The Philippine Government Establishes a New Government Data Classification and Residency Framework
On July 13, President Ferdinand Marcos Jr. signed Executive Order (EO) No. 119, "Updating the Government Data Classification, Establishing a Data Residency Framework, and for Other Purposes." The EO modernizes the government's data classification system by establishing a comprehensive data residency framework and rules governing the cross-border transfer of government data. This is the first comprehensive government-wide policy explicitly linking data sensitivity with storage location requirements. It replaces a classification regime that had been in place since 1964, aligning government data governance with today's digital environment by addressing evolving cybersecurity risks, cloud computing, and cross-border data flows.
Key Provisions
Data Classification
EO 119 covers all government data in digital or hybrid forms, including data processed or stored by private entities on behalf of an agency (e.g., firms in public-private partnerships or those providing critical infrastructure). Commercial data owned by private entities remains exempt. Notably, the routine collection or storage of copies of government-issued identification documents by private entities for legitimate business purposes is not considered government data under this Order.
It establishes a risk-based classification framework for government data, dividing information into two broad categories based on its relevance to national security: Restricted Access Data and Open Access Data. Restricted Access Data is further classified into:
Top Secret
Secret
Confidential
Restricted
Data Residency Requirements

Cross-Border Data Transfer Governance
Cross-border transfers of government data may be undertaken in accordance with the order's Data Classification Framework and its implementing guidelines. Transfers involving personal or sensitive personal information require protection guarantees and compliance mechanisms from the responsible government entity or Personal Information Controller. Importantly, the EO clarifies that all government data remains subject to Philippine law and jurisdiction regardless of where it is processed or stored.
New Oversight and Compliance Structure
EO 119 creates a Joint Oversight Committee for Data Classification (JOC-DC), co-chaired by the Department of Information and Communications Technology (DICT) and the National Security Council. The committee will oversee implementation, issue guidelines, monitor compliance, and report to the President. The EO also requires the establishment of a Government Data Classification Registry System to document classifications and risk assessments. It explicitly prohibits overclassification to avoid unnecessary administrative burdens and inefficiencies
Implementation
Implementation of the framework will be phased over three years, with an accelerated two-year timeline for Top Secret and Secret data. The JOC-DC will issue implementing guidelines within 120 days of the order taking effect, covering classification standards, data residency policies, and the procurement of a secure private cloud platform, with stakeholder consultations expected. During the transition, agencies may continue to use existing infrastructure and services, provided they implement reasonable risk mitigation measures in accordance with the executive order, thereby affording incumbent cloud providers a grace period.
Implications
In ASEAN, the Philippine approach reflects a broader regional trend in which governments, including Indonesia and Vietnam, have increased oversight of strategic data assets while seeking to maintain an environment conducive to digital investment. However, rather than imposing a blanket data localization requirement, EO 119 adopts a risk-based data residency framework that applies stricter sovereignty requirements only to the most sensitive categories of government data. Lower-risk government data may continue to be stored on secure cloud platforms, while certain confidential data may be processed outside the Philippines subject to additional safeguards and government approval. As the framework primarily applies to government data, with commercial and private-sector data largely outside its scope, the immediate compliance impact on businesses is expected to be limited.
DICT emphasized that EO 119 is intended to provide greater regulatory certainty for cloud service providers, data centers, and digital infrastructure investors by establishing clearer standards for data protection while supporting digital transformation. The telecommunications industry similarly welcomed the framework, noting that it provides a more predictable approach to safeguarding government information while enabling the secure adoption of cloud technologies and cross-border digital services.
The effectiveness of EO 119 will ultimately depend on the implementing guidelines expected within 120 days from July 14, 2026, which will be critical in clarifying operational requirements, compliance procedures, and the safeguards governing data classification, residency, and cross-border data transfers.
USABC Advocacy Efforts
Since draft versions of the government's data localization framework first began circulating in 2023, USABC, alongside member companies and industry partners, has undertaken sustained advocacy to promote a balanced, risk-based approach to government data governance. Through extensive engagement with key Philippine government agencies, including the Department of Information and Communications Technology (DICT) and the Office of the President, as well as regular dialogue with US government counterparts and diplomatic representatives, USABC consistently emphasized the importance of preserving cross-border data flows, enabling cloud adoption, and aligning proposed regulations with internationally recognized standards and best practices. The Council also participated in joint industry submissions, policy consultations, and business-government dialogues to encourage transparency and evidence-based policymaking throughout the drafting process.
A central objective of these efforts was to ensure that legitimate national security and data sovereignty concerns could be addressed without introducing overly restrictive localization requirements that could undermine investor confidence, increase compliance costs, limit access to global digital services, or reduce the Philippines' competitiveness as a destination for digital infrastructure and technology investment. The resulting EO 119 reflects many of these principles by adopting a risk-based framework while preserving flexibility for cloud deployment and cross-border data processing under appropriate safeguards.
Going forward, USABC will continue engaging closely with the Joint Oversight Committee for Data Classification (JOC-DC) and relevant government stakeholders as the implementing guidelines are developed, advocating for transparent and inclusive consultation processes, alignment with international, and implementation measures that safeguard national security objectives while maintaining an open, competitive, and investment-friendly digital economy.