← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Philippines Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Philippine resident covered by this Annex; the Data Protection Officer ("DPO") mandated by Republic Act No. 10173 (the Data Privacy Act of 2012 — "DPA") s 21(b) read with the Implementing Rules and Regulations of the Data Privacy Act of 2012 (the "DPA IRR", in force from 9 September 2016) Rule IV Sec 14(a) and NPC Advisory No. 2017-01 on the Designation of Data Protection Officers, with business contact published as the publicly-accessible DPO contact required by DPA IRR Rule IV Sec 14(b) + NPC Advisory 2017-01 § VI.A; the designated contact point for the National Privacy Commission ("NPC"), the Philippine National Police – Anti-Cybercrime Group ("PNP-ACG"), the Philippine National Police – Women and Children Protection Center ("PNP-WCPC"), the National Bureau of Investigation – Cybercrime Division ("NBI-CCD"), the Department of Justice – Office of Cybercrime ("DOJ-OOC"), the Department of Social Welfare and Development ("DSWD"), the Inter-Agency Council Against Trafficking ("IACAT"), the Inter-Agency Council Against Child Pornography ("IACACP"), and the Council for the Welfare of Children ("CWC") under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to Republic Act No. 10173 (the Data Privacy Act of 2012 — "DPA") including any successor data-privacy bill before the Congress of the Philippines (the bicameral 19th Congress was sitting at the Effective date; several DPA-amendment bills have been filed but none enacted); (b) any amendment to the DPA IRR (NPC, in force 9 September 2016); (c) any new or amended NPC Circular — including but not limited to NPC Circular No. 16-01 (Security of Personal Data in Government Agencies), NPC Circular No. 16-02 (Data Sharing Agreements), NPC Circular No. 16-03 (Personal Data Breach Management, the predecessor regime), the principal NPC Circular No. 16-03/series-of-2016 as supplemented by NPC Circular No. 2022-01 (Administrative Fines under the Data Privacy Act), NPC Circular No. 2022-04 (Rules of Procedure on Complaints, Investigations, and Adjudications), and any successor circular on breach notification, data sharing, security of personal data, children's data, or administrative fines; (d) any new or amended NPC Advisory or NPC Advisory Opinion — including NPC Advisory No. 2017-01 (DPOs), NPC Advisory No. 2017-03 (Access Requests), and the body of NPC Advisory Opinions published at https://www.privacy.gov.ph/advisory-opinions/; (e) any decision of the NPC under DPA s 7 + DPA IRR Rule III, any decision of the Court of Appeals under DPA s 36 (judicial review of NPC decisions), or any decision of the Supreme Court of the Philippines bearing on the DPA, the right to privacy (1987 Constitution Art III Sec 3 + Art III Sec 2 + Civil Code Art 26), or the writ of habeas data (A.M. No. 08-1-16-SC); (f) any amendment to Republic Act No. 11930 (the Anti-Online Sexual Abuse or Exploitation of Children Act of 2022 — "OSAEC Law", in force from 30 July 2022) or to its IRR (DOJ-IACACP, in force 4 January 2023); (g) any amendment to Republic Act No. 9775 (the Anti-Child Pornography Act of 2009) or its IRR; (h) any amendment to Republic Act No. 7610 (the Special Protection of Children Against Abuse, Exploitation and Discrimination Act of 1992) or its IRR; (i) any amendment to Republic Act No. 11648 (the act increasing the age of sexual consent to 16, in force from 4 March 2022); (j) any amendment to Republic Act No. 10175 (the Cybercrime Prevention Act of 2012) or to its IRR (DOJ, in force 12 August 2015) including the Supreme Court's modulation of certain provisions in Disini v Secretary of Justice G.R. No. 203335, 18 February 2014; (k) any amendment to Republic Act No. 9995 (the Anti-Photo and Video Voyeurism Act of 2009); (l) any amendment to Republic Act No. 11313 (the Safe Spaces Act of 2019) covering gender-based online sexual harassment; (m) any amendment to Republic Act No. 11862 (the Expanded Anti-Trafficking in Persons Act of 2022); (n) any amendment to Republic Act No. 11967 (the Internet Transactions Act of 2023, in force from 20 January 2024) or to its IRR (DTI, in force from 7 June 2024) — the principal Philippine internet-transactions consumer-protection statute; (o) any amendment to Republic Act No. 8792 (the E-Commerce Act of 2000) or its IRR; (p) any amendment to Republic Act No. 7394 (the Consumer Act of the Philippines of 1992); (q) any amendment to Republic Act No. 4200 (the Anti-Wiretapping Act of 1965); (r) any amendment to Executive Order No. 209 (the Family Code of the Philippines, in force from 3 August 1988) or to Republic Act No. 6809 (lowering the age of majority to 18); (s) any amendment to the Civil Code of the Philippines (RA 386, in force from 18 June 1949) Article 26 (right to privacy / dignity); (t) the entry into force in the Philippines of the Convention on Cybercrime (Budapest Convention, Convention on Cybercrime of 23 November 2001) and its Second Additional Protocol (the Philippines acceded on 28 March 2018; in force for the Philippines from 1 July 2024); (u) any amendment to a sub-processor's Philippine data-handling posture under our sub-processor register; (v) the publication of any Philippine NPC Cross-Border Personal Data Transfer circular or template clauses (none at the Effective date — the operative mechanism is the DPA IRR Sec 44 + Sec 50 + NPC Advisory Opinion overlay); (w) the bringing into force of any post-Effective-date Philippine statute or regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Philippines-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Philippine resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Philippine resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The 1987 Constitution of the Republic of the Philippines Article XIV Section 7 provides that the official languages of the Philippines are Filipino and, until otherwise provided by law, English; the regional languages are auxiliary in the regions and serve as auxiliary media of instruction. Filipino translation is queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Philippine resident (the DPA does not mandate multilingual notification; the NPC's interpretive practice accepts English).


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of the Philippines — the unitary state composed of 17 administrative regions (NCR, CAR, BARMM, Regions I to XIII) and 82 provinces. There is no provincial data-protection sub-layer; the DPA is uniform nationwide.

We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies the Philippines as the country of residence, this Annex applies, even if the other signals are non-Philippine. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The DPA has explicit extraterritorial reach under DPA s 6 — the Act applies to (i) an act done or practice engaged in by an entity with a link to the Philippines; (ii) an entity with a personal-data-processing activity that has a link to the Philippines; and (iii) an entity that has other links to the Philippines, including (a) an entity that carries on business in the Philippines, and (b) an entity that maintains an office, branch, or agency in the Philippines, or carries on business outside the Philippines provided that personal information of Philippine citizens or residents is collected or held by it, or where the processing of personal information is done in the Philippines. The NPC's interpretive practice (NPC Advisory Opinion 2017-049, 2018-058, 2019-053, and the body of NPC decisions published at https://www.privacy.gov.ph/) confirms that an entity outside the Philippines is subject to the DPA in respect of its processing of personal information of Philippine residents where the entity directs activities towards the Philippines. Balance squarely targets Philippine residents through Google Play Philippines, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Philippine-resident parents and kids; the DPA applies in full.


