All guides

Philippines compliance guide

The Philippines Data Privacy Act for Cold Email and B2B Outreach

The Philippines is the easiest APAC market to sell into in English and one of the least understood on compliance. There is no anti-spam statute and no do-not-call registry, which teams routinely misread as an open field. The control that actually applies is the Data Privacy Act of 2012, and it works differently from both Singapore and Malaysia: there is no business contact information carve-out, but there is a legitimate interest basis that the regulator has expressly confirmed can support direct marketing. This guide covers what the Act requires, how to stand up a defensible legitimate interest position, what a stop reply obliges you to do, whether the Act reaches an offshore team, and what non-compliance now costs.

Last reviewed 28 August 2026 · This guide is general information, not legal advice.

What the Data Privacy Act covers, and who enforces it

Republic Act No. 10173, the Data Privacy Act of 2012, is the Philippines' general data protection law. Its Implementing Rules and Regulations took effect in 2016 and it is administered by the National Privacy Commission, an independent regulator with rule-making, investigation, and enforcement powers. In practice the Commission governs through circulars and advisory opinions, and those circulars are where most of the operating detail for a sales team lives.

Personal information means any information from which the identity of an individual is apparent, or can reasonably and directly be ascertained by the entity holding it. A prospect's name, work email address, job title, and mobile number are all personal information. Sensitive personal information is a narrower defined class covering things like health, religion, education, and government-issued identifiers, and it carries stricter rules and heavier penalties. Ordinary B2B prospecting should never touch it.

Unlike Singapore, the Act contains no general exception for business contact information. A named individual's work email is ordinary personal data and needs a lawful basis before you process it. Unlike Malaysia, though, consent is not the only realistic route, and that difference is what makes Philippine outbound workable.

There is no anti-spam law, and that history matters

The Philippines briefly criminalised spam. Section 4(c)(3) of the Cybercrime Prevention Act of 2012 made the transmission of unsolicited commercial communications an offence. In February 2014 the Supreme Court struck that provision down in Disini v. Secretary of Justice, holding that it was an unconstitutional restriction on freedom of expression: commercial speech, the Court reasoned, cannot be banned outright simply because the recipient did not ask for it.

The result is that the Philippines has no operating anti-spam statute, no equivalent of Singapore's Spam Control Act, and no do-not-call registry of the kind Singapore runs. Teams that stop reading there draw the wrong conclusion. Removing the spam offence did not remove the data protection law underneath it, and the Data Privacy Act reaches every step of an outbound programme: how you obtained the contact, why you are allowed to hold it, and what happens when the person tells you to stop.

There is one adjacent rule worth knowing if your motion includes phone or SMS. The SIM Registration Act of 2022 requires every subscriber identity module in the country to be registered to a verified identity, which has made anonymous bulk SMS materially harder and pushed enforcement attention onto message originators.

Legitimate interest: the basis that makes B2B outreach work

Section 12 of the Act lists the lawful criteria for processing personal information. Consent is the first, but section 12(f) provides an alternative: processing that is necessary for the legitimate interests pursued by the controller or by a third party to whom the data is disclosed, except where those interests are overridden by the fundamental rights and freedoms of the data subject. This is the same structure European teams know from the GDPR, and it is the basis most B2B outreach into the Philippines should rely on.

The Commission put this beyond argument in NPC Circular No. 2023-07, its Guidelines on Legitimate Interest, issued in December 2023 and effective from January 2024. Where the processing is limited to personal information rather than sensitive personal information, a controller may use legitimate interest as the lawful basis for direct marketing, and consent is then not required. The circular does not hand this over for free: you must be able to show the interest is real, that the processing is necessary for it, and that it does not override the individual's rights.

That is the three-part legitimate interest assessment the circular requires you to carry out and document. The purpose test asks whether the interest is legitimate and genuine. The necessity test asks whether the processing is actually needed to achieve it. The balancing test weighs your interest against the rights and reasonable expectations of the person. Covered organisations were given until April 2024 to have these assessments on record, and the Commission can ask to see yours.

For an outbound team this is a one-page document, not a legal project. Write down who you target and why the interest is commercial and specific, why a work email address is the minimum data needed to pursue it, and why a relevant business proposition sent to someone whose job is to evaluate exactly that kind of proposition sits inside their reasonable expectations. Note the safeguards you apply: narrow targeting, honest identification, one-click opt-out, permanent suppression. Review it when your targeting changes.

