NPC Advisory 2024-04 and Your Prompt Logs
SEO

NPC Advisory 2024-04 and Your Prompt Logs

NPC Advisory 2024-04 names prompt processing and monitoring, and model clauses are voluntary. What Philippine marketing teams get wrong.

On 19 December 2024 the National Privacy Commission issued Advisory No. 2024-04, applying the Data Privacy Act of 2012 to artificial intelligence systems that process personal data. It names prompt processing, profiling, inference, output generation and monitoring explicitly. And it applies even where the AI system itself sits outside the Philippines.

Almost no marketing proposal written for this market mentions it. Understandable, in a way, because Advisory 2024-04 does not read like a marketing document. It is also a problem, because a modern content and AI-visibility programme touches several of the activities it names by name.

Three other things get widely misstated about Philippine data privacy in agency material. Each of them matters commercially. Model contractual clauses are described as mandatory when the Commission calls them voluntary. Registration thresholds get quoted in a form that comes from a government-contracting provision rather than the general rule. And the maximum administrative fine is described as a floor when it is a ceiling.

What follows: what the framework actually says, what it means for a marketing function specifically, what enforcement has looked like in practice, and how to scope work so that most of this does not arise at all. Orientation, not Philippine legal advice.

The framework, in the order it applies

Republic Act No. 10173, the Data Privacy Act of 2012, is the governing statute, administered by the National Privacy Commission. It applies extraterritorially. Processing of personal data about Philippine citizens and residents falls in scope even where the processor sits abroad and even where the servers are elsewhere. An Indonesia-based, Singapore-based or US-based agency handling Philippine personal data is inside the regime, and there is no clever structure that changes that.

Accountability stays with the controller. The Philippine client is normally the personal information controller. Under the accountability principle it remains responsible for all personal information under its control, including data transferred to a processor domestically or internationally, and it is required to use contractual or other reasonable means to ensure the recipient provides comparable protection. Liability does not travel with the data.

NPC Advisory No. 2024-01, issued 30 May 2024, makes model contractual clauses available for cross-border transfers, referencing several international frameworks including ASEAN, European, UK, New Zealand, Argentine and Ibero-American instruments. Here is the part agency material routinely gets wrong: the Commission describes the use of these clauses as voluntary. Organisations are encouraged, not required, to adopt them. The Commission also states it will not review agreements for conformity. What is required is accountability. The clauses are one instrument for meeting it.

NPC Circular No. 2022-04, effective January 2023, governs registration and supersedes Circular 17-01 in full. Registration is required where any one of three conditions applies: the controller or processor employs 250 or more persons; the processing includes sensitive personal information of 1,000 or more individuals; or the processing is likely to pose a risk to the rights and freedoms of data subjects. Separately, systems involving automated decision-making or profiling must be registered in all cases, with no threshold to fall below.

NPC Circular No. 16-03 sets breach handling. The Commission and affected data subjects must be notified within 72 hours of knowledge or reasonable belief that a personal data breach has occurred, with a full report inside five days unless the Commission allows longer. No delay is permitted where at least 100 data subjects are involved, or where disclosure of sensitive personal information would harm them. Crucially for anyone using a vendor, the Circular requires the controller to secure by contract that a processor reports to it upon discovering a breach.

NPC Circular No. 2022-01, effective 27 August 2022, sets administrative fines. Grave infractions attract 0.5 to 3 percent of annual gross income. Major infractions 0.25 to 2 percent. Other infractions attract fixed amounts. The total imposable fine for a single act or omission, whether it produces one infraction or several, does not exceed five million pesos. That five million figure is the cap, not an alternative to the percentage, and administrative fines sit separately from the criminal penalties in the Act.

Four corrections worth making

What Agency Material Routinely Gets Wrong

Each of these circulates with confidence. Each is checkable against the Commission's own published text.

Model clauses are voluntary, not mandatory

Advisory 2024-01 of 30 May 2024 describes their use as voluntary and states the Commission will not review agreements for conformity. What is mandatory is accountability and comparable protection through contractual or other reasonable means.

Registration has three triggers, not one

Under Circular 2022-04, which superseded Circular 17-01 in full: 250 or more employees, or sensitive personal information of 1,000 or more individuals, or processing likely to pose a risk. Profiling and automated decision-making register in all cases.

