Back to NewsLegislation

Congress Passes Amendments to Data Privacy Act Affecting Law Firms

July 28, 20268 min

Background

Congress has passed significant amendments to Republic Act No. 10173, the Data Privacy Act of 2012, which substantially increase compliance obligations for all entities that process personal information — including law firms.

The amendments, signed into law in July 2026, were prompted by increasing data breach incidents in the legal sector and the need to align Philippine data protection standards with international frameworks such as the EU GDPR.

Key Changes Affecting Law Firms

The amendments introduce several new obligations specifically relevant to legal practice:

  • Mandatory data breach notification to the National Privacy Commission (NPC) within 72 hours of discovery — reduced from the previous "reasonable time" standard.
  • Law firms with 50 or more employees or processing sensitive personal information of 1,000+ individuals must appoint a full-time Data Protection Officer (DPO).
  • Privacy Impact Assessments (PIAs) are now mandatory before implementing new case management systems or client data processing activities.
  • Data retention periods for case files must be explicitly defined and documented. The default retention for closed matters is 10 years, after which personal data must be securely destroyed unless legal retention requirements apply.
  • Cross-border data transfers (e.g., cloud storage hosted outside the Philippines) require explicit client consent and NPC notification.

Penalties

Penalties for non-compliance have been significantly increased:

  • Failure to notify the NPC of a data breach within 72 hours: fine of ₱2,000,000 – ₱5,000,000 and imprisonment of 1–3 years.
  • Unauthorized processing of sensitive personal information: fine of ₱3,000,000 – ₱10,000,000 and imprisonment of 3–7 years.
  • Failure to appoint a DPO when required: fine of ₱500,000 – ₱1,500,000.
  • Failure to conduct a PIA: fine of ₱500,000 – ₱1,000,000.

Law firms should review their current data handling practices and update their privacy policies before the amendments take effect on January 1, 2027.

What Law Firms Should Do Now

To prepare for compliance, law firms should take the following steps:

  • Conduct a comprehensive data audit to identify all personal information being processed, stored, and shared.
  • Appoint a qualified Data Protection Officer if your firm meets the threshold criteria.
  • Update client engagement letters to include data processing consent clauses.
  • Review cloud service providers and ensure data hosting locations comply with cross-border transfer rules.
  • Implement a data breach response plan with clear escalation procedures to meet the 72-hour notification requirement.

Try DueCounsel Free

Built for Philippine law firms. Free migration, onboarding, and training.

Start Free