2. Statutory framework — what applies

The Philippine personal-data-protection regime is dominated by Republic Act No. 10173 (the Data Privacy Act of 2012 — "DPA"), implemented by the DPA IRR (NPC, in force 9 September 2016) and supplemented by NPC Circulars, NPC Advisories, and NPC Advisory Opinions. Adjacent layers: Republic Act No. 11930 (OSAEC Law of 2022); Republic Act No. 9775 (Anti-Child Pornography Act of 2009); Republic Act No. 7610 (Child Protection Act of 1992); Republic Act No. 11648 (raising age of consent to 16); Republic Act No. 10175 (Cybercrime Prevention Act of 2012); Republic Act No. 9995 (Anti-Photo and Video Voyeurism Act of 2009); Republic Act No. 11313 (Safe Spaces Act of 2019); Republic Act No. 11862 (Expanded Anti-Trafficking in Persons Act of 2022); Republic Act No. 11967 (Internet Transactions Act of 2023); Republic Act No. 8792 (E-Commerce Act of 2000); Republic Act No. 7394 (Consumer Act of the Philippines of 1992); Republic Act No. 4200 (Anti-Wiretapping Act of 1965); Executive Order No. 209 (Family Code) + Republic Act No. 6809 (age of majority 18); the Civil Code of the Philippines (RA 386); the 1987 Constitution of the Republic of the Philippines; and the Rules of Court.

