How Does Privacy by Design Apply to Philippine Software Projects?
Introduction
Philippine software developers, e-commerce businesses, government agencies, and technology providers increasingly process names, contact details, payment information, location data, account credentials, and other personal information. Data protection compliance therefore cannot be postponed until after a digital product has been launched.
Privacy by design requires privacy and data protection safeguards to be incorporated into the architecture, development, testing, deployment, and maintenance of a data processing system. In the Philippines, this obligation arises from the Data Privacy Act of 2012, its implementing rules, and regulations and issuances of the National Privacy Commission (NPC).
The requirement is not limited to newly created software. It may also apply when an organization adopts off-the-shelf software, substantially modifies an existing system, integrates third-party services, or introduces new processing functions.
What Is Privacy by Design?
Privacy by design means integrating safeguards into the design or structure of a processing activity or data processing system. It treats privacy as a system requirement rather than as a policy document prepared after development.
Related principles include:
- Privacy by default: personal data should receive protection automatically, without requiring action by the data subject.
- Data minimization: the system should collect and retain only the personal data necessary for the stated purpose.
- Purpose limitation: data should not be used for purposes incompatible with the purpose communicated to the data subject.
- Security by design: confidentiality, integrity, and availability controls should be included in the system architecture.
- Accountability: the organization should be able to demonstrate that privacy obligations were considered and implemented.
The NPC defines privacy engineering as the integration of privacy concerns into systems and software engineering life-cycle processes. Privacy by default means that personal data is automatically protected without intervention by the user or data subject. These definitions appear in NPC Advisory No. 2025-02.
What Laws Govern Privacy by Design?
The principal statute is R.A. No. 10173, or the Data Privacy Act of 2012. It establishes the general data privacy principles of transparency, legitimate purpose, and proportionality, and requires personal information controllers and processors to implement reasonable and appropriate organizational, physical, and technical security measures.
Section 20 of R.A. No. 10173 requires personal information controllers to protect personal information against accidental or unlawful destruction, alteration, disclosure, and other unlawful processing. The appropriate level of security depends on factors including the nature of the personal data, the risks presented by the processing, the organization’s size and operational complexity, current security practices, and the cost of implementation.
The NPC’s more detailed rules include NPC Circular No. 2023-06, which requires personal information controllers and processors to consider privacy by design and enable privacy by default in their data processing systems. The Circular also requires a Privacy Impact Assessment for off-the-shelf software, solutions, or data processing systems.
For covered government entities, the 2026 Implementing Rules and Regulations of R.A. No. 12254 expressly require the adoption of privacy by design, privacy engineering, and privacy by default throughout the personal data processing life cycle.
Who Must Apply Privacy by Design?
The obligation may affect both a personal information controller and a personal information processor. A controller determines what personal information is processed and the purpose or extent of processing. A processor processes personal data on behalf of or under the instructions of another person or organization.
Responsibility must be allocated clearly in contracts and internal governance documents. Outsourcing software development does not automatically transfer the controller’s accountability to the developer or vendor.
Examples of organizations that may need to apply these requirements include:
- e-commerce platforms processing customer and payment information;
- banks, fintech companies, and digital-wallet providers;
- online marketplaces and delivery applications;
- health, education, employment, and government portals;
- cloud service providers and software-as-a-service vendors; and
- businesses using customer relationship management, analytics, or artificial intelligence systems.
What Must Be Built Into the System?
Data collection and purpose specification
The system should identify the personal data required for a defined and legitimate purpose before development begins. Registration forms should not require information that is unrelated to the service being provided.
For example, an online store may reasonably require a customer’s name, delivery address, and payment information to complete an order. It may not automatically require unrelated sensitive information merely because the software is capable of collecting it.
Access controls and authorization
Users, administrators, developers, contractors, and service providers should receive only the access necessary for their functions. Privileged access should be restricted, recorded, periodically reviewed, and removed when no longer justified.
NPC Advisory No. 2025-02 describes access controls as measures that allow only properly authorized users to access the minimum necessary personal data. This supports role-based access, least-privilege permissions, multi-factor authentication, and segregation of administrative functions.
Privacy-preserving defaults
Default settings should provide the highest reasonable level of privacy without requiring the data subject to change them manually. Examples include private user profiles, disabled location tracking, unchecked optional consent boxes, and payment details that are not saved automatically.
Under the 2026 Implementing Rules and Regulations of R.A. No. 12254, systems should also provide clear privacy notices, obtain consent when consent is the lawful basis for processing, and avoid deceptive design patterns.
Data subject rights
Where appropriate, software should include mechanisms that allow data subjects to exercise their rights under R.A. No. 10173. These may include access and download tools, correction or rectification interfaces, deletion or erasure functions, and opt-in or opt-out controls.
The presence of an automated feature does not mean that every request must be granted without review. The organization must still determine whether a legal exception, retention obligation, security concern, or competing right applies.
Retention and disposal
A system should contain a retention policy identifying how long each category of personal data will be stored and why. Data should not be retained indefinitely merely because storage is inexpensive.
The system should support scheduled deletion, anonymization where appropriate, archival controls, and secure disposal. The 2026 Implementing Rules and Regulations of R.A. No. 12254 specifically refer to retention policies and secure disposal procedures that permanently delete personal data when it is no longer needed.
When Is a Privacy Impact Assessment Required?
