The Philippines’ digital economy has been gaining momentum, supported by continued policy focus on e-governance, connectivity, and trusted digital infrastructure. Executive Order No. 119, signed on July 13, 2026, adds another important building block: the country’s first explicit data residency framework for government data. The order classifies government information into access tiers, requires the most sensitive tiers to be stored within Philippine territory, and — significantly for enterprise teams — extends those obligations to private companies that handle government data. This article covers what the order requires, who it reaches, and what infrastructure teams operating in the Philippines should be planning against.
What does Executive Order 119 cover?
EO 119 covers government data in digital or hybrid form that is owned, processed, or controlled by national government agencies and instrumentalities, including government-owned or -controlled corporations and state universities and colleges. The legislative and judicial branches, constitutional commissions, and local government units are encouraged — not required — to adopt it. The order also reaches government data processed or stored by private entities on behalf of an agency in connection with public-private partnerships, public services, public utilities, critical infrastructure, and strategic or sensitive projects.
The order’s central principle is jurisdictional: all government data remains subject to Philippine laws and jurisdiction regardless of where it is physically stored, processed, or handled. A newly created Joint Oversight Committee for Data Classification — co-chaired by the Department of Information and Communications Technology and the National Security Council — will issue the implementing guidelines, monitor compliance, and report annually to the President. The full text is available from the Executive Order No. 119 — Official Gazette of the Philippines, and DICT maintains a Data Residency — Department of Information and Communications Technology resource page tracking the policy.
How do the classification tiers map to storage requirements?
The order divides government data into Restricted Access Data — Top Secret, Secret, Confidential, or Restricted, graded by the damage unauthorized disclosure could cause — and Open Access Data, which carries no access restrictions. Each tier maps to a different residency posture:
- Top Secret and Secret data must be stored within Philippine territory, or in places where the Philippines exercises sovereignty or jurisdiction, such as embassies and consulates.
- Confidential data defaults to domestic storage; overseas processing requires prior approval from the Joint Oversight Committee, with security safeguards attached.
- Restricted data may sit on secured cloud platforms that meet encryption and cybersecurity requirements.
- Open Access data can be stored on secure cloud platforms regardless of physical location, provided security controls are in place.
The practical consequence is that physical location becomes a compliance variable for the upper tiers, not just a performance one. Agencies also retain responsibility for data security wherever the data sits, so contractual and technical safeguards with service providers apply at every tier.
Which private companies are in scope?
The private-entity extension is where EO 119 matters beyond government IT. Companies handling government data through public-private partnerships, public services, public utilities, critical infrastructure, or strategic and sensitive projects fall under the framework, subject to the implementing guidelines the Joint Oversight Committee will issue.
In practice, that reach can include telecommunications operators, utilities, banks and payment operators in government arrangements, systems integrators, cloud vendors serving agencies, and outsourcing providers processing government records. The order does draw one line that will relieve many compliance teams: the routine collection or storage of copies of government-issued identification documents for legitimate business purposes — the KYC records most banks, telcos, and platforms hold — is expressly not government data under the order. Beyond that carve-out, coverage follows the data and the contract, not the location of the infrastructure. What that means operationally is covered below.
What is the compliance timeline?
The order phases compliance over three years, with milestones per year. Within the first year, covered agencies must complete capacity building, inventory their government data, and undertake initial classification of datasets and workloads. Requirements for Top Secret and Secret data must be met within the second year, and full compliance covering all remaining government data within the third. The Joint Oversight Committee’s implementing guidelines are due within 120 days of effectivity, and agencies may continue using existing infrastructure during the transition provided they take reasonable measures to manage risk.
Three years sounds generous, but infrastructure lead times consume it quickly. Migrating classified workloads onshore typically means procuring in-country capacity, re-architecting for a primary site plus disaster recovery, revalidating security certifications, and renegotiating provider contracts to embed the required safeguards. The order’s first-year classification milestone mirrors what teams learned in sector-driven residency transitions elsewhere in APAC — Indonesia’s OJK rules being a recent example: starting with a data classification audit, rather than a procurement exercise, is what keeps the timeline realistic.
How will EO 119 affect your business?
The dividing line is whether your organization handles government data — not whether you operate infrastructure in the Philippines. A company with no government data in its systems has nothing new to do: the Data Privacy Act continues to govern its personal-data processing, and an existing Philippine deployment remains a performance choice rather than a legal one.
For organizations that do handle government data, the work applies even if every rack is already in-country. Three items lead the list:
- Classification mapping. Identify which contracts involve government data and which tier that data will likely fall under. Every other obligation hangs off this mapping, and it determines whether your exposure is paperwork or re-architecture.
- Offshore copies. In-country primary storage satisfies the residency rule, but offshore disaster recovery sites, backups, cloud replicas, and analytics pipelines that receive copies of classified-tier data do not. An in-country primary paired with an overseas replica of Secret-tier data is a gap, not a compliant setup.
- Provider contracts. Safeguard requirements apply wherever the data sits, so colocation, cloud, and managed-service agreements touching government data will likely need amendments.
