September 17, 2026. Outbound teams add the Philippines because it is English speaking and cheap to test, then drop it when a compliance blog says "assume GDPR, get consent." That advice is wrong twice over. The Philippines has no anti-spam statute at all, and its regulator has said in writing that cold emailing strangers is lawful. The exposure is the fields your data vendor attaches to the record, and a rule issued five months ago that reaches the companies who buy lists as well as those who scrape them.
There is no Philippine anti-spam law
There is no Philippine CAN-SPAM, no CASL and no PECR. The Senate's subject index lists spam bills and zero Republic Acts. The two that covered email, the Spam Control Act of 2011 (SB 2900) and its 2013 refiling, proposed to control "unsolicited commercial communications sent in bulk by electronic mail," and both died in committee. The later revivals, SB 2460 and SB 366, are opt-in bills for telephone and mobile subscribers and do not cover email at all. Nobody has filed an email spam bill since 2013.
The E-Commerce Act of 2000 does not fill the gap. It is an electronic transactions statute with no unsubscribe requirement, no labelling rule and no mention of unsolicited commercial communication.
So the entire exposure sits in one instrument, the Data Privacy Act of 2012 (Republic Act 10173), and in the issuances of the National Privacy Commission.
What the regulator actually approved
In Advisory Opinion No. 2023-016, dated 8 September 2023, a company asked the NPC whether the European soft opt-in works in the Philippines. The answer was blunt: "implied or inferred consent is not recognized in this jurisdiction. The data subject's consent must never be assumed, regardless of the lack of explicit objection." The soft opt-in "cannot be applied in the Philippine setting."
Most summaries stop there. The NPC did not. Applying the three part test to a company contacting people who are not yet customers, it concluded that Section 12(f) legitimate interest is "the more appropriate lawful criterion in the processing of potential customers' personal data for direct marketing communications."
NPC Circular 2023-04 then codified it. Section 14(A) provides that where processing is limited to personal information, a controller "may consider direct marketing as a legitimate interest under Section 12 (f) of the DPA and the processing will not require the consent of the data subject." The net position is the inverse of what a UK or Canadian founder expects: stricter than Europe on what counts as consent, more permissive on contacting someone cold.
The trap: education is sensitive data
Section 3(l) of RA 10173 defines sensitive personal information to include information about an individual's "race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations" and about their "health, education, genetic or sexual life."
Age and education are sensitive personal information in the Philippines, and that is load bearing. Section 13 prohibits processing sensitive personal information except in six narrow cases, and the only one realistically available for a stranger is specific prior consent. NPC Circular 2023-07 closes the door: legitimate interest "cannot be relied upon when the processing involves sensitive personal information and privileged information."
University, degree and graduation year are default fields in every major contact database. So the moment your Philippine record carries a degree, you fall out of the one basis the regulator endorsed and into a consent regime you cannot satisfy for a stranger. The NPC signposted the fix in the same opinion: "only personal information which is necessary for the company to be able to contact the potential customers must be processed." The compliant record is deliberately thin. Name, work email, company, title.
The right to object is not in the Act
Section 16 lists six data subject rights, lettered (a) to (f). The phrase "right to object" appears nowhere in the statute, and "direct marketing" appears exactly once in the whole Act, in the Section 3(d) definition, never to be used again.
The right to object lives one level down, in Rule VIII, Section 34(b) of the Implementing Rules, which covers objection "including processing for direct marketing, automated processing or profiling." On objection the controller "shall no longer process the personal data," subject only to a subpoena, an existing contract or employment relationship, or a legal obligation. None can save a cold sender, so an objection is effectively absolute, and it stops processing rather than merely sending. Removing someone from the sequence while the record sits in the CRM does not comply.
April 2026: scraped lists now taint the buyer
The most consequential recent change is NPC Advisory No. 2026-01 on data scraping of publicly available personal data, signed 13 April 2026. The law firms covered it in May. The outbound press did not. Five things it requires:
- Public availability is not consent. Data does not lose DPA protection because it is publicly accessible, and you still need a Section 12 or 13 basis.
- Scraping in breach of a website's terms is unauthorized processing. Section 4 deems it unauthorized when conducted in violation of "the terms of service or terms of use of websites or applications," and says it may give rise to criminal, civil and administrative liability.
- A Privacy Impact Assessment is mandatory, including for scraping done for you by a third party.
- Buyers must verify. Section 7(A) requires controllers obtaining data from other controllers to use "contractual or other reasonable means" to confirm it was lawfully obtained.
- Your privacy notice must name the source of publicly sourced data.
