
Three terms, one regulator, and almost everyone uses them interchangeably. Under the National Privacy Commission’s own rules, they aren’t interchangeable at all, and getting them backwards on your website is a small mistake with an outsized cost.
Open the footer of almost any Philippine website and you’ll find a link labeled “Privacy Policy.” Ask the founder what a Privacy Notice is, and most of the time you’ll get a blank look, followed by “isn’t that the same thing?”
It isn’t, and the distinction isn’t academic. The National Privacy Commission (NPC) has formally defined all three terms, in the same provision, precisely because organizations kept treating them as synonyms and, in doing so, kept publishing the wrong document for the wrong audience. If you’re a founder, a DPO, or the person in the office who got told to “handle the privacy policy,” this is the five-minute read that keeps you from making that mistake.
Where the definitions actually come from
All three terms are defined in one place: NPC Circular No. 2023-04, Guidelines on Consent, Section 3, under the heading “Form.” That single provision draws the line between a Privacy Statement, a Privacy Policy, and a Privacy Notice, and it’s worth reading in full if you’re the one responsible for your organization’s compliance documents.
That single-source origin is worth calling out on its own, because it’s a common misconception, including among people setting out to research this properly, that each term must trace to its own separate issuance. It doesn’t. One circular, one section, three definitions.
The three terms, side by side
| Privacy Statement | Privacy Policy (a.k.a. Privacy Manual) | Privacy Notice | |
|---|---|---|---|
| Audience | General public | Internal — officers, DPO, staff | External — the specific data subject (whose data will be processed) |
| Scope | The organization’s data practices, broadly, across the entire operation | Broad, organization-wide internal governance | One specific processing activity |
| Function | A general public-facing overview | Operational rules and instructions for staff | Tells a data subject what happens to their data for that activity, and how to exercise their rights |
| Is it consent? | No | No | No — it’s a disclosure, not a consent instrument |
| Language | Plain, general | Can be detailed and technical, since the audience is trained staff | Must be clear, plain, and understandable to an ordinary reader |
| When it’s required | Not activity-specific; optional in the sense that no single processing event triggers it | Not activity-triggered; exists as ongoing internal governance | Required for essentially every processing activity, regardless of lawful basis, subject to one narrow exception below |
Privacy Statement: the one almost nobody drafts separately
A Privacy Statement is the broadest of the three: a general account of how an organization handles personal data across its entire operation, aimed at the public rather than at any one data subject or any one processing activity. In practice, most companies fold this into their website’s general “About our data practices” page, if they have one at all, and that’s usually fine. It’s the least legally load-bearing of the three documents, because it isn’t tied to a specific processing activity the way a Notice is, and it isn’t operational instruction the way a Policy is.
Privacy Policy (Privacy Manual): the one for your own people
A Privacy Policy, which the NPC circular also permits calling a Privacy Manual, is an internal document. Its audience is your officers, your DPO, and your staff, not your customers or users. Its job is to tell the people inside your organization how personal data is supposed to be collected, used, stored, and disposed of, and what they’re expected to do to keep that compliant.
This is also the document with real operational teeth, because a separate circular, NPC Circular No. 2023-06, Security of Personal Data in the Government and the Private Sector, requires personal information controllers and processors to actually implement organizational security measures of exactly this kind, current, documented, and followed, not just written once and filed away. Read together, the two circulars answer different questions: 2023-04 tells you what to call the document and who it’s for; 2023-06 tells you that having one, and keeping it current, isn’t optional.
If your Privacy Policy is a page on your public website, that’s a strong signal something is misclassified. This document belongs in your internal compliance file, not on your homepage footer.
Privacy Notice: the one your users actually need to see
A Privacy Notice is the one that matters most to the person using your product. It’s a unilateral, specific statement addressed to a data subject, explaining a particular processing activity, what data is collected, why, who sees it, how long it’s kept, and how the data subject can exercise their rights, in language an ordinary reader can follow without a law degree.
This is also the document that’s required by default. The Circular’s rule is that a Privacy Notice must accompany essentially every instance of processing, whatever the lawful basis, consent, another criterion under Sections 12 or 13 of the Data Privacy Act, or a special case under Section 4. There’s one narrow exception: if the consent form for that specific activity already contains all the essential information a data subject needs, a separate notice isn’t required on top of it. Outside that exception, the Notice requirement applies broadly, not just to consent-based processing.
The general transparency principle behind this, that a data subject is entitled to know the nature, purpose, and extent of processing, along with their rights and how to exercise them, is itself rooted in the Implementing Rules and Regulations of the Data Privacy Act of 2012, which set transparency, legitimate purpose, and proportionality as the baseline principles for any processing activity.
The practical mix-up, and why it costs more than a wrong word
Here’s where this stops being a vocabulary lesson. If the document your app shows a user at signup is labeled “Privacy Policy,” and it reads like an internal governance manual, dense, procedural, written for compliance staff rather than a customer, you’ve handed your user the wrong document. It may not satisfy the Notice requirement at all, because a Notice has to be clear and understandable to the data subject, not merely accurate.
The reverse mistake happens too: a company writes a genuinely good, plain-language Notice, publishes it, and then has no actual internal Policy governing how its own staff handle data day to day. On paper, the public-facing side looks compliant. Internally, there’s nothing telling an employee what they’re allowed to do with a customer record, which is exactly the gap an NPC investigation, or a disgruntled former employee, tends to find.
The fix isn’t complicated once the distinction is clear:
- Your Notice goes wherever your users actually are: the onboarding screen, the signup form, the checkout page. Short, plain, specific to what’s happening right there.
- Your Policy/Manual stays internal: your compliance file, your staff handbook, what your DPO can point to during an audit.
- Your Statement, if you have one, is the general public overview, and it’s the lowest priority of the three.
One habit worth adopting
When you’re naming a document, ask who’s going to read it and why. If the answer is “a user deciding whether to tap Agree,” you’re writing a Notice, and it needs the plain-language, activity-specific treatment the Circular requires. If the answer is “an employee who needs to know what to do with a spreadsheet full of customer emails,” you’re writing a Policy, and it can be as detailed and procedural as it needs to be, because nobody outside the organization is meant to read it.
Most compliance gaps I find during a review aren’t the absence of a document. They’re the right document, doing the wrong job, because it was never clear which of the three it was supposed to be in the first place.
Sources cited in this article:
- NPC Circular No. 2023-04, Guidelines on Consent (7 November 2023), Section 3 — privacy.gov.ph
- NPC Circular No. 2023-06, Security of Personal Data in the Government and the Private Sector (1 December 2023) — privacy.gov.ph
- Implementing Rules and Regulations of Republic Act No. 10173, Data Privacy Act of 2012 — privacy.gov.ph
- Full index of NPC issuances — privacy.gov.ph/pips-and-pics/advisories-circulars
Villarosa Law Office advises founders and product teams on data privacy compliance under the Data Privacy Act, including drafting and reviewing Privacy Notices, Privacy Manuals, and DPO documentation. Schedule a conversation if you’re not sure which document your organization actually needs.