Legal Landscapes: Philippines- TMT
1. What is the current legal landscape for TMT in your jurisdiction?
Current Legal Landscape
The Philippines continues to solidify its position as one of Southeast Asia’s most dynamic hubs for the Technology, Media, and Telecommunications (“TMT”) industry. Driven by accelerating digitalization, expanding internet penetration, growing foreign investment, and sustained government support for technological innovation, the country is undergoing a significant transformation into a digital-first economy. As businesses and consumers increasingly rely on digital platforms, cloud infrastructure, digital payments, artificial intelligence, and data-driven services, regulators have responded with a progressively sophisticated legal framework designed to foster innovation while safeguarding market integrity, consumer protection, cybersecurity, and data privacy.
Gorriceta Africa Cauton & Saavedra (“Gorriceta” or “The Firm”) is widely regarded as the leader in navigating and shaping this legal landscape, advising digital banks, blockchain innovators, telecommunications companies, and data center operators, and helping them navigate the complex compliance obligations that define the Philippine regulatory ecosystem. With deep sector expertise and extensive experience engaging with regulators, industry stakeholders, and policymakers, Gorriceta remains uniquely positioned to guide clients through the legal, regulatory, and commercial challenges arising from the continued digital transformation of the Philippine economy.
Key Regulatory Developments
A Robust Framework for Virtual Assets and Fintech
The Philippine Central Bank or Bangko Sentral ng Pilipinas (“BSP”) and the Securities and Exchange Commission (“SEC”) have continued to develop progressive and robust licensing and compliance frameworks for Virtual Asset Service Providers (“VASPs”) and Crypto-Asset Service Providers (“CASPs”).
• Virtual Assets and Crypto-Finance: The BSP and the SEC have introduced robust regimes governing virtual assets, digital finance, and related service providers. BSP Circular No. 1108 (2021) sets out the baseline for VASPs, imposing stringent requirements on governance, cybersecurity, customer protection, transaction monitoring, and anti-money laundering adherence. SEC Memorandum Circular Nos. 4 and 5 (2025) further institutionalized the oversight of CASPs including local incorporation mandates, minimum capital thresholds, asset segregation, data governance expectations, ongoing reporting, and disclosure regimes for tokenised offerings.
Through BSP Memorandum No. M-2025-031, the BSP continued the moratorium on the acceptance of new VASP applications effective 1 September 2025, citing consumer protection and cybercrime concerns, with the policy remaining subject to future reassessment based on global and domestic developments. BSP Memorandum No. M-2026-003 (January 2026) further reminded BSP-supervised financial institutions to transact only with duly authorized virtual asset and crypto-asset service providers. It likewise provides that retail customers residing in the Philippines may not directly access offshore VASPs unless such platforms are authorized by the BSP or registered with the SEC.
On 5 June 2026, the BSP issued Memorandum No. M-2026-023 or the Coin/Token Listing Guidelines for VASPs, which sets out regulatory expectations for the due diligence and assessment of coins and tokens prior to listing. The Guidelines require VASPs to conduct ongoing monitoring of listed virtual assets, establish appropriate delisting procedures, and prohibit the listing or support of anonymity-enhancing virtual assets (privacy virtual assets).
• Electronic Money Issuance, Payment Infrastructure, and Digital Financial Marketplace: The Philippines’ digital payments ecosystem is governed by a complementary regulatory framework overseeing payment systems, electronic money issuance, merchant acquiring, and digital financial marketplaces. Under the National Payment Systems Act (Republic Act No. 11127), the BSP is vested with exclusive authority over payment systems, defines “Operators of Payment Systems” (“OPS”), and establishes the statutory foundation for the supervision of the country’s national payments infrastructure. Entities operating payment systems are generally required to register with the BSP as an OPS pursuant to the National Payment Systems Act and its implementing regulations. Depending on the nature of their activities, payment service providers may also be required to obtain additional BSP authorizations.
