Start Here

Do I even need a Data Protection Officer?

You scanned this from our leaflet. If you collect names, IDs, or customer details, the Data Privacy Act applies to you. Here are the questions every Region 8 business owner asks first — answered plainly.

Questions, answered

What is the Data Privacy Act, in one sentence?

RA 10173, the Data Privacy Act of 2012, is the Philippine law that says any business collecting personal information must protect it, use it only for declared purposes, and answer to the National Privacy Commission (NPC) if it doesn’t.

Do I even need a Data Protection Officer?

You likely do if your business processes sensitive personal information (health, financial, IDs, biometrics), if handling personal data is core to what you do, or if you employ around 250+ people. Banks, lending and financing firms, hospitals, schools, BPOs, and hotels almost always need one. If you’re unsure, a short assessment settles it.

What is a DPO and what do they actually do?

A Data Protection Officer is the person accountable for your data-privacy compliance: they build your privacy program, register you with the NPC, handle breaches, train staff, and act as your official contact with the NPC. You can appoint one in-house or engage an external DPO.

Do I have to register with the NPC?

If you meet the thresholds, yes — you register your Data Processing Systems with the NPC and renew it. Many businesses don’t realise they qualify until they’re assessed. We handle the eligibility check and the filing.

What happens if I just ignore this?

The NPC can investigate complaints and impose administrative fines reaching millions of pesos, and RA 10173 carries imprisonment for serious offences. Beyond penalties, a breach or a public complaint damages customer trust. Compliance is far cheaper than enforcement.

My business is small. Is this overkill?

Compliance scales. A small clinic, lending office, or hotel doesn’t need an enterprise program — it needs the right basics done properly: lawful basis, notices, security, a retention schedule, and a breach plan. That’s exactly what a right-sized engagement delivers.

What does working with you look like?

A free assessment tells you whether you need a DPO and registration, and what’s missing. From there I can serve as your external DPO (Cert #7000532, TÜV Certified), build your Privacy Management Program, and keep you compliant — based in Region 8, serving Leyte, Samar, and Biliran.

Find out where your business stands

Talk to a TÜV Certified Data Protection Officer — no obligation, no jargon.

Atty. Renerio de Dios Jr. · TÜV Cert #7000532 · Dulag, Leyte · serving all of Region 8