The right to object, and what a stop reply obliges you to do

Section 16 sets out the rights of the data subject, including the right to be informed, the right to access, the right to correct, the right to erasure or blocking, the right to damages, and the right to object. The right to object is the one that governs your day-to-day sending: an individual may object to the processing of their personal data, and where they do, the controller must stop, subject only to narrow exceptions such as a legal obligation or a subpoena.

Legitimate interest and the right to object are two halves of the same bargain. The reason you do not need consent up front is that the person can switch the processing off at any time, so the switch has to actually work. An objection does not need to use any particular form of words or arrive through any particular channel. A reply that says stop, unsubscribe, remove me, or take me off your list is an objection, and so is a message sent to a colleague rather than to you.

The operational standard, therefore, is suppression that is immediate, permanent, and organisation-wide rather than campaign-wide. If a Philippine prospect opts out of one sequence and a different member of the team enrols them in another next quarter, you have not honoured the objection. Because the Philippines has no central registry to check against, your own suppression list is the only control in the system. Singapore sellers who are used to screening a call list against the Do Not Call Registry should note that there is nothing equivalent to screen against here.

Does the Act reach a Singapore team emailing Manila?

Often, yes. Section 6 gives the Act extraterritorial reach. It applies to acts done outside the Philippines where the processing relates to personal information about a Philippine citizen or resident, and the entity has a link to the country. Recognised links include having a branch, office, subsidiary, or central management in the Philippines, entering into a contract in the Philippines, and processing personal data using equipment located there.

A great many regional sellers hit one of those triggers without thinking about it. If you have a Philippine sales hire, a local outsourcing partner, a registered representative office, or infrastructure in a Manila data centre, you are inside the Act's reach for the Philippine prospects in your database.

The accountability rule in section 21 closes the remaining gap. A controller stays responsible for personal information it transfers to a third party, including one abroad, and must use contractual or other reasonable means to ensure comparable protection. If your CRM, enrichment tooling, or sending platform holds Philippine prospect data offshore, the obligation follows the data rather than stopping at the border.

Data protection officers, registration, and breach reporting

Every controller and processor must designate a data protection officer. That obligation is universal rather than threshold-based, which is a genuine difference from Malaysia, where the duty only bites above set processing volumes. For a small sales organisation this is usually a named individual with the responsibility written into their role, not a new hire.

Registration is threshold-based. Under NPC Circular No. 2022-04, which took effect in January 2023 and replaced the 2017 framework, a controller or processor must register its data processing systems if it employs 250 or more people, processes sensitive personal information of 1,000 or more individuals, or carries out processing likely to pose a risk to the rights and freedoms of data subjects. Systems involving automated decision-making or profiling are registrable regardless of size.

Breach notification is fast. Under the Commission's breach management rules, where a reportable breach involves sensitive personal information or data that could enable identity fraud and there is a real risk of serious harm, the controller must notify both the Commission and the affected individuals within 72 hours of knowledge of or reasonable belief in the breach, with a full report following within five days unless the Commission grants more time. A prospect database is personal data, so an exported contact list leaving your control is exactly the scenario these rules were written for.

Penalties: criminal terms and revenue-based fines

The Act's penalties are criminal, and they are not nominal. Unauthorised processing of personal information, meaning processing without a lawful basis or the data subject's consent, carries imprisonment of one to three years and a fine of between PHP 500,000 and PHP 2,000,000. For sensitive personal information the range rises to three to six years and PHP 500,000 to PHP 4,000,000. Concealing a security breach and malicious disclosure carry their own terms on top.

Since August 2022 the Commission has also been able to impose administrative fines directly, under NPC Circular No. 2022-01. These are calculated as a percentage of the organisation's annual gross income for the preceding year: grave infractions attract 0.5 to 3 per cent, with lower bands for major and other infractions, and the total for a single act or omission is capped at PHP 5,000,000. A grave infraction includes breaching the general privacy principles or data subject rights where more than 1,000 individuals are affected, and any repeat of an infraction already penalised under the circular.

The threshold detail is worth reading twice if you run volume outbound. A list of Philippine prospects processed without a documented lawful basis can cross 1,000 affected individuals easily, and that is the line between a major and a grave infraction.

A practical checklist for prospecting into the Philippines

These rules turn the Act and the Commission's circulars into operating habits for a team running outbound into the Philippines.

