Philippines · National Privacy Commission
RA 10173 and automated decisions
What the Data Privacy Act actually requires of an AI system processing personal data, which is not what most summaries say, and where the operative rule really lives.
Covers: RA 10173, DPA IRR s.34/48, NPC Circular 2022-04, NPC Advisory 2024-04Published September 26, 2026
The misconception worth clearing first
A great deal of writing about AI and Philippine privacy law assumes the Data Privacy Act mirrors the GDPR, and in particular that it grants a right not to be subject to solely automated decisions along the lines of GDPR Article 22. It does not. If a compliance position rests on that assumption, it rests on something the statute does not contain.
The practical shape of the Philippine rule is different, and narrower: it is a consent condition sitting in the implementing rules rather than a right sitting in the statute. Getting this right changes what a lender or insurer actually has to build.
What the statute actually says
Republic Act No. 10173, the Data Privacy Act of 2012, is titled “An Act Protecting Individual Personal Information.” It is administered by the National Privacy Commission.
The word “profiling” appears in it zero times. The word “automated” appears twice:
- Section 16(b)(5), concerning the methods of automated access to personal information.
- Section 16(c)(6), giving a data subject access to information on automated processes where the data will, or is likely to, be made the sole basis for any decision significantly affecting them.
Both are transparency and access rights. Neither prohibits automated decision-making, and neither offers a route to refuse it.
Where the real rule lives: IRR Section 48
The 2016 Implementing Rules and Regulations carry the provisions people reach for when they cite the statute. Section 34 includes, within the right to be informed, the existence of automated decision-making and profiling, and within the right to object, processing for direct marketing, automated processing, or profiling.
Section 48(b) is the operative sentence: no decision with legal effects concerning a data subject shall be made solely on the basis of automated processing without the consent of the data subject. Section 48 further requires notifying the National Privacy Commission where automated processing becomes the sole basis for decisions significantly affecting a data subject, and that notification must disclose the methods and logic used.
The NPC issuances that bear on AI
- NPC Circular 2022-04, dated 5 December 2022: registration of data processing systems and notification of automated decision-making and profiling. It defines automated decision-making in Section 3(A), with the notification requirements at Sections 26 to 28.
- NPC Circular 2023-04, dated 7 November 2023: guidelines on consent.
- NPC Circular 2023-06, dated 1 December 2023: guidelines on security of personal data.
- NPC Advisory 2024-04, dated 19 December 2024: guidelines on applying RA 10173 to AI systems processing personal data.
Note the distinction in instrument type. A Circular is binding regulation. An Advisory is the Commission’s interpretation of existing law. That difference matters for how a compliance obligation should be characterized internally.
NPC Advisory 2024-04, and its actual weight
Advisory No. 2024-04 is titled “Guidelines on the Application of Republic Act No. 10173 to Artificial Intelligence Systems Processing Personal Data.” It is the clearest available statement of how the NPC expects the existing law to apply to AI, and it asks for:
- Transparency about the system's inputs and logic.
- Demonstrable accountability for outcomes.
- Privacy impact assessments.
- Monitoring for bias.
- Where effects pose significant risk, mechanisms allowing meaningful human intervention.
- Where effects pose significant risk, mechanisms letting a person question and contest an automated decision.
- No “AI washing”, meaning no overstating what the system's AI actually does.
The last two items are the most consequential for automated lending, collection, and underwriting decisions, because they push toward exactly the contest-and-review pathway the statute itself does not require. Treat the Advisory as the regulator’s stated expectation and design to it, while being accurate internally that it is interpretive guidance rather than a Circular.
Lawful bases and data-subject rights
Lawful bases for processing personal information are in Section 12(a) to (f): consent, contract, legal obligation, vital interests, public authority, and legitimate interests. Sensitive personal information has its own narrower set in Section 13.
The data-subject rights are: to be informed, to object, to access, to rectification, to erasure or blocking, to damages, and to data portability, the last of which comes from IRR Section 36.
