Balance — Philippines Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Philippine resident covered by this Annex; the Data Protection Officer ("DPO") mandated by Republic Act No. 10173 (the Data Privacy Act of 2012 — "DPA") s 21(b) read with the Implementing Rules and Regulations of the Data Privacy Act of 2012 (the "DPA IRR", in force from 9 September 2016) Rule IV Sec 14(a) and NPC Advisory No. 2017-01 on the Designation of Data Protection Officers, with business contact published as the publicly-accessible DPO contact required by DPA IRR Rule IV Sec 14(b) + NPC Advisory 2017-01 § VI.A; the designated contact point for the National Privacy Commission ("NPC"), the Philippine National Police – Anti-Cybercrime Group ("PNP-ACG"), the Philippine National Police – Women and Children Protection Center ("PNP-WCPC"), the National Bureau of Investigation – Cybercrime Division ("NBI-CCD"), the Department of Justice – Office of Cybercrime ("DOJ-OOC"), the Department of Social Welfare and Development ("DSWD"), the Inter-Agency Council Against Trafficking ("IACAT"), the Inter-Agency Council Against Child Pornography ("IACACP"), and the Council for the Welfare of Children ("CWC") under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to Republic Act No. 10173 (the Data Privacy Act of 2012 — "DPA") including any successor data-privacy bill before the Congress of the Philippines (the bicameral 19th Congress was sitting at the Effective date; several DPA-amendment bills have been filed but none enacted); (b) any amendment to the DPA IRR (NPC, in force 9 September 2016); (c) any new or amended NPC Circular — including but not limited to NPC Circular No. 16-01 (Security of Personal Data in Government Agencies), NPC Circular No. 16-02 (Data Sharing Agreements), NPC Circular No. 16-03 (Personal Data Breach Management, the predecessor regime), the principal NPC Circular No. 16-03/series-of-2016 as supplemented by NPC Circular No. 2022-01 (Administrative Fines under the Data Privacy Act), NPC Circular No. 2022-04 (Rules of Procedure on Complaints, Investigations, and Adjudications), and any successor circular on breach notification, data sharing, security of personal data, children's data, or administrative fines; (d) any new or amended NPC Advisory or NPC Advisory Opinion — including NPC Advisory No. 2017-01 (DPOs), NPC Advisory No. 2017-03 (Access Requests), and the body of NPC Advisory Opinions published at https://www.privacy.gov.ph/advisory-opinions/; (e) any decision of the NPC under DPA s 7 + DPA IRR Rule III, any decision of the Court of Appeals under DPA s 36 (judicial review of NPC decisions), or any decision of the Supreme Court of the Philippines bearing on the DPA, the right to privacy (1987 Constitution Art III Sec 3 + Art III Sec 2 + Civil Code Art 26), or the writ of habeas data (A.M. No. 08-1-16-SC); (f) any amendment to Republic Act No. 11930 (the Anti-Online Sexual Abuse or Exploitation of Children Act of 2022 — "OSAEC Law", in force from 30 July 2022) or to its IRR (DOJ-IACACP, in force 4 January 2023); (g) any amendment to Republic Act No. 9775 (the Anti-Child Pornography Act of 2009) or its IRR; (h) any amendment to Republic Act No. 7610 (the Special Protection of Children Against Abuse, Exploitation and Discrimination Act of 1992) or its IRR; (i) any amendment to Republic Act No. 11648 (the act increasing the age of sexual consent to 16, in force from 4 March 2022); (j) any amendment to Republic Act No. 10175 (the Cybercrime Prevention Act of 2012) or to its IRR (DOJ, in force 12 August 2015) including the Supreme Court's modulation of certain provisions in Disini v Secretary of Justice G.R. No. 203335, 18 February 2014; (k) any amendment to Republic Act No. 9995 (the Anti-Photo and Video Voyeurism Act of 2009); (l) any amendment to Republic Act No. 11313 (the Safe Spaces Act of 2019) covering gender-based online sexual harassment; (m) any amendment to Republic Act No. 11862 (the Expanded Anti-Trafficking in Persons Act of 2022); (n) any amendment to Republic Act No. 11967 (the Internet Transactions Act of 2023, in force from 20 January 2024) or to its IRR (DTI, in force from 7 June 2024) — the principal Philippine internet-transactions consumer-protection statute; (o) any amendment to Republic Act No. 8792 (the E-Commerce Act of 2000) or its IRR; (p) any amendment to Republic Act No. 7394 (the Consumer Act of the Philippines of 1992); (q) any amendment to Republic Act No. 4200 (the Anti-Wiretapping Act of 1965); (r) any amendment to Executive Order No. 209 (the Family Code of the Philippines, in force from 3 August 1988) or to Republic Act No. 6809 (lowering the age of majority to 18); (s) any amendment to the Civil Code of the Philippines (RA 386, in force from 18 June 1949) Article 26 (right to privacy / dignity); (t) the entry into force in the Philippines of the Convention on Cybercrime (Budapest Convention, Convention on Cybercrime of 23 November 2001) and its Second Additional Protocol (the Philippines acceded on 28 March 2018; in force for the Philippines from 1 July 2024); (u) any amendment to a sub-processor's Philippine data-handling posture under our sub-processor register; (v) the publication of any Philippine NPC Cross-Border Personal Data Transfer circular or template clauses (none at the Effective date — the operative mechanism is the DPA IRR Sec 44 + Sec 50 + NPC Advisory Opinion overlay); (w) the bringing into force of any post-Effective-date Philippine statute or regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex).
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Philippines row).
- Children's Privacy Notice § 14 (Country annexes — Philippines row).
- Child Safety Standards § 13 (Country annexes — Philippines row).
- Terms of Service § 19 (Philippines consumer-protection carve-out under the Consumer Act of the Philippines RA 7394 + the Internet Transactions Act of 2023 RA 11967).
- Subscription Terms § 20 (Philippines consumer-rights overlay — Consumer Act RA 7394 + Internet Transactions Act RA 11967 + E-Commerce Act RA 8792 + Civil Code Art 1305 et seq. + Art 1390/Art 1397 incapacity-of-minors).
- Data Retention & Deletion Policy § 14 (Philippines NPC complaint route).
- our breach-notification runbook § 9 (Philippines mandatory-data-breach-notification route under NPC Circular 16-03 + DPA IRR Sec 38 — 72-hour benchmark to NPC).
- our international-transfer pack § 6 (DPA Sec 21 accountability-for-transfer + DPA IRR Sec 44 + Sec 50 cross-border-transfer paperwork overlay).
This Annex is the canonical Philippines-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Philippine resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Philippine resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English. The 1987 Constitution of the Republic of the Philippines Article XIV Section 7 provides that the official languages of the Philippines are Filipino and, until otherwise provided by law, English; the regional languages are auxiliary in the regions and serve as auxiliary media of instruction. Filipino translation is queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Philippine resident (the DPA does not mandate multilingual notification; the NPC's interpretive practice accepts English).
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is the Republic of the Philippines — the unitary state composed of 17 administrative regions (NCR, CAR, BARMM, Regions I to XIII) and 82 provinces. There is no provincial data-protection sub-layer; the DPA is uniform nationwide.
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies the Philippines as the country of residence, this Annex applies, even if the other signals are non-Philippine. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
The DPA has explicit extraterritorial reach under DPA s 6 — the Act applies to (i) an act done or practice engaged in by an entity with a link to the Philippines; (ii) an entity with a personal-data-processing activity that has a link to the Philippines; and (iii) an entity that has other links to the Philippines, including (a) an entity that carries on business in the Philippines, and (b) an entity that maintains an office, branch, or agency in the Philippines, or carries on business outside the Philippines provided that personal information of Philippine citizens or residents is collected or held by it, or where the processing of personal information is done in the Philippines. The NPC's interpretive practice (NPC Advisory Opinion 2017-049, 2018-058, 2019-053, and the body of NPC decisions published at https://www.privacy.gov.ph/) confirms that an entity outside the Philippines is subject to the DPA in respect of its processing of personal information of Philippine residents where the entity directs activities towards the Philippines. Balance squarely targets Philippine residents through Google Play Philippines, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Philippine-resident parents and kids; the DPA applies in full.
2. Statutory framework — what applies
The Philippine personal-data-protection regime is dominated by Republic Act No. 10173 (the Data Privacy Act of 2012 — "DPA"), implemented by the DPA IRR (NPC, in force 9 September 2016) and supplemented by NPC Circulars, NPC Advisories, and NPC Advisory Opinions. Adjacent layers: Republic Act No. 11930 (OSAEC Law of 2022); Republic Act No. 9775 (Anti-Child Pornography Act of 2009); Republic Act No. 7610 (Child Protection Act of 1992); Republic Act No. 11648 (raising age of consent to 16); Republic Act No. 10175 (Cybercrime Prevention Act of 2012); Republic Act No. 9995 (Anti-Photo and Video Voyeurism Act of 2009); Republic Act No. 11313 (Safe Spaces Act of 2019); Republic Act No. 11862 (Expanded Anti-Trafficking in Persons Act of 2022); Republic Act No. 11967 (Internet Transactions Act of 2023); Republic Act No. 8792 (E-Commerce Act of 2000); Republic Act No. 7394 (Consumer Act of the Philippines of 1992); Republic Act No. 4200 (Anti-Wiretapping Act of 1965); Executive Order No. 209 (Family Code) + Republic Act No. 6809 (age of majority 18); the Civil Code of the Philippines (RA 386); the 1987 Constitution of the Republic of the Philippines; and the Rules of Court.
