with branches
Where your branches form part of one organization's data processing system, you register once rather than per branch. Separate registration applies where a branch functions as a distinct unit, such as a franchised branch operating under its own corporate name.
Larger organizations can appoint Compliance Officers for Privacy at branch level who report to the central DPO. These officers support the DPO rather than replacing them, and they do not receive separate certificates for their branches.
If None of These Conditions Apply to You
You can still register voluntarily. If you choose not to, you have a declaration to file instead.
Filing the exemption declaration
NPC Circular No. 2022-04 requires organizations that fall below the thresholds and do not register to submit a notarized Sworn Declaration and Undertaking (SDAU) for exemption from DPS registration. The form is in Annex 1 of the circular, it is filed through the NPCRS, and there is no fee for it.
Filing the declaration does not exempt you from the Data Privacy Act itself. You still designate a DPO, implement security measures, uphold data subject rights, and submit your Annual Security Incident Report.
The declaration only records that you sit below the registration threshold.
If you file nothing at all, the NPC treats you as having failed to register. It carries out on-site compliance checks and issues show cause orders to businesses it finds unregistered.
A single sweep of one mall in May 2024 identified 65 tenants without registration.
Registering voluntarily
Any PIC or PIP may register without meeting the thresholds, and you receive the same Certificate of Registration and NPC Seal as a mandatory registrant.
Companies whose clients audit their data handling often take this route, since the Seal is publicly verifiable through the QR code it carries.
Requirements for NPC Registration
Registration covers the two parts described above, and each carries its own requirements.
1. Registering your Data Protection Officer
Covered organisations must designate a DPO who oversees compliance. Registration requires:
- The DPO's name and position
- Contact details, including an official DPO email address for privacy-related communications
- Proof of appointment, such as a board resolution, management order, or appointment letter, properly notarised
- Evidence of relevant data privacy training or qualifications, which is not always required but supports the appointment
The NPC expects the DPO to be an organic employee of your organisation, meaning a regular, contractual, or part-time member of staff. In practice this is often a compliance officer, legal counsel, or IT head who takes the role alongside their existing duties. Outsourcing the function carries conditions, so confirm your arrangement before appointing someone external.
2. Registering your Data Processing Systems
A Data Processing System is any system, automated or manual, that collects, stores, uses, or otherwise processes personal data. This typically covers:
- HR systems and payroll databases
- Customer databases and CRM platforms
- Billing and accounting systems
- Websites and mobile applications that collect user data
- CCTV systems, visitor logs, and access control
- Cloud storage and vendor-managed systems
For each system, you provide:
- The name and description of the system
- The purposes it serves, such as employment administration, billing, or regulatory reporting
- The categories of data subjects, such as employees, customers, patients, or suppliers
- The types of personal data involved, and whether any of it is sensitive
- The recipients of the data, including internal departments, third parties, and government agencies
- Whether data is transferred outside the Philippines, and to which countries
- Whether processing is outsourced, and to which processors
- A general description of your security measures
- References to your relevant internal policies
It is advisable to maintain an inventory of all active systems, since every covered system has to appear in your registration.
Where a PIC supplies the system that a PIP uses, the obligation to register that system sits with the PIC. This is worth settling in writing between the parties, since both sides often assume the other has filed it.
The NPC Registration Process
The NPC registration process now runs online through the NPC Registration System (NPCRS). However. you cannot start filing until your DPO is formally appointed and your data processing systems are documented. So most of the effort goes into the preparation rather than the submission itself.
1. Prepare before you file
Start by confirming which route applies to you. If you meet any of the conditions mentioned above, registration is mandatory. If you do not, you have to choose between registering voluntarily and filing the exemption declaration.
Once that is settled, appoint your DPO formally. A board resolution or management order is the usual instrument for that.
The last piece of preparation is your inventory of active data processing systems. This is normally the longest part of the job, because you need every system that touches personal data, including things like visitor logbooks, CCTV, or even spreadsheets that are held on a shared drive.
2. Create your account and complete the registration
Your DPO or compliance officer creates the organizational account on the NPCRS. From there, you complete the organizational profile, using your company's legal name exactly as it appears on your SEC or DTI records, along with your TIN, registered business address, and contact details.
After that, you need to register your DPO with the supporting appointment documents, and encode each active data processing system with the details set out in the requirements above.
3. Submit the sworn declaration and pay the fee
Your DPO or another authorized officer submits a sworn statement confirming that everything you have provided is truthful and complete. After that, you pay the registration fee through the system, and your submission goes to the NPC for review.
