
By Pierre Tito Galla, co-founder and co-convener, Democracy.Net.PH
At a glance
- Executive Implementation Continues: Executive agencies are moving existing digital governance frameworks into practice through new government data residency rules, cybersecurity accreditation and vulnerability disclosure mechanisms, and expanded data protection guidance.
- Online Safety and AI Governance Move Towards More Formal Rules: Proposed measures on child online safety, false information and AI governance would introduce stronger platform responsibilities, safeguards against online harms and a more consolidated framework for AI, while sector-specific AI rules are already emerging in areas such as the judiciary.
- Digital Infrastructure and Resilience Support Policy Implementation: The Philippines is expanding the infrastructure needed to implement digital policy at scale through the National Digital Connectivity Plan, implementation of the Konektadong Pinoy Act and the National Single Window, while also strengthening domestic digital capability.
Share this insight
As of August 2026, the Philippines achieved a reclassification to an upper middle-income country (UMIC). The digital economy reached USD 44.5 billion (PHP 2.74 trillion) gross value added (GVA) at current prices in 2025, equivalent to 9.8% of the country’s GDP.
Despite the positive news, however, technology policymaking is taking place against a more unsettled domestic political backdrop, with the legislative branch of government occupied with various issues, such as the ongoing impeachment trial of the Philippines’ Vice President Sara Duterte. In this context, there has been little headway in the progress of ICT-related policy reforms. On the other hand, some policies have been implemented by the executive branch that may provide some interim progress.
This has resulted in an uneven governance trajectory. Operational measures are implementing existing frameworks in areas such as government data, cybersecurity, data protection, and connectivity. Meanwhile, broader reforms in AI, child online safety, and information integrity are still in the development phase. The Philippines’ experience at mid-2026 reflects a nuanced approach to both implementation and policy consolidation.
Key Policy Trends
Data Governance: Introducing Risk-Based Residency Requirements
The Philippines is updating its approach to the classification, storage, and transfer of government data. For example, the Office of the President (OP) issued Executive Order (EO) No. 119 series of 2026, “Updating the Government Data Classification, Establishing a Data Residency Framework, and for Other Purposes”. The EO mandates all covered government entities to adopt a unified, and risk-based framework for the classification, protection, handling, and management of government data. It updates the Government Data Classification Framework established under Memorandum Circular (MC) No. 78 series of 1964; however, some operationalisation provisions still depend on MC No. 196 series of 1968.
Of interest in EO No. 119 s. 2026 are the provisions Section 7 “Data Residency Requirements,” Section 8 “Cross-Border Data Transfers,” and Section 9 “Applicability of Information Security.” Due to data residency requirements for specific government data classifications, there is expected an increase in demand for local cloud instances. However, this also merits a review of the existing “Cloud First” policy adopted by the Department of Information and Communications Technology of the Philippines (DICT) in 2017 through Department Circular (DC) No. 2017-002, as amended by Department Circular (DC) No. 10 s. 2020.
Cybersecurity and Data Protection: Building Operational Assurance
Cybersecurity and data protection is transitioning from broader framework to more focused operational assurance, accreditation, and compliance mechanisms. Department Circular No. HRA-001 s. 2026, “Accreditation of DICT Trusted Assessment Providers (DTAPs),” is intended to facilitate an orderly transition to the accreditation of DICT Trusted Assessment Providers (DTAPs) framework from the previous program for the recognition of cybersecurity assessment providers, and in response to the need to institute a formal accreditation framework for vulnerability assessment and penetration testing (VAPT) and information security management system (ISMS) service providers to guarantee the quality, reliability, and ethical competency of services rendered, specifically VAPT and ISMS audit and assessment services. Implementing guidelines were also issued immediately after.
Department Circular No. HRA-002 s. 2026, “Prescribing the Revised and Consolidated Guidelines, Rules and Regulations Governing the Vulnerability Disclosure Initiative, Safe Harbor Policy, and Bug Bounty Program,” revises the existing vulnerability disclosure initiative of the DICT Department Circular No. 006, s. 2024 and establishes the Safe Harbor Policy and Bug Bounty Program (SHPBBP). The framework provides protections for ethical hackers acting in good faith, formalises responsible vulnerability disclosure and introduces mechanisms to recognise valid vulnerability reports.
On data protection, the National Privacy Commission (NPC) also released two issuances. NPC Advisory No. 2026-01, “Guidelines on Data Scraping of Publicly Available Personal Data,” acknowledges that data scraping practices and technologies may raise data privacy concerns and provides guidelines on how data scraping may be aligned with the provisions of the Data Privacy Act (Republic Act No. 10173). NPC Advisory No. 2026-02, “Clarification on the Submission of Personal Data Breach Notification through Data Breach Notification Management System,” provides clarificatory guidance for the implementation of NPC Circular No. 16-03, “Personal Data Breach Management.” Also, in June 2026, the NPC put out a call for comments on the draft Guidelines on the Processing of Personal Data for the Availment of Statutory, Government-Mandated, and Other Special Privileges to be adopted by the NPC.