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| 1987 Constitution of the Republic of the Philippines | Constitution — Art III Bill of Rights: Sec 1 (due process + equal protection); Sec 2 (unreasonable searches and seizures); Sec 3(1) (privacy of communication and correspondence — inviolable except upon lawful order of the court, or when public safety or order requires otherwise); Sec 3(2) (exclusionary rule for evidence obtained in violation of Sec 2 or Sec 3(1)); Sec 7 (right of the people to information on matters of public concern); Sec 17 (right against self-incrimination). Art II Sec 11 (full respect for human rights); Art II Sec 12 (sanctity of family life + protection of children "from all forms of neglect, abuse, cruelty, exploitation and other conditions prejudicial to their development"); Art XV Sec 1–3 (family + parental responsibility); Art XIV Sec 7 (official languages — Filipino and English). The Supreme Court has read an enforceable right to privacy into Art III Sec 1 + 2 + 3 read together with Civil Code Art 26 (Ople v Torres G.R. No. 127685, 23 July 1998; Vivares v St. Theresa's College G.R. No. 202666, 29 September 2014; Sps. Hing v Choachuy G.R. No. 179736, 26 June 2013; Disini v Secretary of Justice G.R. No. 203335, 18 February 2014). The constitutional Writ of Habeas Data (A.M. No. 08-1-16-SC, in force 2 February 2008) is a separate constitutional remedy for any natural or legal person whose right to privacy in life, liberty, or security is violated or threatened by an unlawful act of a public official or employee, or of a private individual or entity engaged in the gathering, collecting, or storing of data or information regarding the person, family, home, and correspondence of the aggrieved party. | The constitutional anchor. The right to privacy in the Philippines is constitutional (Art III + judicial doctrine + Writ of Habeas Data) AND statutory (DPA + Civil Code Art 26). | Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below. |
| Republic Act No. 10173 — Data Privacy Act of 2012 | DPA — approved 15 August 2012; in force 8 September 2012 (Sec 47). Substantive sections: Ch I General Provisions (Sec 1 title; Sec 2 declaration of policy; Sec 3 definitions — personal information, sensitive personal information, personal information controller "PIC", personal information processor "PIP", data subject, processing, consent; Sec 4 carve-outs — government performance of duties / journalism / research / banking / regulated processing); Sec 5 scope; Sec 6 extraterritorial application (treated in § 1 above); Ch II National Privacy Commission (Sec 7 functions — administrative + quasi-judicial + recommendation power; Sec 8 confidentiality of NPC information; Sec 9 organisational structure; Sec 10 Secretariat); Ch III Processing of Personal Information (Sec 11 General Data Privacy Principles — transparency / legitimate purpose / proportionality; Sec 12 lawful bases for processing personal information — consent + contract + legal obligation + vital interest + national emergency / public order / public health / public function); Sec 13 lawful bases for processing sensitive personal information and privileged information — consent + existing law / contract + protection of life and health / lawful processing for organisations / medical treatment / protection of lawful rights and interests in court proceedings + government processing in carrying out constitutional/statutory mandates; Sec 14 subcontracting; Sec 15 extension of privileged communications; Ch IV Rights of the Data Subject (Sec 16 the eight rights — right to be informed / right to object to processing / right of access / right to correct / right to erasure or blocking / right to damages / right to data portability / right to file a complaint with NPC; Sec 17 transmissibility of rights; Sec 18 rights of next of kin); Ch V Security of Personal Information (Sec 19 non-applicability of certain Sec 16 rights in narrow circumstances; Sec 20 security obligations — appropriate organisational, physical, and technical measures); Ch VI Accountability for Transfer of Personal Information (Sec 21 accountability — the PIC is responsible for personal information under its control or custody, including information that has been transferred to a third party for processing, whether domestically or internationally); Ch VII Security of Sensitive Personal Information in Government (Sec 22–24); Ch VIII Penalties (Sec 25 unauthorized processing — 1 to 3 years + PHP 500K to 2M; Sec 26 accessing personal information due to negligence — 1 to 3 years + PHP 500K to 2M; Sec 27 improper disposal — 6 months to 3 years + PHP 100K to 1M; Sec 28 processing for unauthorized purposes — 1 year 6 months to 5 years + PHP 500K to 1M; Sec 29 unauthorized access or intentional breach — 1 to 3 years + PHP 500K to 2M; Sec 30 concealment of security breaches — 1 year 6 months to 5 years + PHP 500K to 1M; Sec 31 malicious disclosure — 1 year 6 months to 5 years + PHP 500K to 1M; Sec 32 unauthorized disclosure — 1 to 3 years + PHP 500K to 1M for personal information / 3 to 5 years + PHP 500K to 2M for sensitive personal information; Sec 33 combination of acts — 3 to 6 years + PHP 1M to 5M; Sec 34 extent of liability — responsible officers; Sec 35 large-scale — maximum penalty when 100 or more individuals are affected; Sec 36 offence committed by public officer — disqualification from public office + accessory penalties); Ch IX Miscellaneous (Sec 37 NPC operational autonomy + Sec 38–47). | The principal statute. Applies in full to Balance as a PIC operating from outside the Philippines directing activities to Philippine residents (per DPA s 6 + NPC interpretive practice). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. | |
| Implementing Rules and Regulations of the DPA (DPA IRR) | DPA IRR — NPC, in force 9 September 2016. Rule I Preliminary Provisions; Rule II Definition of Terms; Rule III National Privacy Commission; Rule IV Data Protection Officers (Sec 14 mandatory DPO designation; Sec 14(a) PIC and PIP must designate a DPO; Sec 14(b) the DPO's contact details must be made publicly available; the DPO need not be a citizen or resident of the Philippines but must be readily accessible); Rule V Lawful Processing of Personal Data (Sec 17 transparency; Sec 18 criteria for lawful processing of personal information; Sec 19–21 criteria for lawful processing of sensitive and privileged information; Sec 22 subcontracting); Rule VI Security Measures for the Protection of Personal Data (Sec 25 organisational + Sec 26 physical + Sec 27 technical security measures); Rule VII Security of Sensitive Personal Information in Government (Sec 28–33); Rule VIII Rights of Data Subjects (Sec 34 enumeration; Sec 34(a) Right to be informed; Sec 34(b) Right to object; Sec 34(c) Right to access; Sec 34(d) Right to rectification; Sec 34(e) Right to erasure or blocking; Sec 34(f) Right to damages; Sec 34(g) Right to data portability + Sec 36 right to data portability; Sec 35 transmissibility); Rule IX Data Breach Notification (Sec 38 notification of breach + Sec 39 mandatory notification of NPC and affected data subjects within 72 hours from knowledge of, or reasonable belief by, the PIC or PIP that a personal data breach has occurred where (a) the breach involves sensitive personal information or any other information that may be used to enable identity fraud; and (b) the personal information involved has been acquired by an unauthorised person or persons; and (c) the unauthorised acquisition is likely to give rise to a real risk of serious harm; Sec 40 form of notification; Sec 41 contents of notification; Sec 42 delay in notification; Sec 43 breach report to NPC); Rule X Accountability for Transfer of Personal Data (Sec 44 PIC is responsible for personal data under its control + custody; Sec 45 outsourcing; Sec 50 contract or other legal arrangement for outsourcing/subcontracting + cross-border transfer accountability requirements; the legally enforceable obligation construct is implemented through Data Sharing Agreements + Outsourcing/Sub-Processing Agreements under NPC Circular 16-02); Rule XI Registration of Data Processing Systems (Sec 47 mandatory registration of data processing systems with the NPC where the PIC processes personal data of more than 1,000 individuals OR processes sensitive personal information of at least 1,000 individuals OR uses 250+ employees or processes data on more than 1,000 individuals; Balance's processing surface engages the registration trigger and is covered by § 8.3 below); Rule XII Rules on Accountability (Sec 49 PIC + PIP responsibilities); Rule XIII Miscellaneous Provisions; Rule XIV Penalties + Sec 60 right to information from PIC. | The principal interpretive layer of the DPA. Applies in full. Treatment in §§ 3, 4, 6, 8, 11 below. | |
| NPC Circular No. 16-01 | NPC Circular 16-01 — Security of Personal Data in Government Agencies (in force 10 October 2016). | Applies to government agencies only; Balance is a private PIC and Circular 16-01 is not directly engaged. Applied as an interpretive guide for the technical/physical/organisational security standard at DPA IRR Rule VI Sec 25–27. | |
| NPC Circular No. 16-02 | NPC Circular 16-02 — Data Sharing Agreements Involving Government Agencies (in force 10 October 2016). | Applies to data sharing involving government agencies; Balance does not engage in data sharing with Philippine government agencies in the operational flow. Applied as an interpretive guide for the contractual-clauses substance of any cross-border processor arrangement. | |
