Date of Publication: 11 August 2026
Manuel L. Manaligod, Jr. | Fernand Joseph D. Miranda
Executive Order No. 119 (EO 119), issued on 13 July 2026, primarily establishes a new data classification and residency framework for government agencies. However, its implications extend well beyond the public sector. Companies that process, host, store, or manage government data, including cloud service providers, IT vendors, BPOs, infrastructure operators, and participants in government projects, should therefore assess how the new framework may affect their operations and contractual arrangements.
EO 119 modernizes the government’s decades-old data classification system by introducing a unified, risk-based framework governing the classification, protection, storage, and cross-border transfer of government data. While much of the implementation will depend on forthcoming guidelines, EO 119signals a significant shift in the government’s approach to digital governance and cybersecurity.
Why This Matters to the Private Sector
One of the most notable aspects of EO 119 is that, although it does not regulate private commercial data, it expressly applies to government data processed or stored by private entities on behalf of government agencies. This includes private entities engaged in public-private partnerships, public utilities, critical infrastructure, strategic government projects, and other arrangements involving government information. Government agencies also remain responsible for ensuring that service providers handling government data implement appropriate contractual and technical safeguards.
As government agencies implement the new framework, private contractors and technology providers can expect corresponding obligations to be reflected in procurement documents, service agreements, outsourcing contracts, and cloud services arrangements.
A New Layer of Data Governance
EO 119 complements the Data Privacy Act, which regulates the processing of personal data. EO 119, on the other hand, governs government data, regardless of whether such information constitutes personal data. Consequently, organizations handling government information may need to comply with both regulatory frameworks simultaneously. This distinction is particularly significant for organizations providing digital services to government agencies, where privacy compliance alone may no longer be sufficient.
Potential Impact on Cloud and Outsourcing Arrangements
EO 119 introduces data residency rules based on the sensitivity of government information.
Highly classified government data must remain within Philippine territory (or other areas under Philippine jurisdiction), while certain categories of government data may only be processed outside the Philippines under prescribed conditions and approvals. Other government data may be stored on secure cloud platforms, subject to applicable cybersecurity and encryption requirements.
Although implementing guidelines are still forthcoming, organizations should anticipate closer scrutiny of:
• cloud hosting locations;
• offshore processing arrangements;
• cross-border data transfers;
• subcontracting structures; and
• contractual allocation of cybersecurity responsibilities.
Technology providers operating regional cloud infrastructure or centralized service centers may therefore need to evaluate whether future government engagements require adjustments to their existing data architecture.
Implications for Government Procurement and Public Sector Projects
EO 119 is also expected to influence government procurement. Organizations participating in government projects may increasingly encounter requirements relating to:
• government data classification;
• data residency;
• encryption and cybersecurity controls;
• incident reporting;
• audit rights; and
• ongoing compliance monitoring.
Private entities should therefore review existing contracts with government agencies and monitor future bidding documents for new compliance obligations arising from the implementing guidelines.
Additional Considerations for Corporate Transactions
EO 119 may likewise become relevant in mergers and acquisitions involving technology companies, managed service providers, cybersecurity firms, and government contractors. Legal due diligence may increasingly include assessments of:
• whether the target processes government data;
• where government data is stored;
• whether existing cloud arrangements satisfy applicable residency requirements;
• contractual obligations relating to government information; and
• potential remediation costs associated with future compliance.
Accordingly, EO 119 introduces another regulatory consideration that may affect transaction risk assessments and post-closing integration planning.
Looking Ahead
EO 119 establishes only the framework. Much of its practical effect will depend on the implementing guidelines to be issued by the newly created Joint Oversight Committee for Data Classification within 120 days of its effectivity. The guidelines are expected to prescribe the detailed standards for data classification, residency, cloud governance, and related compliance requirements.
In the meantime, organizations that provide technology, cloud, outsourcing, or managed services to government agencies, or that otherwise process government information, should begin identifying where government data resides within their operations and evaluate whether their contractual, technical, and governance frameworks are capable of accommodating the new regulatory landscape.
Key Takeaway
EO 119 should not be viewed solely as an internal government reform. It signals the Philippines’ broader move toward more structured governance of government data in the digital environment. For private sector organizations that support government operations, early preparation will place them in a stronger position as implementing rules begin to reshape procurement requirements, cloud deployment models, and contractual expectations.
EO 119 may be accessed through:
https://www.officialgazette.gov.ph/2026/07/13/executive-order-no-119-s-2026/
