
Is your Data Protection Officer designation actually documented, or just a name in a dropdown?
Are you asking users to "consent" to processing that's actually built on legitimate interest, weakening both?
Is your cloud provider, payment gateway, or analytics vendor processing personal data with no Data Processing Agreement behind it?
If something leaked today, would anyone know who's supposed to notify the NPC, and by when?
You're building the product; I make sure the paperwork underneath it can survive a regulator's question. From the first permission screen to your vendor contracts, we close the gap between what your app does and what your compliance file says it does.
The corporate resolution, the Secretary's Certificate, and the registration itself, done in the right order so nothing is submitted before it's actually true.
A documented risk assessment tied to your actual data flows, not a checklist copied from another company's product.
Review of onboarding, consent, and permission screens for whether the wording matches the legal basis you're actually relying on.
A procedure with named owners and a notification clock, built and rehearsed before you need it.
Practical guidance for founders, startups, and organizations building or scaling under the Data Privacy Act.
Most companies don’t need a privacy lawyer until something forces the question: a new app collecting more data than anyone planned for, a partner asking for a Data Processing Agreement you don’t have, a regulator’s form with a field nobody can answer confidently, or a board member asking whether the company is actually compliant or just hopeful.
That’s the point where a generic template stops being useful. Data privacy work in the Philippines isn’t one law — it’s the Data Privacy Act layered under NPC circulars, advisories, and sector-specific rules that change how a single clause should be written. Getting it right requires someone who reads the current issuances, not someone reciting the 2012 statute from memory.
Startups preparing to launch a product that touches personal data. Companies formalizing compliance ahead of a funding round, a partnership, or a regulatory inquiry. Founders who know something needs to be documented properly and would rather have that conversation now than after a complaint.
Disclaimer: Services listed strictly cover legal consultation, drafting, and due diligence. Fees are based on the recommended minimum fee schedule of the IBP Negros Occidental Chapter. Final legal fees will depend on the complexity of the legal matter.