The Philippines has long debated data privacy, cybersecurity, cloud computing, and digital government, yet a fundamental question has remained: does the government truly know what data it holds, how sensitive that information is, and what level of protection it requires?
Executive Order No. 119, titled “Updating the Government Data Classification, Establishing a Data Residency Framework, and for Other Purposes,” addresses this gap. It requires agencies to identify their information, assess potential harm from misuse or disclosure, and apply controls that match the identified risk.
The order separates government data into two primary classes: Restricted Access Data and Open Access Data. Restricted Access Data includes information whose unauthorized disclosure could jeopardize national security, government operations, public interest, or individual privacy, while Open Access Data covers information outside those protected categories.
Agencies must inventory all data under their custody, conduct risk and impact assessments, assign appropriate classifications, and review those classifications over time. The classification, legal basis, and risk assessment must be recorded in a government registry, establishing a continuous governance process rather than a one‑time label.
Both underclassification and overclassification carry serious risks. Weak classification exposes the state to security breaches, fraud, privacy violations, and operational disruption, whereas excessive classification can hinder transparency, delay inter‑agency collaboration, and limit legitimate public access.
The order ties data residency to classification. Top Secret and Secret data must remain within Philippine territory or other jurisdictions under Philippine sovereignty or jurisdiction. Confidential data may be stored offshore only with strict approval and safeguards, while less sensitive information can be placed on secure cloud platforms with encryption and risk controls.
By adopting a risk‑based framework, the government can match security requirements to actual sensitivity instead of applying blanket restrictions. This approach also clarifies procurement decisions, helping agencies determine whether information should reside on a sovereign platform, a private cloud, a commercial cloud service, or an open public system.
Inconsistent or poorly classified information creates uncertainty, causing agencies to hesitate in sharing data, delaying cloud projects, and stalling open‑data initiatives. A coherent framework can make cloud procurement more predictable, improve data sharing, and provide service providers with clear standards.
Beyond domestic benefits, the new classification system strengthens the Philippines’ position in ASEAN’s digital economy. Credible rules governing data movement are essential for a country aspiring to play a larger role in cloud, data centers, cybersecurity, and digital services.
Implementation remains the greatest challenge. Agencies must develop sound judgment to distinguish genuine security needs from bureaucratic caution, avoiding unnecessary classification while ensuring legitimate open access does not compromise protection.
Executive Order No. 119 establishes a Joint Oversight Committee for Data Classification, co‑chaired by the Department of Information and Communications Technology and the National Security Council. The order gives agencies a three‑year period to comply fully, with the goal of avoiding a mass relabeling exercise.
The order is not about adding more paperwork but about improving government understanding and governance of information. By knowing what data exists and how it should be handled, the Philippines can protect, move, share, and use it—including for artificial intelligence—more effectively, a critical step in its digital transformation.