| NPC Circular No. 16-03 | NPC Circular 16-03 — Personal Data Breach Management (in force 15 December 2016). Implements DPA IRR Rule IX. Mandatory NPC notification within 72 hours from knowledge of the breach + mandatory affected-data-subject notification + mandatory annual security incident report. | Applies in full. Treatment in § 11 below. | |
| NPC Circular No. 2022-01 | NPC Circular 2022-01 — Guidelines on Administrative Fines Imposed by the National Privacy Commission (in force 13 March 2022). Establishes the administrative-fine schedule for DPA violations: (i) grave infractions — fine of 0.5% to 3% of annual gross income of the immediately preceding year, or PHP 50,000 to PHP 5,000,000 per violation, whichever is higher; (ii) major infractions — fine of 0.25% to 2% of annual gross income, or PHP 50,000 to PHP 4,000,000; (iii) other infractions — fine of 0.5% of annual gross income, or PHP 25,000 to PHP 3,000,000. | Sets the administrative-penalty layer. Applies in full alongside the criminal penalty stack at DPA Chapter VIII. | |
| NPC Circular No. 2022-04 | NPC Circular 2022-04 — Rules of Procedure of the National Privacy Commission (in force from 23 June 2022) — supersedes NPC Circular No. 16-04. Sets the procedural rules for NPC complaints, sua sponte investigations, compliance checks, mediation, adjudication, and appeals to the Court of Appeals under DPA s 36. | Applies in full as the NPC procedural layer. | |
| NPC Advisory No. 2017-01 | NPC Advisory 2017-01 — Designation of Data Protection Officers (issued 14 March 2017). The DPO designation is mandatory; the DPO's contact details must be publicly available; the DPO need not be a Filipino citizen or Philippine resident but must be readily accessible during regular Philippine business hours. | Applied in full. The Balance DPO is , contactable at . Publication satisfies the public-availability requirement. |
|
| NPC Advisory No. 2017-03 | NPC Advisory 2017-03 — Access to Personal Data by Data Subjects. | Applies as interpretive guidance for DPA Sec 16(c) + DPA IRR Sec 34(c) access right. | |
| NPC Advisory Opinions | The body of NPC Advisory Opinions published at https://www.privacy.gov.ph/advisory-opinions/, including opinions on extraterritorial scope, cross-border transfer, processor agreements, children's data, and breach notification. |
Applied as persuasive interpretive guidance. | |
| Republic Act No. 11930 — Anti-Online Sexual Abuse or Exploitation of Children Act of 2022 (OSAEC Law) | OSAEC Law — approved 30 July 2022; in force 4 August 2022 (15 days after publication in the Official Gazette on 20 July 2022). Implements the Convention on the Rights of the Child + the Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (Philippines ratified 28 May 2002). Sec 3 definitions including child, online sexual abuse or exploitation of children ("OSAEC"), child sexual abuse or exploitation material ("CSAEM"), Internet intermediary; Sec 4 unlawful or prohibited acts (commission of OSAEC; production, distribution, offering, or sale of CSAEM); Sec 5 unlawful acts of Internet intermediaries (failure to remove CSAEM after notice; failure to retain data; failure to report); Sec 7 offences and penalties (imprisonment up to reclusion perpetua + fines up to PHP 5,000,000); Sec 9–13 procedural overlay (warrant to disclose computer data; cybertip line; Internet intermediary preservation orders; international cooperation); Sec 12 duties of Internet intermediaries — (a) maintain a mechanism to immediately report OSAEC; (b) preserve data for 6 months from receipt of takedown order; (c) provide information to law-enforcement upon issuance of warrant; (d) report incidents to PNP-WCPC or NBI-CCD within 7 days; (e) deploy reasonable steps to prevent and detect OSAEC and CSAEM; Sec 18 establishment of the Inter-Agency Council Against Child Pornography ("IACACP") chaired by DSWD with DOJ as principal implementing agency. The OSAEC IRR (DOJ-IACACP, in force 4 January 2023) operationalises Secs 4, 5, 7, 9–13, and 18. | The principal Philippine OSAEC + child-safety statute. Balance's posture is described in §§ 5, 13, and 14 below. Balance is best characterised as a private parental-control client that does not host third-party content publicly, does not enable user-to-user communication outside the parent-kid pairing of a single household, and does not constitute an "Internet intermediary" within the OSAEC Law's definition (the OSAEC Law's Internet intermediary definition tracks search engines, social-media platforms, ISPs, and hosting providers); Balance nevertheless cooperates with PNP-WCPC, NBI-CCD, DSWD, IACACP, and the National Coordination Centre Against OSAEC (NCCAOC) per § 14 below. | |
| Republic Act No. 9775 — Anti-Child Pornography Act of 2009 | RA 9775 — approved 17 November 2009; in force 8 December 2009. Definitions Sec 3 + Sec 4 unlawful acts (production, distribution, sale, possession, hiring or employment of a child for production of CSAM; failure of an ISP to notify; failure of a photo or video developing service to notify); Sec 5 syndicated child pornography; Sec 6 + 7 + 8 + 9 penalties; Sec 10 Internet service provider obligations to report and retain; Sec 11 mall owners' duties; Sec 19–22 Inter-Agency Council Against Child Pornography (IACACP). | The principal pre-OSAEC anti-CSAM statute (overlaid by RA 11930 OSAEC). Applies. Treatment in § 14 below. | |
| Republic Act No. 7610 — Special Protection of Children Against Abuse, Exploitation and Discrimination Act of 1992 | RA 7610 — approved 17 June 1992; in force 5 July 1992. Articles I–XI: best-interest principle Art I Sec 2; child defined as below 18 OR over 18 but unable to fully take care of or protect himself/herself from abuse, neglect, cruelty, exploitation or discrimination because of a physical or mental disability or condition; Art III child abuse / child trafficking / obscene publications; Art VI offences (Sec 5 child prostitution + Sec 6 attempt to commit child prostitution); Art XI Bantay Bata Hotline. | The foundational child-protection statute. Applies. Treatment in § 5 + § 14 below. | |
| Republic Act No. 11648 — Increasing the Age of Sexual Consent to 16 (2022) | RA 11648 — approved 4 March 2022; in force 4 March 2022. Amends Revised Penal Code Art 266-A (Rape) + Art 266-B + RA 8353 + RA 7610 + RA 9262. Raises the age of sexual consent from 12 to 16. | Applies as a context-setting fact. Cross-reference in § 14 below. | |
| Republic Act No. 10175 — Cybercrime Prevention Act of 2012 | RA 10175 — approved 12 September 2012. Substantive sections: Ch II Punishable Acts — Sec 4(a) offences against the confidentiality, integrity and availability of computer data and systems (illegal access, illegal interception, data interference, system interference, misuse of devices, cyber-squatting); Sec 4(b) computer-related offences (forgery, fraud, identity theft); Sec 4(c) content-related offences (cybersex, child pornography through a computer system, unsolicited commercial communications, libel — libel through a computer system upheld in part by Disini v Secretary of Justice G.R. No. 203335, 18 February 2014, with the unconstitutional elements struck down); Sec 5 attempt + aiding or abetting (the aiding or abetting clause was upheld for the Sec 4(a)–(b) computer-confidentiality offences but struck down by the Supreme Court for the Sec 4(c) content offences); Sec 6 higher penalty (one degree higher than equivalent Revised Penal Code offence); Sec 7 plurality of crimes (also struck down as to libel + child pornography in Disini); Sec 13 preservation of computer data (6 months extendible by another 6 months upon order); Sec 14 disclosure of computer data via court-issued warrant; Sec 15 search/seizure/examination of computer data via court warrant; Sec 17 destruction of computer data; Sec 24 DOJ Office of Cybercrime — central authority; Sec 26 PNP and NBI as primary investigating bodies. IRR in force 12 August 2015. | The principal cybercrime statute. Applies. Treatment in § 13 below. | |
| Republic Act No. 9995 — Anti-Photo and Video Voyeurism Act of 2009 | RA 9995 — approved 17 February 2009; in force 23 March 2009. Criminalises capture and copying/reproduction/sale/distribution/publication of any picture/video of a person's private area without consent. | The principal intimate-image-non-consensual-distribution statute. Applies. Treatment in § 14 below. | |
| Republic Act No. 11313 — Safe Spaces Act of 2019 | RA 11313 — approved 17 April 2019; in force 3 August 2019. Definitions Sec 3. Sec 12 gender-based online sexual harassment — penalties for use of information and communications technology in terrorising and intimidating victims through physical, psychological, and emotional threats; unwanted sexual misogynistic, transphobic, homophobic and sexist remarks and comments online; invasion of victim's privacy through cyber-stalking; non-consensual photo/video sharing; etc. Sec 13 PNP Anti-Cybercrime Group designated as a Women and Children Cyber Protection Unit (WCCPU). | Applies. Treatment in § 14 below. | |
| Republic Act No. 11862 — Expanded Anti-Trafficking in Persons Act of 2022 | RA 11862 — approved 23 June 2022. Amends RA 9208 (Anti-Trafficking in Persons Act of 2003). Expands liability of Internet intermediaries; sets up the IACAT (Inter-Agency Council Against Trafficking). | The principal anti-trafficking-of-children statute. Applies. Treatment in § 14 below. | |