Instrument Short cite What it does Balance's posture
1987 Constitution of the Republic of the Philippines Constitution — Art III Bill of Rights: Sec 1 (due process + equal protection); Sec 2 (unreasonable searches and seizures); Sec 3(1) (privacy of communication and correspondence — inviolable except upon lawful order of the court, or when public safety or order requires otherwise); Sec 3(2) (exclusionary rule for evidence obtained in violation of Sec 2 or Sec 3(1)); Sec 7 (right of the people to information on matters of public concern); Sec 17 (right against self-incrimination). Art II Sec 11 (full respect for human rights); Art II Sec 12 (sanctity of family life + protection of children "from all forms of neglect, abuse, cruelty, exploitation and other conditions prejudicial to their development"); Art XV Sec 1–3 (family + parental responsibility); Art XIV Sec 7 (official languages — Filipino and English). The Supreme Court has read an enforceable right to privacy into Art III Sec 1 + 2 + 3 read together with Civil Code Art 26 (Ople v Torres G.R. No. 127685, 23 July 1998; Vivares v St. Theresa's College G.R. No. 202666, 29 September 2014; Sps. Hing v Choachuy G.R. No. 179736, 26 June 2013; Disini v Secretary of Justice G.R. No. 203335, 18 February 2014). The constitutional Writ of Habeas Data (A.M. No. 08-1-16-SC, in force 2 February 2008) is a separate constitutional remedy for any natural or legal person whose right to privacy in life, liberty, or security is violated or threatened by an unlawful act of a public official or employee, or of a private individual or entity engaged in the gathering, collecting, or storing of data or information regarding the person, family, home, and correspondence of the aggrieved party. The constitutional anchor. The right to privacy in the Philippines is constitutional (Art III + judicial doctrine + Writ of Habeas Data) AND statutory (DPA + Civil Code Art 26). Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below.
Republic Act No. 10173 — Data Privacy Act of 2012 DPA — approved 15 August 2012; in force 8 September 2012 (Sec 47). Substantive sections: Ch I General Provisions (Sec 1 title; Sec 2 declaration of policy; Sec 3 definitionspersonal information, sensitive personal information, personal information controller "PIC", personal information processor "PIP", data subject, processing, consent; Sec 4 carve-outs — government performance of duties / journalism / research / banking / regulated processing); Sec 5 scope; Sec 6 extraterritorial application (treated in § 1 above); Ch II National Privacy Commission (Sec 7 functions — administrative + quasi-judicial + recommendation power; Sec 8 confidentiality of NPC information; Sec 9 organisational structure; Sec 10 Secretariat); Ch III Processing of Personal Information (Sec 11 General Data Privacy Principles — transparency / legitimate purpose / proportionality; Sec 12 lawful bases for processing personal information — consent + contract + legal obligation + vital interest + national emergency / public order / public health / public function); Sec 13 lawful bases for processing sensitive personal information and privileged information — consent + existing law / contract + protection of life and health / lawful processing for organisations / medical treatment / protection of lawful rights and interests in court proceedings + government processing in carrying out constitutional/statutory mandates; Sec 14 subcontracting; Sec 15 extension of privileged communications; Ch IV Rights of the Data Subject (Sec 16 the eight rights — right to be informed / right to object to processing / right of access / right to correct / right to erasure or blocking / right to damages / right to data portability / right to file a complaint with NPC; Sec 17 transmissibility of rights; Sec 18 rights of next of kin); Ch V Security of Personal Information (Sec 19 non-applicability of certain Sec 16 rights in narrow circumstances; Sec 20 security obligationsappropriate organisational, physical, and technical measures); Ch VI Accountability for Transfer of Personal Information (Sec 21 accountability — the PIC is responsible for personal information under its control or custody, including information that has been transferred to a third party for processing, whether domestically or internationally); Ch VII Security of Sensitive Personal Information in Government (Sec 22–24); Ch VIII Penalties (Sec 25 unauthorized processing — 1 to 3 years + PHP 500K to 2M; Sec 26 accessing personal information due to negligence — 1 to 3 years + PHP 500K to 2M; Sec 27 improper disposal — 6 months to 3 years + PHP 100K to 1M; Sec 28 processing for unauthorized purposes — 1 year 6 months to 5 years + PHP 500K to 1M; Sec 29 unauthorized access or intentional breach — 1 to 3 years + PHP 500K to 2M; Sec 30 concealment of security breaches — 1 year 6 months to 5 years + PHP 500K to 1M; Sec 31 malicious disclosure — 1 year 6 months to 5 years + PHP 500K to 1M; Sec 32 unauthorized disclosure — 1 to 3 years + PHP 500K to 1M for personal information / 3 to 5 years + PHP 500K to 2M for sensitive personal information; Sec 33 combination of acts — 3 to 6 years + PHP 1M to 5M; Sec 34 extent of liability — responsible officers; Sec 35 large-scalemaximum penalty when 100 or more individuals are affected; Sec 36 offence committed by public officer — disqualification from public office + accessory penalties); Ch IX Miscellaneous (Sec 37 NPC operational autonomy + Sec 38–47). The principal statute. Applies in full to Balance as a PIC operating from outside the Philippines directing activities to Philippine residents (per DPA s 6 + NPC interpretive practice). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Implementing Rules and Regulations of the DPA (DPA IRR) DPA IRR — NPC, in force 9 September 2016. Rule I Preliminary Provisions; Rule II Definition of Terms; Rule III National Privacy Commission; Rule IV Data Protection Officers (Sec 14 mandatory DPO designation; Sec 14(a) PIC and PIP must designate a DPO; Sec 14(b) the DPO's contact details must be made publicly available; the DPO need not be a citizen or resident of the Philippines but must be readily accessible); Rule V Lawful Processing of Personal Data (Sec 17 transparency; Sec 18 criteria for lawful processing of personal information; Sec 19–21 criteria for lawful processing of sensitive and privileged information; Sec 22 subcontracting); Rule VI Security Measures for the Protection of Personal Data (Sec 25 organisational + Sec 26 physical + Sec 27 technical security measures); Rule VII Security of Sensitive Personal Information in Government (Sec 28–33); Rule VIII Rights of Data Subjects (Sec 34 enumeration; Sec 34(a) Right to be informed; Sec 34(b) Right to object; Sec 34(c) Right to access; Sec 34(d) Right to rectification; Sec 34(e) Right to erasure or blocking; Sec 34(f) Right to damages; Sec 34(g) Right to data portability + Sec 36 right to data portability; Sec 35 transmissibility); Rule IX Data Breach Notification (Sec 38 notification of breach + Sec 39 mandatory notification of NPC and affected data subjects within 72 hours from knowledge of, or reasonable belief by, the PIC or PIP that a personal data breach has occurred where (a) the breach involves sensitive personal information or any other information that may be used to enable identity fraud; and (b) the personal information involved has been acquired by an unauthorised person or persons; and (c) the unauthorised acquisition is likely to give rise to a real risk of serious harm; Sec 40 form of notification; Sec 41 contents of notification; Sec 42 delay in notification; Sec 43 breach report to NPC); Rule X Accountability for Transfer of Personal Data (Sec 44 PIC is responsible for personal data under its control + custody; Sec 45 outsourcing; Sec 50 contract or other legal arrangement for outsourcing/subcontracting + cross-border transfer accountability requirements; the legally enforceable obligation construct is implemented through Data Sharing Agreements + Outsourcing/Sub-Processing Agreements under NPC Circular 16-02); Rule XI Registration of Data Processing Systems (Sec 47 mandatory registration of data processing systems with the NPC where the PIC processes personal data of more than 1,000 individuals OR processes sensitive personal information of at least 1,000 individuals OR uses 250+ employees or processes data on more than 1,000 individuals; Balance's processing surface engages the registration trigger and is covered by § 8.3 below); Rule XII Rules on Accountability (Sec 49 PIC + PIP responsibilities); Rule XIII Miscellaneous Provisions; Rule XIV Penalties + Sec 60 right to information from PIC. The principal interpretive layer of the DPA. Applies in full. Treatment in §§ 3, 4, 6, 8, 11 below.
NPC Circular No. 16-01 NPC Circular 16-01 — Security of Personal Data in Government Agencies (in force 10 October 2016). Applies to government agencies only; Balance is a private PIC and Circular 16-01 is not directly engaged. Applied as an interpretive guide for the technical/physical/organisational security standard at DPA IRR Rule VI Sec 25–27.
NPC Circular No. 16-02 NPC Circular 16-02 — Data Sharing Agreements Involving Government Agencies (in force 10 October 2016). Applies to data sharing involving government agencies; Balance does not engage in data sharing with Philippine government agencies in the operational flow. Applied as an interpretive guide for the contractual-clauses substance of any cross-border processor arrangement.
NPC Circular No. 16-03 NPC Circular 16-03 — Personal Data Breach Management (in force 15 December 2016). Implements DPA IRR Rule IX. Mandatory NPC notification within 72 hours from knowledge of the breach + mandatory affected-data-subject notification + mandatory annual security incident report. Applies in full. Treatment in § 11 below.
NPC Circular No. 2022-01 NPC Circular 2022-01 — Guidelines on Administrative Fines Imposed by the National Privacy Commission (in force 13 March 2022). Establishes the administrative-fine schedule for DPA violations: (i) grave infractions — fine of 0.5% to 3% of annual gross income of the immediately preceding year, or PHP 50,000 to PHP 5,000,000 per violation, whichever is higher; (ii) major infractions — fine of 0.25% to 2% of annual gross income, or PHP 50,000 to PHP 4,000,000; (iii) other infractions — fine of 0.5% of annual gross income, or PHP 25,000 to PHP 3,000,000. Sets the administrative-penalty layer. Applies in full alongside the criminal penalty stack at DPA Chapter VIII.
NPC Circular No. 2022-04 NPC Circular 2022-04 — Rules of Procedure of the National Privacy Commission (in force from 23 June 2022) — supersedes NPC Circular No. 16-04. Sets the procedural rules for NPC complaints, sua sponte investigations, compliance checks, mediation, adjudication, and appeals to the Court of Appeals under DPA s 36. Applies in full as the NPC procedural layer.
NPC Advisory No. 2017-01 NPC Advisory 2017-01 — Designation of Data Protection Officers (issued 14 March 2017). The DPO designation is mandatory; the DPO's contact details must be publicly available; the DPO need not be a Filipino citizen or Philippine resident but must be readily accessible during regular Philippine business hours. Applied in full. The Balance DPO is , contactable at . Publication satisfies the public-availability requirement.
NPC Advisory No. 2017-03 NPC Advisory 2017-03 — Access to Personal Data by Data Subjects. Applies as interpretive guidance for DPA Sec 16(c) + DPA IRR Sec 34(c) access right.
NPC Advisory Opinions The body of NPC Advisory Opinions published at https://www.privacy.gov.ph/advisory-opinions/, including opinions on extraterritorial scope, cross-border transfer, processor agreements, children's data, and breach notification. Applied as persuasive interpretive guidance.