Electronic Money Issuers (“EMIs”) are subject to the relevant provisions of the Manuals of Regulations for Banks and Non-Bank Financial Institutions, as updated by BSP Circular No. 1166, Series of 2023, which enhanced the regime governing e-money issuance and operations, covering liquidity management, redemption safeguards, consumer protection, and capitalisation requirements. In 2024, the BSP further strengthened the digital payments ecosystem by expanding oversight into Merchant Payment Acceptance Activities (“MPAA”) through BSP Circular No. 1198, Series of 2024 which introduced industry best practices and additional consumer safeguards for payment acceptance operators, reinforcing trust in retail digital payments. In particular, entities engaged in merchant acquiring or Merchant Payment Acceptance Activities (“MPAA”) are required to secure an OPS-Merchant Acquiring License (“OPS-MAL”), which authorizes the acquisition and processing of merchants’ payment transactions and subjects licensees to prudential, operational, governance, and consumer protection standards prescribed by the BSP.
More recently, BSP Circular No. 1237, Series of 2026, introduced the regulatory framework governing digital financial marketplaces and the offering and presentation of financial products and services through digital platforms by BSP-supervised financial institutions (“BSFIs”). The Circular seeks to promote responsible digital innovation while strengthening governance, operational and technology risk management, cybersecurity, anti-money laundering, counter-terrorism financing and counter-proliferation financing (“AML/CTPF”) controls, consumer protection, and data governance, including data privacy, data sharing, and financial data portability.
Gorriceta support clients from market entry and licensing—including BSP and SEC sandbox applications—to regulatory approvals, product launches, and ongoing compliance.
Regulatory Sandboxes: Controlled Innovation with Legal Clarity
Regulatory sandboxes have become a cornerstone of the Philippines’ approach to fostering controlled innovation with legal clarity. These frameworks allow fintech and other TMT players to pilot novel products and business models under closely supervised, time-bound conditions while receiving tailored regulatory feedback. In addition to the BSP’s FinTech Regulatory Sandbox, the Securities and Exchange Commission’s Strategic Sandbox (“Stratbox”) has emerged as a key channel for innovation, particularly for products that straddle traditional securities regimes and emerging crypto-asset constructs.
Gorriceta has been at the forefront of advising clients on participation in both regulatory sandbox frameworks, including representing early adopters under the SEC Strategic Sandbox (StratBox) and the Crypto-Asset Service Provider (CASP) Thematic Sandbox. The Firm assists clients in structuring innovative products and services for regulatory testing, including CASP-related offerings such as controlled-leverage derivatives and staking services, ensuring that proposed business models are appropriately scoped for phased and risk-calibrated testing. Through this end-to-end support, Gorriceta enables clients to validate innovative business models in a controlled regulatory environment, engage constructively with regulators throughout the testing process, and establish a clear pathway toward commercial deployment and full regulatory compliance.
Sandboxes have also empowered both large incumbents and emerging players, such as Pluang Philippines, to expand their offerings, promote financial inclusion, and drive technological advancement, particularly in underserved markets. The sandboxes now function as a regulatory laboratory for the TMT sector and serve as a model for collaborative policy development between government and industry.
Reducing Market Entry Barriers: The Konektadong Pinoy Act Now in Force
A significant legislative milestone is the Konektadong Pinoy Act (Republic Act No. 12234), which lapsed into law on 24 August 2025. Its implementing rules and regulations (“IRR”), signed by the Department of Information and Communications Technology (“DICT”) and co-agencies including the National Telecommunications Commission (“NTC”) and Philippine Competition Commission (“PCC”), took effect on 17 December 2025.
The law removes the requirement for a congressional legislative franchise or a Certificate of Public Convenience and Necessity (“CPCN”) for data transmission services, replacing it with a streamlined NTC registration and certification process – including a cybersecurity audit by the DICT – for data transmission industry participants (“DTIPs”) across five network segments. The KPA enshrines open access, fair competition, and technology neutrality as governing policies, and imposes cybersecurity, information security, and data privacy obligations on all DTIPs.
This reform opens the door for more agile market participation, especially by foreign investors, emerging digital telcos, and regional players seeking to invest in Philippine connectivity infrastructure. Gorriceta has already been engaged by early entrants preparing to operate under this streamlined regime and has been instrumental in advising on structuring, capitalisation, and cross-border compliance strategies.
Furthermore, the NTC issued Memorandum Circular No. 002-02-2026, which operationalises the Konektadong Pinoy Act by setting the eligibility, registration and authorisation requirements for DTIPs across the international gateway, core or backbone, middle mile and last mile segments, thereby providing the practical entry framework for new data transmission players.