| Republic Act No. 11967 — Internet Transactions Act of 2023 | RA 11967 — approved 5 December 2023; in force 20 January 2024. IRR (DTI, in force 7 June 2024). Sec 2 declaration of policy — protect consumer rights in internet transactions. Sec 3 definitions including digital platform, e-marketplace, e-retailer, online merchant, online consumer. Sec 4 scope — covers any internet transaction with a nexus to the Philippines (consumer located in the Philippines; merchant offering goods/services through a digital platform accessible in the Philippines; etc.). Sec 5 functions of the Department of Trade and Industry (DTI) + the new e-Commerce Bureau as the principal regulatory authority. Sec 7 obligations of digital platforms, e-marketplaces, e-retailers, and online merchants — including registration with DTI; complaint-handling mechanism; protection of consumer privacy in coordination with NPC; cooperation with DTI takedown directives; mandatory complaint mechanism reachable within 5 working days; refund mechanism. Sec 8 consumer rights — clear pricing, accurate description, right to cancel, right to refund, protection from misleading advertising. Sec 22 prohibited acts. Sec 23–26 offences + penalties. | The principal Philippine internet-transactions consumer-protection statute. Applies. Treatment in § 16 below. | |
| Republic Act No. 8792 — E-Commerce Act of 2000 | RA 8792 — approved 14 June 2000. Recognition of electronic documents and electronic signatures + electronic contracts + consumer-protection overlay on electronic transactions. | Applies. Subordinate to RA 11967 (which governs internet transactions specifically). | |
| Republic Act No. 7394 — Consumer Act of the Philippines (1992) | RA 7394 — approved 13 April 1992. Art 50 deceptive sales practices; Art 52 unfair or unconscionable sales practices; Title III Consumer Product and Service Warranties; Art 100 liability for defective products; Art 101 liability for defective services; Title V Consumer Protection Against Hazards to Health and Safety; enforced by the DTI + the Department of Health (DOH) + the Bureau of Food and Drugs + the Philippine Competition Commission (PCC) under RA 10667. | The foundational Philippine consumer-protection statute. Applies in full alongside RA 11967. Treatment in § 16 below. | |
| Republic Act No. 4200 — Anti-Wiretapping Act of 1965 | RA 4200 — approved 19 June 1965. Prohibits wire-tapping + recording private communications without the consent of all parties. Court-ordered exception under RA 4200 Sec 3 with judicial process for specific enumerated offences (treason, espionage, sedition, kidnapping, etc.). | Applies. Treatment in § 13 below — relevant to E2EE posture and lawful-access framework. | |
| Executive Order No. 209 — Family Code of the Philippines (1988) + RA 6809 (1989) | Family Code — in force 3 August 1988. Art 209–225 Parental Authority — joint parental authority of father and mother (Art 211); in case of separation, parental authority is exercised by the parent designated by the court (Art 212); Art 220–221 parental rights and duties; Art 234 age of emancipation (originally 18; modified by RA 6809 to age of majority 18 absolute). RA 6809 — in force 18 December 1989 — sets the age of majority at 18. | The principal parental-authority framework. Applies. Treatment in § 5 + § 7 below. | |
| Civil Code of the Philippines — Republic Act No. 386 (1949) | Civil Code — approved 18 June 1949; in force 30 August 1950. Art 26 every person shall respect the dignity, personality, privacy and peace of mind of his neighbours and other persons — a tort-style cause of action for violation of privacy, dignity, and peace of mind, independent of the constitutional and DPA layers. Art 32 any public officer or employee, or any private individual, who directly or indirectly obstructs, defeats, violates or in any manner impedes or impairs any of the enumerated civil rights and liberties of another person (including the right to privacy of communication and correspondence under Art III Sec 3) shall be liable to the latter for damages. Art 1305 et seq. contracts (offer, acceptance, consideration); Art 1318 essential requisites of contracts; Art 1327 + 1390 incapacity to give consent — minors below 18 (under Art 234 Family Code + RA 6809); Art 1397 voidable contracts entered into by minors. Art 2199 + 2217–2220 actual + moral damages. | The principal civil-law privacy + contracts framework. Applies. Treatment in §§ 6, 13, 16 below. | |
| Writ of Habeas Data — A.M. No. 08-1-16-SC (Supreme Court Rule, in force 2 February 2008) | Habeas Data — constitutional writ. Any aggrieved party may file a petition before a Regional Trial Court / Sandiganbayan / Court of Appeals / Supreme Court (concurrent jurisdiction). The writ is a remedy for any natural or legal person whose right to privacy in life, liberty, or security is violated or threatened by an unlawful act of (a) a public official or employee, or (b) a private individual or entity engaged in the gathering, collecting, or storing of data or information regarding the person, family, home, and correspondence of the aggrieved party. Reliefs available: (i) updating, rectification, suppression, or destruction of the database or information; (ii) injunctive relief; (iii) damages (with the court referring damages to ordinary civil court). | The constitutional remedy for data subjects in the Philippines. Applies. Treatment in §§ 6, 13 below. | |
| EU adequacy | None. The Philippines does not hold an EU adequacy decision under GDPR Art 45 at the Effective date. EU/EEA → Philippines transfers are governed by EU SCCs + Transfer Impact Assessment. | Cross-reference in EU / EEA annex § 8. | The absence of EU adequacy does not affect Balance's posture because Balance has no Philippine data residency (the backend is in the US — see § 9 below). |
| APEC Cross-Border Privacy Rules (CBPR) | The Philippines is a participating economy in the APEC Cross-Border Privacy Rules (CBPR) system since 2020 and in the APEC Privacy Recognition for Processors (PRP) system since 2020. The Philippine Accountability Agent is the National Privacy Commission. | The APEC CBPR is one of the recognised cross-border-transfer mechanisms under the DPA IRR Sec 50 legally enforceable obligation framework. | Applies as a context-setting fact (Balance relies on the DPA IRR Sec 50 contract route rather than APEC CBPR certification at the Effective date). |
| Convention 108 / Convention 108+ | Not applicable. The Philippines is not a party to the Council of Europe Convention 108 or Convention 108+. | Applies as a context-setting fact. | Not engaged. |
| Budapest Convention on Cybercrime | The Philippines acceded on 28 March 2018 and the Convention entered into force for the Philippines on 1 July 2024. The Second Additional Protocol on Enhanced Co-operation and Disclosure of Electronic Evidence has been signed and is being considered for ratification. | Applies as a substantive overlay on the lawful-access framework. Treatment in § 13 below. |
(Any prospective Philippine regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date NPC Circular in that area, the DICT's voluntary National AI Strategy Roadmap, any future Philippine AI Act or AI Development and Regulation Bill before the Congress of the Philippines, and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Philippine regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authorities
3.1 NPC — National Privacy Commission
The principal supervisory authority is the National Privacy Commission ("NPC"), an independent body attached to the Department of Information and Communications Technology (DICT) under DPA Sec 7 + DPA IRR Rule III. The NPC has administrative, quasi-judicial, recommendation, and rule-making powers under DPA Sec 7. The NPC's decisions are appealable to the Court of Appeals under DPA Sec 36.
| Field | Value |
|---|---|
| Name | National Privacy Commission (NPC) |
| Headquarters | 5th Floor, Delegation Building, Philippine International Convention Center (PICC) Complex, Vicente Sotto Street, Pasay City 1307, Metro Manila |
| Website | https://www.privacy.gov.ph/ |
| Complaint channel | NPC online complaint portal at https://www.privacy.gov.ph/file-a-complaint/, or NPC Mediation Form; email info@privacy.gov.ph and complaints@privacy.gov.ph |
| Phone | +63 2 8234 2228 |
| Mandatory-Breach-Notification channel | NPC online Personal Data Breach Notification portal per DPA IRR Sec 38 + NPC Circular 16-03 — at https://dbnms.privacy.gov.ph/ — submission within 72 hours of knowledge of, or reasonable belief by the PIC of, a notifiable breach |
| Commissioner | At the Effective date — published at https://www.privacy.gov.ph/about-us/ |
The NPC is the first-line forum for any DPA-grounded complaint from any Philippine resident. A Philippine resident may petition the NPC after first raising the matter with Balance (per NPC Circular 2022-04 § II.A and NPC Advisory 2017-03 — the NPC's published policy is exhaust internal remedies first). We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the DPO under DPA Sec 21(b) + DPA IRR Rule IV Sec 14) and respond within the DPA timelines (see § 6 below).
A Philippine resident may also pursue private remedies via (i) the Writ of Habeas Data (A.M. No. 08-1-16-SC); (ii) the Civil Code Art 26 / Art 32 cause of action; (iii) the Right to Damages under DPA Sec 16(f) (judicial action for damages); (iv) the criminal-complaint route under DPA Ch VIII to the Office of the Prosecutor / DOJ.