Five million pesos is a ceiling

Circular 2022-01 sets 0.5 to 3 percent of annual gross income for grave infractions and 0.25 to 2 percent for major ones. The total for a single act does not exceed five million pesos. A cap, not an alternative floor.

AI guidance already exists here

Advisory 2024-04 of 19 December 2024 applies the Act across the AI lifecycle, naming prompt processing, profiling, inference and monitoring, and reaching systems located outside the Philippines. Very little marketing material mentions it.

And one obligation that lands in your vendor contract

Circular 16-03 requires the controller to secure, by contract or other reasonable means, that a processor reports to it upon discovering a breach. Because the controller's own clock to notify the Commission runs to 72 hours, a vendor agreement with a vague or absent internal notification deadline transfers a timing risk onto the client that the client cannot manage.

Sources: NPC Advisory No. 2024-01, 30 May 2024 • NPC Advisory No. 2024-04, 19 December 2024 • NPC Circular No. 2022-04, effective January 2023 • NPC Circular No. 2022-01, effective 27 August 2022 • NPC Circular No. 16-03, effective 5 October 2018 • Republic Act No. 10173, all via privacy.gov.ph, verified August 2026
Created by Arfadia • arfadia.com/blog

Why Advisory 2024-04 lands on marketing

The Advisory applies wherever personal data is processed in the development, deployment, training or testing of an AI system. Collection, model training, testing, prompt processing, profiling, inference, output generation, monitoring, system improvement. The principles it enforces are the familiar ones: transparency, legitimate purpose, proportionality, data quality, security, accountability, and protection of data-subject rights.

Two of its provisions matter more than the rest for a marketing function.

The first is reach. The Advisory applies to a controller or processor using AI in the Philippines or processing data about Philippine citizens and residents, even where the AI system sits elsewhere. Using a US-hosted assistant from an office in Jakarta on behalf of a Manila client does not place the activity outside the framework. Geography of the server is not the test.

The second is accountability. The Advisory confirms the controller remains responsible for outcomes and consequences of the processing even where a third-party AI provider performs it. "The tool did it" does not survive contact with this text.

Now picture an ordinary month in a marketing team. Someone pastes a customer list into an assistant to segment it. Someone builds a media contact database from public sources. Someone runs sentiment monitoring on named individuals. Someone uploads campaign logs to an analytics tool hosted abroad. Someone tests a hundred prompts to see whether the brand gets named, and the prompt log quietly accumulates identifiers along the way.

Every one of those is a defensible business activity. Every one is also an Advisory 2024-04 question, and under the accountability principle the answer arrives with the controller's name on it.

Exposure, by marketing activity

Activity Exposure Control that actually helps
Synthetic prompt testing for brand visibilityLowKeep prompts free of identifiers. A question about payroll software for a Cebu retailer contains no personal data at all
Auditing public pages and published AI answersLowDo not append identifiers the task does not require. Store the answer text, not the tester's account details
Aggregate visibility and ranking reportingLowReport aggregated by default rather than on request, so the granular version is never created
Media and influencer contact databasesMediumDocument source, purpose, access and retention before building it, not after somebody asks
Sentiment monitoring on named individualsMedium to highApply necessity and proportionality tests and record the reasoning. Monitoring named people is closer to profiling than to listening
Prompt logs carrying user IDs, emails or IP addressesHighUse stable internal prompt IDs instead. If real identifiers are unavoidable, a processing agreement and retention schedule go in first
Uploading customer records into an assistantHighProhibit without documented approval and a lawful basis on file. Check whether the tool trains on inputs by default
Audience profiling or automated segmentation decisionsHighCircular 2022-04 requires registration for profiling and automated decision-making in all cases, with no threshold exemption

The pattern is the useful part here. Content, entity and public-answer work sits at the low-exposure end, and that is a design property rather than a loophole. A well-scoped Philippine AI-visibility programme can run with almost no personal data in scope. Exposure appears at the moment somebody decides it would be convenient to pull real customer records into the testing environment. Convenience is the risk factor. Not the discipline.

What enforcement has actually looked like

Frameworks read as abstract until a regulator acts. So it is worth knowing that the Commission does act, and how.