Republic Act No. 11930 — Anti-Online Sexual Abuse or Exploitation of Children Act of 2022 (OSAEC Law) OSAEC Law — approved 30 July 2022; in force 4 August 2022 (15 days after publication in the Official Gazette on 20 July 2022). Implements the Convention on the Rights of the Child + the Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (Philippines ratified 28 May 2002). Sec 3 definitions including child, online sexual abuse or exploitation of children ("OSAEC"), child sexual abuse or exploitation material ("CSAEM"), Internet intermediary; Sec 4 unlawful or prohibited acts (commission of OSAEC; production, distribution, offering, or sale of CSAEM); Sec 5 unlawful acts of Internet intermediaries (failure to remove CSAEM after notice; failure to retain data; failure to report); Sec 7 offences and penalties (imprisonment up to reclusion perpetua + fines up to PHP 5,000,000); Sec 9–13 procedural overlay (warrant to disclose computer data; cybertip line; Internet intermediary preservation orders; international cooperation); Sec 12 duties of Internet intermediaries — (a) maintain a mechanism to immediately report OSAEC; (b) preserve data for 6 months from receipt of takedown order; (c) provide information to law-enforcement upon issuance of warrant; (d) report incidents to PNP-WCPC or NBI-CCD within 7 days; (e) deploy reasonable steps to prevent and detect OSAEC and CSAEM; Sec 18 establishment of the Inter-Agency Council Against Child Pornography ("IACACP") chaired by DSWD with DOJ as principal implementing agency. The OSAEC IRR (DOJ-IACACP, in force 4 January 2023) operationalises Secs 4, 5, 7, 9–13, and 18. The principal Philippine OSAEC + child-safety statute. Balance's posture is described in §§ 5, 13, and 14 below. Balance is best characterised as a private parental-control client that does not host third-party content publicly, does not enable user-to-user communication outside the parent-kid pairing of a single household, and does not constitute an "Internet intermediary" within the OSAEC Law's definition (the OSAEC Law's Internet intermediary definition tracks search engines, social-media platforms, ISPs, and hosting providers); Balance nevertheless cooperates with PNP-WCPC, NBI-CCD, DSWD, IACACP, and the National Coordination Centre Against OSAEC (NCCAOC) per § 14 below.
Republic Act No. 9775 — Anti-Child Pornography Act of 2009 RA 9775 — approved 17 November 2009; in force 8 December 2009. Definitions Sec 3 + Sec 4 unlawful acts (production, distribution, sale, possession, hiring or employment of a child for production of CSAM; failure of an ISP to notify; failure of a photo or video developing service to notify); Sec 5 syndicated child pornography; Sec 6 + 7 + 8 + 9 penalties; Sec 10 Internet service provider obligations to report and retain; Sec 11 mall owners' duties; Sec 19–22 Inter-Agency Council Against Child Pornography (IACACP). The principal pre-OSAEC anti-CSAM statute (overlaid by RA 11930 OSAEC). Applies. Treatment in § 14 below.
Republic Act No. 7610 — Special Protection of Children Against Abuse, Exploitation and Discrimination Act of 1992 RA 7610 — approved 17 June 1992; in force 5 July 1992. Articles I–XI: best-interest principle Art I Sec 2; child defined as below 18 OR over 18 but unable to fully take care of or protect himself/herself from abuse, neglect, cruelty, exploitation or discrimination because of a physical or mental disability or condition; Art III child abuse / child trafficking / obscene publications; Art VI offences (Sec 5 child prostitution + Sec 6 attempt to commit child prostitution); Art XI Bantay Bata Hotline. The foundational child-protection statute. Applies. Treatment in § 5 + § 14 below.
Republic Act No. 11648 — Increasing the Age of Sexual Consent to 16 (2022) RA 11648 — approved 4 March 2022; in force 4 March 2022. Amends Revised Penal Code Art 266-A (Rape) + Art 266-B + RA 8353 + RA 7610 + RA 9262. Raises the age of sexual consent from 12 to 16. Applies as a context-setting fact. Cross-reference in § 14 below.
Republic Act No. 10175 — Cybercrime Prevention Act of 2012 RA 10175 — approved 12 September 2012. Substantive sections: Ch II Punishable Acts — Sec 4(a) offences against the confidentiality, integrity and availability of computer data and systems (illegal access, illegal interception, data interference, system interference, misuse of devices, cyber-squatting); Sec 4(b) computer-related offences (forgery, fraud, identity theft); Sec 4(c) content-related offences (cybersex, child pornography through a computer system, unsolicited commercial communications, libel — libel through a computer system upheld in part by Disini v Secretary of Justice G.R. No. 203335, 18 February 2014, with the unconstitutional elements struck down); Sec 5 attempt + aiding or abetting (the aiding or abetting clause was upheld for the Sec 4(a)–(b) computer-confidentiality offences but struck down by the Supreme Court for the Sec 4(c) content offences); Sec 6 higher penalty (one degree higher than equivalent Revised Penal Code offence); Sec 7 plurality of crimes (also struck down as to libel + child pornography in Disini); Sec 13 preservation of computer data (6 months extendible by another 6 months upon order); Sec 14 disclosure of computer data via court-issued warrant; Sec 15 search/seizure/examination of computer data via court warrant; Sec 17 destruction of computer data; Sec 24 DOJ Office of Cybercrime — central authority; Sec 26 PNP and NBI as primary investigating bodies. IRR in force 12 August 2015. The principal cybercrime statute. Applies. Treatment in § 13 below.
Republic Act No. 9995 — Anti-Photo and Video Voyeurism Act of 2009 RA 9995 — approved 17 February 2009; in force 23 March 2009. Criminalises capture and copying/reproduction/sale/distribution/publication of any picture/video of a person's private area without consent. The principal intimate-image-non-consensual-distribution statute. Applies. Treatment in § 14 below.
Republic Act No. 11313 — Safe Spaces Act of 2019 RA 11313 — approved 17 April 2019; in force 3 August 2019. Definitions Sec 3. Sec 12 gender-based online sexual harassment — penalties for use of information and communications technology in terrorising and intimidating victims through physical, psychological, and emotional threats; unwanted sexual misogynistic, transphobic, homophobic and sexist remarks and comments online; invasion of victim's privacy through cyber-stalking; non-consensual photo/video sharing; etc. Sec 13 PNP Anti-Cybercrime Group designated as a Women and Children Cyber Protection Unit (WCCPU). Applies. Treatment in § 14 below.
Republic Act No. 11862 — Expanded Anti-Trafficking in Persons Act of 2022 RA 11862 — approved 23 June 2022. Amends RA 9208 (Anti-Trafficking in Persons Act of 2003). Expands liability of Internet intermediaries; sets up the IACAT (Inter-Agency Council Against Trafficking). The principal anti-trafficking-of-children statute. Applies. Treatment in § 14 below.
Republic Act No. 11967 — Internet Transactions Act of 2023 RA 11967 — approved 5 December 2023; in force 20 January 2024. IRR (DTI, in force 7 June 2024). Sec 2 declaration of policy — protect consumer rights in internet transactions. Sec 3 definitions including digital platform, e-marketplace, e-retailer, online merchant, online consumer. Sec 4 scope — covers any internet transaction with a nexus to the Philippines (consumer located in the Philippines; merchant offering goods/services through a digital platform accessible in the Philippines; etc.). Sec 5 functions of the Department of Trade and Industry (DTI) + the new e-Commerce Bureau as the principal regulatory authority. Sec 7 obligations of digital platforms, e-marketplaces, e-retailers, and online merchants — including registration with DTI; complaint-handling mechanism; protection of consumer privacy in coordination with NPC; cooperation with DTI takedown directives; mandatory complaint mechanism reachable within 5 working days; refund mechanism. Sec 8 consumer rights — clear pricing, accurate description, right to cancel, right to refund, protection from misleading advertising. Sec 22 prohibited acts. Sec 23–26 offences + penalties. The principal Philippine internet-transactions consumer-protection statute. Applies. Treatment in § 16 below.
Republic Act No. 8792 — E-Commerce Act of 2000 RA 8792 — approved 14 June 2000. Recognition of electronic documents and electronic signatures + electronic contracts + consumer-protection overlay on electronic transactions. Applies. Subordinate to RA 11967 (which governs internet transactions specifically).
Republic Act No. 7394 — Consumer Act of the Philippines (1992) RA 7394 — approved 13 April 1992. Art 50 deceptive sales practices; Art 52 unfair or unconscionable sales practices; Title III Consumer Product and Service Warranties; Art 100 liability for defective products; Art 101 liability for defective services; Title V Consumer Protection Against Hazards to Health and Safety; enforced by the DTI + the Department of Health (DOH) + the Bureau of Food and Drugs + the Philippine Competition Commission (PCC) under RA 10667. The foundational Philippine consumer-protection statute. Applies in full alongside RA 11967. Treatment in § 16 below.
Republic Act No. 4200 — Anti-Wiretapping Act of 1965 RA 4200 — approved 19 June 1965. Prohibits wire-tapping + recording private communications without the consent of all parties. Court-ordered exception under RA 4200 Sec 3 with judicial process for specific enumerated offences (treason, espionage, sedition, kidnapping, etc.). Applies. Treatment in § 13 below — relevant to E2EE posture and lawful-access framework.
Executive Order No. 209 — Family Code of the Philippines (1988) + RA 6809 (1989) Family Code — in force 3 August 1988. Art 209–225 Parental Authority — joint parental authority of father and mother (Art 211); in case of separation, parental authority is exercised by the parent designated by the court (Art 212); Art 220–221 parental rights and duties; Art 234 age of emancipation (originally 18; modified by RA 6809 to age of majority 18 absolute). RA 6809 — in force 18 December 1989 — sets the age of majority at 18. The principal parental-authority framework. Applies. Treatment in § 5 + § 7 below.
Civil Code of the Philippines — Republic Act No. 386 (1949) Civil Code — approved 18 June 1949; in force 30 August 1950. Art 26 every person shall respect the dignity, personality, privacy and peace of mind of his neighbours and other persons — a tort-style cause of action for violation of privacy, dignity, and peace of mind, independent of the constitutional and DPA layers. Art 32 any public officer or employee, or any private individual, who directly or indirectly obstructs, defeats, violates or in any manner impedes or impairs any of the enumerated civil rights and liberties of another person (including the right to privacy of communication and correspondence under Art III Sec 3) shall be liable to the latter for damages. Art 1305 et seq. contracts (offer, acceptance, consideration); Art 1318 essential requisites of contracts; Art 1327 + 1390 incapacity to give consent — minors below 18 (under Art 234 Family Code + RA 6809); Art 1397 voidable contracts entered into by minors. Art 2199 + 2217–2220 actual + moral damages. The principal civil-law privacy + contracts framework. Applies. Treatment in §§ 6, 13, 16 below.
Writ of Habeas Data — A.M. No. 08-1-16-SC (Supreme Court Rule, in force 2 February 2008) Habeas Data — constitutional writ. Any aggrieved party may file a petition before a Regional Trial Court / Sandiganbayan / Court of Appeals / Supreme Court (concurrent jurisdiction). The writ is a remedy for any natural or legal person whose right to privacy in life, liberty, or security is violated or threatened by an unlawful act of (a) a public official or employee, or (b) a private individual or entity engaged in the gathering, collecting, or storing of data or information regarding the person, family, home, and correspondence of the aggrieved party. Reliefs available: (i) updating, rectification, suppression, or destruction of the database or information; (ii) injunctive relief; (iii) damages (with the court referring damages to ordinary civil court). The constitutional remedy for data subjects in the Philippines. Applies. Treatment in §§ 6, 13 below.
EU adequacy None. The Philippines does not hold an EU adequacy decision under GDPR Art 45 at the Effective date. EU/EEA → Philippines transfers are governed by EU SCCs + Transfer Impact Assessment. Cross-reference in EU / EEA annex § 8. The absence of EU adequacy does not affect Balance's posture because Balance has no Philippine data residency (the backend is in the US — see § 9 below).
APEC Cross-Border Privacy Rules (CBPR) The Philippines is a participating economy in the APEC Cross-Border Privacy Rules (CBPR) system since 2020 and in the APEC Privacy Recognition for Processors (PRP) system since 2020. The Philippine Accountability Agent is the National Privacy Commission. The APEC CBPR is one of the recognised cross-border-transfer mechanisms under the DPA IRR Sec 50 legally enforceable obligation framework. Applies as a context-setting fact (Balance relies on the DPA IRR Sec 50 contract route rather than APEC CBPR certification at the Effective date).
Convention 108 / Convention 108+ Not applicable. The Philippines is not a party to the Council of Europe Convention 108 or Convention 108+. Applies as a context-setting fact. Not engaged.
Budapest Convention on Cybercrime The Philippines acceded on 28 March 2018 and the Convention entered into force for the Philippines on 1 July 2024. The Second Additional Protocol on Enhanced Co-operation and Disclosure of Electronic Evidence has been signed and is being considered for ratification. Applies as a substantive overlay on the lawful-access framework. Treatment in § 13 below.