3.2 DICT — Department of Information and Communications Technology
The Department of Information and Communications Technology ("DICT") is the parent department of the NPC and the principal ICT-policy department of the Philippine government, established by Republic Act No. 10844 (the DICT Act of 2015).
| Field | Value |
|---|---|
| Name | Department of Information and Communications Technology (DICT) |
| Headquarters | C.P. Garcia Avenue, Diliman, Quezon City 1101, Metro Manila |
| Website | https://dict.gov.ph/ |
| Phone | +63 2 8920 0101 |
3.3 Other regulatory bodies
| Body | Subject matter | URL |
|---|---|---|
| Department of Justice (DOJ) — Office of Cybercrime (OOC) | RA 10175 Cybercrime Prevention Act — central authority for cybercrime; international cooperation; warrant for disclosure of computer data | https://cybercrime.doj.gov.ph/ |
| Philippine National Police – Anti-Cybercrime Group (PNP-ACG) | RA 10175 cybercrime investigation; RA 11930 OSAEC | https://acg.pnp.gov.ph/ |
| Philippine National Police – Women and Children Protection Center (PNP-WCPC) | Cyber-CSAE; RA 7610; RA 9775; RA 11930 OSAEC | https://wcpc.pnp.gov.ph/ |
| National Bureau of Investigation – Cybercrime Division (NBI-CCD) | RA 10175 cybercrime; CSAE; financial cyber-fraud | https://nbi.gov.ph/ |
| Department of Social Welfare and Development (DSWD) | RA 7610 + RA 11930 child-protection lead agency; chairs IACACP | https://www.dswd.gov.ph/ |
| Council for the Welfare of Children (CWC) | Child-welfare coordinating body | https://cwc.gov.ph/ |
| Inter-Agency Council Against Trafficking (IACAT) | RA 9208 / RA 11862 anti-trafficking | https://iacat.gov.ph/ |
| Inter-Agency Council Against Child Pornography (IACACP) | RA 9775 + RA 11930 OSAEC | via DSWD |
| Department of Trade and Industry (DTI) — e-Commerce Bureau | RA 11967 Internet Transactions Act + RA 7394 Consumer Act | https://www.dti.gov.ph/ |
| Philippine Competition Commission (PCC) | RA 10667 competition law | https://www.phcc.gov.ph/ |
| Commission on Human Rights (CHR) | Human rights including privacy (constitutional remedy auxiliary) | https://chr.gov.ph/ |
| Bantay Bata 163 (ABS-CBN Foundation) | Child-protection helpline | https://www.bantaybata163.com/ — Hotline 163 |
| Stairway Foundation | Children online-safety NGO | https://www.stairwayfoundation.org/ |
| End Child Prostitution and Trafficking (ECPAT) Philippines | CSAE advocacy | https://www.ecpat.org/ |
3.4 The DPO
DPA Sec 21(b) + DPA IRR Rule IV Sec 14 + NPC Advisory 2017-01 require every PIC and PIP to designate one or more Data Protection Officers. NPC Advisory 2017-01 § VI.A + DPA IRR Rule IV Sec 14(b) require that the DPO's contact details be made publicly available (typically on the PIC's website). The DPO need not be a Filipino citizen or Philippine resident but must be readily accessible during regular Philippine business hours.
The Balance DPO is:
- , Director, BabaYaga Program, TOO —
.
The DPO's business contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying DPA IRR Rule IV Sec 14(b) + NPC Advisory 2017-01 § VI.A. The DPO is the contact point for the NPC on any regulatory matter and for data subjects on rights-exercise matters.
4. Lawful bases — DPA Sec 12 + Sec 13 + DPA IRR Sec 18–21
The DPA is a multi-basis regime modulated by the General Data Privacy Principles at DPA Sec 11 (transparency / legitimate purpose / proportionality). Balance processes personal data of Philippine residents on the following DPA mapping:
| Processing purpose | DPA basis | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | DPA Sec 12(a) consent (parent's express consent at sign-up) + DPA Sec 12(b) contract (processing necessary for the performance of a contract to which the data subject is a party) + DPA IRR Sec 18 + Sec 19 + DPA Sec 11 general principles | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal data | DPA Sec 12(a) consent of the parent (given on behalf of the kid under Family Code Art 220–225 parental authority + Civil Code Art 1327 + 1390 incapacity of minors below 18) + DPA IRR Sec 18 + the most-protective reading of the DPA's transparency + proportionality principles + NPC interpretive practice in NPC Advisory Opinions on children's data | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | DPA Sec 12(a) + Sec 12(b) (primary purpose) | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | DPA Sec 12(f) legitimate interests pursued by the PIC (read with DPA Sec 11 proportionality + DPA Sec 20 security obligation) | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations | DPA Sec 12(c) compliance with a legal obligation to which the PIC is subject | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | DPA Sec 12(a) — collection of the parent's personal data for the primary purpose of obtaining VPC | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | DPA Sec 12(b) contract — necessary for the performance of the subscription contract; RA 11967 + RA 7394 + RA 8792 consumer-protection overlay in § 16 below | H4; § 16 below |
Balance does not process sensitive personal information under DPA Sec 3(l) + DPA Sec 13 in respect of any Philippine resident (no race, ethnic origin, marital status, age, colour, religious, philosophical or political affiliations; no health, education, genetic or sexual life, or proceedings; no government-issued ID number, social security number, licence, tax return, etc.).
Balance does not collect any government-issued identification number of any Philippine resident — including the Philippine Identification System (PhilSys) Number ("PSN"), the PhilSys Card Number ("PCN") issued under RA 11055 (the Philippine Identification System Act of 2018), the Taxpayer Identification Number ("TIN"), the Social Security System number ("SSS"), the Government Service Insurance System number ("GSIS"), the PhilHealth number, the Pag-IBIG number, the driver's licence number, or the passport number. DPA Sec 13 + RA 11055 Sec 12 + the NPC's Advisory Opinion on the Collection of Government-Issued ID Numbers impose strict limits on the collection of such numbers; Balance's posture aligns: none collected.
5. Children's rights overlay
The Philippines does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the DPA + the DPA IRR + the NPC's Advisory Opinions on children's data; (ii) the 1987 Constitution Art II Sec 12 + Art XV Secs 1–3; (iii) RA 7610 (Special Protection of Children); (iv) RA 11930 (OSAEC Law); (v) RA 9775 (Anti-Child Pornography); (vi) RA 11648 (age of consent 16); (vii) the Family Code Arts 209–225 (parental authority) + RA 6809 (age of majority 18); (viii) the Civil Code Arts 1327 + 1390 (incapacity of minors); (ix) the UN Convention on the Rights of the Child (Philippines ratified 21 August 1990); (x) the Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (Philippines ratified 28 May 2002).
5.1 Definitions
For the purposes of this Annex:
- Child (under RA 7610 + RA 9775 + RA 11930): a person below 18 years of age, or over 18 but unable to fully take care of or protect himself/herself from abuse, neglect, cruelty, exploitation, or discrimination because of a physical or mental disability or condition.
- Minor (general — Civil Code + Family Code + RA 6809): below 18 years of age.
- Age of sexual consent (per RA 11648): 16 years.
- Age of digital consent under DPA: the DPA does not set a numerical age of digital consent. The NPC's interpretive practice (NPC Advisory Opinions + the public NPC guidance on children's data) treats persons below 18 as requiring parental consent for the processing of their personal data, subject to maturity-based exceptions. Balance applies the most-protective reading and obtains parental consent regardless of the child's age.
5.2 Verifiable Parental Consent (VPC) for Philippine kids
Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Philippine kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Philippine residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the DPA + the Writ of Habeas Data + Civil Code Art 26 / Art 32.
5.3 No kid-self-serve consent path
Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the DPA + Family Code Arts 209–225 parental authority + Civil Code Art 1327 + 1390 + RA 7610 + RA 11930.
5.4 No advertising directed at children
Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. This is consistent with: (i) RA 7610 Art III Sec 12 prohibitions; (ii) the DTI's Department Administrative Order on advertising to children; (iii) the NPC's interpretive position on the use of children's data for direct marketing; (iv) RA 11930 OSAEC posture on child-online safety. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.5 Cooperation routes
The principal Philippine child-protection bodies are: (i) DSWD — the principal child-welfare lead agency; (ii) PNP-WCPC — Women and Children Protection Center; (iii) PNP-ACG — Anti-Cybercrime Group with the Women and Children Cyber Protection Unit under RA 11313 Sec 13; (iv) NBI-CCD — Cybercrime Division; (v) IACACP — Inter-Agency Council Against Child Pornography (chaired by DSWD); (vi) IACAT — Inter-Agency Council Against Trafficking; (vii) CWC — Council for the Welfare of Children; (viii) Bantay Bata 163 — ABS-CBN Foundation 24-hour child-protection helpline; (ix) Stairway Foundation — children's online-safety NGO; (x) ECPAT Philippines; (xi) the DSWD 1383 hotline — child-protection helpline; (xii) the 1343 Actionline — IACAT anti-trafficking hotline. Balance cooperates with each on incidents involving Philippine kids — see § 14 below.
6. DPA rights catalogue
6.1 The rights catalogue
A Philippine resident has the following rights under the DPA Sec 16 + DPA IRR Sec 34 + Sec 36 as in force at the Effective date.
