For Banks

Data privacy compliance for banks

You scanned this from our Bank Risk Summary. Here are straight answers to what banks in Region 8 actually ask about the Data Privacy Act — where it overlaps with the BSP, and what a breach of financial data really costs.

Questions, answered

Our bank is already supervised by the BSP. Do we also answer to the NPC?

Yes — they cover different things. The BSP regulates you as a financial institution (MORB, IT risk, consumer protection). The National Privacy Commission (NPC) regulates how you collect and handle personal data under the Data Privacy Act (RA 10173). A BSP-compliant bank can still be penalised by the NPC. The two overlap heavily, so your privacy program should be built to satisfy both at once.

Does a bank legally need a Data Protection Officer?

In practice, yes. Banks process sensitive personal and financial information as a core activity and on a large scale — exactly the criteria that require a designated DPO under RA 10173 and NPC Advisory No. 2017-01. The DPO is also the registered contact the NPC deals with.

What happens if customer financial data is breached?

A breach of financial data carries some of the highest stakes under the law: account numbers, balances, and IDs enable fraud directly. You must assess and, where required, notify the NPC and affected clients within 72 hours of knowledge of the breach. Late or missing notification is itself a violation — on top of the breach.

Do we have to register with the NPC, and how often?

Banks meeting the thresholds must register their Data Processing Systems with the NPC and renew the registration. We handle eligibility assessment, the filing, and keeping the registration current so it does not lapse.

We use third-party processors (core banking, e-KYC, collections). Are we still liable?

Yes. As the Personal Information Controller, the bank stays accountable for data handled by vendors. That liability has to be managed through proper data-sharing and outsourcing agreements and vendor due diligence — which the DPO oversees.

What can NPC penalties actually cost us?

Beyond reputational damage and BSP scrutiny, NPC administrative fines and the imprisonment provisions of RA 10173 can reach millions of pesos per offence. For a bank, the cost of a compliant privacy program is a fraction of a single enforcement action.

Can you act as our external DPO?

Yes. As a TÜV Certified DPO (Cert #7000532) based in Region 8, I can serve as your designated external DPO, build your Privacy Management Program, train staff, and be your point of contact with the NPC — without the cost of a full-time hire.

Protect your customers' financial data

Talk to a TÜV Certified Data Protection Officer — no obligation, no jargon.

Atty. Renerio de Dios Jr. · TÜV Cert #7000532 · Dulag, Leyte · serving all of Region 8