The Philippines’ new privacy advisory extends legal obligations on AI systems processing personal data, prompting organisations to enhance data governance and minimise privacy risks in AI-enabled marketing activities.
Philippine privacy rules now sit squarely inside AI workflow design. The National Privacy Commission’s Advisory No. 2024-04, issued on 19 December 2024, applies the Data Privacy Act of 2012 to artificial intelligence systems that process personal data and expressly covers prompt processing, profiling, inference, output generation and monitoring. The advisory also reaches systems outside the Philippines if they handle personal data about Philippine citizens or residents, reinforcing the law’s extraterritorial scope as set out on the Commission’s official website.
That matters for marketing, where routine tasks can drift into regulated processing without much notice. Synthetic prompt testing, audience analysis, sentiment review, contact database building and log inspection can all be carried out with little or no personal data. But once real names, email addresses, account identifiers or behavioural profiles enter the workflow, the activity moves from ordinary campaign work into privacy-sensitive processing. The practical question is not whether AI is used, but what data the team feeds into it and why.
The broader legal framework is familiar, but often underappreciated. The NPC’s official data privacy materials make clear that the Act can apply to entities outside the country if they process data about Philippine citizens or residents, or have sufficient links to the Philippines. That extraterritorial reach is important for foreign agencies and software vendors, because server location alone does not remove the obligation to comply.
For organisations building AI-assisted marketing or content programmes, the safest approach is to minimise personal data at the design stage. Use synthetic prompts where possible. Keep prompt registries tied to internal IDs rather than customer records. Separate testing environments from production data stores. Redact identifiers before analysis. These are not merely technical preferences; they are controls that reduce the chance that an otherwise ordinary visibility project becomes a personal-data processing exercise under the Data Privacy Act.
The same caution applies to vendor management. If a third-party tool handles prompts, logs or outputs on a client’s behalf, the controller still needs to understand what the tool stores, who can access it and whether it trains on inputs by default. Cross-border transfers do not end the inquiry. Under the Commission’s framework, accountability remains with the controller, which means contracts and operational controls matter as much as the software itself.
For firms selling into the Philippine market, the message is straightforward: AI visibility work is no longer just a search or content problem. It is also a data governance issue. The more a workflow relies on genuine customer information, the more it needs documentation, purpose limitation, retention rules and contract terms that match the privacy risk.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