- DPA Sec 16(a) + DPA IRR Sec 34(a) — Right to be informed. The data subject has the right to be informed of the existence of any operation or set of operations to be performed upon his or her personal data; the categories of personal data; the recipients to whom the personal data is or may be disclosed; the methods utilised for automated access (if any); the identity and contact details of the PIC; the period for which the data will be stored; and the existence of the rights to access, correct, object, and complain. Honored at
and in-app at the privacy notice screen. - DPA Sec 16(b) + DPA IRR Sec 34(b) — Right to object to the processing of personal data, including processing for direct marketing, automated processing, or profiling. Honored at
. - DPA Sec 16(c) + DPA IRR Sec 34(c) — Right of access. The data subject has the right to reasonable access to (i) the contents of the personal data processed; (ii) the sources from which the personal data was obtained; (iii) the names and addresses of recipients; (iv) the manner by which the personal data was processed; (v) the reasons for disclosure to recipients; (vi) information on automated processes producing decisions affecting the data subject; (vii) the date when the personal data was last accessed and modified; (viii) the identity and address of the PIC. Honored in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a plain-language English summary.
- DPA Sec 16(d) + DPA IRR Sec 34(d) — Right to correct any inaccuracy or error in the personal data. Honored in-app at Settings → Account → Edit and at
. - DPA Sec 16(e) + DPA IRR Sec 34(e) — Right to erasure or blocking. The data subject has the right to suspend, withdraw, or order the blocking, removal, or destruction of his or her personal data from the PIC's filing system, upon discovery and substantial proof that the personal data is incomplete, outdated, false, unlawfully obtained, used for unauthorised purposes, or no longer necessary for the purposes for which it was collected.
- DPA Sec 16(f) + DPA IRR Sec 34(f) — Right to damages. The data subject has a right to be indemnified for any damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorised use of personal data. Judicial action available before the Regional Trial Court.
- DPA Sec 16(g) + DPA IRR Sec 34(g) + Sec 36 — Right to data portability. Where personal data is processed by electronic means and in a structured and commonly used format, the data subject has the right to obtain a copy of his or her personal data from the PIC in an electronic or structured format that is commonly used and allows for further use. Honored via the same JSON export referenced above.
- DPA Sec 16(h) — Right to file a complaint with the NPC.
- Constitutional Writ of Habeas Data (A.M. No. 08-1-16-SC) — independent constitutional remedy.
- Civil Code Art 26 / Art 32 cause of action — independent tort/quasi-delict cause of action.
6.2 Timeline
- DPA Sec 16(c) access: the NPC's interpretive practice (NPC Advisory 2017-03 + NPC Advisory Opinions) is that PICs should respond as soon as practicable and in any event within a reasonable period — the NPC's published guidance benchmarks this at 30 days from receipt, extendible with notice to the data subject. Balance adheres to a 30-day target.
- DPA Sec 16(d) correction: as soon as practicable, in any event within 30 days.
- DPA Sec 16(e) erasure/blocking: Balance gives effect to an erasure/blocking request within 30 days, consistent with NPC published guidance.
- DPA Sec 16(b) right to object: acted on immediately at the next processing cycle.
- NPC complaint: the NPC's published target under NPC Circular 2022-04 is mediation within 30 days + adjudication thereafter; complex matters may take longer.
Where the access carve-outs at DPA IRR Sec 37 apply (national security, public order, public safety, prevention/investigation/prosecution of criminal offences, regulatory enforcement, court proceedings, journalism, research), Balance may decline to provide access and explain the reasons.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.
6.4 Fees
Under DPA IRR Sec 34(c) + NPC interpretive practice, a PIC may charge a reasonable fee for processing an access request, provided the fee is not excessive. Balance does not charge for access in practice.
6.5 Language
A request may be submitted in English or Filipino. The NPC accepts complaints in English and Filipino.
7. Children's data — DPA + Family Code parental authority + RA 7610 + RA 11930
Balance processes personal data of Philippine kids under the following layered framework:
- DPA Sec 12(a) consent + DPA Sec 11 general principles read with the NPC's interpretive practice on children's data — for any child below 18 years, the PIC should obtain consent from the parent or guardian exercising parental authority under the Family Code Arts 209–225.
- Civil Code Art 1327 + 1390 incapacity of minors — contracts entered into by a minor below 18 are voidable; the parent's consent ratifies the relevant processing arrangement.
- Family Code Arts 209–225 — joint parental authority of father and mother (Art 211); in case of separation, parental authority is exercised by the parent designated by the court (Art 212); parental rights and duties at Art 220–221; substitute parental authority at Art 216.
- RA 7610 + RA 11930 + RA 9775 — child-protection layer.
- UN Convention on the Rights of the Child (Philippines ratified 21 August 1990) + the Optional Protocol on the Sale of Children, Child Prostitution and Child Pornography (Philippines ratified 28 May 2002) — internalised through the Philippine child-welfare statutes.
For Balance:
- Verifiable Parental Consent. Identical mechanism to A-US § 5. The VPC screen is in English (Filipino queued for Phase 2 locale rollout).
- No kid-self-serve consent path. Per § 5.3 above.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from the Philippines — DPA Sec 21 + DPA IRR Sec 44 + Sec 50
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Philippine resident's personal data leaves the Philippines at the point of being uploaded to the Balance backend.
8.1 The Philippines-to-US transfer mechanism — DPA Sec 21 + DPA IRR Sec 44 + Sec 50
DPA Sec 21 is the accountability principle: each PIC is responsible for personal information under its control or custody, including information that has been transferred to a third party for processing, whether domestically or internationally, subject to cross-border arrangements and cooperation. DPA IRR Sec 44 + Sec 50 operationalise the accountability principle by requiring the PIC to (i) use contractual or other reasonable means to provide a comparable level of protection while the personal data is being processed by the third party (Sec 44); (ii) maintain a written outsourcing/subcontracting agreement that imposes obligations on the PIP including security, breach notification, audit, retention, and return/destruction at end of engagement (Sec 50).
Balance relies on the following stack to satisfy DPA Sec 21 + DPA IRR Sec 44 + Sec 50 for the Philippines → US transfer:
- DPA IRR Sec 50 written outsourcing/subcontracting agreement. Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor agreement that imposes legally enforceable obligations on the recipient to provide a standard of protection comparable to the DPA. The full transfer pack is in our international-transfer pack § 6. The contractual safeguards are reinforced by EU SCC substance + UK IDTA substance + APP-aligned substance + Quebec-Private-Sector-Act-aligned substance as substantive overlays.
- DPA Sec 12(a) consent overlay. As a belt-and-braces overlay, the parent's sign-up consent prominently and expressly discloses the cross-border transfer to the United States, expressly states that the US recipient is bound by contractual obligations to provide DPA-comparable protection, identifies the country of destination and the categories of recipients, and informs the parent of any risk arising from the transfer.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's processor agreement forbids onward transfer of Philippine-resident personal data to a third country outside the DPA Sec 21 + DPA IRR Sec 44 + Sec 50 framework without the controller's prior written authorisation.
8.2 The Philippines-to-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Philippines-KZ axis is covered by the DPA IRR Sec 50 written outsourcing/subcontracting agreement — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
8.3 NPC registration of data processing systems
DPA IRR Rule XI Sec 47 requires PICs to register their data processing systems with the NPC where the PIC processes personal data of more than 1,000 individuals OR processes sensitive personal information of at least 1,000 individuals OR uses 250+ employees or processes data on more than 1,000 individuals. Balance's projected user base at and after the Philippine rollout crosses the 1,000-individual personal-data threshold. Balance will register its data processing systems with the NPC via the NPC Registration System portal at https://register.privacy.gov.ph/ once the operational rollout threshold is reached and will maintain the registration as required. The registration filing is tracked at our internal compliance tracker.
9. Data residency for Philippine residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Philippine resident's personal data held in the Philippines? | No. Every Philippine resident's personal data is held in the United States. The DPA Sec 21 + DPA IRR Sec 44 + Sec 50 transfer mechanism in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements. |
| Is there a Philippines establishment? | No. Balance has no permanent establishment in the Philippines. The DPA's extraterritorial reach (Sec 6 + NPC interpretive practice) is the basis for Balance's DPA compliance. |
| Where is the supervisory authority? | The Philippines — NPC + DICT + the regulatory bodies in § 3.3 above. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. The Philippines does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Bangko Sentral ng Pilipinas Circular No. 982 of 2017 on outsourcing by banks — not applicable to Balance) and the National ID System under RA 11055 (data of the PhilSys database must be stored within the Philippines — Balance does not process PhilSys data).
10. Sub-processors touching Philippine-resident data
| Sub-processor | Role | Location of processing | Philippine transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | DPA IRR Sec 50 written outsourcing agreement with DPA-comparable-protection clauses + DPA Sec 12(a) parent's consent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
DPA IRR Sec 50 written outsourcing agreement (Google Cloud Data Processing Addendum) + DPA Sec 12(a) consent; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
DPA IRR Sec 50 written outsourcing agreement (Google Cloud Data Processing Addendum) + DPA Sec 12(a) consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Philippine kid + parent devices | United States | DPA IRR Sec 50 + DPA Sec 12(a) as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | DPA IRR Sec 50 + DPA Sec 12(a) as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | DPA IRR Sec 50 + DPA Sec 12(a) + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Philippine parent users | United States | DPA IRR Sec 50 + DPA Sec 12(a). |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + DPA Sec 20 security obligation. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.