(Any prospective Philippine regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date NPC Circular in that area, the DICT's voluntary National AI Strategy Roadmap, any future Philippine AI Act or AI Development and Regulation Bill before the Congress of the Philippines, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Philippine regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 NPC — National Privacy Commission

The principal supervisory authority is the National Privacy Commission ("NPC"), an independent body attached to the Department of Information and Communications Technology (DICT) under DPA Sec 7 + DPA IRR Rule III. The NPC has administrative, quasi-judicial, recommendation, and rule-making powers under DPA Sec 7. The NPC's decisions are appealable to the Court of Appeals under DPA Sec 36.

Field Value
Name National Privacy Commission (NPC)
Headquarters 5th Floor, Delegation Building, Philippine International Convention Center (PICC) Complex, Vicente Sotto Street, Pasay City 1307, Metro Manila
Website https://www.privacy.gov.ph/
Complaint channel NPC online complaint portal at https://www.privacy.gov.ph/file-a-complaint/, or NPC Mediation Form; email info@privacy.gov.ph and complaints@privacy.gov.ph
Phone +63 2 8234 2228
Mandatory-Breach-Notification channel NPC online Personal Data Breach Notification portal per DPA IRR Sec 38 + NPC Circular 16-03 — at https://dbnms.privacy.gov.ph/ — submission within 72 hours of knowledge of, or reasonable belief by the PIC of, a notifiable breach
Commissioner At the Effective date — published at https://www.privacy.gov.ph/about-us/

The NPC is the first-line forum for any DPA-grounded complaint from any Philippine resident. A Philippine resident may petition the NPC after first raising the matter with Balance (per NPC Circular 2022-04 § II.A and NPC Advisory 2017-03 — the NPC's published policy is exhaust internal remedies first). We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the DPO under DPA Sec 21(b) + DPA IRR Rule IV Sec 14) and respond within the DPA timelines (see § 6 below).

A Philippine resident may also pursue private remedies via (i) the Writ of Habeas Data (A.M. No. 08-1-16-SC); (ii) the Civil Code Art 26 / Art 32 cause of action; (iii) the Right to Damages under DPA Sec 16(f) (judicial action for damages); (iv) the criminal-complaint route under DPA Ch VIII to the Office of the Prosecutor / DOJ.