Breach notification: the 72 hours is not in the law
The statute, at Section 20(f), requires only that the Commission and the affected data subjects be promptly notified. The familiar 72-hour deadline is not statutory. It is IRR Section 38, which requires notification within 72 hours upon knowledge of, or reasonable belief in, a notifiable personal data breach.
The distinction is not academic. Citing the statute for a 72-hour obligation is the kind of error that undermines an otherwise sound compliance document.
What this adds up to for an AI system
- Identify whether any decision with legal effects is made solely by automated processing. If so, consent under IRR Section 48(b) is the gate, and NPC notification with methods and logic disclosed is required.
- Keep a human genuinely in the loop where you can. The word “solely” is the hinge of the whole provision.
- Run a privacy impact assessment, and be able to produce it.
- Be able to state the system's inputs and logic in plain language, per Advisory 2024-04 and the IRR's disclosure requirement.
- Build a contest-and-review path for significant-risk decisions, per Advisory 2024-04, even though the statute does not compel one.
- Monitor for bias, and retain the evidence that you did.
- Hold to the IRR Section 38 72-hour breach clock, not the statute's “promptly.”
- Do not overstate the system's AI capability in customer-facing material.
How Nova AIS is built around it
Nova AIS puts a permission model and an immutable audit trail under the systems built on it, which is the part of this that is architectural rather than procedural. Every read and write against a business object is attributable, so a question about which inputs fed a given decision is answerable from the record rather than reconstructed after the fact. That is what the IRR’s methods-and-logic disclosure and the Advisory’s transparency expectation actually require in operational terms.
The design preference throughout is to keep a human in the decision path for anything with legal effect, which keeps the system outside the reach of the Section 48(b) consent gate rather than relying on consent to satisfy it, and to expose a contest-and-review pathway where the effects on a person are significant.
Common questions.
- Does the Philippine Data Privacy Act give people a right not to be subject to automated decisions?
- Not in the statute. RA 10173 contains no equivalent of GDPR Article 22, and the word “profiling” does not appear in it at all. The nearest rule is in the 2016 Implementing Rules and Regulations, Section 48(b): no decision with legal effects concerning a data subject shall be made solely on the basis of automated processing without the consent of the data subject. That is a consent condition, not a right to opt out, and it carries no statutory right to an explanation or to human review.
- What does RA 10173 itself say about automated processing?
- The word “automated” appears twice. Section 16(b)(5) concerns the methods of automated access, and Section 16(c)(6) gives a data subject access to information on automated processes where the data will, or is likely to, be made the sole basis for a decision significantly affecting them. Both are transparency and access provisions. Neither is a prohibition or an opt-out.
- Is NPC Advisory 2024-04 binding on AI systems?
- No. NPC Advisory No. 2024-04, dated 19 December 2024, is titled “Guidelines on the Application of Republic Act No. 10173 to Artificial Intelligence Systems Processing Personal Data.” It is an Advisory, which is interpretive guidance on how the NPC reads the existing law. It is not a Circular and it does not create new binding obligations, though it is a clear statement of how the regulator expects the law to be applied.
- Do I have to tell the NPC that my system makes automated decisions?
- Yes, in the circumstances the rules describe. IRR Section 48 requires notifying the National Privacy Commission when automated processing becomes the sole basis for decisions significantly affecting a data subject, and the notification must disclose the methods and logic used. NPC Circular 2022-04, dated 5 December 2022, covers registration and the notification of automated decision-making and profiling, and defines automated decision-making in its Section 3(A).
- Is the 72-hour breach notification deadline in the Data Privacy Act?
- No, and this is a common error. The statute, Section 20(f), says only that the Commission and affected data subjects must be promptly notified. The 72-hour figure comes from IRR Section 38, which requires notification within 72 hours upon knowledge of, or reasonable belief in, a notifiable personal data breach.
- What does the NPC expect an AI system processing personal data to have?
- Per Advisory 2024-04: transparency about inputs and logic, demonstrable accountability, privacy impact assessments, monitoring for bias, and, where the effects pose significant risk, mechanisms allowing meaningful human intervention and mechanisms letting people question and contest automated decisions. The Advisory also warns against “AI washing,” meaning overstating a system's AI capability.