Using AI Now Triggers a Mandatory Assessment

The NPC has proposed its first full Privacy Impact Assessment overhaul since 2016. What it means for using AI at your company.

Author
AuthorAuthor

AI Engineer · 36+ years in IT · Japanese, based in Manila for 13+ years

Using AI Now Triggers a Mandatory Assessment

Audience: Executives, country managers, and back-office leads at Japanese companies whose Philippine operations handle customer or employee data — especially companies already using AI tools in their work, or considering them

Reading time: 15 minutes

What this case study covers: The Philippines' National Privacy Commission (NPC) has published a draft overhaul of its Privacy Impact Assessment (PIA) rules. We read it not as regulatory commentary but as a checklist for your own company. The draft is still at the public-consultation stage, but the direction is already clear.

Part 1: Read → Draw the Implications for Your Company

Here is what the draft changes.

ItemDetail
ScopeA full replacement of the 2017 Advisory No. 2017-03. The first review of the framework since 2017
How the duty appliesFrom "thinly on everyone" to only processing that falls into eight categories
Treatment of AIUse of AI, machine learning, facial recognition and behavioural analysis is named in the eight categories
Numerical thresholds250 or more employees, or sensitive personal information on 1,000 or more data subjects, counts as large-scale
Procedures imposedA 5x5 risk scoring matrix, annual review, DPO sign-off, dated document control
Deadlines and penaltiesConsultation closes 14 August 2026. 90 days to comply after effectivity. Fines up to 3% of annual gross income (capped at PHP 5 million per count)

What happened

The NPC has published a draft circular that would entirely replace its 2017 rules on PIAs (Advisory No. 2017-03) and has opened a public consultation. Comments are due by August 14, 2026, and an online briefing session is scheduled for August 25. Registration for the briefing closes on August 20. This is the first overhaul of the PIA framework since 2017.

The biggest change is how the obligation applies. Under the current framework, organizations processing personal data have been broadly expected to conduct PIAs. The draft changes that: only processing that falls into one of eight categories triggers a mandatory PIA, and processing that matches none of them falls outside the obligation (voluntary assessments remain possible).

Among those eight categories, the use of new technologies — AI, machine learning, facial recognition, and behavioral analytics — is named explicitly. The others include sensitive personal information; financial, biometric, and children's data; "large-scale" processing (250 or more employees, or sensitive personal information of 1,000 or more individuals); data of vulnerable groups; automated decisions with legal or significant effects; advertising based on behavioral data; and cross-border transfers to jurisdictions with insufficient safeguards.

Related: Government Data Now Comes With a Classification and a Location: Reading Executive Order 119 as a Vendor Checklist explains this in detail.

What the issues are

The direction is a shift from "a thin layer for everyone" to "a thick layer for what qualifies." Routine payroll and ordinary customer records drop out of the obligation, while qualifying processing faces concrete procedures: a risk scoring matrix (a 5-by-5 grid where the high-risk band means processing cannot proceed until risks are reduced), an annual review, sign-off by the DPO (Data Protection Officer), and dated, controlled documentation. The draft allows 90 days to comply after the circular takes effect, and penalties include processing bans and fines of up to 3% of annual gross income, capped at PHP 5 million per violation.

The other issue is the numeric thresholds. For the first time, "large-scale" processing has hard numbers attached — 250 employees or 1,000 data subjects. A line that each company used to draw for itself is now drawn for everyone.

Related: Government AI Rules Reach the Vendors Too — Reading the DICT-CSC Circular as a Procurement Condition | Case Study for Japanese Companies in the Philippines explains this in detail.

Implications for your company

If your company has put even one AI tool into its operations, you will almost certainly land on the mandatory side through the AI and machine learning category. A chatbot, AI screening of job applications, or a sales-analysis AI can each qualify depending on what it processes. "We're small, so this doesn't apply to us" does not survive this category structure. On the other hand, the burden on non-qualifying processing gets lighter — so overall, the framework rewards companies that can determine for themselves what qualifies.

Part 2: Key Terms for Executives

PIA (Privacy Impact Assessment) — The exercise of mapping where personal data enters, flows through, and leaves your organization, and documenting the risks and controls along the way. It is designed as a tool for catching incidents before they happen, not as paperwork for auditors.

PIC and PIP — The PIC (Personal Information Controller) decides how data is handled — that is your company. The PIP (Personal Information Processor) processes data on the PIC's behalf — cloud providers, AI vendors, and the like. The draft allows a PIC to have its PIP carry out a PIA, but makes clear that accountability stays with the PIC.

Risk scoring matrix — A grid multiplying five levels of likelihood by five levels of impact, for a maximum score of 25. Scores of 15 and above are "Critical": the processing cannot begin until the risk is brought down.

DPO sign-off — Assessment results require the involvement and signature of the DPO (or the officer responsible for privacy compliance). A document that a staff member wrote and nobody reviewed will no longer pass.

Related: Lessons from Meta's "NameTag" Face-Recognition Controversy: Handling Biometric Data in the Philippines explains this in detail.

