Your Philippine BPO is processing customer data right now. And there's a strong chance your outsourcing contract has a compliance gap that neither your lawyer nor your vendor flagged — because most US companies have never heard of Republic Act 10173, the Philippines Data Privacy Act.
That gap is your exposure, not theirs.
TL;DR — Key Facts
-
RA 10173 applies to your US company — not just your Philippine vendor — if you control how personal data is processed.
-
Four obligations flow to you: DPO appointment, Data Sharing Agreement, NPC registration verification, and breach notification clauses.
-
A standard NDA does not satisfy the DSA requirement — this is where most contracts fall short.
-
The NPC can fine foreign-linked processors up to ₱5 million per violation.
-
Breach notification timelines are tighter than most US founders expect: 72 hours to the NPC, but your contract should demand 48 hours to you.
What RA 10173 Is — and Why Your US Business Is Already Inside It
The Philippines Data Privacy Act of 2012 (Republic Act 10173) is the country's GDPR — a broad data protection law covering collection, storage, use, and cross-border transfer of personal information. Most US founders are at least vaguely aware of GDPR and CCPA. RA 10173 rarely comes up until there's a problem. That's the blindspot.
The law doesn't stop at Philippine borders. It applies to any entity, foreign or domestic, that controls or processes personal data of Philippine residents — or that uses a Philippine-based processor. The moment you send customer records, employee files, or any personally identifiable information to a Philippine BPO, you're operating inside RA 10173's scope.
Key Takeaway If your Philippine BPO handles customer data on your behalf, RA 10173 obligations flow upstream to you as the personal information controller (PIC). Your vendor is the personal information processor (PIP) — they execute your instructions. You own the compliance accountability.
Your 4 Core DPA Obligations When Outsourcing to the Philippines
These aren't suggestions. They're the four areas the National Privacy Commission (NPC) will examine when something goes wrong.
1 Appoint a Data Protection Officer (DPO) If your vendor processes sensitive personal information at scale — health records, financial data, government IDs — RA 10173 requires them to designate a DPO. As the PIC directing that processing, you should designate one internally too. This person owns your DPA compliance and is your point of contact if the NPC comes calling.
2 Execute a Data Sharing Agreement (DSA) A DSA is a formal contractual instrument — distinct from an NDA — required before any personal data crosses to your Philippine processor. Standard confidentiality clauses don't cut it. The DSA must specify data categories, processing purposes, security standards, and retention limits. This is the most commonly missing document in US-to-Philippines outsourcing arrangements.
3 Verify NPC Registration Philippine processors handling data of 1,000 or more individuals must register with the National Privacy Commission. Ask your vendor for their NPC registration number before data flows begin. No registration, processing at scale? That's a red flag worth pausing over. See the full breakdown of what to include — and watch for — in your Philippines outsourcing contract.
4 Build Breach Notification Into Your Contract Under RA 10173, your vendor must notify the NPC within 72 hours of a qualifying breach. That window doesn't automatically include you — unless your contract says so. You likely have parallel US state obligations too; California, New York, and Texas all run their own timelines. Require vendor notification to you within 48 hours. That 24-hour buffer is when you assess US-side exposure before the NPC clock runs out.
Did You Know? The NPC can impose fines up to ₱5 million (~$85,000 USD) per violation and has pursued enforcement actions involving foreign-linked data processors. A foreign headquarters doesn't change who's accountable for data directed to a Philippine processor. If your BPO mishandles data you told them to process, the exposure lands on both parties.
What to Put in Your Outsourcing Contract to Stay Compliant
This is where compliance either holds or falls apart. The DSA is the foundation; your SLA reinforces it. Everything else is unenforceable without the right contract language.
"DPOs, DSAs, breach protocols — none of it means anything unless it's in writing. Most US outsourcing contracts aren't close."
A SaaS founder running a 12-person Philippine support team for two years discovered his contract was a startup-template NDA with no DSA attached. The retroactive fix — renegotiating the contract, formalizing the DSA, documenting lawful processing bases — took six weeks and legal fees he hadn't budgeted. Getting it right from the start would have cost a fraction of that.
