DPO-as-a-Service
A named person is accountable for your compliance. That is the product.
Philippine data privacy compliance is not a document — it is a demonstrable, continuing program. We design it, build it, and then run it, with a designated Data Protection Officer standing behind it.
Most organizations we meet have one of three problems
No DPO was ever appointed
The obligation applies anyway. Every organization that collects personal data is a Personal Information Controller under Republic Act No. 10173, and that status does not scale down for small companies.
A DPO exists on paper only
Someone was designated, then given no program, no time and no budget. The role exists in a board resolution and nowhere else.
A template manual was bought and filed
Purchased two years ago, filed, and nothing done since — which is worse than having nothing, because it evidences that you knew what was required.
Five things you must be able to demonstrate
Appoint a Data Protection Officer
A designated, registered, independent DPO — and Compliance Officers for Privacy wherever you have branches.
Know what you hold and what it risks
Records of processing activities, and a Privacy Impact Assessment for each system that handles personal data.
Be accountable in writing
A Privacy Management Program and a Privacy Manual written to how your organization actually operates.
Demonstrate compliance
Notices, consent, data subject rights, contracts, retention, security controls and training — with evidence for each.
Be ready for a breach
A response team, a tested plan, and evidence that you actually exercise it.
What the NPC expects
None of these is a document you buy once. All five are a program you run continuously — and someone has to be accountable for running it.
Four phases. You always know what is happening now.
Every engagement follows the same four phases, so you know what is next and what evidence exists at the end of each one.
Weeks 0–2
At the end of Engage, you have
- Signed engagement
- Board resolution and designation letter
- NPC filing confirmation
- Kickoff plan
Where the rules get specific
Four sectors carry obligations beyond the Data Privacy Act itself. If you are in one of them, the overlay matters more than the baseline.
Constraints we impose on ourselves
Independence, in writing
Where Nexthread is your Data Protection Officer of record, it will not also supply, build, host or administer the systems that process your personal data. That would put us in a position to determine the means of processing we are appointed to supervise — which NPC Advisory 2017-01 treats as a conflict of interest.
Deliverables carry your name, not ours
A Privacy Manual with a consultant’s branding on it reads as an off-the-shelf purchase rather than the organization’s own policy — which is exactly the wrong impression to give a regulator.
Evidence, not intention
The internal audit tests evidence, not intention. An unevidenced yes is a no. That is an uncomfortable standard to be held to, and it is the only one that survives contact with the NPC.
The compliance calendar comes off your desk
The 72-hour clock, the five-day report, the 31 March filing, the annual renewal, and every new NPC issuance — tracked, with a written impact assessment when something changes.
Four free steps before you commit to anything
You get a written, fixed-fee proposal before any money changes hands.
- 1Free
Introductory call
We describe the obligations that actually apply to you, and answer questions. Including if the answer is that very little applies.
30 minutes
- 2Free
Mutual non-disclosure agreement
Signed before we look at anything confidential.
Same day
- 3Free
Discovery questionnaire and scoping call
We assess whether NPC registration is mandatory for you, and size the engagement.
1 week
- 4Free
Written proposal
Fixed scope, fixed fee, and a delivery schedule.
3 working days
- 5Per proposal
Engagement begins
Agreement signed, DPO designated, work starts.
1 week
The boundaries, stated up front
Start with the question that actually matters
Are you required to register with the National Privacy Commission? Four questions will tell you, and the call afterwards is free.