Data Privacy Act of 2012, cross-border transfer accountability
Republic Act No. 10173 (2012), Section 21
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 15 August 2012.
A cross border transfer rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app transferring the personal information of an individual in the Philippines, including a faceprint, voiceprint, or other biometric identifier, to a recipient outside the country remains accountable for that data and must use contractual or other reasonable means to secure a level of protection comparable to the Act.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 21's Principle of Accountability makes a personal information controller responsible for personal information under its control or custody, including data transferred to a third party for processing domestically or internationally, and requires the controller to use contractual or other reasonable means to provide a comparable level of protection while the data is processed abroad.
This is an accountability-based transfer regime rather than an adequacy list or a localization mandate; no data-localization requirement was found.
When LexLint raises it
crawls_webtrains_modelsprocesses_voiceprocesses_biometrics
Read the law
National Privacy Commission's official HTML reproduction of the Act
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.