Part 3: Applying This to Your Company

Work through it in five steps.

StepWhat to doOutput and point
1Map processing against the eight categoriesTwo lists: what falls in scope and what does not
2Find the AI-related processing firstInclude staff pasting customer data into consumer AI tools on their own initiative
3Compare any existing PIA with the new procedureWith nothing in place, draft one for a single in-scope process rather than starting blank
4Decide how to treat vendorsThe work can be delegated; the responsibility stays with you
5Plan for the 90 days after effectivityWho, starting from which process, finishing by when

Step 1: Map every operation that uses personal data against the eight categories

List the operations where personal data moves — customer management, payroll, recruitment, marketing, inquiry handling — and judge each one against the eight categories. The deliverables here are two lists: processing that qualifies, and processing that does not. Having the second list matters, because it lets you explain what you do not need to do.

Step 2: Surface every process that involves AI first

Of the eight categories, the one Japanese companies most often miss is AI use. Check not only the tools you formally adopted but also whether staff are pasting customer information into generative AI on their own initiative. If this leaks through, the whole inventory loses credibility.

Step 3: Check whether you have an existing PIA, and how far it is from the new procedure

Companies that produced a PIA under the 2017 framework still need to check the distance to the new procedure: the scoring matrix, the annual review, signatures, and date control. Companies with nothing yet should not start from a blank page — the realistic move is to pilot the process on a single qualifying operation.

Step 4: Decide how to handle your vendors

If you outsource processing to cloud or AI vendors, the draft permits you to have the vendor conduct the PIA and to use the report in vendor selection. But as noted above, delegating the work does not delegate the accountability. I have watched system projects fail after being handed over wholesale: leave the requirements vague, and you get something that "runs but can't be used." The projects that worked were the ones where the client fixed the initial design and the decision criteria themselves, and left the implementation and day-to-day details to the vendor. A PIA follows the same shape: set the evaluation criteria yourself, and delegate the labor.

Step 5: Use the consultation and the briefing, and plan the 90 days after effectivity

If the numeric thresholds or the scope create practical problems for you, the comment window until August 14 and the August 25 briefing are your chances to say so. Then, working from the 90-day compliance window after the circular takes effect, decide who assesses which processing in what order and by when. Start after the deadline arrives and you will not make it.

Part 4: Common Failure Patterns (What Not to Do)

Mistake 1: Doing nothing because "it's only a draft"

Details may change through the consultation, but the direction — a thick layer on qualifying processing — and the fact that AI is named are unlikely to move. Given the 90-day window after effectivity, finishing just the inventory now is worth it.

Mistake 2: Assuming "the data belongs to the Japan head office (or the client)"

Even as a service provider, your company carries PIC obligations wherever it decides how data is handled. The most dangerous reading is to conclude "this doesn't concern us" without checking how your contracts split the PIC and PIP roles.

Mistake 3: Running a uniform PIA over everything

The point of the draft is proportionality. If you assess non-qualifying processing at the same depth, your staff burn out and the assessments that matter — the high-risk ones — get thin. Sort with the inventory first, then concentrate effort.

Mistake 4: Leaving it all to the DPO

The DPO signs, but the people who know how processing actually works are in each department. If the DPO does not know which AI tools the front line is using, the signed document and reality drift apart. Run the inventory across departments, and let the DPO focus on judgment and approval.

Mistake 5: Reusing your Japanese privacy-law templates as-is

The thinking is similar, but the scoring format, the annual review, and the signature and dating requirements follow the Philippine rules. Recycling the head-office template and declaring the work "done" will not survive an inspection.

Practical Tips (3 Tips)

Tip 1: Pilot on one process — Start with a company-wide program and you will stall. Pick one process that uses AI and build the data-flow map and scoring sheet for it. Once one is through, you have a template, and the rest is replication.

Tip 2: Keep the "does not qualify" list too — For processing with no obligation, write one line each on why it does not qualify. It becomes a record of your judgment and answers the questions that come later.

Tip 3: Put the annual review on the business calendar — An annual review done "when someone remembers" always gets dropped. In my own daily operations I keep services running by fixing work priorities to time slots; reviews work the same way. Put them on the same calendar as the financial close and the audit.

Bonus: How to Make Use of PH AI Works

We can work through which of your operations are likely to fall under the eight categories, and how to run the inventory of how AI tools are actually being used — in terms of your actual business. Preparing at the draft stage is reliably cheaper than scrambling to outsource after the rules take effect.

References

About the author

Author
Author

Founder / AI Engineer (36+ years in IT)

  • From Tokyo · based in Manila for 13+ years
  • 36+ years in IT (development, SEO, AI)
  • IBM Certified Generative AI Engineer
  • AI chatbots, RAG & AI agent development

A Japanese AI engineer with 36+ years in IT and 13+ years on the ground in the Philippines. I write from hands-on experience to help Japanese companies adopt AI that actually delivers results — chatbots, workflow automation, AI agents, and AI-driven marketing. Feel free to reach out in Japanese or English.

Your Competitors Are Already Using AI!

Is your business keeping up?