39.3 Data Privacy, Intellectual Property, and Electronic Commerce

Key Takeaways

  • The Data Privacy Act of 2012 (RA 10173) governs the processing of personal information under principles of Transparency, Legitimate Purpose, and Proportionality, mandating that security breaches involving sensitive personal data be reported to the National Privacy Commission (NPC) within 72 hours.

  • Processing of sensitive personal information is prohibited except with specific consent, legal authority, protection of life, noncommercial purposes of public organizations, medical treatment, or legal claims.

  • A personal information controller remains responsible for data it outsources to a processor and must secure it through contracts and other means.

  • Under the Intellectual Property Code (RA 8293), patents are granted under the first-to-file rule for a non-renewable term of 20 years from filing, trademarks are protected for 10-year renewable terms subject to Declarations of Actual Use, and copyright vests automatically upon creation lasting for the author's life plus 50 years.

  • Electronic documents and signatures have the same legal effect as paper documents and signatures under RA 8792 if their integrity and reliability are shown.

Last updated: September 2026

Data Privacy, Intellectual Property, and Electronic Commerce

Businesses handle personal data, create intellectual property, and transact electronically. This section covers the Data Privacy Act of 2012 (RA 10173), the Intellectual Property Code (RA 8293) on patents, trademarks, and copyright, and the Electronic Commerce Act (RA 8792).


1. Data Privacy Act of 2012 (RA 10173)

Extraterritorial Application and Regulatory Authority

Enacted under Republic Act No. 10173, the Data Privacy Act (DPA) protects the fundamental human right to privacy while ensuring the free flow of information to promote innovation. The law is administered and enforced by the National Privacy Commission (NPC).

  • Extraterritorial Scope: The DPA applies to the processing of personal data outside the Philippines if:
    1. The act, practice, or processing relates to personal data about a Philippine citizen or resident;
    2. The entity has a link with the Philippines (e.g., commercial contract, branches, or operations in the country); or
    3. The entity is doing business in the Philippines.

Personal Information vs. Sensitive Personal Information

The DPA establishes two distinct classes of personal data with differing legal standards of protection:

                                Classes of Protected Data
                                            │
     ┌──────────────────────────────────────┴──────────────────────────────────────┐
     ▼                                                                             ▼
Personal Information (PI)                                             Sensitive Personal Information (SPI)
Any information from which the identity of an                         • Race, ethnic origin, marital status, age, color,
individual is apparent or can be reasonably and                       religious, philosophical, or political affiliations;
directly ascertained (e.g., name, personal email,                     • Health, education, genetic or sexual life;
home address, phone number).                                          • Government IDs (SSS, GSIS, TIN, passport, driver's lic.);
                                                                      • Criminal proceeding or offense records.

Strict Rule on Processing SPI (Section 13): Processing of sensitive personal information (and privileged information) is prohibited, except when: (1) the data subject has given specific consent before processing; (2) processing is provided for by existing laws and regulations; (3) processing is necessary to protect the life and health of the data subject or another person and the data subject cannot legally or physically consent; (4) processing is needed to achieve the lawful, noncommercial objectives of public organizations and their associations, limited to their members; (5) processing is necessary for medical treatment by a medical practitioner or institution; or (6) processing is necessary to protect lawful rights and interests in court proceedings, to establish, exercise, or defend legal claims, or is provided to government under its constitutional or statutory mandate.

General Principles of Data Privacy (Section 11)

Personal data processing must adhere to three foundational principles:

  1. Transparency: The data subject must be aware of the nature, purpose, and extent of the processing of their personal data, including the identity of the personal information controller;
  2. Legitimate Purpose: The processing of information must be compatible with a declared, specified, and legitimate purpose that is not contrary to law, morals, or public policy;
  3. Proportionality: The processing of information shall be adequate, relevant, suitable, and not excessive in relation to the declared purposes. Data must be discarded once the legitimate purpose is fulfilled.

Rights of the Data Subject (Section 16)

Data subjects enjoy eight fundamental rights:

  1. Right to be Informed: Prior notice of data collection, processing methods, and third-party recipients;
  2. Right to Access: Reasonable access to contents of processed data and sources;
  3. Right to Object: Right to withhold consent or object to processing (including direct marketing);
  4. Right to Erasure or Blocking: Right to order removal or destruction of incomplete, outdated, or unlawfully obtained data;
  5. Right to Damages: Indemnification for damages sustained due to inaccurate, incomplete, or unlawful processing;
  6. Right to Rectification: Right to dispute inaccuracies and have them corrected immediately;
  7. Right to Data Portability: Right to obtain a copy of data in an electronic or structured format;
  8. Right to File a Complaint: Right to seek redress before the National Privacy Commission.

Mandatory 72-Hour Data Breach Notification (Section 20(f))

When sensitive personal information or information that may be used to enable identity fraud is reasonably believed to have been acquired by an unauthorized person, and there is real risk of serious harm, the personal information controller must notify both the National Privacy Commission (NPC) and affected data subjects within seventy-two (72) hours upon knowledge of the security breach.