Collectively, these developments signify a deliberate move by Philippine regulators toward a more open, technology-forward business environment – one that aligns with global trends while fostering localised innovation. Gorriceta continues to be at the forefront of this transformation, leveraging its domain expertise to help clients capitalise on these legal tailwinds.
Faster Pipes, Fewer Permits: The Telco Acceleration Playbook
The government has accelerated telco roll-outs through complementary measures that simplify permits and expand shared infrastructure. The streamlining drive began with the Revised Joint Memorandum Circular No. 01, Series of 2021 issued by allied authorities such as the Anti-Red Tape Authority, the Department of Information and Communications Technology, and the Department of the Interior and Local Government which introduced single-window processing, standardised requirements, and time-bound Service Legal Agreements for towers and related civil works at both national and LGU levels. Building on and broadening those reforms, Executive Order No. 32 issued in 2023 later institutionalised end-to-end permit simplification across agencies and Local Government Units and extended it beyond towers to fiber, poles, in-building solutions, and underground facilities.
From Cart to Compliance: Internet Transactions Act and its IRR
The Internet Transactions Act, implemented by its IRR, establishes a unified framework for online trade and platform governance, aiming to build trust between digital platforms, online merchants, and consumers. It vests the e-Commerce Bureau with supervisory and enforcement powers, requires platform-level merchant verification and disclosures, sets consumer redress mechanisms and notice-and-takedown duties, and clarifies obligations for foreign operators serving Philippine users. The regime aligns commercial practices with data/privacy, cybersecurity, and advertising rules, and introduces registration and reporting touchpoints that digital marketplaces must incorporate into product and compliance roadmaps.
Algorithms with Accountability: AI Strategy to Statute
AI policy has been moving on two tracks. First, the Department of Trade and Industry’s National AI Strategy Roadmap 2.0 (“NAISR 2.0”) sets the executive-branch agenda for responsible adoption, skills and R&D, and the Center for AI Research (“CAIR”) as a hub for industry-academia collaboration. This policy track is increasingly complemented by sector-specific AI regulation, particularly the Supreme Court’s A.M. No. 25-11-28-SC establishing a governance framework for AI use in the judiciary and DepEd Order No. 003, s. 2026 establishing the Education Center for AI Research (ECAIR) as DepEd’s hub for AI research and innovation. Second, the Artificial Intelligence Regulation Act (“AIRA”), a bill that would establish a National AI Commission (“NAIC”) attached to the Department of Science and Technology, aims to create a National Registry of AI Systems and make registration a prerequisite for licensing and commercial deployment, and implement a risk-based framework with an AI Ethics Review Board, transparency and labeling duties, incident reporting, and administrative/civil/criminal penalties for non-compliance. Similar proposals are reflected in numerous other measures filed in the 20th Congress, including seven Senate Bills and approximately forty House Bills addressing AI governance, development, and regulation. As of June 2026, however, no comprehensive AI-specific statute has yet been enacted.
Public Rails & Trust Layers: Free Public Wi-Fi, Backbone, and National PKI
Connectivity and digital-trust programs continue to underpin market growth. The Free Public Internet Access program of the Department of Information and Communications Technology expands last-mile connectivity in priority sites (e.g. Geographically Isolated and Disadvantaged Areas), complementing the National Fiber Backbone to reduce access costs for ISPs and enterprises. Additionally, to strengthen security and transactional trust, the Philippine National Public Key Infrastructure (“PNPKI”) provides government-grade digital certificates for agencies and private users, enabling secure e-services, e-signatures, and encrypted communications across the ecosystem. Legislative efforts are also increasingly focused on digital inclusion and affordability, including House Bill No. 9859, filed on 11 June 2026, which proposes a 20% discount on mobile load and internet services for students enrolled in recognised educational institutions, reflecting broader policy efforts to expand internet access and stimulate digital participation.
2. What three essential pieces of advice would you give to clients involved in TMT matters?
Establish Regulatory Compliance as a Strategic Pillar from Day One
In a sector where technological advantage is often measured in speed, many innovators overlook foundational compliance. However, in the TMT space, where businesses interface with multiple regulatory authorities (e.g., BSP, SEC, NPC, NTC), mapping all regulatory touchpoints early is not just optional but is a prerequisite for sustainable growth.