A Privacy Impact Assessment, or PIA, evaluates the privacy and security consequences of a proposed processing activity or system. It considers the nature of the personal data, data flows, processing risks, current privacy practices, implementation costs, organizational size, and operational complexity.
The PIA should be conducted before deployment where the proposed processing may create significant privacy risks. It should also be revisited when the organization materially changes the system, introduces new data categories, adds a new third-party provider, expands the system’s purpose, or faces new security risks.
NPC Circular No. 2023-06 states that a PIA must also be conducted for off-the-shelf software, solutions, or data processing systems. Functions that lack a lawful basis or are incompatible with the general data privacy principles must be disabled or deactivated.
How Should a Software Team Apply Privacy by Design?
A software project should treat privacy requirements as part of its ordinary development process. The following sequence is suitable for most projects:
- Map the processing. Identify the personal data collected, the source of the data, the purpose, recipients, storage locations, transfers, and deletion points.
- Identify the lawful basis. Determine whether processing relies on consent, contract, legal obligation, protection of vital interests, public authority, or another recognized basis under R.A. No. 10173.
- Conduct risk assessment. Evaluate unauthorized access, excessive collection, disclosure, profiling, discrimination, loss, alteration, and inability to exercise data subject rights.
- Design safeguards. Use minimization, access controls, encryption where appropriate, pseudonymization, logging, retention controls, secure interfaces, and privacy-protective defaults.
- Test before deployment. Conduct security testing, code reviews, vulnerability scans, privacy architecture reviews, and testing of privacy notices and user controls.
- Monitor after deployment. Review logs, access permissions, incidents, vendor compliance, system changes, and the continuing appropriateness of the PIA.
The testing requirements are reflected in NPC Advisory No. 2025-02 and the 2026 Implementing Rules and Regulations of R.A. No. 12254. They include data privacy and security testing, usability testing of privacy interfaces, code reviews, vulnerability scans, and privacy architecture reviews.
What Should E-Commerce Businesses Do?
An e-commerce business should begin by documenting the complete customer data life cycle. This includes account creation, product browsing, checkout, payment processing, delivery, customer support, marketing, analytics, fraud prevention, refunds, and account closure.
Particular attention should be given to payment service providers, courier companies, advertising platforms, analytics providers, cloud hosts, and customer support contractors. Each recipient should be assessed to determine its role, permitted processing, security obligations, retention period, incident reporting duties, and rules for subcontracting.
Marketing features should not be silently activated through pre-checked consent boxes or bundled consent. Optional marketing processing should be distinguishable from processing necessary to complete the customer’s purchase.
What Should Developers and Vendors Document?
Technical documentation should show how privacy requirements were translated into system controls. Useful records include:
- the data inventory and data-flow diagram;
- the PIA and risk register;
- the system’s lawful-basis and purpose analysis;
- privacy and security requirements in the software specification;
- access-control and retention matrices;
- test results, vulnerability findings, and remediation records;
- privacy notices and consent-screen versions; and
- vendor agreements, data processing agreements, and incident procedures.
These records help demonstrate accountability. They also assist in investigating complaints, responding to data subject requests, assessing data breaches, and explaining design decisions to management, regulators, and affected individuals.
How Does Philippine Jurisprudence Treat Digital Privacy?
The Supreme Court has recognized that informational privacy includes both the right not to have private information disclosed and the right to live freely without surveillance and intrusion. The usual inquiry considers whether the person has an actual or legitimate expectation of privacy and whether that expectation is objectively reasonable.
These principles are discussed in KAPIT, et al. v. City of Manila, et al., General Register Nos. 261892, 262192, and 263752, 2026. The decision also distinguishes the constitutional question of whether privacy has been infringed from the separate question of whether the minimum requirements of the Data Privacy Act have been observed.
For software projects, this distinction means that constitutional privacy analysis and statutory compliance analysis should not be treated as identical. A system may raise constitutional concerns because of surveillance or disclosure, while also presenting separate compliance issues involving lawful basis, proportionality, security, transparency, retention, or data subject rights.
What Are Common Compliance Failures?
Common problems include collecting excessive information, leaving administrator accounts uncontrolled, retaining inactive customer records indefinitely, enabling location or tracking features by default, using vague privacy notices, and allowing third-party vendors to reuse personal data for unrelated purposes.
Another recurring problem is conducting a PIA only after the software has been completed. At that point, correcting the architecture may be costly or may require disabling functions that have already been marketed to users.
Organizations should also avoid assuming that consent cures every privacy problem. Consent must be appropriate to the processing, and processing must still comply with transparency, legitimate purpose, proportionality, security, and other requirements of R.A. No. 10173.
Final Recommendations
Organizations developing or acquiring software in the Philippines should appoint responsible privacy and security personnel at the planning stage. The project should have a documented data inventory, a lawful-basis analysis, a PIA where required, privacy requirements in the technical specification, and testing evidence before deployment.
Software teams should make privacy-protective settings the default, minimize collection and retention, restrict access, maintain audit trails, provide usable rights mechanisms, and review vendor arrangements regularly. Government entities should additionally comply with the security, interoperability, privacy engineering, and minimum information security requirements under the 2026 Implementing Rules and Regulations of R.A. No. 12254.
Privacy by design is therefore not merely a website notice or a post-launch compliance exercise. It is a continuing engineering and governance duty that should be visible in the system’s architecture, development records, user interfaces, contracts, testing procedures, and operating controls.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