Item four is what changes procurement. Section 7(A) closes by providing that "any further processing of personal data obtained through data scraping activities under Section 4 of this Advisory shall likewise be considered unauthorized." A regulator has turned a platform's private contract terms into a public law trigger, and made the buyer of a list answerable for how the seller built it.
What the penalties say, and what happens
On paper the numbers are severe. Unauthorized processing under Section 25(a) carries one to three years and PHP 500,000 to PHP 2,000,000. Section 35 makes the maximum penalty mandatory "when the personal information of at least one hundred (100) persons is harmed, affected or involved," which any real campaign clears in one send, and Section 34 provides that an alien offender "shall be deported." Administrative fines run separately under NPC Circular 2022-01, at 0.5% to 3% of annual gross income for grave infractions, capped at PHP 5,000,000 per act. The base is gross income, not profit.
Then there is the record. A search of the NPC's published decisions, orders and press releases turns up no enforcement action about unsolicited commercial email in ten years. The docket is lending apps, banks and breach notification failures. The largest monetary outcome in any legitimate interest case on the public record is PHP 15,000 in nominal damages against Shopee, which won on the criminal counts precisely because Section 12(f) covered its processing.
Part of that is structural: the NPC cannot levy criminal fines itself, it recommends prosecution to the Department of Justice. So the near term risk is a cease and desist order and a compliance check that asks for a document most senders do not have.
Does it even reach a foreign sender?
This part is unresolved, and worth knowing before anyone quotes a scare number at you. Section 6 of the Act is conjunctive, with limbs (a), (b) and (c) joined by "and," so read literally a foreign sender needs a further link such as carrying on business in the Philippines. Rule II, Section 4 of the Implementing Rules is disjunctive and catches an act that "relates to personal data about a Philippine citizen or Philippine resident" on its own. The texts disagree, nothing resolves it, and the NPC asserts extraterritorial jurisdiction anyway.
What it means for operators
You may cold email into the Philippines, you may not treat silence as consent, and what catches you out will be your enrichment stack rather than your sequence. Strip the Philippine segment to contact fields before it reaches the CRM. Write the legitimate interest assessment down, since Circular 2023-07 makes documentation mandatory and lets the NPC demand it during a compliance check. And put a verification clause in your data vendor contract, because since April a vendor's terms of service breach is your problem too.
A thin record and a clean sending setup are the same project. If you are standing up domains and authentication for a new market, that is what our email infrastructure work covers, and the segmentation sits inside cold email marketing and lead generation.
A checklist for Philippine sends
- Document a legitimate interest assessment under Circular 2023-07 before the first send.
- Drop education, age, degree and alma mater fields from Philippine records.
- Disclose direct marketing as a purpose in your privacy notice, and name your data source.
- Honour an objection by stopping all processing, not by suppressing one address.
- Get a written lawful sourcing warranty from any vendor supplying Philippine contacts.
- Never treat a public profile as consent. The regulator has said so twice.
Frequently Asked Questions
Yes. There is no Philippine anti-spam statute, and in Advisory Opinion No. 2023-016 the National Privacy Commission said that legitimate interest under Section 12(f) of the Data Privacy Act is the appropriate lawful basis for contacting potential customers. NPC Circular 2023-04, Section 14(A) confirms that direct marketing on that basis does not require consent.
Not if you rely on legitimate interest and the record contains only personal information. You do need consent the moment the record includes sensitive personal information, and you must never treat silence or a lack of objection as consent, because the NPC has expressly rejected the European soft opt-in.
Section 3(l) of Republic Act 10173 classifies information about a person's education and age as sensitive personal information, alongside health and religion. NPC Circular 2023-07 states that legitimate interest cannot be relied on for sensitive personal information, so an enriched record carrying a degree or university falls outside the basis the regulator endorsed.
Probably, but the texts disagree. Section 6 of the Act is drafted conjunctively and appears to require a further link to the Philippines, while Rule II, Section 4 of the Implementing Rules is disjunctive and catches processing that merely relates to a Philippine citizen or resident. No NPC opinion or court ruling resolves the conflict, and the NPC has asserted extraterritorial jurisdiction in practice.
Rule VIII, Section 34(b) of the Implementing Rules says the controller shall no longer process the personal data, subject only to a subpoena, an existing contract or employment relationship, or a legal obligation. None of those apply to a cold prospect, so the objection is effectively absolute and it stops processing rather than just sending.
No enforcement action about unsolicited commercial email appears in the NPC's published decisions, orders or press releases. The only marketing campaign inquiry it has published was closed in April 2026 with no finding. The realistic near term risk is a cease and desist order or a compliance check rather than a fine.