The National Privacy Commission is rewriting the rulebook on when a Philippine business actually has to conduct a formal Privacy Impact Assessment — and the direction of the change cuts both ways. A draft circular now out for public consultation would replace the blanket 2017 advisory that effectively told every organization processing personal data to run a PIA, with a narrower “threshold analysis” that confines the mandatory requirement to processing falling into one of eight specifically defined categories. Everything outside those eight is explicitly exempt.
The 17-page draft, formally intended to supersede NPC Advisory No. 2017-03 in its entirety, applies to any organization operating in the Philippines or handling the personal data of Philippine residents — including companies based entirely abroad. Written comments were due August 14, and the NPC has scheduled a live online consultation session for August 25 at 2:00 p.m., putting the process squarely in its final public-input phase this week. What makes the draft notable isn’t just that it narrows the rule; it’s what the NPC chose to carve out for tighter treatment while loosening everything else: AI systems, biometric enrollment programs, and cross-border data transfers are all named as areas facing new or stricter PIA requirements even as routine processing gets relief.
Most Businesses Get a Real Compliance Break
For the average Philippine startup running standard SaaS operations — payroll, CRM, e-commerce order fulfillment, basic customer support tooling — the 2017 advisory’s blanket approach had always been a genuine burden: a formal Privacy Impact Assessment for every system that touched personal data, regardless of actual risk. The threshold-analysis model flips that logic. If your processing doesn’t fall into one of the eight flagged categories, you’re no longer required to produce a full PIA at all, which should meaningfully cut the compliance overhead for the large majority of companies whose data handling is genuinely routine. That’s a real, substantive change, not a cosmetic one — it’s the difference between treating a PIA as a default paperwork exercise and treating it as a targeted tool aimed at processing that actually carries elevated risk.
AI and Biometrics Are Getting the Opposite Treatment
The tightening half of the draft doesn’t come out of nowhere. The NPC has spent the past year actively enforcing against exactly the kind of processing it’s now singling out. In October 2025, the commission issued a cease-and-desist order against Tools for Humanity, the company behind Worldcoin’s World App, halting its collection of iris scans and other biometric data from Filipinos. The NPC’s own order found that the program’s privacy notice failed to meet the Data Privacy Act’s consent and transparency standards, and — more pointedly — that offering financial incentives worth as much as the peso equivalent of $100 in cryptocurrency in exchange for an iris scan amounted to undue influence rather than freely given consent. Tools for Humanity has since filed a motion for reconsideration and is appealing, arguing its system only verifies “humanness” without storing identifying details. Whatever the outcome of that specific case, it’s a clear signal of where the NPC’s attention already was before this draft circular formalized it into a standing rule: biometric collection tied to financial incentives, AI systems trained or deployed on personal data, and any transfer of Philippine residents’ data across borders are treated as inherently higher-risk categories that deserve mandatory scrutiny even in a framework designed to reduce paperwork everywhere else.
A Regulator Learning From Its Own Enforcement Record
What’s genuinely useful about watching this draft circular alongside the Worldcoin case is seeing a regulator visibly codify a lesson from its own enforcement history rather than legislate in the abstract. The 2017 advisory’s flat, everything-triggers-a-PIA approach didn’t stop the NPC from having to intervene against Worldcoin’s biometric program after the fact — a formal document requirement doesn’t substitute for judgment about which categories of processing are actually dangerous. The new draft appears to be an attempt to fix that mismatch directly: instead of asking every company to fill out the same form regardless of risk, it asks a narrower set of companies — the ones doing AI, biometrics, or cross-border transfers — to actually think through the specific harms those activities can cause, while letting a payroll system or a basic CRM ship without the same overhead.
What This Means for Philippine Founders
If your startup’s product touches any of the three flagged categories — you’re training or deploying an AI model on user data, you’re collecting biometric identifiers of any kind, or you’re routing Philippine user data through servers or vendors based outside the country, which is genuinely common for startups using US-based cloud infrastructure or outsourced backend teams — this draft circular is the single clearest advance notice you’re likely to get before the compliance obligation becomes final and binding. The public comment window has technically closed, but the practical deadline that matters is whenever the NPC formally adopts the circular, and founders in these categories should start building a real Privacy Impact Assessment process now rather than treating it as a future problem. The inverse lesson matters too: if your product is genuinely routine — you’re not doing AI, biometrics, or cross-border transfer — don’t over-engineer your own compliance program to match a rule that was specifically designed to stop applying to you. Knowing which side of that line your product sits on is now a real strategic question, not just a legal footnote.
Share this article