11. Breach notification — DPA IRR Sec 38 + NPC Circular 16-03 (Personal Data Breach Management)
DPA IRR Sec 38–43 + NPC Circular No. 16-03 (Personal Data Breach Management, in force from 15 December 2016) is the principal breach-notification regime, with a 72-hour deadline for NPC notification:
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| NPC | A notifiable personal data breach has occurred — defined at DPA IRR Sec 38 as a breach where (a) the personal data involves sensitive personal information or any other information that may be used to enable identity fraud; and (b) the personal information has been acquired by an unauthorised person; and (c) the unauthorised acquisition is likely to give rise to a real risk of serious harm to any affected data subject. | Within 72 hours from knowledge of, or reasonable belief by, the PIC or PIP that a personal data breach requiring notification has occurred (DPA IRR Sec 38 + NPC Circular 16-03 § III.B). Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery (matched to the GDPR Art 33 benchmark and DPA IRR Sec 38). | NPC online Data Breach Notification Management System at https://dbnms.privacy.gov.ph/ |
| Affected individuals | Same trigger as NPC notification. | Within 72 hours from the same knowledge/reasonable-belief trigger (DPA IRR Sec 38 + NPC Circular 16-03 § III.C), individually OR via mass-media or alternative means where individual notification is not practicable. | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English. |
| OSAEC-specific | An incident with a CSAE/OSAEC component. | Per § 14 below + the internal runbook (M1). | PNP-WCPC + NBI-CCD + DSWD + IACACP. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under DPA IRR Sec 38 completed within 72 hours of discovery, NPC notification within the statutory 72-hour deadline, affected-individual notification within the same 72-hour window unless a NPC Circular 16-03 § III.C delay carve-out applies (notification likely to compromise an ongoing investigation; the data has been rendered unintelligible; etc.).
11.1 Minimum content of the NPC notification (DPA IRR Sec 41 + NPC Circular 16-03 § IV)
The NPC notification states:
- the nature of the breach, the description of how the breach happened, the personal data possibly involved, the chronology of the events leading up to the loss of control of the personal data;
- the number of data subjects involved (or the best estimate);
- the description of the likely consequences of the breach;
- the measures taken or proposed to be taken to address the breach (including measures to mitigate possible harm or negative consequences);
- the name and contact details of the DPO (, named individual: ) — the contact from whom the affected data subjects may obtain additional information.
The English-language template lives in our breach-notification runbook § 8.1.
11.2 Non-compliance — DPA Ch VIII + NPC Circular 2022-01
- DPA Sec 30 — Concealment of security breaches — imprisonment of 1 year and 6 months to 5 years + fine of PHP 500,000 to PHP 1,000,000.
- NPC Circular 2022-01 — Administrative fines — grave infraction (which includes failure to notify a notifiable breach) attracts a fine of 0.5% to 3% of annual gross income of the immediately preceding year, or PHP 50,000 to PHP 5,000,000 per violation, whichever is higher.
11.3 Annual security incident report
DPA IRR Sec 43 + NPC Circular 16-03 § V require PICs to submit an Annual Security Incident Report to the NPC by 31 March of the following year, regardless of whether any notifiable breach occurred. Balance complies via the NPC online portal.
12. Cookies, spam, and electronic direct marketing
The Philippines does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) DPA Sec 12(a) + Sec 11 transparency for any cookie that processes personal data; (ii) the NPC's interpretive position on cookies (NPC Advisory Opinions on online tracking); (iii) RA 7394 Consumer Act and RA 11313 Safe Spaces Act on direct marketing harassment; (iv) RA 10175 Cybercrime Prevention Act Sec 4(c)(3) on unsolicited commercial communications (the relevant subsection was largely upheld in Disini v Secretary of Justice G.R. No. 203335 with constitutional modulation); (v) RA 11967 Internet Transactions Act on consumer-facing communications.
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send commercial electronic messages to Philippine residents within the meaning of RA 10175 Sec 4(c)(3). The only email Balance sends to Philippine parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. If Balance ever introduces a marketing channel, we will comply with RA 10175 Sec 4(c)(3) as modulated by Disini v Secretary of Justice + NPC Advisory Opinions on direct marketing + DTI DAO on advertising + RA 11313 anti-harassment.
12.4 No telemarketing
Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Philippine residents.
13. Lawful-access requests and the encryption posture
Philippine authorities may serve a lawful-access request on Balance via:
- A judicial Warrant to Disclose Computer Data ("WDCD") under RA 10175 Sec 14 + the Rule on Cybercrime Warrants (A.M. No. 17-11-03-SC, in force from 5 August 2018) — the principal mechanism for compelling production of stored personal data in connection with a cybercrime investigation.
- A judicial Warrant to Intercept Computer Data ("WICD") under RA 10175 Sec 15 + the Rule on Cybercrime Warrants.
- A judicial Warrant to Search, Seize and Examine Computer Data ("WSSECD") under RA 10175 Sec 15 + the Rule on Cybercrime Warrants.
- A judicial Warrant to Examine Computer Data ("WECD") under RA 10175 Sec 15 + the Rule on Cybercrime Warrants.
- A judicial Subpoena Duces Tecum under Rule 21 of the Rules of Court.
- A Search Warrant under Rule 126 of the Rules of Court.
- An NPC compliance order or compliance notice under DPA Sec 7 + NPC Circular 2022-04.
- A judicial Disclosure of Subscriber Information / Traffic Data via court process under RA 10175 Sec 13 + the Rule on Cybercrime Warrants.
- An OSAEC-related warrant or order under RA 11930.
- A Mutual Legal Assistance Treaty ("MLAT") request channelled through the DOJ-OOC under the Budapest Convention on Cybercrime (in force for the Philippines since 1 July 2024) or under a bilateral MLAT.
- A Writ-of-Habeas-Data return + court order under A.M. No. 08-1-16-SC.
- A Subpoena Ad Testificandum or Subpoena Duces Tecum from the NBI under RA 157 (NBI Charter) + Section 1, Rule 21.
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media. RA 4200 (Anti-Wiretapping Act) + RA 10175 Sec 4(a)(2) illegal interception + DPA Sec 25 unauthorized processing all reinforce the design choice.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Philippine counsel to assess the validity of the request and the appropriate response under DPA Sec 4 carve-outs + DPA Sec 12(c) legal-obligation basis + the Rule on Cybercrime Warrants + applicable Rules of Court; 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules and the RA 10175 Sec 13 + RA 11930 Sec 12 preservation regime — minimum 6 months extendible); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- OSAEC-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with PNP-WCPC, PNP-ACG, NBI-CCD, DSWD, IACACP, IACAT, and DOJ-OOC on any OSAEC-related referral, via the routes in § 14 below. Balance is not an "Internet intermediary" within the OSAEC Law definition (the OSAEC Law's Internet intermediary definition tracks search engines, social-media platforms, ISPs, and hosting providers), but voluntarily honors the spirit of RA 11930 Sec 12 cooperation duties.
- Notification of the data subject. Where the lawful-access request is not accompanied by a non-disclosure obligation, we will inform the affected parent of the request (DPA Sec 16(a) right to be informed). Where the request is accompanied by a statutory non-disclosure obligation (e.g., under RA 10175 + the Rule on Cybercrime Warrants + RA 11930 + the Bank Secrecy Act — though none of these typically engage Balance), we will comply with the order and inform the parent as soon as the order permits.
The full encryption posture is in our encryption-posture record.
14. OSAEC / CSAE reporting routes — Philippines
A Philippine resident (parent, kid, or third party) who wishes to report an OSAEC or CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in English. - Philippine National Police – emergency 911; PNP non-emergency 117.
- PNP Anti-Cybercrime Group (PNP-ACG) — phone: +63 2 8723 0401 local 7491 / +63 998 598 8116; hotline
(02) 8414-1560/0998-598-8116; onlinehttps://acg.pnp.gov.ph/— Online Complaint Form + iReportTayo app. - PNP Women and Children Protection Center (PNP-WCPC) — for CSAE / OSAEC investigation; phone: +63 2 8532 6690 / +63 919 777 7377; online
https://wcpc.pnp.gov.ph/. - NBI Cybercrime Division (NBI-CCD) — phone: +63 2 8523 8231 to 38 local 3454; online
https://nbi.gov.ph/— Complaint Form. - DOJ Office of Cybercrime (DOJ-OOC) — phone: +63 2 8521 8344 / +63 2 8526 2747; online
https://cybercrime.doj.gov.ph/. - Department of Social Welfare and Development (DSWD) — child-protection hotline 1383 ("Bantay Bata 163" partnership); online
https://www.dswd.gov.ph/. - Bantay Bata 163 — ABS-CBN Foundation 24-hour child-protection helpline. Phone: 163 (within Metro Manila + select areas) / +63 2 8415 2163 / +63 2 8414 5151; online
https://www.bantaybata163.com/. - 1343 Actionline Against Human Trafficking — IACAT anti-trafficking 24-hour hotline. Phone: 1343 (within Metro Manila) / +63 2 1343 (outside).
