Can Philippine IT Companies Outsource Their Data Protection Officer?

Can Philippine IT Companies Outsource Their Data Protection Officer?

Introduction

Philippine IT companies often engage external privacy consultants because data protection requires specialized legal, technical, and organizational knowledge. Outsourcing privacy functions may be permitted, but it does not transfer the company’s statutory accountability for compliance with the Data Privacy Act of 2012.

The central distinction is between outsourcing the functions of a Data Protection Officer (DPO) and eliminating the company’s responsibility to designate an accountable privacy officer. A third-party consultant may perform DPO or Compliance Officer for Privacy functions, subject to independence, sufficient resources, confidentiality, absence of conflicts of interest, and continuing oversight.

What Laws Govern Outsourced Data Protection Officers?

The principal statute is Republic Act No. 10173, or the Data Privacy Act of 2012. Its implementing rules require organizations involved in processing personal data to comply with privacy and security obligations, while the National Privacy Commission (NPC) supervises and enforces the law.

The IRR of Republic Act No. 10173 permits a personal information controller (PIC) to subcontract or outsource the processing of personal data, provided that contractual or other reasonable safeguards protect the confidentiality, integrity, and availability of the information. The PIC must also prevent unauthorized use and ensure compliance with the Data Privacy Act, its IRR, and NPC issuances.

For an outsourced DPO arrangement, the principal administrative guidance is NPC Advisory No. 2017-01, Designation of Data Protection Officers. The Advisory applies to natural or juridical persons and government or private-sector bodies engaged in processing personal data within or outside the Philippines, subject to the Data Privacy Act, its IRR, and other NPC issuances.

Is Outsourcing the DPO Function Allowed?

Yes. A PIC or personal information processor (PIP) may outsource or subcontract the functions of its DPO or Compliance Officer for Privacy, provided that the arrangement does not reduce the organization’s responsibilities under Philippine data protection law.

NPC Advisory No. 2017-01 states that, to the extent possible, the DPO or Compliance Officer for Privacy must oversee the performance of the functions by the third-party service provider. The DPO or Compliance Officer for Privacy must also remain the organization’s contact person in dealings with the NPC.

Accordingly, an IT company may retain an external privacy professional or consulting firm to perform privacy compliance work. However, it should not treat the engagement as a complete transfer of legal accountability to the consultant.

Who Remains Accountable for Compliance?

The PIC or PIP remains responsible for complying with the Data Privacy Act, its IRR, NPC issuances, and other applicable laws. NPC Advisory No. 2017-01 identifies compliance responsibility as belonging to the PIC or PIP, which must be capable of demonstrating its capacity to comply.

This principle was also recognized in NPC 21-122, NPC Decision, 2023. The NPC explained that outsourcing the collection of unpaid accounts to third-party agents is allowed, but the PIC remains accountable for the actions of its personal information processors and must ensure the confidentiality and security of personal data.

The same principle applies to outsourced DPO services. A consultant may perform assigned functions, but the IT company must maintain adequate supervision, authority, resources, documentation, and internal controls.

What Requirements Apply to an Outsourced DPO?

1. The organization must designate an accountable privacy officer

A PIC or PIP must designate an individual or individuals to function as DPOs. The designated officer is accountable for ensuring compliance with the Data Privacy Act, its IRR, NPC issuances, and other applicable privacy and security laws.

The designation should be documented through a board resolution, management appointment, written designation, service agreement, or another formal organizational record. The document should identify the officer, scope of authority, reporting line, contact details, term of engagement, and responsibilities.

2. The DPO must act independently

The DPO or Compliance Officer for Privacy must act independently and enjoy sufficient autonomy. The officer must not receive instructions from the PIC or PIP regarding the exercise of privacy and data protection tasks.

Independence does not mean that the DPO may disregard legitimate business decisions. It means that management should not direct the DPO to suppress findings, disregard a reportable incident, approve unlawful processing, or place commercial objectives above legal compliance.

3. The consultant must avoid conflicts of interest

An individual serving as DPO may perform other functions only when those functions do not create a conflict of interest. The consultant should not simultaneously decide the purposes and means of processing while supposedly auditing or independently monitoring that same processing.