The implementing guidelines will settle the mechanics — evidence, audits, approval workflows — so treat this as the current reading and revisit once the Joint Oversight Committee publishes them.
What does EO 119 not change?
The order is a government-data framework, not a general localization mandate — its text states outright that it does not apply to the private sector or to commercial data owned by private entities. The Data Privacy Act of 2012 continues to govern personal data in the commercial sphere, and it regulates how data is processed and protected rather than where it must physically sit; EO 119 leans on it rather than replacing it, requiring that cross-border transfers of government data containing personal information carry protection comparable to the DPA’s standard. For purely commercial workloads, deploying in the Philippines remains a latency, performance, and control decision.
The broader policy direction reinforces that reading. The Konektadong Pinoy Act (Republic Act No. 12234), the country’s open-access data transmission framework enacted in 2025, directs DICT to formulate data-safeguarding policies “with primacy given to cross-border data flows as a key enabler of the global economy.” EO 119 is best read as a carve-out for government data within a national policy that otherwise favors open data flows — not as a turn toward general localization.
Sector rules also continue to apply on their own tracks — banks and financial institutions still answer to Bangko Sentral ng Pilipinas guidance on outsourcing and operational resilience, for example. The clean way to think about the new landscape: EO 119 adds a residency overlay for government-linked data, while the existing regimes for commercial and sector-regulated data stay in place. Our security and compliance resources cover the regional picture in more depth.
How does EO 119 fit the regional picture?
Seen from outside the Philippines, EO 119 is not an isolated regulation — it is the Philippine chapter of a trend running across APAC. Indonesia’s financial regulator now requires in-country primary and recovery infrastructure for supervised institutions, India’s central bank mandates domestic storage of payment data, and Vietnam’s new data law restricts cross-border transfers of sensitive categories. Governments across the region are strengthening rules around government data, critical infrastructure, and sovereign digital capability.
Within that trend, the Philippine approach is notably measured: a tiered framework that localizes only the most sensitive government data, keeps open-access data cloud-friendly, and sits inside a national policy that otherwise gives primacy to cross-border data flows. For hyperscalers, cloud and AI companies, financial institutions, and other regulated industries evaluating the market, that combination reads as a maturing digital governance framework — the kind of signal that builds confidence to commit long-term infrastructure investment, rather than a barrier to entry.
What does this mean for infrastructure planning in the Philippines?
The regulatory floor is only part of the story. Beyond what EO 119 mandates, many enterprises operating in the Philippines are localizing workloads by choice — to shorten latency to a large and heavily online user base, to strengthen cybersecurity and operational continuity, to keep AI training and inference close to the data they run on, and to build customer trust in regulated sectors. The order adds a compliance-driven demand layer on top of a localization trend that was already underway.
For workloads touching classified government data, in-country capacity moves from optional to mandatory within the compliance window — and the evaluation criteria tighten accordingly. Certifications become the entry ticket: buyers will want a facility whose audit stack maps to government security requirements. Digital Edge’s Philippines facilities are anchored by the carrier-neutral NARRA1 facility in Laguna Technopark, which holds ANSI/TIA-942-C Rating-3 alongside ISO/IEC 27001, SOC 2 Type II, and PCI DSS, and provisions cabinets with N+1 uninterruptible power and a 100% dual-power SLA.
The market’s physical realities still apply to residency-driven deployments. Power redundancy carries extra weight against a Luzon grid that periodically issues supply alerts; land economics favor the Laguna corridor south of Metro Manila over congested, flood-exposed metro parcels; and tropical-climate cooling makes efficiency numbers operational data — NARRA1 runs StatePoint liquid cooling at an annualised PUE of 1.24 and WUE of 1.082, limiting exposure to both power tariffs and local water stress. Residency-driven workloads also still need connectivity: carrier neutrality and interconnection options determine how an onshore deployment reaches users, agencies, and the rest of a regional architecture.
Conclusion
Executive Order 119 gives the Philippines its first tiered data residency framework, and its most consequential feature for enterprise teams is the private-entity extension: companies in public-private partnerships, utilities, critical infrastructure, and government-facing services now share the compliance burden. The three-year phase-in is workable, but only for teams that treat classification mapping as a now task rather than a later one — and the ones best positioned will be those that know precisely which of their workloads carry residency obligations and which remain a latency-led choice under the Data Privacy Act.
The larger point is that EO 119 is more than another compliance requirement. Clear classification tiers, defined oversight, and predictable timelines are the building blocks that make a market attractive for cloud, AI, hyperscale, and mission-critical digital infrastructure investment — and the Philippines has just put another one in place. Digital Edge is investing on the same conviction: resilient, carrier-neutral, hyperscale-ready and AI-ready, sustainable infrastructure built to support the long-term growth of the Philippine digital economy.
If your organization handles government data in the Philippines — or expects to under a public-private partnership — our team can walk through how colocation services at our Philippines facilities support residency-driven deployments; reach out to our team to discuss capacity, certifications, and migration timelines.