4. Respond to the review and collect your certificate
If the NPC finds a deficiency, it notifies you and gives you five days to supply what is missing. That window is short, so keep your supporting documents accessible after filing. Reassembling a notarized appointment letter inside five days is difficult.
Once your submission clears review, your Certificate of Registration and NPC Seal become available to download from the NPCRS.
If you would rather not manage the filing yourself, our team can handle the process on your behalf, from creating the NPCRS account through to certificate issuance. Fill out the form below to talk to our local experts.
Deadlines After Registration
Your obligations continue after the certificate is issued. Any change to your systems or your DPO has to be reported to the NPC within a set period, and the registration itself expires after a year. There are four types of deadlines depending on the event:
| Event | Deadline |
|---|---|
| New Data Processing System, or your inaugural DPO | Register within 20 days of the system commencing or the appointment taking effect |
| Minor amendments, including updates to an existing system or a change of DPO | Update the NPCRS within 10 days |
| Major amendments, such as a change of entity name or business address | Update within 30 days |
| Renewal of your Certificate of Registration | Begin at least 30 days before expiry |
As mentioned earlier, your certificate and seal are valid for one year from issuance, and the NPC does not send reminders. Therefore, put the renewal date in your compliance calendar when the certificate is issued.
NPC Registration Fees
The NPC began collecting fees on 1 October 2024 under NPC Circular No. 2023-01, the schedule of fees and charges.
| Transaction | Individual or professional | Municipalities | Regional, provincial, Metro Manila, cities | Multinational, national, foreign branch |
|---|---|---|---|---|
| Initial registration | PHP 500 | PHP 500 | PHP 1,000 | PHP 2,500 |
| Annual renewal | PHP 350 | PHP 350 | PHP 500 | PHP 1,000 |
| Major amendment | PHP 500 | PHP 500 | PHP 1,000 | PHP 2,500 |
Displaying the NPC Seal of Registration
The NPC issued a public advisory on 13 November 2023 confirming that displaying the Seal is mandatory. You need to display it as per following:
- At the main entrance of your place of business, or the most conspicuous location visible to visitors
- Within every office, branch office, sub-branch, and satellite office where personal data processing takes place
- On your main website, either as a clickable link to your privacy notice or directly on the privacy notice page. For a global website, the Seal goes on the Philippines-specific page
The Seal carries the word "Registered," its validity period, and a QR code that lets anyone verify your registration status and DPO contact details.
Penalties for Non-Compliance
Administrative fines sit in NPC Circular No. 2022-01, issued on 8 August 2022, which sorts infractions into three categories.
Other infractions, which include failure to register or to keep your registration information current, carry fines of PHP 50,000 to PHP 200,000.
Major infractions affect between one and 1,000 data subjects. Grave infractions affect 1,000 or more, and carry fines of 0.5% to 3% of your annual gross income for the preceding year. Repeated major or other infractions are treated as grave.
The maximum penalty is PHP 5,000,000 per act.
Registering with the NPC with Emerhub
Emerhub's Philippines team handles NPC registration end to end. We assess whether you need to register, appoint and document your DPO, prepare your system descriptions, and file everything through the NPCRS on your behalf.
We also track post registration compliance, including the five-day deficiency window, your Seal display, and your renewal date.
Contact our Philippines team for a consultation on where your organization stands under the Data Privacy Act.
Frequently asked questions
Who needs to register with the NPC?
Any PIC or PIP employing 250 or more people, processing sensitive personal information of 1,000 or more individuals, processing data likely to pose a risk to data subjects' rights, or operating as a government body. Separately, any system involving automated decision-making or profiling must be registered regardless of these thresholds.
Can an individual professional register with the NPC?
Yes. Individuals acting as a PIC or PIP, such as independent consultants or healthcare professionals holding patient records, can and often must register. The fee schedule includes an individual and professional rate of PHP 500 for initial registration and PHP 350 for renewal.
How long is the NPC Certificate of Registration valid?
One year from the date of issuance, along with the NPC Seal. Begin your renewal at least 30 days before expiry.
Do I register every branch separately?
Not where your branches operate within one organization's data processing system. Separate registration applies where a branch functions as a distinct unit, such as a franchised branch under a separate corporate name. Compliance Officers for Privacy appointed at branch level do not receive their own certificates.
What if my organization does not meet the thresholds?
You can register voluntarily and receive the same certificate and Seal, or submit a notarized Sworn Declaration and Undertaking for exemption through the NPCRS. If you do neither, the NPC treats you as having failed to register.
