Joel Dabao l July 24, 2026 l BusinessWorld

The Philippines has spent years discussing data privacy, cybersecurity, cloud computing, and digital government. Yet one basic question has often remained unanswered: does government actually know what data it holds, how sensitive that data is, and what level of protection each dataset requires?
Executive Order No. 119, “Updating the Government Data Classification, Establishing a Data Residency Framework, and for Other Purposes,” begins with that problem. Its significance is not limited to where government data may be stored. More fundamentally, it requires agencies to identify their information, assess the harm that could result from misuse or disclosure, and apply controls proportionate to the risk. A government cannot protect data it has not properly identified.
EO 119 divides government information into two broad classes: Restricted Access Data and Open Access Data. Restricted Access Data includes information requiring protection because unauthorized disclosure may harm national security, government operations, public interest, or individuals. Open Access Data covers information outside those protected categories.
More important than the labels is the method. Agencies must inventory the data under their custody, conduct risk and impact assessments, assign the appropriate classification, and review those classifications over time. Data may be downgraded or declassified when circumstances change. The classification, legal basis, and risk assessment must also be recorded in a government registry.
This is a necessary shift from treating classification as a stamp on a document to treating it as a continuing governance process. Both underclassification and overclassification carry risks. Weak classification exposes the State to security breaches, fraud, privacy violations, and operational disruption. Excessive classification can obstruct transparency, delay inter-agency work, and make legitimate public access more difficult. The objective must be precision.
The Order also correctly links data residency to classification. Top Secret and Secret data must generally remain within Philippine territory or other territories under Philippine sovereignty or jurisdiction. Confidential data is subject to similar treatment, although offshore storage or processing may be permitted under strict approval and safeguards. Less sensitive government information may be stored on secure cloud platforms, subject to encryption and risk controls.
This is more practical than requiring all government data to remain inside the country. A national-security file should not be treated like a published statistical report. A risk-based framework allows government to match security requirements with actual sensitivity rather than rely on blanket restrictions. It can also improve technology procurement by giving agencies a clearer basis for deciding whether information belongs on a sovereign platform, a private cloud, a commercial cloud service, or an open public system.
The economic implications are equally important. Poorly classified information creates uncertainty. Agencies hesitate to share data, cloud projects are delayed, vendors face inconsistent requirements, and open-data initiatives stall because officials are unsure what can be released. A coherent framework can make cloud procurement more predictable, improve data sharing, and give service providers clearer standards.
It can also strengthen the Philippines’ position in ASEAN’s digital economy. A country seeking a larger role in cloud, data centers, cybersecurity, and digital services needs not only infrastructure, but credible rules governing the information that moves through it.
The challenge, however, will be implementation. The hardest task will not be creating registries or templates, but developing sound judgment within agencies. Officials must distinguish genuine security from bureaucratic caution. They must avoid classifying information simply to escape scrutiny, while also ensuring that legitimate open access does not weaken protection.
EO 119 creates a Joint Oversight Committee for Data Classification, co-chaired by the Department of Information and Communications Technology and the National Security Council, and gives agencies three years to comply fully. That transition period should not become a mass relabeling exercise.
The purpose is not to create more stamps, folders, and reports. It is to improve how government understands and governs information. Executive Order No. 119 is ultimately about institutional discipline: before government can protect data, move it, share it, or use it for artificial intelligence, it must first know what that data is.
That may be the least glamorous part of digital transformation, but it may also be one of the most important.
***The views expressed herein are his own and do not necessarily reflect the opinion of his office as well as FINEX. For comments, email joeldabao@mykcat.com. Photo is from Pinterest.