On 8 October 2025 the National Privacy Commission issued a cease-and-desist order against Tools for Humanity, operator of the World App, over unauthorised collection of biometric data. The reasoning matters more than the order. The Commission established that consent obtained through financial incentives is not freely given, and therefore not valid consent under the Act.

Sit with that principle for a moment, because it generalises further than biometrics.

Marketing runs on incentives. Prize draws in exchange for a data form. A discount code for newsletter signup. A free report behind a lead-gen gate. Payment for user-generated content that includes a face or a voice. None of those are automatically invalid, and this article is not suggesting they are. But the Commission has now stated on the record that a financial inducement can undermine the freeness of consent, which means the design of an incentive is a privacy question rather than purely a conversion-rate question.

The practical read: where consent is your lawful basis and an incentive is attached, the incentive should not be so central that a reasonable person would say they had no real choice. Where that line sits is exactly the kind of thing your own counsel should look at, not an agency.

One honest limit. No enforcement decision specifically evaluating AI-visibility prompt monitoring was located in the Commission's published enforcement decisions. The framework establishes general duties. It has not been tested against this particular activity, so anyone claiming settled practice here is over-reading the record.

Scoping so the question mostly does not arise

The strongest compliance position for this kind of work is not a thicker contract. It is a scope that does not need one.

Default to synthetic prompts. Most citation and visibility testing needs nothing more than realistic buyer questions written by a human. A prompt asking which enterprise payroll platform suits a mid-sized Cebu retailer contains no identifiable person, and it tells you everything a real customer query would have told you.

Key panels to internal IDs. Prompt registries should reference internal identifiers, not customer records. Costs nothing at setup. Removes an entire category of question later.

Separate testing from production storage. Synthetic visibility testing should never share a data store with live customer conversation logs. Once they mix, the whole store inherits the higher classification and everything in it comes with it.

Redact before analysts see exports. Where support transcripts or query exports feed vocabulary research, strip names, emails and account numbers at the point of export rather than the point of publication.

Set retention by measurement need. Answer captures need to live long enough to compare periods, which is a defined window rather than indefinitely. Write the number down.

Check whether tools train on inputs. A marketing-stack question rather than a legal one, and answerable in an afternoon. Enterprise terms that disable provider training by default, with control over retention, deletion, subprocessors and audit rights, are the sensible baseline.

Put the notification deadline in the vendor contract. Because the controller's own clock runs to 72 hours under Circular 16-03, a processor's internal reporting deadline needs to be materially shorter than that. Twenty-four hours is common and workable.

Scope first, contract second

Five Decisions Made at Setup That Remove the Question

Each costs almost nothing on day one and is expensive to retrofit six months in.

Synthetic prompts as the default

Realistic buyer questions written by a human, containing no identifiable person. Most visibility and citation testing needs nothing more, and the results are equivalent.

Internal IDs, never customer identifiers

Prompt registries reference internal keys. Free to implement at setup, and it removes an entire category of question before it can be asked.

Testing store separated from production

Synthetic testing must not share storage with live customer conversation logs. Once they mix, the combined store inherits the higher classification and so does everything inside it.

Retention written as a number

Answer captures need to survive long enough to compare periods. A defined window, not indefinitely. Write the number into the scope document rather than leaving it to habit.

And a vendor notification deadline shorter than 72 hours

Circular 16-03 gives the controller 72 hours from knowledge to notify the Commission, and requires the controller to secure by contract that a processor reports to it on discovery. A contract saying the processor will notify promptly leaves the client holding a deadline it cannot control. Twenty-four hours is a common and workable figure to write in instead.

Sources: NPC Advisory No. 2024-04, 19 December 2024 • NPC Circular No. 16-03, Sections 16 to 18 • NPC Circular No. 2022-04 • Republic Act No. 10173, accountability principle. All via privacy.gov.ph, verified August 2026. General information, not legal advice
Created by Arfadia • arfadia.com/blog

What to ask a foreign vendor, and what a good answer sounds like

Philippine procurement teams increasingly ask these questions. Vendors who have not thought about them tend to answer with reassurance rather than specifics, which is itself the answer.

Ask what personal data the engagement requires, and why. A vendor who cannot answer this precisely has not scoped the work, and for most visibility programmes the correct answer is very little or none.

