Start Here

Do I even need a Data Protection Officer?

You scanned this from our leaflet. If you collect names, IDs, or customer details, the Data Privacy Act applies to you. Here are the questions every Region 8 business owner asks first — answered plainly.

Questions, answered

What is the Data Privacy Act, in one sentence?

RA 10173, the Data Privacy Act of 2012, is the Philippine law that says any business collecting personal information must protect it, use it only for declared purposes, and answer to the National Privacy Commission (NPC) if it doesn’t.

Do I even need a Data Protection Officer?

Yes. If your business processes personal data at all, it must designate one — IRR Section 26(a) and NPC Advisory 2017-01 apply the duty to every organization, with no size threshold and no small-business exemption. What size does decide is whether you must also register your data processing systems with the NPC. If you meet none of the registration grounds you still appoint a DPO and file a notarized sworn declaration instead. A short assessment settles which side you are on.

What is a DPO and what do they actually do?

A Data Protection Officer is the person accountable for your data-privacy compliance: they build your privacy program, register you with the NPC, handle breaches, train staff, and act as your official contact with the NPC. You can appoint one in-house or engage an external DPO.

Do I have to register with the NPC?

Only if one of four grounds applies (Circular 2022-04 Section 5): 250 or more persons employed; sensitive personal information on 1,000 or more individuals; processing likely to pose a risk to rights and freedoms; or automated decision-making or profiling, which has no threshold. If none applies you file a notarized sworn declaration instead — never nothing. Many businesses don’t realise which side they fall on until they’re assessed. We handle the eligibility check and the filing.

What happens if I just ignore this?

The NPC can investigate complaints and impose administrative fines of 0.5%–3% of your prior-year gross income for a grave infraction — capped at ₱5 million for any single act — plus ₱50,000–₱200,000 per infraction for failing to register. RA 10173 carries imprisonment separately, for serious offences, and it falls on responsible officers personally. Beyond penalties, a breach or a public complaint damages customer trust. Compliance is far cheaper than enforcement.

My business is small. Is this overkill?

Compliance scales. A small clinic, lending office, or hotel doesn’t need an enterprise program — it needs the right basics done properly: lawful basis, notices, security, a retention schedule, and a breach plan. That’s exactly what a right-sized engagement delivers.

What does working with you look like?

A free assessment tells you whether you need a DPO and registration, and what’s missing. From there I can serve as your external DPO (Cert #7000532, TÜV Certified), build your Privacy Management Program, and keep you compliant — based in Region 8, serving Leyte, Samar, and Biliran.

Find out where your business stands

Talk to a TÜV Certified Data Protection Officer — no obligation, no jargon.

Atty. Renerio de Dios Jr. · TÜV Cert #7000532 · Dulag, Leyte · serving all of Region 8