How DPA 2012 Applies to AI Systems
The Republic Act No. 10173, known as the Data Privacy Act of 2012 (DPA), protects individual personal information across all processing systems in the Philippines. While the law was drafted before the widespread adoption of modern generative AI, its core principles apply directly to artificial intelligence systems. Under the DPA, any AI model that processes, stores, or analyzes personal data—including names, contact details, employee records, or client data—is subject to strict compliance oversight.
Whether you are using off-the-shelf generative AI, external APIs, or custom-trained machine learning algorithms, your organization remains legally responsible for the data fed into these models and the decisions they output.
NPC Guidance on Automated Decision Systems (ADS)
The National Privacy Commission (NPC) has issued specific circulars addressing Automated Decision Systems (ADS). ADS refers to AI workflows that make automated judgments about individuals without direct human intervention—such as automated loan screening, recruitment filters, or performance tracking. Key compliance rules under the NPC guidelines include:
- Right to be Informed: Data subjects must be explicitly notified if their personal data is processed by an automated decision system.
- Right to Object: Individuals have the right to contest automated decisions and demand human intervention, especially when the decision significantly impacts their employment, credit rating, or legal rights.
- Algorithm Transparency: Organizations must be able to explain the logic behind automated decisions, ensuring that the model does not utilize biased or discriminatory datasets.
Privacy Impact Assessments (PIA) for AI Pipelines
Before deploying any AI system that processes personal data, companies are legally required to conduct a Privacy Impact Assessment (PIA). The PIA evaluates how personal data is collected, stored, and protected throughout the AI lifecycle. For AI systems, the assessment must address several unique vectors:
- Data Egress Tracking: Where does the data flow? If your AI pipeline calls external APIs (e.g., public OpenAI or Anthropic endpoints), the PIA must document the cross-border data transfers.
- Data Security: Are inputs encrypted in transit and at rest? How are prompt records protected against external breaches?
- Data Minimization: Ensuring that the AI pipeline only processes the minimum personal data required to execute its function. Masking and anonymization tools must be built into the pipeline before data enters the model.
Consent and Personal Data in Model Training
One of the most complex areas of AI compliance is the training phase. If your organization is fine-tuning or training custom models using historical corporate databases, you must ensure that you possess the legal authority to do so. Under the DPA, using personal data for AI model training requires explicit consent from the data subjects unless the data has been fully anonymized. Anonymization must be irreversible; if the model can be queried to reconstruct or reveal individual personal identities, it remains in scope under the DPA.
Furthermore, consent forms must clearly specify that the data may be utilized for machine learning model development and operational testing.
Building a Compliant Governance Framework
To ensure long-term compliance and minimize data breach risks, enterprises must establish a structured AI governance framework. A compliant framework should include:
- Corporate AI Policies: Clear, written guidelines detailing which AI tools are approved for use and what types of data are strictly forbidden from entering public prompts.
- Secure Wrappers: Deploying private, enterprise-grade API endpoints that guarantee that prompt data is never retained by providers or utilized for model training.
- Auditable Decision Logs: Maintaining detailed logs of all automated decisions, including the inputs fed into the model and the outputs generated, to support regulatory audits.
Secure Your AI Compliance
Greencon provides compliance-grade AI audits and privacy impact assessments to align your machine learning pipelines with DPA 2012 rules.
To learn more about implementing secure operational audits for your AI pipelines, consult our dedicated AI audit Philippines page.