There's a persistent myth that the Data Privacy Act of 2012 is a big-company problem. It isn't. RA 10173 applies to any system that processes personal information, a barangay records database, a school enrollment form, a clinic intake sheet. Size doesn't exempt you; it changes what compliance looks like.
The baseline obligations are concrete: collect only what you need, tell people what you're collecting and why, secure it appropriately, and don't keep it forever. For a small system, that translates to a short privacy notice, role-based access, encrypted storage for sensitive fields, and a retention policy someone follows.
The mistakes I see most: shared admin accounts, personal data in spreadsheets emailed around, and no record of who accessed what. None of these require expensive tooling to fix, they require deciding that data protection is part of the system, not an afterthought.
Registration with the National Privacy Commission is required for many processing activities, and breaches involving sensitive personal information carry real penalties, including criminal liability. The cost of basic compliance is trivial next to the cost of a breach of public trust.
The practical takeaway: treat privacy as a feature you ship, not a document you file. If the system collects a name, it earns the obligation to protect it.