3.2 DICT — Department of Information and Communications Technology

The Department of Information and Communications Technology ("DICT") is the parent department of the NPC and the principal ICT-policy department of the Philippine government, established by Republic Act No. 10844 (the DICT Act of 2015).

Field Value
Name Department of Information and Communications Technology (DICT)
Headquarters C.P. Garcia Avenue, Diliman, Quezon City 1101, Metro Manila
Website https://dict.gov.ph/
Phone +63 2 8920 0101

3.3 Other regulatory bodies

Body Subject matter URL
Department of Justice (DOJ) — Office of Cybercrime (OOC) RA 10175 Cybercrime Prevention Act — central authority for cybercrime; international cooperation; warrant for disclosure of computer data https://cybercrime.doj.gov.ph/
Philippine National Police – Anti-Cybercrime Group (PNP-ACG) RA 10175 cybercrime investigation; RA 11930 OSAEC https://acg.pnp.gov.ph/
Philippine National Police – Women and Children Protection Center (PNP-WCPC) Cyber-CSAE; RA 7610; RA 9775; RA 11930 OSAEC https://wcpc.pnp.gov.ph/
National Bureau of Investigation – Cybercrime Division (NBI-CCD) RA 10175 cybercrime; CSAE; financial cyber-fraud https://nbi.gov.ph/
Department of Social Welfare and Development (DSWD) RA 7610 + RA 11930 child-protection lead agency; chairs IACACP https://www.dswd.gov.ph/
Council for the Welfare of Children (CWC) Child-welfare coordinating body https://cwc.gov.ph/
Inter-Agency Council Against Trafficking (IACAT) RA 9208 / RA 11862 anti-trafficking https://iacat.gov.ph/
Inter-Agency Council Against Child Pornography (IACACP) RA 9775 + RA 11930 OSAEC via DSWD
Department of Trade and Industry (DTI) — e-Commerce Bureau RA 11967 Internet Transactions Act + RA 7394 Consumer Act https://www.dti.gov.ph/
Philippine Competition Commission (PCC) RA 10667 competition law https://www.phcc.gov.ph/
Commission on Human Rights (CHR) Human rights including privacy (constitutional remedy auxiliary) https://chr.gov.ph/
Bantay Bata 163 (ABS-CBN Foundation) Child-protection helpline https://www.bantaybata163.com/ — Hotline 163
Stairway Foundation Children online-safety NGO https://www.stairwayfoundation.org/
End Child Prostitution and Trafficking (ECPAT) Philippines CSAE advocacy https://www.ecpat.org/

3.4 The DPO

DPA Sec 21(b) + DPA IRR Rule IV Sec 14 + NPC Advisory 2017-01 require every PIC and PIP to designate one or more Data Protection Officers. NPC Advisory 2017-01 § VI.A + DPA IRR Rule IV Sec 14(b) require that the DPO's contact details be made publicly available (typically on the PIC's website). The DPO need not be a Filipino citizen or Philippine resident but must be readily accessible during regular Philippine business hours.

The Balance DPO is:

The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying DPA IRR Rule IV Sec 14(b) + NPC Advisory 2017-01 § VI.A. The DPO is the contact point for the NPC on any regulatory matter and for data subjects on rights-exercise matters.


4. Lawful bases — DPA Sec 12 + Sec 13 + DPA IRR Sec 18–21

The DPA is a multi-basis regime modulated by the General Data Privacy Principles at DPA Sec 11 (transparency / legitimate purpose / proportionality). Balance processes personal data of Philippine residents on the following DPA mapping:

Processing purpose DPA basis Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) DPA Sec 12(a) consent (parent's express consent at sign-up) + DPA Sec 12(b) contract (processing necessary for the performance of a contract to which the data subject is a party) + DPA IRR Sec 18 + Sec 19 + DPA Sec 11 general principles H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data DPA Sec 12(a) consent of the parent (given on behalf of the kid under Family Code Art 220–225 parental authority + Civil Code Art 1327 + 1390 incapacity of minors below 18) + DPA IRR Sec 18 + the most-protective reading of the DPA's transparency + proportionality principles + NPC interpretive practice in NPC Advisory Opinions on children's data § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts DPA Sec 12(a) + Sec 12(b) (primary purpose) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access DPA Sec 12(f) legitimate interests pursued by the PIC (read with DPA Sec 11 proportionality + DPA Sec 20 security obligation) H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations DPA Sec 12(c) compliance with a legal obligation to which the PIC is subject § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data DPA Sec 12(a) — collection of the parent's personal data for the primary purpose of obtaining VPC § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data DPA Sec 12(b) contract — necessary for the performance of the subscription contract; RA 11967 + RA 7394 + RA 8792 consumer-protection overlay in § 16 below H4; § 16 below

Balance does not process sensitive personal information under DPA Sec 3(l) + DPA Sec 13 in respect of any Philippine resident (no race, ethnic origin, marital status, age, colour, religious, philosophical or political affiliations; no health, education, genetic or sexual life, or proceedings; no government-issued ID number, social security number, licence, tax return, etc.).

Balance does not collect any government-issued identification number of any Philippine resident — including the Philippine Identification System (PhilSys) Number ("PSN"), the PhilSys Card Number ("PCN") issued under RA 11055 (the Philippine Identification System Act of 2018), the Taxpayer Identification Number ("TIN"), the Social Security System number ("SSS"), the Government Service Insurance System number ("GSIS"), the PhilHealth number, the Pag-IBIG number, the driver's licence number, or the passport number. DPA Sec 13 + RA 11055 Sec 12 + the NPC's Advisory Opinion on the Collection of Government-Issued ID Numbers impose strict limits on the collection of such numbers; Balance's posture aligns: none collected.


5. Children's rights overlay

The Philippines does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the DPA + the DPA IRR + the NPC's Advisory Opinions on children's data; (ii) the 1987 Constitution Art II Sec 12 + Art XV Secs 1–3; (iii) RA 7610 (Special Protection of Children); (iv) RA 11930 (OSAEC Law); (v) RA 9775 (Anti-Child Pornography); (vi) RA 11648 (age of consent 16); (vii) the Family Code Arts 209–225 (parental authority) + RA 6809 (age of majority 18); (viii) the Civil Code Arts 1327 + 1390 (incapacity of minors); (ix) the UN Convention on the Rights of the Child (Philippines ratified 21 August 1990); (x) the Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (Philippines ratified 28 May 2002).

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Philippine kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Philippine residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the DPA + the Writ of Habeas Data + Civil Code Art 26 / Art 32.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the DPA + Family Code Arts 209–225 parental authority + Civil Code Art 1327 + 1390 + RA 7610 + RA 11930.

