The Level of Awareness on Data Privacy Act Among the Selected Employees in Metro Manila

Authors

  • Joffer Brezuela Jumaquio Author

DOI:

https://doi.org/10.65339/ijsair.V2.I2.301

Keywords:

Awareness, Compliance, Data Privacy Act of 2012, Data Protection, Government Employees, Metro Manila, Organizational Compliance, Private Employees

Abstract

This study aimed to assess the level of awareness of selected government and private employees in Metro Manila regarding the Data Privacy Act of 2012 (Republic Act No. 10173). Anchored on Organizational Compliance Theory (Weaver, Treviño, & Cochran, 1999) and the legal framework of the Data Privacy Act, the study examined how awareness, organizational practices, and compliance mechanisms influence data privacy implementation. A quantitative research design was employed using a structured and validated survey questionnaire administered to 110 respondents selected through stratified random sampling from one government and one private institution. Data were analyzed using frequency, percentage, and weighted mean. Findings revealed that respondents, despite having high educational attainment and extensive years of service, demonstrated only a slight level of awareness of the Data Privacy Act, with a grand mean of 2.44. While they were highly aware of the importance of protecting personal and sensitive information, they showed low awareness regarding mandatory training and penalties for non-compliance. The study also identified significant issues and challenges, particularly inadequate training, low awareness of key provisions, limited resources, and insufficient technological capability, which contributed to compliance difficulties (AWM = 3.12). In response, the proposed solutions—rated as highly recommended (AWM = 3.39)—emphasized regular training programs, improved cybersecurity systems, integration of data privacy education into organizational processes, and capacity-building initiatives. The study concluded that enhancing employee awareness through continuous training and strengthening institutional capabilities are critical for improving compliance with data privacy regulations. The findings align with SDG 16 (Peace, Justice, and Strong Institutions) by promoting accountability, data protection, and institutional integrity, and SDG 4 (Quality Education) through the emphasis on continuous learning and capacity-building. In terms of sustainability impact, the study contributes to strengthening organizational governance, improving data protection practices, and fostering a culture of accountability and security within institutions, thereby supporting long-term institutional resilience and public trust.

References

Abubakar, M., Umar, A., & Abubakar, M. (2024). Personal data and privacy protection: State of literature. ResearchGate.

Agup, R. M. (2024). Data privacy act: Awareness, compliance, and challenges of nurses of government hospitals in Northern Philippines. SEEJPH, XXV, 2215–2224.

Ayuyang, D. M. (2024). Extent of implementation and level of awareness of employees on the data privacy and cybersecurity acts of Cagayan State University. Frontiers in Health Informatics, 13(7).

Bamberger, K. A., & Mulligan, D. K. (2019). Privacy on the ground: Driving corporate behavior in the United States and Europe. MIT Press.

Barlaan, J. V. (2023). Exploring local government employees' awareness of data privacy act: Insights and recommendations in the lenses of the Theory of Planned Behavior.

Bennett, C. J., & Raab, C. D. (2018). The governance of privacy: Policy instruments in global perspective. MIT Press.

Castro, C. K. (2021). The implementation of the Data Privacy Act among higher educational institutions in the Province of Pangasinan. Asian Journal of Multidisciplinary Studies, 4(2), 103–111.

Cavoukian, A. (2011). Privacy by design: The 7 foundational principles. Information and Privacy Commissioner of Ontario.

Ching, M. R. D., & Celis, N. J. (2018). Data privacy act of 2012: Compliance performance of CHED and COMELEC. De La Salle University Repository.

Claveria, P. S., Abante, M. V., & Vigonte, F. (2025). Understanding the Data Privacy Act of 2012: Safeguarding the Filipino’s digital rights. SSRN. https://doi.org/10.2139/ssrn.5274285

Conduah, A. K., Ofoe, S., & Siaw-Marfo, D. (2025). Data privacy in healthcare: Global challenges and solutions. Digital Health, 11. https://doi.org/10.1177/20552076251343959

DataGuidance. (2017). GDPR v. Data Privacy Act and IRRs Philippines.

Diyoke, M. C., & Tochukwu, S. (2020). An analysis of data protection and compliance in Nigeria. ResearchGate, 4, 377–382.

DLA Piper. (2025). Data protection in the Philippines: Country overview. DLA Piper Data Protection Handbook.

European Union. (2016). General Data Protection Regulation (GDPR). Official Journal of the European Union.

Foronda, S. M. (2023). Implementation of Republic Act 10173: A systematic literature review. SSRN Electronic Journal.

Foronda, S. M., Ching, M. R. D., & Pitogo, V. A. (2023). Understanding institutional determinants of data privacy compliance. Philippine Journal of Public Administration, 67(2), 145–168.

Foronda, S. M., Javier, N., Vigonte, F., & Abante, M. V. (2023). Implementation of RA 10173 in ALECO. SSRN Electronic Journal.

Hoel, T., & Chen, W. (2018). Privacy and data protection in learning analytics. Research and Practice in Technology Enhanced Learning, 13(1).

International Association of Privacy Professionals (IAPP). (2017). GDPR matchup: Philippines’ Data Privacy Act. Privacy Tracker.

Lacity, M., & Khan, S. (2021). Data privacy and governance frameworks in digital organizations. Journal of Information Systems Management, 38(3), 203–218.

Li, W., Li, Z., Li, W., Zhang, Y., & Li, A. (2025). Mapping GDPR effectiveness: A systematic review. Computer Law & Security Review, 57, 106129.

Meyer, J. W., & Rowan, B. (1991). Institutionalized organizations: Formal structure as myth and ceremony. In The new institutionalism in organizational analysis. University of Chicago Press.

Miano, L. C. (2025). Awareness on data privacy vis-à-vis data management practices. Edelweiss Applied Science and Technology, 9(1).

National Privacy Commission (NPC). (2016). Implementing Rules and Regulations of RA 10173.

National Privacy Commission (NPC). (2020). NPC advisory guidelines on Data Protection Officer functions.

National Privacy Commission (NPC). (2021). Annual report on enforcement and compliance monitoring.

Parker, C., & Nielsen, V. L. (2017). Explaining compliance: Business responses to regulation. Edward Elgar.

Pesito, P. M. F., et al. (2020). Efficiency of compliance to Data Privacy Act of 2012. International Journal of Advanced Trends in Computer Science and Engineering, 9(5), 7669–7675.

Pitogo, V. A. (2019). National government agency’s compliance on Data Privacy Act of 2012. De La Salle University Repository.

Republic of the Philippines. (2012). Republic Act No. 10173: Data Privacy Act of 2012. Official Gazette of the Republic of the Philippines.

Santana, P. C., & Ansari, F. A. (2023). Data protection and privacy as a fundamental right. Journal of Liberty and International Affairs, 9(3), 555–576.

Suchman, M. C. (1995). Managing legitimacy. Academy of Management Review, 20(3), 571–610.

Supeno, S., Rosmidah, R., & Iqbal, S. M. U. (2025). Personal data protection in legal theory. Journal of Law and Legal Reform, 6(3), 1349–1376.

Westin, A. (1967). Privacy and freedom. Atheneum Press.

Downloads

Published

2026-04-26

Issue

Section

Articles

How to Cite

Jumaquio, J. (2026). The Level of Awareness on Data Privacy Act Among the Selected Employees in Metro Manila. International Journal of Sustainability and Advanced Integrated Research, 2(2), 1133-138. https://doi.org/10.65339/ijsair.V2.I2.301