A Nine-Year-Old Rule Gets Its First Rewrite
On August 10, 2026, the National Privacy Commission opened public consultation on a draft circular titled Updated Guidelines on the Conduct of Privacy Impact Assessment, intended to replace NPC Advisory No. 2017-03 in its entirety. Comments are due by August 14 — a four-day window — with an online session set for August 25.
The draft's core move is a threshold-analysis test. Instead of asking every organization to run its own subjective risk call, the circular confines mandatory PIAs to eight defined categories: processing of sensitive personal information, high-risk data (biometric, financial, children's), large-scale processing (reported thresholds of roughly 250 employees or 1,000 data subjects), automated decision-making with legal or significant effects, novel or high-risk technologies including AI and facial recognition, targeted advertising and behavioral tracking, processing involving vulnerable groups, and cross-border transfers to jurisdictions without adequate safeguards.
The 2017 Rule Was Never Quite "Blanket"
Coverage of the draft has framed it as scrapping a blanket requirement. That overstates the old rule. NPC Advisory No. 2017-03 said a PIA "should be undertaken for every processing system," but let a controller forgo one if it "determines that the processing involves minimal risks to the rights and freedoms of individuals" — weighed against factors like data sensitivity, duration, and potential harm. The 2017 advisory was risk-based in theory; it was just self-graded. A small HR vendor and a facial-recognition startup applied the same fuzzy standard, with the same regulator second-guessing both after the fact.
The threshold test replaces that guesswork with an actual list. That is a genuine improvement, not merely a relaxation.
Steelmanning the Case for a Tighter Net
The NPC has reason to want AI, biometrics, and cross-border transfers named explicitly. In October 2025 the Commission issued a cease-and-desist order against Tools for Humanity, operator of the World App and Orb iris-scanning system, after finding that Filipinos were induced with cryptocurrency payments to submit to iris and face scans — a case the NPC treated as invalid consent obtained through financial inducement, thin transparency, and biometric collection in excess of the stated "proof of humanity" purpose. Deputy Privacy Commissioner Jose Amelito Belarmino II framed the problem directly: financial inducement compromises the voluntariness that consent requires. Biometric identifiers can't be reset the way a password can; a body scan compromised once is compromised for life. That is precisely the category of harm a subjective, case-by-case self-assessment is worst-positioned to catch before the fact rather than after a cease-and-desist order.
Where the Reform Gets the Balance Right
Outside those eight categories, the draft frees ordinary processing — payroll systems, customer-service logs, routine vendor contracts — from a compliance ritual that consumed hours and legal fees without generating much privacy benefit when the processing was never actually risky. That is the correct trade for a developing digital economy: concentrate regulatory scrutiny where the potential for harm is real (biometrics, children's data, opaque algorithmic decisions, cross-border leakage) and get out of the way of processing that poses none. The approach also converges with international practice. The EU's GDPR requires a Data Protection Impact Assessment only where processing is "likely to result in a high risk to the rights and freedoms of natural persons" (Article 35), not for processing generally — the same risk-tiering logic, arrived at nine years earlier. A Philippine framework that finally names its own high-risk categories, rather than leaving the line-drawing to each controller's lawyer, gives businesses something they can actually plan around, and gives the NPC a clearer basis to act when a company decides a facial-recognition rollout falls just outside the rule.
The Four-Day Problem
The substance is close to right. The process is not. A circular that will govern PIA obligations for every AI deployment, biometric program, and cross-border data flow handled in or from the Philippines deserves more than four days of public comment before the NPC finalizes it — even with a follow-up session on August 25. Multinational compliance teams, domestic SMEs newly exempted from the old rule, and civil-society privacy advocates all have a legitimate stake in where the eight-category lines land, particularly the numeric large-scale-processing thresholds that will determine which mid-sized firms fall in or out. A rushed comment period invites exactly the kind of definitional ambiguity — what counts as "large-scale," which "novel technologies" trigger the AI category — that will generate years of interpretive disputes the threshold test was designed to prevent.
The NPC does not need to abandon the eight-category structure to fix this. It needs to extend the window, publish the specific numeric thresholds for open comment rather than folding them into a take-it-or-leave-it draft, and treat August 25 as the start of engagement rather than its close. A good rule adopted after a real consultation will hold up better than the same rule rushed through in four days.