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. This is consistent with: (i) RA 7610 Art III Sec 12 prohibitions; (ii) the DTI's Department Administrative Order on advertising to children; (iii) the NPC's interpretive position on the use of children's data for direct marketing; (iv) RA 11930 OSAEC posture on child-online safety. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

The principal Philippine child-protection bodies are: (i) DSWD — the principal child-welfare lead agency; (ii) PNP-WCPC — Women and Children Protection Center; (iii) PNP-ACG — Anti-Cybercrime Group with the Women and Children Cyber Protection Unit under RA 11313 Sec 13; (iv) NBI-CCD — Cybercrime Division; (v) IACACP — Inter-Agency Council Against Child Pornography (chaired by DSWD); (vi) IACAT — Inter-Agency Council Against Trafficking; (vii) CWC — Council for the Welfare of Children; (viii) Bantay Bata 163 — ABS-CBN Foundation 24-hour child-protection helpline; (ix) Stairway Foundation — children's online-safety NGO; (x) ECPAT Philippines; (xi) the DSWD 1383 hotline — child-protection helpline; (xii) the 1343 Actionline — IACAT anti-trafficking hotline. Balance cooperates with each on incidents involving Philippine kids — see § 14 below.


6. DPA rights catalogue

6.1 The rights catalogue

A Philippine resident has the following rights under the DPA Sec 16 + DPA IRR Sec 34 + Sec 36 as in force at the Effective date.

6.2 Timeline

Where the access carve-outs at DPA IRR Sec 37 apply (national security, public order, public safety, prevention/investigation/prosecution of criminal offences, regulatory enforcement, court proceedings, journalism, research), Balance may decline to provide access and explain the reasons.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.

6.4 Fees

Under DPA IRR Sec 34(c) + NPC interpretive practice, a PIC may charge a reasonable fee for processing an access request, provided the fee is not excessive. Balance does not charge for access in practice.

6.5 Language

A request may be submitted in English or Filipino. The NPC accepts complaints in English and Filipino.


7. Children's data — DPA + Family Code parental authority + RA 7610 + RA 11930

Balance processes personal data of Philippine kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from the Philippines — DPA Sec 21 + DPA IRR Sec 44 + Sec 50

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Philippine resident's personal data leaves the Philippines at the point of being uploaded to the Balance backend.

8.1 The Philippines-to-US transfer mechanism — DPA Sec 21 + DPA IRR Sec 44 + Sec 50

DPA Sec 21 is the accountability principle: each PIC is responsible for personal information under its control or custody, including information that has been transferred to a third party for processing, whether domestically or internationally, subject to cross-border arrangements and cooperation. DPA IRR Sec 44 + Sec 50 operationalise the accountability principle by requiring the PIC to (i) use contractual or other reasonable means to provide a comparable level of protection while the personal data is being processed by the third party (Sec 44); (ii) maintain a written outsourcing/subcontracting agreement that imposes obligations on the PIP including security, breach notification, audit, retention, and return/destruction at end of engagement (Sec 50).

Balance relies on the following stack to satisfy DPA Sec 21 + DPA IRR Sec 44 + Sec 50 for the Philippines → US transfer:

8.2 The Philippines-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Philippines-KZ axis is covered by the DPA IRR Sec 50 written outsourcing/subcontracting agreement — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.3 NPC registration of data processing systems

DPA IRR Rule XI Sec 47 requires PICs to register their data processing systems with the NPC where the PIC processes personal data of more than 1,000 individuals OR processes sensitive personal information of at least 1,000 individuals OR uses 250+ employees or processes data on more than 1,000 individuals. Balance's projected user base at and after the Philippine rollout crosses the 1,000-individual personal-data threshold. Balance will register its data processing systems with the NPC via the NPC Registration System portal at https://register.privacy.gov.ph/ once the operational rollout threshold is reached and will maintain the registration as required. The registration filing is tracked at our internal compliance tracker.


9. Data residency for Philippine residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Philippine resident's personal data held in the Philippines? No. Every Philippine resident's personal data is held in the United States. The DPA Sec 21 + DPA IRR Sec 44 + Sec 50 transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there a Philippines establishment? No. Balance has no permanent establishment in the Philippines. The DPA's extraterritorial reach (Sec 6 + NPC interpretive practice) is the basis for Balance's DPA compliance.
Where is the supervisory authority? The Philippines — NPC + DICT + the regulatory bodies in § 3.3 above.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. The Philippines does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Bangko Sentral ng Pilipinas Circular No. 982 of 2017 on outsourcing by banks — not applicable to Balance) and the National ID System under RA 11055 (data of the PhilSys database must be stored within the Philippines — Balance does not process PhilSys data).


10. Sub-processors touching Philippine-resident data

Sub-processor Role Location of processing Philippine transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States DPA IRR Sec 50 written outsourcing agreement with DPA-comparable-protection clauses + DPA Sec 12(a) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) DPA IRR Sec 50 written outsourcing agreement (Google Cloud Data Processing Addendum) + DPA Sec 12(a) consent; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) DPA IRR Sec 50 written outsourcing agreement (Google Cloud Data Processing Addendum) + DPA Sec 12(a) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Philippine kid + parent devices United States DPA IRR Sec 50 + DPA Sec 12(a) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States DPA IRR Sec 50 + DPA Sec 12(a) as above.
Google LLC — Google Play Billing Processes subscription purchases United States DPA IRR Sec 50 + DPA Sec 12(a) + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Philippine parent users United States DPA IRR Sec 50 + DPA Sec 12(a).

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + DPA Sec 20 security obligation. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification — DPA IRR Sec 38 + NPC Circular 16-03 (Personal Data Breach Management)

DPA IRR Sec 38–43 + NPC Circular No. 16-03 (Personal Data Breach Management, in force from 15 December 2016) is the principal breach-notification regime, with a 72-hour deadline for NPC notification:

Audience Trigger Deadline Channel
NPC A notifiable personal data breach has occurred — defined at DPA IRR Sec 38 as a breach where (a) the personal data involves sensitive personal information or any other information that may be used to enable identity fraud; and (b) the personal information has been acquired by an unauthorised person; and (c) the unauthorised acquisition is likely to give rise to a real risk of serious harm to any affected data subject. Within 72 hours from knowledge of, or reasonable belief by, the PIC or PIP that a personal data breach requiring notification has occurred (DPA IRR Sec 38 + NPC Circular 16-03 § III.B). Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery (matched to the GDPR Art 33 benchmark and DPA IRR Sec 38). NPC online Data Breach Notification Management System at https://dbnms.privacy.gov.ph/
Affected individuals Same trigger as NPC notification. Within 72 hours from the same knowledge/reasonable-belief trigger (DPA IRR Sec 38 + NPC Circular 16-03 § III.C), individually OR via mass-media or alternative means where individual notification is not practicable. Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English.
OSAEC-specific An incident with a CSAE/OSAEC component. Per § 14 below + the internal runbook (M1). PNP-WCPC + NBI-CCD + DSWD + IACACP.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under DPA IRR Sec 38 completed within 72 hours of discovery, NPC notification within the statutory 72-hour deadline, affected-individual notification within the same 72-hour window unless a NPC Circular 16-03 § III.C delay carve-out applies (notification likely to compromise an ongoing investigation; the data has been rendered unintelligible; etc.).