These developments suggest that cybersecurity and data protection governance is increasingly focused on the mechanisms needed to implement and assure compliance with existing frameworks.
Platform Regulation: Strengthening Online Safety
The country is moving towards a more proactive approach to online harms. Ensuring child online safety is becoming a growing focus in platform governance, with suggested responsibilities including age assurance, safety-oriented design, and recommendation systems. House Bill No. 9965 or the Children’s Social Media Safety Act was filed on 29 June, 2026, eight days after the shooting in a school in Tacloban City that involved minor gunmen aged 15 and 14.The bill mandates platforms to apply the highest privacy and safety settings by default for child users, restrict geolocation sharing and financial transactions and prohibit the unnecessary collection or use of children’s biometric and sensitive personal data. It would also introduce obligations around recommender systems and platform design, requiring platforms to limit children’s exposure to harmful content and address potentially manipulative design features. Children below 13 years old would be prohibited from creating, maintaining, or using social media accounts unless access is provided with verifiable parental or guardian consent and active supervision.
In addition to that, the Government is moving towards a more coordinated and increasingly formalised approach to deliberate online false information. On 12 April 2026, the Department of Justice (DOJ), the DICT, and the Presidential Communications Office (PCO) signed a Memorandum of Agreement (MOA) establishing a unified, whole-of-government response against the deliberate manufacture and spread of false information and media. The agreement formalises an inter-agency framework designed to protect public safety and national security from malicious information operations, ensuring a safer and more resilient cyber environment. Legislative efforts are also making progress. The proposed Digital Media Anti-False Information Act (House Bill No. 9465), was approved on 3 June 2026 on third and final reading. The bill seeks to protect Filipinos from deliberate online deception, organised disinformation campaigns, and digital operations that threaten public safety, national security, and democratic institutions, and imposes penalties against individuals found guilty of knowingly and deliberately creating, financing, directing or materially assisting false information intended to cause verifiable public harm or pose a serious threat to national security.
The Philippine government and Meta have agreed to establish a technical working group to improve coordination and response times in addressing harmful content, online threats of violence, and child sexual abuse and exploitation material on the company’s platforms. The commitments emerged from a meeting in Singapore between Philippine officials and executives of Meta, the parent company of Facebook and Instagram, in August 2026.
The DICT will push for stronger accountability from major technology platforms across ASEAN, citing the need for faster action against scams, harmful content, deepfakes and other cross-border digital threats. The proposal follows calls for an ASEAN-wide framework covering harmful content, fraudulent advertisements, misinformation, online scams and other digital risks that cross national borders. DICT Secretary is expected to raise the issue during the Ministerial Roundtable Meeting on “AI: A Boon or Bane for Information and Media Cooperation” on 9 to 10 October 2026 in Metro Manila, as well as the ASEAN Senior Officials’ Meeting on Harnessing New Media for a Stronger ASEAN Narrative on 15 to 17 October 2026.
Such developments indicate a movement toward a more structured approach to managing online safety, combining proposed platform responsibilities with stronger mechanisms for addressing harmful information. As they progress, a crucial aspect of implementation will be how obligations and enforcement thresholds are defined while maintaining appropriate safeguards for lawful expression.
AI Governance: Consolidating Legislative Proposals as Sectoral Frameworks Emerge
On the AI Governance agenda, the country is attempting to consolidate its fragmented AI legislative landscape, while sector-specific governance frameworks are beginning to emerge. On 30 January 2026, the Technical Working Group (TWG) on AI under the House Committee on Information and Communications Technology, presented a comprehensive 24-month legislative roadmap to transition the Philippines from “AI-ready” to “AI-powered”. TWG is consolidating over 20 fragmented bills into House Bill No. 1196, or the AI Development and Governance Act of 2026, which will feature an AI Bill of Rights to protect citizens from algorithmic discrimination and unsafe systems.
The AI Governance Framework is expected to be finalised by September 2026. According to DEPDev’s presentation at the 2026 National Innovation Day held on 29 April 2026, the draft framework has already been presented to various stakeholders, including the academe. Further consultations will be conducted to ensure the framework adheres to good governance principles.
At the same time, AI governance is being developed within specific sectors. On 18 February 2026, the Supreme Court of the Philippines issued an en banc resolution AM No. 25-11-28 SC adopting the “Proposed Governance Framework on the Use of Human-Centered Augmented Intelligence in the Judiciary,” providing guidance for the use of AI in the Philippine judicial system.
Cross-cutting Governance Trends
Implementation Capacity: Building the Infrastructure for Policy Implementation
Regulations implementation is paired with physical, institutional and digital infrastructure needed to implement governance at scale. On 5 February 2026, the National Digital Connectivity Plan (NDCP) was formally launched. The 11-year roadmap aims to bridge the digital divide by accelerating fiber, wireless, and satellite broadband access, especially in remote areas.