Gorriceta strongly advises clients to develop a licensing and regulatory roadmap that accounts for every function in the business model, whether it involves handling user data, facilitating transactions, offering financial services, or hosting third-party content. With early planning, businesses can preempt costly regulatory missteps and avoid product rollbacks or public enforcement actions.
In particular, data privacy compliance must be deeply embedded into an organisation’s culture. The Data Privacy Act of 2012 remains a key law, but its enforcement has become more proactive. Gorriceta assists clients in going beyond mere checkbox compliance by applying privacy-by-design principles, performing data protection impact assessments (DPIAs), and integrating privacy provisions into user agreements, vendor contracts, and platform operations.
Take a Proactive, Not Reactive, Approach to Intellectual Property (IP) Protection
The advent of AI, open-source systems, and user-generated content has significantly complicated IP strategy. Algorithms trained on third-party data, generative tools creating potentially infringing content, and platforms relying on licensed APIs all carry latent risks.
Gorriceta urges clients to secure their IP early and broadly, including trademarks, source code, software licenses, and proprietary methodologies. The Firm regularly advises on IP registration strategies, platform-specific IP policies, and drafting of robust licensing, confidentiality, and data usage agreements. In emerging sectors like NFT marketplaces and AI-assisted content creation, Gorriceta has also provided legal risk frameworks that help clients balance innovation with enforceability.
Adopt a Dynamic Mindset: Regulation Moves Fast, and So Should You
The TMT sector is marked by rapid regulatory evolution, often driven by emerging technologies, new consumer behaviors, or global developments. Clients must remain strategically agile to avoid compliance bottlenecks.
The full enforcement of the Internet Transactions Act, the enactment of the Konektadong Pinoy Act and its IRR, the SEC CASP Rules and Guidelines, and the extension of the BSP VASP moratorium collectively illustrate how quickly the Philippine regulatory environment can shift. Gorriceta equips clients with forward-compatible contracts, modular platform terms, and governance structures that can quickly pivot as new laws take effect. The Firm also conducts regulatory horizon scanning, helping businesses anticipate legislative changes and adjust their internal systems accordingly.
3. What are the greatest threats and opportunities in TMT law in the next 12 months?
Threats:
Cybersecurity Vulnerabilities and Digital Fraud
The rapid digitisation of financial and TMT services has materially increased clients’ exposure to cyber threats, ranging from data breaches, ransomware, and phishing to sophisticated insider and supply-chain attacks. Philippine regulators now expect robust, enterprise-grade cybersecurity and fraud prevention controls, particularly from VASPs, CASPs, electronic money issuers, and fintech platforms. Compliance overlay includes the Data Privacy Act (and NPC implementing rules) on personal data protection and breach notification, recently clarified through NPC Advisory No. 2026-02 by providing guidance on the submission of personal data breach notifications through the Data Breach Notification Management System (DBNMS), the Cybercrime Prevention Act’s framework for responding to unlawful intrusions, and sectoral guidance from the BSP and SEC requiring incident detection, escalation, and timely remediation protocols.
Gorriceta assists clients in designing and implementing multi-layered cybersecurity and anti-fraud architectures, including governance policies, third-party risk management, encryption standards, continuous monitoring, and red-team exercises. The Firm drafts tailored incident response and data breach playbooks, advises on regulatory notification obligations and timing, and coordinates with the NPC and relevant law enforcement or cybercrime units during post-incident investigations. In addition, Gorriceta counsels on cyber insurance placement, conducts legal and technical risk audits, and integrates cyber resilience into broader compliance and product design strategies to mitigate legal, reputational, and operational fallout from digital threats.
The Rise of Deepfakes and AI Voice Cloning
AI-generated impersonations of public figures, family members, and executives have enabled sophisticated scams and reputational attacks. The misuse of deepfake videos and voice cloning technology has already triggered legal debates around digital identity theft, consent, and platform liability.
Gorriceta is currently working with digital content platforms and telecom providers to embed AI verification tools, establish consent frameworks for voice and likeness usage, and draft terms of service that delineate platform liability. The Firm anticipates this issue escalating into a central compliance area, especially as generative AI tools become more accessible.