- CSAM CyberTipLine — National Coordination Centre Against OSAEC (NCCAOC) — under DSWD-IACACP. Cross-reports also routed to NCMEC CyberTipline via
https://report.cybertip.org/. - Council for the Welfare of Children (CWC) — online
https://cwc.gov.ph/. - Stairway Foundation —
https://www.stairwayfoundation.org/. - ECPAT Philippines —
https://www.ecpat.org/. - End Violence Against Children Philippines —
https://www.endviolenceagainstchildren.ph/. - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Philippines coordination via PNP + INTERPOL Manila. - INHOPE — the Philippines does not currently host a domestic INHOPE-member hotline at the Effective date. Cross-border CSAM reports flow through NCMEC + INHOPE international + INTERPOL Manila.
- In Touch Crisis Line — emotional-support helpline. Phone: +63 2 8893 7603 / +63 917 800 1123.
- HopeLine — mental-health crisis helpline. Phone: +63 2 8804 4673 / +63 917 558 4673 / 2919 (Globe and TM subscribers, free).
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
A Philippine resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| National Privacy Commission (NPC) | DPA | 5th Floor, Delegation Building, PICC Complex, Vicente Sotto Street, Pasay City 1307; https://www.privacy.gov.ph/; +63 2 8234 2228 |
| Department of Information and Communications Technology (DICT) | ICT policy + NPC parent department | C.P. Garcia Avenue, Diliman, Quezon City 1101; https://dict.gov.ph/; +63 2 8920 0101 |
| PNP Anti-Cybercrime Group (PNP-ACG) | Cybercrime + OSAEC | https://acg.pnp.gov.ph/; (02) 8414-1560 / 0998-598-8116 |
| PNP Women and Children Protection Center (PNP-WCPC) | RA 7610 + RA 11930 + RA 9775 | https://wcpc.pnp.gov.ph/; +63 2 8532 6690 |
| NBI Cybercrime Division (NBI-CCD) | Cybercrime | https://nbi.gov.ph/; +63 2 8523 8231 to 38 local 3454 |
| DOJ Office of Cybercrime (DOJ-OOC) | Cybercrime central authority + Budapest Convention 24/7 point of contact | https://cybercrime.doj.gov.ph/; +63 2 8521 8344 |
| DSWD | Child protection / OSAEC / IACACP chair | https://www.dswd.gov.ph/; 1383 |
| DTI — e-Commerce Bureau | RA 11967 Internet Transactions Act + RA 7394 Consumer Act | https://www.dti.gov.ph/; +63 2 8751 3330 |
| Philippine Competition Commission (PCC) | RA 10667 competition law | https://www.phcc.gov.ph/; +63 2 8771 9722 |
| Commission on Human Rights (CHR) | Human rights | https://chr.gov.ph/; +63 2 8294 8704 |
| Regional Trial Courts | DPA Sec 16(f) right to damages + Civil Code Art 26/Art 32 + Writ of Habeas Data | via https://sc.judiciary.gov.ph/ |
| Court of Appeals | Appeals from NPC under DPA Sec 36 + concurrent jurisdiction in Writ of Habeas Data | via https://sc.judiciary.gov.ph/ |
| Supreme Court of the Philippines | Concurrent jurisdiction in Writ of Habeas Data; appellate review on certiorari | https://sc.judiciary.gov.ph/ |
A Philippine resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the DPO under DPA Sec 21(b) + DPA IRR Rule IV Sec 14). We will respond within the DPA timelines. The NPC's published policy is exhaust internal remedies first (NPC Circular 2022-04 § II.A + NPC Advisory 2017-03), but the NPC will accept a complaint directly where the data subject demonstrates that internal-remedy exhaustion is impracticable.
16. Consumer rights — the RA 7394 + RA 11967 + RA 8792 + Civil Code overlay
The Consumer Act of the Philippines (RA 7394 of 1992), the Internet Transactions Act of 2023 (RA 11967, in force from 20 January 2024) + its IRR (DTI, in force 7 June 2024), the E-Commerce Act of 2000 (RA 8792), and the Civil Code of the Philippines (RA 386) — in particular Arts 1305 et seq. on contracts, Art 1327 + 1390 on incapacity of minors, and Art 1397 on voidable contracts — apply to Balance's subscription flow as a consumer transaction. The parent is a consumer / online consumer within RA 7394 Art 4(n) + RA 11967 Sec 3. Treatment is implemented in Subscription Terms § 20.
16.1 Deceptive + unfair + unconscionable sales practices (RA 7394 Arts 50–52)
RA 7394 Art 50 prohibits deceptive sales practices (false or misleading representations regarding the nature, characteristics, terms, or geographic origin of consumer products or services). RA 7394 Art 52 prohibits unfair or unconscionable sales practices that take advantage of the consumer's inability to protect his or her own interests. The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each RA 7394 Art 50 / Art 52 risk.
16.2 Consumer rights under RA 11967 + RA 7394 + RA 8792
- RA 11967 Sec 8 — consumer rights in internet transactions: clear and accurate pricing; accurate description of the digital service; right to cancel; right to refund; protection from misleading advertising; complaint-handling mechanism reachable within 5 working days.
- RA 7394 Art 100–101 — liability for defective products + defective services.
- RA 7394 Title III — implied warranties.
- RA 8792 Sec 14–16 — recognition of electronic contracts + electronic signatures + electronic documents.
16.3 Civil Code minors' incapacity + parental ratification
Civil Code Art 1327 — minors (below 18) cannot give consent to a contract. Civil Code Art 1390 — contracts entered into by minors are voidable. Civil Code Art 1397 — voidable contracts may be ratified. The Balance subscription contract is between Balance and the parent (age 18+); the kid is not a party to the subscription contract. The kid's use of the parental-control service is under the parent's contract and the parent's parental authority (Family Code Arts 209–225), not as a separate contracting party.
16.4 Forum and choice of law
The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace RA 7394, RA 11967, RA 8792, or the Civil Code to the prejudice of the Philippine consumer are subject to the protection of consumer welfare doctrine + the public policy doctrine + RA 7394 Art 161 (which authorises DTI enforcement action against unfair contractual terms in consumer contracts).
16.5 Refunds and the Philippine subscription posture
Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the RA 11967 + RA 7394 minimum standards for a subscription-service supply. The 14-day refund window is documented at Subscription Terms § 20.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — written processor agreements with DPA-comparable-protection clauses on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA).
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- Peru Country Annex: Peru annex (A-PE).
- Uruguay Country Annex: Uruguay annex (A-UY).
- Canada Country Annex: Canada annex (A-CA).
- Australia Country Annex: Australia annex (A-AU).
- New Zealand Country Annex: New Zealand annex (A-NZ).
- Singapore Country Annex: Singapore annex (A-SG).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the DPA (RA 10173) or to the DPA IRR (NPC, in force 9 September 2016) triggers an off-cycle rewrite of §§ 2, 4, 6, 8, and 11.
- A new or amended NPC Circular — including NPC Circular 16-03 on breach management, NPC Circular 2022-01 on administrative fines, NPC Circular 2022-04 on rules of procedure, or any successor circular on cross-border-transfer template clauses (currently none at the Effective date — the operative mechanism is the DPA IRR Sec 44 + Sec 50 contract route) — triggers an off-cycle update.
- A new or amended NPC Advisory or NPC Advisory Opinion — in particular any guidance on children's data or on cross-border transfer — triggers an off-cycle update.
- A material amendment to RA 11930 (OSAEC Law) or its IRR triggers an off-cycle update to §§ 2, 5, 13, 14.
- A material amendment to RA 9775 (Anti-Child Pornography), RA 7610 (Child Protection), or RA 11648 (age of consent) triggers an off-cycle update to §§ 5 + 14.
- A material amendment to RA 10175 (Cybercrime Prevention Act), to the Rule on Cybercrime Warrants (A.M. No. 17-11-03-SC), or to RA 4200 (Anti-Wiretapping) triggers an off-cycle update to § 13.
- A material amendment to RA 11967 (Internet Transactions Act), its IRR, RA 7394 (Consumer Act), or RA 8792 (E-Commerce Act) triggers an off-cycle update to § 16 + Subscription Terms.
- A material amendment to the Family Code (EO 209) or RA 6809 (age of majority) triggers an off-cycle update to § 5 + § 7.
- A material amendment to the Civil Code Arts 26 / 32 / 1327 / 1390 / 1397 triggers an off-cycle update to § 6 + § 16.
- A material NPC decision under DPA Sec 7, or any decision of the Court of Appeals under DPA Sec 36, or any judgment of the Supreme Court bearing on the DPA, the constitutional right to privacy, or the Writ of Habeas Data, triggers an off-cycle update.
- The entry into force of the Second Additional Protocol to the Budapest Convention (signed but not yet ratified by the Philippines at the Effective date) triggers an off-cycle update to § 13.
- A new EU adequacy decision for the Philippines (currently none at the Effective date) triggers an off-cycle update to § 8 + § 9.
- A material change to a sub-processor's DPA-comparable-protection status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The DPO signs the review off; the Designated Child Safety Officer co-signs any change to § 3 (supervisory authorities), § 5 (children's rights), § 11 (breach), § 13 (lawful-access), or § 14 (OSAEC/CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. The Filipino translation is queued for the Phase-2 locale rollout per our internal compliance tracker.
End of Philippines Country Annex.