In related implementation of the Konektadong Pinoy Act, on 30 April 2026, the National Telecommunications Commission (NTC) released application forms for use for entities to be authorized or registered as data transmission industry participants (DTIPs). The availability of these forms signals to existing DTIPs and to new entrants the readiness of the NTC to implement the Konektadong Pinoy Act.
This implementation focus is also visible beyond connectivity. On 19 June 2026, the DICT brought the National Single Window – Integrated Trade Facilitation Platform (NSW-ITFP) into pilot go-live operation. A total of 72 Trade-Related Government Agencies (TRGAs) and Other Government Agencies (OGAs) are scheduled to be onboarded to the NSW-ITFP through four phased rollouts from 2026 to 2028, with the Bureau of Internal Revenue (BIR) and the National Tobacco Administration (NTA) having been the first two onboarded.
These initiatives indicate that the Government is increasingly complementing policy frameworks with the administrative processes, connectivity infrastructure and shared digital systems needed to put them into practice.
Digital Resilience: Strengthening Critical Digital Capability
Greater emphasis is placed on strengthening domestic capability and resilience across critical digital infrastructure. This is being pursued partly through international partnerships that bring investment, infrastructure and technical capacity into the country.
The Philippines joined the Pax Silica initiative in April 2026. This initiative, led by the US, seeks to build a secure and resilient AI supply chain. Under the Pax Silica, The Philippines and the US are developing a 4,000-acre AI industrial hub in New Clark City. The project seeks to enhance the Philippines’ role in higher-value segments of semiconductor and AI-related supply chains, while attracting investment and generating higher-skilled employment opportunities. Although it is anticipated to move forward, discussions regarding formal negotiations are still ongoing. Concerns have been expressed regarding legal, environmental and social safeguards. The Government has emphasised that any final arrangement must comply with Philippine law and serve the interests of the Filipino people.
Regional Coordination: Advancing Cross-Border Interoperability and Cooperation
Along with emphasis on domestic capability, cross-border regulatory cooperation and interoperability are also being strengthened. At the AI Impact Summit 2026 in India, the DICT advanced the Philippines’ regional AI priorities. Co-chairing the Human Capital Working Group, three proposals were adopted in the summit’s outcomes covering digital public infrastructure for skills, employer-led reskilling and AI observatories.
On 1 June 2026, the National Privacy Commission (NPC) and the Personal Information Protection Commission (PPC) of Japan formally signed a Memorandum of Cooperation (MoC) to strengthen cross-border cooperation on personal data protection and privacy enforcement. Under the MoC, the NPC and the PPC will collaborate on information sharing and mutual assistance in privacy investigations, as well as exchange of best practices, and experiences on data protection policies and privacy-enhancing technologies. The MoC also opens opportunities for joint research initiatives, capacity-building activities, training and education programs, and other mutually agreed undertakings aimed at advancing data protection and privacy.
On 8 June 2026, the DICT signed a Memorandum of Understanding (MOU) with My Blockchain Infrastructure Sdn. Bhd. (MBI) of Malaysia and Zetrix Philippines Inc. to explore cross-border digital identity interoperability and secure credential verification between the Philippines and Malaysia. The MOU sets a framework for cooperation to explore secure and standards-based systems that allow government-issued digital credentials to be verified across borders, in line with strict privacy, cybersecurity, and national security safeguards. Once implemented, the initiative is expected to reduce the need for repeated identity checks when Filipinos access services in Malaysia and when Malaysians do so in the Philippines, helping make cross-border transactions more seamless, faster, and more secure.
In July 2026, the DICT and the Korea International Cooperation Agency (KOICA) broke ground on the National Cybersecurity Center (NCSC) in Valenzuela City to strengthen the country’s ability to prevent cyberthreats in July 2026. KOICA is funding the project through a USD 25.6M grant. The center will serve as the country’s central hub for cyber threat monitoring, intelligence sharing and incident response.
Moving Forward
While efforts to strengthen the regulatory framework continue, the Philippines may face slower policy momentum in the near term given the Government’s attention to broader political issues, including the impeachment proceedings concerning Vice President Sara Duterte. Despite these headwinds, the Philippines continues to prioritise reforms in the ICT sector. Much groundwork has already been laid in terms of ICT rights, governance, development, and security policies and programs by mid-2026. Progress remains uneven, with several major reforms still under development even as executive agencies move existing frameworks into practice. Looking ahead, the Philippines’ digital transformation program is one to watch among its peers in the region, and participation in this journey is an opportunity for stakeholders in the ICT space.
The views and recommendations expressed in this article, published in September 2026, are solely of the author and do not necessarily reflect the views and position of the Tech for Good Institute.