For example, a consultant that designs and controls an IT company’s customer profiling system may face a conflict if it is also expected to independently determine whether that system complies with privacy requirements. The service agreement should identify and manage potential conflicts before the engagement begins.

4. Confidentiality and secrecy obligations must be imposed

The DPO or Compliance Officer for Privacy is bound by secrecy or confidentiality concerning the performance of privacy functions. The consulting agreement should contain continuing confidentiality obligations covering personal data, security information, investigation materials, breach reports, and communications with data subjects or the NPC.

Confidentiality provisions should survive the termination of the engagement and should address return, deletion, retention, and secure disposal of company and personal data.

5. The DPO must receive sufficient resources

An organization must provide sufficient time and resources for the DPO to perform the role effectively. These resources may include budget, access to systems and records, personnel support, training, incident-response assistance, and authority to communicate with senior management.

A nominal appointment without access to relevant processing systems or decision-makers may not demonstrate meaningful compliance. The company should be able to show that the outsourced DPO was involved early enough to identify and address privacy risks.

6. The DPO must be involved from the earliest appropriate stage

NPC Advisory No. 2017-01 requires the PIC or PIP to allow the DPO or Compliance Officer for Privacy to participate from the earliest possible stage in matters involving privacy and data protection.

For an IT company, this should include software development, system procurement, cloud migration, artificial intelligence projects, employee monitoring, customer analytics, cybersecurity programs, data-sharing arrangements, and international transfers of personal data.

What Must the Outsourcing Agreement Contain?

The outsourcing arrangement should be governed by a written contract or other legal act. Under the IRR of Republic Act No. 10173, an agreement for outsourced processing should state the subject matter and duration of processing, nature and purpose of processing, types of personal data, categories of data subjects, the parties’ rights and obligations, and the geographic location of processing.

For an outsourced DPO engagement, the agreement should also address:

  • Scope of services: monitoring, advice, policy review, training, impact assessments, incident response, audit assistance, and NPC coordination.
  • Authority and reporting: direct or sufficiently independent access to senior management and relevant records.
  • Independence: protection from instructions that compromise the DPO’s professional assessment.
  • Conflicts of interest: disclosure, mitigation, and termination procedures.
  • Security controls: access restrictions, authentication, encryption, secure communications, and incident reporting.
  • Subcontracting: prior approval and equivalent privacy obligations for any additional service provider.
  • Data handling after termination: return or deletion of personal data, subject to retention required by law.
  • NPC communications: designation of the continuing contact person for regulatory matters.

Can a Consultant Be the Company’s Official DPO?

Conditionally, yes. NPC Advisory No. 2017-01 permits outsourcing or subcontracting of DPO or Compliance Officer for Privacy functions. The arrangement must nevertheless preserve the DPO’s independence, accountability, confidentiality, and access to the organization.

The company should formally identify the individual who will serve as its DPO or the person responsible for performing the outsourced DPO functions. Naming only a consulting firm, without identifying a responsible individual and reliable contact person, may create uncertainty regarding accountability and regulatory communication.

Consultants, project personnel, seasonal employees, probationary employees, and casual employees should not be designated as DPOs under NPC Advisory No. 2017-01. A short-term consultant may therefore provide privacy services without necessarily being suitable for formal designation as the organization’s DPO, depending on the structure and continuity of the engagement.

What Duties Should the Outsourced DPO Perform?

The outsourced DPO should monitor compliance with the Data Privacy Act, its IRR, NPC issuances, and other applicable laws and policies. The engagement may include the following work:

  • Maintaining or reviewing privacy policies, notices, and internal procedures.
  • Advising on lawful bases for processing and data-sharing arrangements.
  • Reviewing contracts with personal information processors and other vendors.
  • Conducting or assisting with privacy impact assessments.
  • Reviewing technical and organizational security measures.
  • Providing employee training and privacy awareness programs.
  • Assisting with data subject requests and complaints.
  • Coordinating breach response and communications with the NPC when required.
  • Preparing compliance reports and recommending corrective measures.

