Philippines Philippines SIM registration cyberlibel NPC

Manila Confirms AI Outsourcing Does Not Dissolve Data Privacy Act Liability

NPC's July 2026 warning restates a 2012 legal principle for the AI era: controllers, not vendors, carry the compliance risk.

Philippines' AI Data Liability, By the Numbers People of Internet Research · Philippines ₱5M Max DPA Criminal Fine Ceiling for combined-offense viola… ₱500K–5M AI Advisory Fine Range Administrative fines the NPC can i… 100 people Large-Scale Breach Threshold Data subjects affected before the … peopleofinternet.com
Philippines' AI Data Liability, By the… People of Internet Research · Philippines ₱5M Max DPA Criminal Fine ₱500K–5M AI Advisory Fine Range 100 people Large-Scale Breach Threshold peopleofinternet.com

Key Takeaways

A Warning, Not a New Rule

On July 23, 2026, Deputy Privacy Commissioner Jose Amelito S. Belarmino II of the Philippines' National Privacy Commission told businesses plainly: handing personal data to a third-party AI vendor does not transfer legal responsibility for that data. Companies remain "legally accountable under the Data Privacy Act" for how their AI systems — built in-house or bought off the shelf — process personal information, MLex reported. Belarmino urged firms to map how data actually flows through the AI tools they deploy and to fold AI governance into existing privacy compliance rather than treat it as a separate function.

The statement is notable less for what it says than for how unoriginal it is by design. The NPC is not inventing a new liability regime for AI; it is applying Section 21 of Republic Act No. 10173, the Data Privacy Act of 2012, which has said since its enactment that "each personal information controller is responsible for personal information under its control or custody, including information that have been transferred to a third party for processing," and that the controller must use "contractual or other reasonable means to provide a comparable level of protection" when a third party is doing the processing. The NPC's December 19, 2024 Advisory No. 2024-04 had already extended this accountability principle explicitly across the AI lifecycle — development, training, testing, and deployment — making clear that outsourcing processing to an AI vendor does not outsource the legal risk. The July 2026 statement is a reminder, aimed at businesses that assumed a vendor's AI product came with its own compliance shield.

The Case for Saying It Loudly

There is a real problem this warning is trying to head off. Vendor contracts for AI tools — chatbots, HR screening models, credit-scoring systems, fraud detection — are frequently boilerplate, drafted by the vendor, and silent on what happens to Filipino users' personal data once it enters a foreign-hosted model. A controller that never asks how its vendor trains, retains, or re-uses that data has, in practice, delegated a compliance decision to someone with no stake in Philippine law. NPC Advisory 2024-04 backs this with teeth: administrative fines of ₱500,000 to ₱5,000,000 for AI-related Data Privacy Act violations, on top of the underlying statute's own criminal penalties — up to ₱5,000,000 and six years' imprisonment for combined offenses under Section 33, with maximum penalties triggered automatically once a breach affects at least 100 data subjects under Section 35. Given those stakes, a regulator that stayed silent while AI adoption outpaces vendor diligence would be failing its statutory mandate. Businesses that treat "we bought an AI product" as due diligence deserve the correction.

Where Proportionality Still Matters

The steelman only goes so far, though. The DPA's accountability principle was written for an era of outsourced call centers and cloud storage vendors — bilateral relationships where a controller could reasonably audit a processor's practices. Modern AI supply chains are layered: a Philippine bank's chatbot vendor may itself be reselling access to a foundation model built by a company the bank has never contracted with and cannot audit. Asking a small or mid-sized personal information controller to achieve the same visibility into a foundation-model provider's training pipeline that it once had into a local processor's server room is a different order of diligence, and the NPC's advisory does not yet draw a clear line between "reasonable contractual safeguards" and an unattainable standard of technical omniscience.

The risk of leaving that line fuzzy is not abstract. The Philippines' track record with the SIM Registration Act (Republic Act No. 11934, signed October 10, 2022) is instructive: a law built around a legitimate goal — traceability against SMS-based fraud and scam networks — that human rights groups and media organizations warned would chill anonymous speech and expose registrants' data to breach risk, without the NPC's own subsequent engagement with telcos fully resolving those concerns. A regulator that repeats the pattern with AI — clear on the liability, vague on the safe harbor — invites the same dynamic: real compliance cost for good-faith actors, deterred AI adoption among smaller Philippine firms who cannot afford outside counsel to interpret "comparable level of protection," and no corresponding drop in bad-faith violations by operators who were never going to comply regardless.

What Good Guidance Would Add

The fix is not to soften the accountability principle — it is sound law, and abandoning it would let controllers hide behind vendors precisely where accountability matters most. What is missing is a tiered safe harbor: model contract clauses for AI processing, a defined floor of vendor due diligence (data flow mapping, retention limits, audit rights) that satisfies Section 21 for standard use cases, and a distinction between a controller that skipped diligence entirely and one that reasonably relied on a vendor's misrepresented certifications. The NPC's Advisory 2024-04 already gestures at Privacy Impact Assessments and continuous monitoring as expectations; formalizing a compliance checklist would let the Commission enforce hard against negligence while giving compliant businesses — especially the SMEs the DICT's own June 2026 AI framework for the public sector says it wants to see adopt AI — a predictable path rather than an open-ended liability warning.

Sources & Citations

  1. Republic Act No. 10173 — Data Privacy Act of 2012 (LawPhil)
  2. Republic Act No. 11934 — SIM Registration Act (ADB Law and Policy Reform Program)
  3. MLex: Philippines warns companies remain liable for personal data in third-party AI
  4. Regulations.ai summary of NPC Advisory No. 2024-04
  5. Baker McKenzie: Philippines Launches Responsible AI Governance Framework