Opportunities:
Unprecedented Growth in Digital Infrastructure, M&A, and Cross-Border Investment
The Philippines is entering a golden age for digital infrastructure investment, fueled by liberalised FDI rules, consumer demand for high-speed connectivity, and regulatory reforms. This has catalysed a new wave of joint ventures, acquisitions, and project finance arrangements in the TMT space.
Gorriceta represents leading players across these deal types, including investors entering the data center space, fiber broadband consortia, and cloud infrastructure ventures. The Firm has handled the full deal lifecycle, from term sheet negotiation and legal due diligence to regulatory approvals with the NTC, SEC, and Philippine Competition Commission (“PCC”).
Notably, there is an increasing shift toward asset-light models, wherein telcos outsource tower operations, SaaS platforms migrate infrastructure to hyperscalers, and fintechs adopt leaner structures. Gorriceta’s corporate and TMT teams are well-positioned to provide tailored legal support for these emerging configurations.
4. How do you ensure high client satisfaction levels are maintained by your practice?
Gorriceta’s TMT practice sustains high client satisfaction by blending deep subject-matter expertise with a genuinely client-centric execution model and a long-term partnership mindset.
The team is made up of specialists who understand the technical, legal, and commercial intricacies of the digital economy. Whether navigating complex business models, licensing requirements, architecting compliance for cloud-native products, or structuring cross-border data and localisation arrangements, the legal advice is commercially aligned, and implementable.
Gorriceta is grounded in a holistic understanding of each client’s operating model, from onboarding and monetisation to growth plans, so that legal opinions and solutions are practical, implementable, and aligned with business objectives. Clients regularly highlight Gorriceta’s responsiveness, clarity, and ability to translate complex regulatory risk into manageable, business-forward actions.
Finally, the relationship is seen as lasting rather than transactional. Gorriceta advises clients through multiple funding rounds, product evolutions, and geographic expansions, proactively anticipating legal friction points and adapting advice as the client’s innovation trajectory shifts. This continuity fosters trust, and reinforces satisfaction across each client’s business lifecycle.
5. What technological advancements are reshaping TMT law and how can clients benefit from them?
Blockchain and Smart Contracts: Codifying Trust
Blockchain has transitioned from a concept to an established infrastructure. Today, it supports a wide range of applications, including cross-border payments, digital ID systems, tokenised real estate, and digital collectibles. The rise of stablecoins, cryptocurrencies pegged to fiat currencies, has significantly impacted remittance flows in the Philippines. The technology is also increasingly being adopted in the public sector, as seen in the Department of Public Works and Highways’ 2026 rollout of the “Integrity Chain,” a blockchain-based monitoring platform designed to enhance transparency, accountability, and auditability in the implementation of infrastructure projects.
Gorriceta assists clients in structuring blockchain-based operations with complete regulatory compliance, including token issuance strategies, smart contract auditing, and platform governance protocols. The Firm has also provided advice on securities classification, AML protocols, and custodial arrangements related to tokenised assets.
Artificial Intelligence (AI): Automating Compliance and Efficiency
AI is playing an increasingly central role in digitised businesses by automating compliance workflows and improving operational precision, ranging from KYC/KYB onboarding and real-time anomaly/fraud detection to smart contract drafting, predictive risk scoring, and regulatory monitoring. At the same time, its use introduces novel legal and governance considerations around data privacy, explainability, bias, and automated decision-making.
Gorriceta advises clients on the full spectrum of these issues: conducting legal due diligence on AI-enabled systems, assessing privacy and data-use implications under the Data Privacy Act in light of NPC Advisory No. 2024-04 (guidelines on AI systems processing personal data) and NPC Advisory No. 2025-02 (privacy engineering), designing governance frameworks for algorithmic accountability, and embedding transparency and auditability into model deployment.
The Firm also helps structure contractual allocations of liability with vendors, drafts appropriate disclosures for end-users, and builds internal policies for internal oversight. In parallel, Gorriceta engages in early-stage regulatory dialogue and horizon scanning on emerging Philippine AI policy, positioning clients to harness efficiency gains while proactively managing compliance and reputational risk.