Ask where prompt logs, answer captures and reports are stored, and who has access. Location and access control are separate questions and both need answers.

Ask what the internal breach-notification deadline is, in hours. Vague language here is a real risk transfer, given your own 72-hour clock.

Ask whether any tool in the delivery stack trains on inputs by default. Answerable, and a vendor should already know.

Ask whether they will sign a processing agreement, and whether they are familiar with the model clauses under Advisory 2024-01. A well-informed vendor will confirm they will sign, and will also know the clauses are voluntary rather than a legal requirement. That second half is a useful signal all by itself.

Ask what happens to content, prompt registries and captured data at termination. These should transfer to you, and the answer should not require a negotiation.

The honest limits of this article

Three things worth stating plainly. We are not Philippine lawyers and this is orientation rather than advice. Anything touching Philippine personal data at volume should be reviewed by qualified Philippine counsel or your own Data Protection Officer.

No enforcement decision specifically evaluating AI-visibility prompt monitoring was located in the Commission's published enforcement decisions. The framework establishes general duties. It has not yet been tested against this particular activity, so treat the absence as an open question rather than as permission.

And the Commission has stated it will not review agreements for conformity with model clauses, which means no vendor can offer you regulatory pre-approval of a contract. Anyone implying otherwise is describing a service that does not exist.

Our GEO service for the Philippines defaults to a synthetic-prompt scope for exactly these reasons, and our SEO service for the Philippines follows the same principle on analytics and reporting.


Frequently Asked Questions


Does the Data Privacy Act apply to an agency based outside the Philippines?

Yes. Republic Act No. 10173 applies extraterritorially to processing of personal data concerning Philippine citizens and residents, including where the processor and its servers sit abroad. NPC Advisory No. 2024-04 confirms the same reach for AI systems, applying where personal data is processed in the development, deployment, training or testing of an AI system even when that system is located elsewhere.


Are model contractual clauses mandatory for cross-border transfers?

No, and this is widely misstated. NPC Advisory No. 2024-01 of 30 May 2024 makes model contractual clauses available and describes their use as voluntary, referencing several international frameworks including ASEAN, European, UK, New Zealand, Argentine and Ibero-American instruments. The Commission also states it will not review agreements for conformity with them. What is mandatory is the accountability principle: the controller must use contractual or other reasonable means to ensure comparable protection. The clauses are one accepted way to do that.


Do we need to register our processing with the National Privacy Commission?

It depends on your own processing, not on hiring a vendor. Under NPC Circular No. 2022-04, which superseded Circular 17-01 in full, registration is required where any one of three conditions applies: you employ 250 or more persons, your processing includes sensitive personal information of 1,000 or more individuals, or the processing is likely to pose a risk to the rights and freedoms of data subjects. Separately, systems involving automated decision-making or profiling must be registered in all cases with no threshold exemption.


What are the actual penalties under the Data Privacy Act?

NPC Circular No. 2022-01, effective 27 August 2022, sets administrative fines at 0.5 to 3 percent of annual gross income for grave infractions and 0.25 to 2 percent for major infractions, with fixed amounts for other categories. The total imposable fine for a single act or omission, whether it produces one infraction or several, does not exceed five million pesos. That figure is a ceiling rather than an alternative to the percentage. Administrative fines are separate from the criminal penalties in the Act, and a controller can face both.


Does prompt monitoring for AI visibility create a privacy problem?

It can, depending entirely on what the prompts contain. NPC Advisory No. 2024-04 names prompt processing, profiling, inference and monitoring explicitly. A synthetic prompt asking which payroll platform suits a mid-sized Cebu retailer contains no personal data at all, and most citation testing needs nothing more than that. A prompt log carrying user IDs, email addresses, IP addresses or customer complaints is a different matter and brings the full set of obligations with it.


Has the National Privacy Commission actually enforced against anyone?

Yes. On 8 October 2025 the Commission issued a cease-and-desist order against Tools for Humanity, operator of the World App, over unauthorised collection of biometric data. The reasoning has wider reach than the case: the Commission established that consent obtained through financial incentives is not freely given and therefore not valid consent. For marketing teams that matters, because prize draws, discount codes for signup and paid user-generated content all attach an inducement to a consent flow. None of those is automatically invalid, but the design of the incentive becomes a privacy question rather than purely a conversion question.