These duties should be tailored to the company’s processing activities. An IT company handling health information, financial information, biometric information, children’s data, or large-scale monitoring may require more extensive oversight than a small business processing limited customer contact details.

What Are the Company’s Duties Toward the Outsourced DPO?

The organization must communicate the DPO’s designation and functions to its personnel. It must also involve the DPO in privacy-related matters, provide sufficient time and resources, grant appropriate access to personal data and processing systems, and consult the DPO promptly in the event of a personal data breach or security incident.

The organization should also include the DPO in relevant working groups dealing with personal data processing, whether the activities occur internally or involve other organizations. Excluding the DPO until after a system launch or data incident weakens the compliance structure.

Who Is Responsible When Another Vendor Processes Data?

An IT company may itself be a PIC, a PIP, or both, depending on the processing activity. If it determines the purposes and means of processing customer data, it may be acting as a PIC. If it processes data solely on behalf of another organization, it may be acting as a PIP.

Under Sections 43 to 45 of the IRR of Republic Act No. 10173, a PIC may outsource processing only if it uses contractual or other reasonable means to ensure proper safeguards. The processor must follow documented instructions, preserve confidentiality, implement appropriate security measures, avoid unauthorized subcontracting, assist with data subject rights and compliance duties, and return or delete personal data at the end of the service when required.

The PIP must also comply with the Data Privacy Act, its IRR, applicable laws, NPC issuances, and contractual obligations. Outsourcing does not authorize the processor to use personal data for its own unrelated purposes.

What Happens During a Data Breach?

The DPO should be promptly consulted when a personal data breach or security incident occurs. The company should maintain a documented incident-response procedure identifying the breach response team, escalation channels, preservation of evidence, risk assessment, notification responsibilities, and communications with affected data subjects and the NPC when legally required.

Outsourcing breach-response functions does not remove the PIC’s responsibility. In NPC BN 21-097, In re: PowerVision EAP, Inc., NPC Order, 2022, the Commission emphasized that outsourcing functions of a data breach response team does not reduce the requirements imposed by the Data Privacy Act, its IRR, and related issuances. The DPO remains accountable for compliance.

The same order stressed the importance of prompt compliance where an incident involves sensitive personal information and more than one hundred affected individuals. The company should therefore ensure that an external DPO can reach decision-makers and obtain the information needed for timely action.

What Are Common Compliance Errors?

Common problems in outsourced DPO arrangements include appointing a consultant without formal documentation, giving the consultant no access to systems or management, allowing conflicting operational duties, treating the DPO as a purely nominal position, and failing to identify who will respond to the NPC.

Another error is assuming that a contract with a consultant automatically satisfies all data protection requirements. The company must still maintain appropriate security measures, privacy policies, records, training, vendor controls, and procedures for handling data subject requests and security incidents.

Recommended Compliance Checklist for IT Companies

Before retaining an external DPO or privacy consultancy, an IT company should:

  1. Classify its processing activities and determine whether it acts as a PIC, PIP, or both.
  2. Adopt a written designation identifying the DPO or responsible individual.
  3. Conduct a conflict-of-interest review before signing the engagement.
  4. Execute a written agreement covering duties, independence, confidentiality, security, subcontracting, and termination.
  5. Provide the DPO with sufficient access, budget, personnel, and management support.
  6. Include the DPO in system design, vendor selection, data-sharing, and incident-response decisions.
  7. Maintain records showing the DPO’s advice, monitoring activities, training, assessments, and corrective recommendations.
  8. Review the engagement periodically as the company’s products, customers, technologies, and processing activities change.

Conclusion

Philippine IT companies may outsource the functions of a Data Protection Officer or Compliance Officer for Privacy. The arrangement is lawful only if it preserves independence, confidentiality, sufficient resources, conflict-free performance, meaningful organizational access, and continuing accountability.

The company remains responsible for compliance even when privacy work is performed by an external consultant. A sound arrangement therefore combines a formal designation, a detailed written contract, direct management access, documented oversight, appropriate security controls, and prompt involvement in privacy and breach-related decisions.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH