Cybersecurity

What the NPC Actually Expects from Small Businesses Handling Customer Data

What the NPC Actually Expects from Small Businesses Handling Customer Data

The NPC Stopped Sending Reminders and Started Sending Show Cause Orders

On 15 May 2024 the National Privacy Commission walked into one Philippine mall, went tenant by tenant, and found 65 businesses that had never registered — mall tenants, not banks or BPOs. If you collect customer names, numbers, addresses or photos of a valid ID, the Data Privacy Act has applied to you since 2012; what changed last year is that somebody started checking. That is where Data Privacy Act compliance for a small business now begins.

NPC Circular No. 2024-01, signed 26 January 2024 and effective 10 February 2024, amended the Commission's 2021 Rules of Procedure to cover compliance checks — privacy sweeps, warning letters, notices to submit documents, onsite visits — powers that turn a year old this month. On 5 June 2024 the NPC warned that businesses not complying with the Data Privacy Act and NPC Circular 2022-04 would receive show cause orders, and that checks would continue nationwide, Calabarzon included.

Two acronyms first: a personal information controller (PIC) decides why and how personal data is collected — you, if customers hand you their details — while a personal information processor (PIP) handles it on your instructions (payroll bureau, web host, courier). Below: who must register, what else the NPC expects, and what to fix in 30 days.

Do You Actually Have to Register? The NPC Circular 2022-04 Thresholds in Plain English

NPC Circular No. 2022-04, issued 5 December 2022 and effective 11 January 2023, sets mandatory registration of Data Protection Officers and data processing systems. Three triggers:

Trigger Threshold
Headcount You employ 250 or more persons
Sensitive personal information Records on 1,000 or more individuals
Risk Processing likely to pose a risk to data subjects' rights and freedoms

Read those as OR, not AND: one trigger is enough. Below the thresholds registration is voluntary — but not exempt. Notice, consent, security measures, retention limits and breach response bind every PIC.

The original deadline was 10 July 2023, so nobody is early — registering now is catching up before anyone asks. Non-compliance also exposes you to administrative fines under NPC Circular No. 2022-01, as Baker McKenzie notes. We will not quote peso figures; the ones going around are guesses.

The third trigger has no headcount floor, which is why it catches small businesses. "Risk to rights and freedoms" is a judgment call; when a client is on the line we say register, because a form is cheaper than a show cause order. A check looks at how data is held anyway — access rights, shared logins, ex-staff accounts — so we treat NPC filing and cybersecurity services for Philippine SMEs as one job.

What counts as "sensitive personal information" in a Philippine SME

Sensitive personal information (SPI) is a defined DPA category: health records; government ID numbers and photocopies — SSS, PhilHealth, Pag-IBIG, TIN, driver's license, PhilSys; religious or political affiliation; legal proceedings.

Who crosses 1,000 faster than expected: a dental or diagnostic clinic; a pawnshop holding borrower IDs; a recruitment agency's applicant records; a cooperative's member list; an online store collecting ID photos for cash-on-delivery.

One thousand is cumulative, not monthly. An agency taking 30 applicants a month passes the line before its third anniversary — and almost nobody disposes of old records.

Why "we're only 12 people" is not an exemption

Headcount is one trigger of three: a five-person clinic can pass the SPI threshold in its second year, and a five-person shop collecting ID photos sits inside the risk-based trigger. Those 65 unregistered businesses were tenants — small retail with a counter and a POS.

Beyond Registration: The Six Obligations NPC Circular 2023-06 Spells Out

NPC Circular 2023-06, reported by the Philippine Star on 2 April 2024, enumerates what an entity handling personal data must do — Privacy Commissioner John Henry Naga was quoted on its purpose:

  • Designate and register a Data Protection Officer — a named person accountable for privacy, with published contacts.
  • Register your data processing systems — POS, payroll, CRM, website form, spreadsheet: everything holding personal data.
  • Conduct privacy impact assessments (PIAs) — what could go wrong with one system, in writing.
  • Implement a privacy management program — standing policies, not a project.
  • Train personnel — and keep proof.
  • Comply with NPC directives.

Its companion, NPC Circular 2023-05, set up the Philippine Privacy Mark (effective 15 March 2024, ISO/IEC 27001 and 27701 required first) — a stretch goal, not a prerequisite for a 12-person business.

Clients most often miss the second: they register the company but never enumerate the systems, so payroll software, the Messenger inbox and the manager's spreadsheet stay invisible.

What Compliance Actually Looks Like Inside a 12-Person Business

Your DPO can be an existing employee — an operations or admin lead with a written designation and real authority. What fails is a name on a form who was never told; the designation and published contact details are what a check asks for.

Keep six documents in one folder you can hand over same-day:

  1. The DPO designation, signed and dated
  2. Your privacy notice, on the website and on paper forms
  3. An inventory of data processing systems
  4. A retention and disposal schedule
  5. A breach response plan with named responders
  6. Data processing agreements with your web host, payroll provider, courier and agency

Data Privacy Act compliance in a small business rarely fails at the policy level; it fails at the habits. What we find: customer lists forwarded to personal Gmail; ID photos in a Drive folder with link-sharing on; a Messenger chat serving as the order system; resigned employees' accounts never disabled; one shared POS login. Least-privilege access and an offboarding checklist close most of that.

On breaches, you must notify the NPC and the affected data subjects and keep an incident log; Circular 2024-01 touched that procedure. Check the circular text for the timing rather than a seminar's number, and have a plan naming who calls whom at 11 p.m. on a Saturday.

Training is an obligation, not a nice-to-have

Circular 2023-06 lists training as its own item; a 45-minute quarterly briefing with an attendance sheet is a defensible start.

The SSS, PhilHealth, TIN and driver's license photocopies in your files are raw material for accounts opened in someone else's name — and Congress has criminalized that end of the chain. Republic Act No. 12010, the Anti-Financial Account Scamming Act, approved 20 July 2024, reaches money-mule conduct, fictitious accounts and misused identity documents at BSP-supervised banks and payment providers. Its implementing rules are still pending and it does not bind your shop, but it explains why that photocopy is worth stealing.

Your Website, Online Store, and Checkout Are Data Processing Systems Too

If you sell online, your inventory is longer than you think: contact form, checkout, abandoned-cart emails, live-chat plugin, analytics, CRM. A WooCommerce install, a custom store and a spreadsheet of Facebook orders all count.

Two controls to switch on this week: WooCommerce 9.6, released 20 January 2025, shipped configurable Store API rate limiting for checkout endpoints — protection against card testing and denial-of-service — plus a Remote Logging privacy UI. Then check what your plugins log — more on the platform in whether WooCommerce is still right for Philippine online stores in 2025, published earlier this month.

Privacy and e-commerce duties now arrive together. Republic Act No. 11967, the Internet Transactions Act of 2023, approved 5 December 2023, imposes duties on e-marketplaces — verifying merchant identity, keeping an updated merchant registry, publishing required business information — and requires consumer data privacy protection and accessible complaint mechanisms across internet transactions. If you sell through a marketplace, the platform verifies you; the data privacy duty is yours either way. Its implementing rules, signed 24 May 2024, carry six agency signatures, the DTI's and the National Privacy Commission's among them. See the Internet Transactions Act and what it means for online sellers.

Your third parties are your exposure: web host, payment gateway, courier and email tool are processors acting for you, and each needs a written data processing agreement. Picking a host or a build partner is now partly a compliance decision, so we scope custom software built with data protection in mind around access, not just screens.

If the NPC Comes Knocking: Show Cause Orders, Sweeps, and What Not to Do

NPC Circular 2024-01's instruments are the privacy sweep, the warning letter, the notice to submit documents and the onsite visit. It also reworked complaints handling, mediation, breach notification and electronic service of judgments.

A show cause order is not a fine: it is a formal demand that you explain why you should not be held liable, by a deadline. The NPC committed publicly on 5 June 2024 to issuing them; the fines framework sits in NPC Circular 2022-01.

A breach brings the same scrutiny from another direction — see what the PhilHealth ransomware attack taught Philippine businesses.

Three things reliably make it worse: backdating documents, naming a DPO who does not know it, and answering a notice with silence.

The reassuring part: almost everything the NPC asks for is documentation a small business can produce in a week of focused work. The failure we see is never money; it is that nobody was assigned.

Your 30-Day Data Privacy Act Compliance Sprint for a Small Business

Week 1 — Inventory. Every place personal data lives: POS, payroll, website forms, CRM, spreadsheets, Messenger threads, the drawer of ID photocopies. For each, note what data, whose, why, how long you keep it and who can see it. That one document feeds registration, the PIA and the retention schedule.

Week 2 — Decide your status. Test the business against the three Circular 2022-04 triggers and register if any applies. If none does, write down the decision and the date, and revisit when headcount or customer count moves.

Week 3 — DPO and notices. Designate the DPO in writing, publish their contact details, refresh the privacy notice online and on paper forms, and run one privacy impact assessment on your highest-risk system, usually payroll.

Week 4 — People and response. A staff briefing with an attendance sheet, an offboarding checklist for disabling accounts, and a breach response plan naming who calls whom. Then calendar the annual review — the Philippines observes National Data Privacy Awareness Week in the last week of May, NPC-led under Proclamation No. 527.

The rules are not the hard part; finding someone in a 12-person company to own them is. We sit with Philippine SMEs to map where personal data lives, test the Circular 2022-04 thresholds and harden the systems holding it. This is an explainer, not legal advice — have a lawyer review what you file. Book a free privacy-readiness call.

Empowering Businesses with Customized Software Solutions

Tell us what you need — we typically reply within the day. Let’s build something that drives your business forward.