What is the breach notification deadline, and how does it affect a vendor contract?

Under NPC Circular 16-03 the Commission and affected data subjects must be notified within 72 hours of knowledge or reasonable belief that a breach has occurred, with a full report inside five days unless the Commission grants longer. No delay is permitted where at least 100 data subjects are involved or where disclosure of sensitive personal information would harm them. The Circular also requires the controller to secure by contract that a processor reports to it on discovering a breach, so a vendor agreement should carry an internal deadline materially shorter than 72 hours. Twenty-four hours is common and workable.


Has the Commission ruled on AI visibility or prompt monitoring specifically?

No matching enforcement decision was located in the Commission's published enforcement decisions. The existing framework establishes general duties across the AI lifecycle through Advisory 2024-04, but it has not been tested against this particular activity. Treat the absence as an open question rather than permission, and scope accordingly.


Can a vendor get our data processing agreement approved by the NPC?

No. The Commission has stated it will not review agreements for conformity with model contractual clauses. There is no pre-approval mechanism for a vendor contract, so any offer of regulatory sign-off on an agreement describes a service that does not exist.

Sources & References:

  • Republic Act No. 10173, the Data Privacy Act of 2012, signed 15 August 2012, effective 8 September 2012, Implementing Rules and Regulations in force from 9 September 2016. Administered by the National Privacy Commission. Extraterritorial application to processing concerning Philippine citizens and residents.
  • NPC Advisory No. 2024-04, issued 19 December 2024: Guidelines on the Application of Republic Act No. 10173, its Implementing Rules and Regulations, and the Issuances of the Commission to Artificial Intelligence Systems Processing Personal Data. Applies across collection, model training, testing, prompt processing, profiling, inference, output generation, monitoring and system improvement. Applies where the AI system is located outside the Philippines. Confirms the controller remains responsible for outcomes even where a third-party AI provider performs the processing.
  • NPC Advisory No. 2024-01, issued 30 May 2024: Model Contractual Clauses for Cross-Border Transfers of Personal Data. The Commission describes adoption as voluntary, references ASEAN, European, UK, New Zealand, Argentine and Ibero-American frameworks, and states it will not review agreements for conformity. The Advisory does not amend the Act or its Implementing Rules.
  • NPC Circular No. 2022-04, effective January 2023, superseding NPC Circular No. 17-01 in its entirety. Registration required where the controller or processor employs 250 or more persons, processes sensitive personal information of 1,000 or more individuals, or carries out processing likely to pose a risk to the rights and freedoms of data subjects. Data processing systems involving automated decision-making or profiling must be registered in all instances.
  • NPC Circular No. 2022-01, issued 12 August 2022, effective 27 August 2022: Guidelines on Administrative Fines. Grave infractions 0.5 to 3 percent of annual gross income; major infractions 0.25 to 2 percent; other infractions up to PHP 50,000 or PHP 200,000 depending on the violation. Total imposable fine for a single act or omission does not exceed PHP 5,000,000. Administrative fines are separate from criminal penalties under the Act.
  • NPC Circular No. 16-03, Personal Data Breach Management, in force from 5 October 2018. Notification to the Commission and to affected data subjects within 72 hours of knowledge or reasonable belief of a breach; full report within five days unless extended. No delay permitted where at least 100 data subjects are involved or where disclosure of sensitive personal information would harm the data subject. Section 16 requires the controller to use contractual or other reasonable means to ensure the processor reports to it upon knowledge or reasonable belief of a breach.
  • Enforcement precedent: the National Privacy Commission issued a cease-and-desist order against Tools for Humanity, operator of the World App, on 8 October 2025, over unauthorised collection of biometric data, establishing that consent obtained through financial incentives is not freely given and therefore not valid consent under the Act.
  • No enforcement decision specifically evaluating AI-visibility prompt monitoring was located in the Commission's published enforcement decisions as at August 2026. The framework establishes general duties; it has not been tested against this activity.
  • This article is strategic and operational orientation, not Philippine legal advice. Engagements involving Philippine personal data should be reviewed by qualified Philippine counsel or the organisation's Data Protection Officer.
0 Comments 0 Comments
0 Comments 0 Comments