Your six-point contract checklist for RA 10173-compliant outsourcing arrangements:
-
NPC registration number — Require it as a contract exhibit, with an obligation to notify you of any change in status.
-
DPO contact details in the SLA — Name, email, and response SLA for your vendor's designated DPO. Non-negotiable if the engagement touches sensitive data.
-
Data Sharing Agreement as a formal exhibit — Not a buried clause in the master services agreement. A standalone DSA specifying data categories, processing instructions, security standards, and retention periods.
-
48-hour internal breach notification — Contractually require your vendor to notify you within 48 hours of any breach, preserving your buffer before the NPC's 72-hour clock expires.
-
Lawful processing bases specified — Consent, contractual necessity, or legitimate interest. Document which applies. This becomes critical under audit.
-
Data deletion or return schedule at contract end — Vague "data will be destroyed" language invites disputes. Define exactly what happens when the engagement closes.
For regulated industries the stakes compound further. Fintech companies outsourcing KYC and AML functions face layered obligations across RA 10173, BSP regulations, and US FinCEN requirements simultaneously. How compliance infrastructure affects vendor cost is covered in our breakdown of Philippines BPO pricing models — and what a suspiciously cheap vendor is probably skipping.
✅ Bottom Line: RA 10173 Compliance Checklist for US Outsourcers
-
Confirm your vendor's NPC registration number before data flows begin.
-
Execute a formal Data Sharing Agreement — not just an NDA.
-
Designate a DPO internally; require your vendor's DPO contact in the SLA.
-
Build a 48-hour breach notification clause into every outsourcing contract.
-
Specify lawful processing bases and a data deletion schedule at engagement end.
iSuporta builds DPA-compliant outsourcing engagements from day one — Data Sharing Agreements, registered DPOs, and NPC-compliant vendors included.
Frequently Asked Questions
Does the Philippines Data Privacy Act apply to US companies that outsource there?
Yes. RA 10173 applies to any entity that controls or processes personal data of Philippine residents, regardless of headquarters location. A US company directing its Philippine BPO to handle customer or employee data has direct compliance obligations under the Act — not just the vendor.
What is a Data Sharing Agreement and do I need one with my Philippine BPO?
A Data Sharing Agreement (DSA) is a formal contract exhibit required under RA 10173 whenever personal data is transferred to a processor. Standard NDAs don't substitute. You must execute one before any personal data flows to your vendor — specifying data categories, processing purposes, security measures, and retention periods.
How quickly must a Philippine BPO notify me of a data breach?
Under RA 10173, your vendor must notify the NPC within 72 hours of discovering a qualifying breach. Your contract should require them to notify you within 48 hours — giving you a 24-hour window to assess parallel US state notification obligations before the NPC deadline hits.
RA 10173 compliance isn't a Philippine problem. It's a shared obligation the moment US data enters a Philippine BPO's systems. Get the contract right before data flows. Not after a breach forces the conversation.
Ready to outsource without the compliance risk? iSuporta's US-managed BPO model includes built-in DPA compliance infrastructure — DSAs, NPC-registered vendors, and DPO contacts included from day one.
— DSAs, NPC-registered vendors, and DPO contacts included from day one. Build a Compliant Team
Bottom Line RA 10173 extends to every US company that directs a Philippine BPO to process personal data — no exceptions for offshore headquarters. Before data flows, you need a signed Data Sharing Agreement, a verified NPC-registered processor, and a 48-hour breach notification clause in your contract. Companies that treat Philippine data privacy law as a vendor problem — rather than a shared obligation — are one breach away from a very expensive lesson. Get the framework right on day one, and outsourcing becomes a competitive advantage rather than a liability.
Need compliant pay documentation for your Philippine team? Generate accurate, professionally formatted pay stubs for remote employees and contractors — built to satisfy documentation requirements across US states.