On September 4, 2026, as the FY2027 budget went through congressional review, the Department of Information and Communications Technology (DICT) confirmed it wants P2.7 billion in its FY2027 budget for e-government, about P800 million of it for the eGovPH super app. According to The Daily Tribune's report, the app now hosts 1,332 government services across 95 modules. Usage is up about 700 percent in a year, and the platform has processed more than 900 million transactions. DICT also reports more than 92 million digital national IDs issued and over 300 million eVerify identity checks run for agencies and financial institutions.
This is real delivery. It also concentrates a great deal of identity and transaction data in one stack, and that is where policy attention should go.
The strongest case for the request
The case for funding is strong. Republic Act 12254, the E-Governance Act signed on September 5, 2025, makes DICT the lead implementor of a government-wide transition to digital services. It requires an E-Government Master Plan and a project management office to oversee ICT projects across agencies. A dedicated budget line is what the statute contemplates.
Fragmented agency portals are expensive, insecure and slow. A shared service layer means a citizen proves identity once instead of queuing at ten counters. A shared verification layer also lets a bank or agency check an identity without photocopying documents. DICT says in-house developers have hit capacity limits, and its plan to bring in local firms and hackathon developers for maintenance is a sensible use of the domestic tech sector. Digitised business permits for local governments target one of the most familiar frictions in the Philippine economy.
A critic who dismisses all of this as vanity IT is wrong. The scale of usage suggests citizens want these services.
Where the design risks sit
Three parts of the 2027 plan deserve scrutiny, and none is a reason to withhold funding.
1. Verification at 300 million checks. eVerify sits on the Philippine Identification System created by Republic Act 11055. That Act ties authentication to consent specific to the purpose and says identity information may not be used except for the purpose authorised. It also says proof of identity is not necessarily proof of eligibility for benefits. These are good design constraints. The test is whether 300 million checks, many by private financial firms, are each tied to a documented purpose, and whether registered persons can see who verified them and why. DICT has reported volume. It has not published a per-purpose breakdown or an access log that individuals can inspect.
2. A generative-AI layer on document processing. The planned eGovAI tool will automate document processing. The Data Privacy Act of 2012 (RA 10173) requires that personal data be 'adequate and not excessive' for the purpose of processing. Automated document handling is a legitimate efficiency gain, but a model trained or tuned on citizen submissions is a new purpose. Agencies should say what the tool is trained on, what is retained, and where a human reviews the output. Section 21 of the same Act holds each controller responsible for data it transfers to a third party. That matters when local vendors and contractors maintain the system.
3. Repatriating offshore-hosted data. Moving government data to domestic servers is the most politically attractive item on the list, and it has genuine merits. It reduces exposure to foreign legal process, and it can improve latency and resilience. But location is not security. A poorly secured domestic server is worse than a well-secured foreign one. The EFF's September 2026 analysis of digital sovereignty warns that sovereignty framing can swap dependence on Big Tech for dependence on state infrastructure, and urges governments to give users control of their own data and to favour open-source tools. Localisation should be judged by controls: encryption with keys held by the agency, independent audits and breach disclosure. It should not be judged by the address of the data centre.
What proportionate oversight looks like
None of this needs new legislation. The statutes already exist, and the National Privacy Commission already has the authority to apply them. What is missing is public evidence that they are being applied to the fastest-growing government platform in the country.
Three low-cost steps would close that gap:
- Publish an annual transparency report for eVerify: checks by requester category, purpose, and rejected or disputed requests.
- Release privacy impact assessments for eGovAI and the cloud migration before the money is spent, not afterwards.
- Commit to open, documented APIs so that private-sector developers, including the local firms DICT wants to partner with, can build on the platform without lock-in to any one vendor, foreign or domestic.
These measures protect users and also help innovation. Banks, fintechs and startups building on eVerify need predictable rules, and a platform whose data practices are legible is one they can trust and integrate with.
The bottom line
Congress should fund the request. The usage numbers show demand, and the legal foundation in RA 12254 is in place. But a platform that mediates 1,332 services and hundreds of millions of identity checks is infrastructure, and infrastructure earns trust through published rules and audits. The 2027 budget is the moment to attach those conditions, while the architecture is still being decided.