Controllers, Processors, and Compliance

  • A personal information controller (PIC) decides what data to process and why; a personal information processor (PIP) processes data on the PIC's behalf under an outsourcing or subcontracting agreement. The PIC remains responsible for data transferred to a processor and must use contractual and other means to secure it.
  • PICs and PIPs must designate a data protection officer, implement organizational, physical, and technical security measures, and register their data processing systems with the NPC when required by its rules (for example, entities with at least 250 employees or processing sensitive personal information of at least 1,000 individuals).

2. Intellectual Property Code of the Philippines (RA 8293)

Administered by the Intellectual Property Office of the Philippines (IPOPHL), Republic Act No. 8293 regulates three distinct regimes of intellectual property:

                          The Three Core Intellectual Property Regimes
                                               │
     ┌─────────────────────────────────────────┼─────────────────────────────────────────┐
     ▼                                         ▼                                         ▼
Patents                                  Trademarks                                Copyright
Inventions (Novelty, Inventive           Visible signs identifying source          Literary and artistic creations;
Step, Industrial Applicability);         (Distinctiveness); 10-year term           vests automatically upon creation;
20 years from filing; First-to-File      renewable; DAU required                   Life of Author + 50 years

Comprehensive Comparative Matrix: Patents, Trademarks, and Copyright

FeaturePatents (Part II)Trademarks (Part III)Copyright (Part IV)
Subject Matter ProtectedTechnical inventions, processes, machines, or improvementsVisible signs, marks, names, or logos identifying sourceOriginal literary, artistic, scientific, and scholarly works
Statutory StandardNovelty, Inventive Step (non-obvious), Industrial ApplicabilityDistinctiveness (not generic, descriptive, or misleading)Originality; intellectual creation
How Protection ArisesOfficial Grant by IPOPHL upon examinationRegistration with IPOPHLAutomatic upon creation (no registration needed)
Priority RuleFirst-to-File RuleFirst-to-File RuleDate of creation / fixation in tangible medium
Term of Protection20 years from filing date (Strictly non-renewable)10 years from issuance (Renewable indefinitely for 10-year periods)Life of the author + 50 years after author's death
Maintenance RequirementAnnual patent maintenance feesDeclaration of Actual Use (DAU) filed within 3rd and 5th yearsNone required (registration is purely for record-keeping)

Specific Legal Doctrines in Intellectual Property

  1. First-to-File Rule (Patents and Trademarks): If two or more persons independently create the same invention or mark, priority belongs to the person who first filed the application with the IPOPHL, regardless of who invented or used it first.
  2. Declaration of Actual Use (DAU) in Trademarks: Registration is canceled if the owner fails to file a formal DAU with proof of use in commerce within:
    • Three (3) years from the application filing date;
    • Within one (1) year from the 5th anniversary of registration; and
    • Within one (1) year from each 10-year renewal date.
  3. Economic vs. Moral Rights in Copyright:
    • Economic Rights: The exclusive right to commercially exploit the work (reproduction, adaptation, public performance, commercial rental, distribution).
    • Moral Rights: Non-economic personal rights of the author: (a) right of attribution (paternity); (b) right of integrity (preventing derogatory distortion or alteration); and (c) right to withhold publication.

3. Electronic Commerce Act (RA 8792)

Electronic Commerce Act of 2000 (RA 8792)

  • Legal Recognition of Electronic Data Messages: Information shall not be denied legal effect, validity, or enforceability solely on the ground that it is in the form of an electronic data message or electronic document.
  • Legal Equivalence to Written Instruments: An electronic document satisfies any statutory requirement that a contract or record be in writing, provided it maintains integrity and remains accessible for subsequent reference.
  • Electronic Signatures: An electronic signature satisfies the requirement of a handwritten signature if a reliable method is used to identify the signatory and indicate their approval of the message.
  • Evidentiary Weight: Electronic documents are admissible in court proceedings under the Rules on Electronic Evidence.
  • Carriage of goods: actions related to contracts for the carriage of goods (such as issuing receipts and bills of lading and giving instructions) may be done through electronic data messages.
  • E-government: government offices must accept and issue electronic documents and payments, subject to their security requirements.
  • Online businesses are further regulated by the Internet Transactions Act of 2023 (RA 11967), which covers online merchants, e-marketplaces, and digital platforms dealing with Philippine consumers and created the DTI's E-Commerce Bureau.
Test Your Knowledge

A multinational technology corporation operating a cloud hosting subsidiary in the Philippines suffered a cyberattack. Forensic audits revealed that an unauthorized third party exfiltrated a database containing customers' medical records, biometric data, and government passport numbers, posing a grave risk of identity theft. Under the Data Privacy Act of 2012 (RA 10173), what is the mandatory regulatory timeline within which the corporation must formally notify the National Privacy Commission and affected data subjects?

A

Within 24 hours from the initial detection of unauthorized server access.

B

Within 72 hours upon knowledge or reasonable belief of the security breach.

C

Within 5 business days following completion of the comprehensive forensic audit report.

D

Within 30 calendar days from the date the breach occurred.

Test Your Knowledge

Two inventors independently develop the same invention. Inventor A completed it first but filed a patent application in June; Inventor B completed it later but filed in March of the same year. Under the IP Code, who has the better right to the patent?

A

Inventor A, because she invented it first

B

Inventor B, under the first-to-file rule

C

Both jointly

D

Neither, because the invention lost novelty

Sections you finish are checked off in the contents.