  • Write and keep a legitimate interest assessment covering the purpose, necessity, and balancing tests, and revisit it when your targeting changes.
  • Rely on legitimate interest rather than consent, and keep processing to ordinary personal information so the basis stays available to you.
  • Never let sensitive personal information into a prospecting database; the penalty range doubles and no marketing purpose needs it.
  • Target narrowly enough that the message is plainly relevant to the person's role, which is what carries the balancing test.
  • Identify your company honestly in every send, with a real reply route and a working one-click opt-out.
  • Treat any stop, unsubscribe, or remove-me reply as a section 16 objection: suppress immediately, permanently, and across the whole organisation.
  • Record where every contact came from, because provenance is the first thing you will be asked for.
  • Designate a data protection officer; the duty applies to every controller, with no volume threshold.
  • Check whether your headcount or processing triggers registration of your data processing systems with the Commission.
  • Know which of your systems hold Philippine prospect data offshore, and keep the transfer accountability under section 21 documented.
  • Have a breach plan that can reach the Commission and affected individuals inside 72 hours, with the full report five days later.

Prospecting into the Philippines?

HuntSales handles the operational half of this: honest sender identity on every send, one-click opt-outs written to a permanent suppression list that applies across your whole organisation, and a source record behind every contact. Start with the Philippines playbook.

Read the Philippines playbook

Frequently asked

Is B2B cold email legal in the Philippines?

Yes, on a proper footing. There is no anti-spam statute, because the Supreme Court struck down the Cybercrime Prevention Act's unsolicited commercial communications offence in 2014. What governs outreach is the Data Privacy Act, which requires a lawful basis for processing a prospect's personal data. The Commission's 2023 guidelines confirm that legitimate interest under section 12(f) can support direct marketing where only ordinary personal information is involved, so consent is not required if you document the assessment and honour objections.

Do I need consent before emailing a Philippine prospect?

Not if you rely on legitimate interest. Section 12(f) permits processing necessary for the legitimate interests of the controller unless overridden by the individual's rights, and NPC Circular No. 2023-07 expressly allows direct marketing on that basis where the processing is limited to personal information. The trade-off is that you must carry out and retain a three-part assessment, and stop processing the moment the person objects.

What is a legitimate interest assessment, and must I write it down?

It is a short documented analysis with three parts: a purpose test showing the interest is genuine and legitimate, a necessity test showing the processing is actually needed for it, and a balancing test weighing your interest against the individual's rights and reasonable expectations. NPC Circular No. 2023-07 requires covered organisations to document and keep records of these assessments, and the Commission can ask to see yours, so an undocumented assessment is effectively no assessment.

How does the Philippines differ from Singapore and Malaysia?

Singapore disapplies the consent obligations for business contact information such as work emails and job titles, so B2B outreach sits outside them entirely. Malaysia has no such carve-out and no general legitimate interest basis, which leaves consent as the main route and makes named-individual outreach the greyest of the three. The Philippines sits in between: no business contact carve-out, but a legitimate interest basis the regulator has confirmed covers direct marketing. Singapore also runs a do-not-call registry; neither Malaysia nor the Philippines does.

Is there a do-not-call registry in the Philippines?

No. There is no national registry for marketing calls, SMS, or email, so there is nothing to screen a list against before you send. The practical consequence is that your own suppression list carries all the weight, and it has to be permanent and organisation-wide rather than per campaign. If your motion includes SMS or calls, note that the SIM Registration Act of 2022 has tied every number to a verified identity.

What must I do when a prospect asks to be removed?

Stop. Section 16 gives the data subject the right to object to processing, and an objection to marketing must be honoured, subject only to narrow exceptions such as a legal obligation. It does not need particular wording or a particular channel. Suppress the contact immediately and permanently, across every campaign and every user in your organisation, and keep the record so you can show the objection was actioned.

Does the Act apply to my company if we are based in Singapore?

Very possibly. Section 6 extends the Act to acts done outside the Philippines where the processing concerns a Philippine citizen or resident and the entity has a link to the country, such as a branch, office, subsidiary, or central management there, a contract entered into in the Philippines, or the use of equipment located there. A local sales hire, an outsourcing partner, or Philippine infrastructure is usually enough. Section 21 also keeps you accountable for personal data you transfer to third parties abroad.

What are the penalties for getting this wrong?

Unauthorised processing of personal information carries one to three years' imprisonment and a fine of PHP 500,000 to PHP 2,000,000, rising to three to six years and up to PHP 4,000,000 for sensitive personal information. Separately, since August 2022 the Commission can impose administrative fines set as a percentage of annual gross income, from 0.5 to 3 per cent for grave infractions, capped at PHP 5,000,000 for a single act or omission. Affecting more than 1,000 individuals is one of the triggers for the grave band.

Outreach that stays on the right side of the rules

Suppression lists, unsubscribe handling, and a calling workflow built for APAC compliance, in one outreach CRM. Free for solo founders.

Start free

More guides