11.1 Minimum content of the NPC notification (DPA IRR Sec 41 + NPC Circular 16-03 § IV)

The NPC notification states: - the nature of the breach, the description of how the breach happened, the personal data possibly involved, the chronology of the events leading up to the loss of control of the personal data; - the number of data subjects involved (or the best estimate); - the description of the likely consequences of the breach; - the measures taken or proposed to be taken to address the breach (including measures to mitigate possible harm or negative consequences); - the name and contact details of the DPO (, named individual: ) — the contact from whom the affected data subjects may obtain additional information.

The English-language template lives in our breach-notification runbook § 8.1.

11.2 Non-compliance — DPA Ch VIII + NPC Circular 2022-01

11.3 Annual security incident report

DPA IRR Sec 43 + NPC Circular 16-03 § V require PICs to submit an Annual Security Incident Report to the NPC by 31 March of the following year, regardless of whether any notifiable breach occurred. Balance complies via the NPC online portal.


12. Cookies, spam, and electronic direct marketing

The Philippines does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) DPA Sec 12(a) + Sec 11 transparency for any cookie that processes personal data; (ii) the NPC's interpretive position on cookies (NPC Advisory Opinions on online tracking); (iii) RA 7394 Consumer Act and RA 11313 Safe Spaces Act on direct marketing harassment; (iv) RA 10175 Cybercrime Prevention Act Sec 4(c)(3) on unsolicited commercial communications (the relevant subsection was largely upheld in Disini v Secretary of Justice G.R. No. 203335 with constitutional modulation); (v) RA 11967 Internet Transactions Act on consumer-facing communications.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send commercial electronic messages to Philippine residents within the meaning of RA 10175 Sec 4(c)(3). The only email Balance sends to Philippine parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. If Balance ever introduces a marketing channel, we will comply with RA 10175 Sec 4(c)(3) as modulated by Disini v Secretary of Justice + NPC Advisory Opinions on direct marketing + DTI DAO on advertising + RA 11313 anti-harassment.

12.4 No telemarketing

Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Philippine residents.


13. Lawful-access requests and the encryption posture

Philippine authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. OSAEC / CSAE reporting routes — Philippines

A Philippine resident (parent, kid, or third party) who wishes to report an OSAEC or CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Philippine resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
National Privacy Commission (NPC) DPA 5th Floor, Delegation Building, PICC Complex, Vicente Sotto Street, Pasay City 1307; https://www.privacy.gov.ph/; +63 2 8234 2228
Department of Information and Communications Technology (DICT) ICT policy + NPC parent department C.P. Garcia Avenue, Diliman, Quezon City 1101; https://dict.gov.ph/; +63 2 8920 0101
PNP Anti-Cybercrime Group (PNP-ACG) Cybercrime + OSAEC https://acg.pnp.gov.ph/; (02) 8414-1560 / 0998-598-8116
PNP Women and Children Protection Center (PNP-WCPC) RA 7610 + RA 11930 + RA 9775 https://wcpc.pnp.gov.ph/; +63 2 8532 6690
NBI Cybercrime Division (NBI-CCD) Cybercrime https://nbi.gov.ph/; +63 2 8523 8231 to 38 local 3454
DOJ Office of Cybercrime (DOJ-OOC) Cybercrime central authority + Budapest Convention 24/7 point of contact https://cybercrime.doj.gov.ph/; +63 2 8521 8344
DSWD Child protection / OSAEC / IACACP chair https://www.dswd.gov.ph/; 1383
DTI — e-Commerce Bureau RA 11967 Internet Transactions Act + RA 7394 Consumer Act https://www.dti.gov.ph/; +63 2 8751 3330
Philippine Competition Commission (PCC) RA 10667 competition law https://www.phcc.gov.ph/; +63 2 8771 9722
Commission on Human Rights (CHR) Human rights https://chr.gov.ph/; +63 2 8294 8704
Regional Trial Courts DPA Sec 16(f) right to damages + Civil Code Art 26/Art 32 + Writ of Habeas Data via https://sc.judiciary.gov.ph/
Court of Appeals Appeals from NPC under DPA Sec 36 + concurrent jurisdiction in Writ of Habeas Data via https://sc.judiciary.gov.ph/
Supreme Court of the Philippines Concurrent jurisdiction in Writ of Habeas Data; appellate review on certiorari https://sc.judiciary.gov.ph/

A Philippine resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the DPO under DPA Sec 21(b) + DPA IRR Rule IV Sec 14). We will respond within the DPA timelines. The NPC's published policy is exhaust internal remedies first (NPC Circular 2022-04 § II.A + NPC Advisory 2017-03), but the NPC will accept a complaint directly where the data subject demonstrates that internal-remedy exhaustion is impracticable.


16. Consumer rights — the RA 7394 + RA 11967 + RA 8792 + Civil Code overlay

The Consumer Act of the Philippines (RA 7394 of 1992), the Internet Transactions Act of 2023 (RA 11967, in force from 20 January 2024) + its IRR (DTI, in force 7 June 2024), the E-Commerce Act of 2000 (RA 8792), and the Civil Code of the Philippines (RA 386) — in particular Arts 1305 et seq. on contracts, Art 1327 + 1390 on incapacity of minors, and Art 1397 on voidable contracts — apply to Balance's subscription flow as a consumer transaction. The parent is a consumer / online consumer within RA 7394 Art 4(n) + RA 11967 Sec 3. Treatment is implemented in Subscription Terms § 20.

16.1 Deceptive + unfair + unconscionable sales practices (RA 7394 Arts 50–52)

RA 7394 Art 50 prohibits deceptive sales practices (false or misleading representations regarding the nature, characteristics, terms, or geographic origin of consumer products or services). RA 7394 Art 52 prohibits unfair or unconscionable sales practices that take advantage of the consumer's inability to protect his or her own interests. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each RA 7394 Art 50 / Art 52 risk.

16.2 Consumer rights under RA 11967 + RA 7394 + RA 8792

16.3 Civil Code minors' incapacity + parental ratification

Civil Code Art 1327 — minors (below 18) cannot give consent to a contract. Civil Code Art 1390 — contracts entered into by minors are voidable. Civil Code Art 1397 — voidable contracts may be ratified. The Balance subscription contract is between Balance and the parent (age 18+); the kid is not a party to the subscription contract. The kid's use of the parental-control service is under the parent's contract and the parent's parental authority (Family Code Arts 209–225), not as a separate contracting party.

16.4 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace RA 7394, RA 11967, RA 8792, or the Civil Code to the prejudice of the Philippine consumer are subject to the protection of consumer welfare doctrine + the public policy doctrine + RA 7394 Art 161 (which authorises DTI enforcement action against unfair contractual terms in consumer contracts).

16.5 Refunds and the Philippine subscription posture

Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the RA 11967 + RA 7394 minimum standards for a subscription-service supply. The 14-day refund window is documented at Subscription Terms § 20.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Philippines Country Annex.

← Back to Privacy Policy · Children's Privacy Notice