EO 119 (2026) Explained: Philippine Government Data Classification & Residency Framework

EO 119 (2026): What the Philippines' New Government Data Classification and Residency Framework Means for Your Agency
Short answer: Executive Order No. 119 (2026) is a Philippine government policy that establishes a risk-based framework for classifying, storing, and protecting government data. It requires agencies to classify data by sensitivity, control where that data resides (data residency), implement layered security controls, establish clear governance and accountability structures, and maintain business continuity and disaster recovery capabilities. Bequik Information Solutions helps government agencies meet these requirements through an end-to-end cybersecurity and compliance architecture.
What Is Executive Order No. 119 (2026)?
Executive Order No. 119, titled "Updating the Government Data Classification, Establishing a Data Residency Framework, and for Other Purposes," was signed by President Ferdinand R. Marcos Jr. on July 13, 2026.1 It updates the Philippine government's approach to data classification, establishes a data residency framework, and modernizes how government agencies classify, store, process, and protect their data.1,2
EO 119 replaces Memorandum Circular No. 78 (s. 1964) — a 60-year-old, paper-era classification system — with a framework built for cloud computing, AI, and modern cybersecurity threats.6
The order exists to enable secure cloud adoption across government while ensuring that data residency, cybersecurity, and accountability requirements are met.3,4 In practice, EO 119 asks a simple but demanding question of every government agency: do you know what data you hold, how sensitive it is, where it lives, who can access it, and how quickly you can recover it if something goes wrong?
In short: EO 119 replaces a one-size-fits-all approach to government data with a risk-based model — higher-sensitivity data gets stronger controls and stricter residency requirements.
Why Was EO 119 Introduced?
As Philippine government agencies increasingly adopt cloud platforms, digital services, and interconnected systems, the risk surface for sensitive government data has grown substantially. EO 119 responds to this shift by:
- Promoting security through mandated technical, administrative, and physical safeguards
- Promoting accountability through clear governance structures, audits, and monitoring
- Promoting responsible innovation by giving agencies a compliant pathway to modern, cloud-enabled digital services
The policy's stated goal is straightforward: secure data, stronger governance, and a more resilient digital Philippines.
The 5 Key Requirements of EO 119
EO 119 is built around five core requirements. Every government agency covered by the order needs a plan for each.
1. Data Classification
Agencies must classify data based on its sensitivity and impact — not treat all government data as equally critical. EO 119 sorts government data into two broad categories: Restricted Access Data (graded Top Secret, Secret, Confidential, or Restricted, based on the harm unauthorized disclosure could cause) and Open Access Data (no access restrictions).5,8. This classification determines what controls and residency rules apply downstream.
2. Data Residency
Once data is classified, agencies must determine where it is stored — within or outside the Philippines — based on that classification level. Higher-sensitivity data carries stricter residency requirements5,9
- Top Secret & Secret — must be stored within Philippine territory or Philippine jurisdiction (including embassies and consulates)
- Confidential — must generally remain in the Philippines; offshore storage or processing is allowed only as a regulated exception with prior approval
- Restricted & Open Access — may be hosted on secure, encrypted cloud platforms regardless of physical location
All government data, regardless of where it is physically stored, remains subject to Philippine law and jurisdiction under EO 119's jurisdictional principle.9
3. Security Controls
Agencies must implement technical, administrative, and physical safeguards appropriate to each data classification's risk level. This is where most of the day-to-day compliance work happens — identity management, endpoint protection, network security, and more.
4. Governance and Accountability
EO 119 requires agencies to establish clear policies, defined roles, regular audits, and ongoing monitoring — so that data protection isn't a one-time project but an accountable, continuous function.
5. Business Continuity and Disaster Recovery
Agencies must ensure the availability, backup, and recovery of critical government data and systems, so that operations can continue — and be restored quickly — after an incident.
Who Does EO 119 Apply To?
EO 119 applies to Philippine government agencies and the information systems and data they manage. Any agency handling government data — particularly sensitive or classified information — falls within its scope, along with the technology vendors and managed service providers that support those systems.
Who Oversees EO 119 Compliance?
EO 119 creates the Joint Oversight Committee for Data Classification (JOC-DC), co-chaired by the Department of Information and Communications Technology (DICT) and the National Security Council, with participation from the DILG, National Intelligence Coordinating Agency, Department of Foreign Affairs, National Privacy Commission, Philippine Statistics Authority, and National Archives of the Philippines.4,9
The JOC-DC is responsible for issuing implementing guidelines, setting classification standards, monitoring agency compliance, resolving inter-agency classification disputes, and reporting annually to the President. The committee must issue its implementing guidelines within 120 days of EO 119 taking effect.4,9
What Is the EO 119 Compliance Timeline?
EO 119 gives covered agencies a three-year phased transition period:5,7
- Year 1 — Agencies conduct data inventories, build internal capacity, and begin initial data classification and workload mapping
- Year 2 — Full compliance required for all Top Secret and Secret data
- Year 3 — Full compliance required across all remaining government data classifications
This phased approach gives agencies room to plan and budget for the security architecture EO 119 requires, rather than forcing an immediate, all-at-once migration.
What Does EO 119 Compliance Actually Require in Practice?
Meeting EO 119 is not a single software purchase — it requires a layered security architecture that covers data from the moment a user logs in to the moment data is backed up and recovered. Based on the framework Bequik has built for government clients, real-world compliance touches at least nine domains:
| EO 119 Requirement | What It Covers |
| Data Classification & Handling | Preventing sensitive data loss across users, devices, applications, and cloud platforms |
| Identity & Access Management | Ensuring only authorized users reach the right resources at the right time |
| Cybersecurity & Threat Protection | Preventing, detecting, and responding to threats across endpoints and servers |
| Network Security | Securing government networks with advanced visibility and control |
| Network Detection & Response | Detecting threats in real time across the network |
| Network Forensics & Investigation | Investigating, visualizing, and responding to cybersecurity incidents |
| Data Protection, Backup & Disaster Recovery | Protecting critical data and ensuring fast recovery and continuity |
| Secure & Resilient Infrastructure | Running compliant, high-performance workloads on resilient platforms |
| Secure Email & Collaboration | Protecting communication from phishing, data leaks, and impersonation |
A tenth function — managed security services — ties all of the above together with continuous, 24/7 monitoring.
Bequik's EO 119 Compliance Solutions
Bequik Information Solutions, Inc. has built a compliance and solution framework mapped directly to EO 119's requirements.10,11 Below is how each requirement is addressed, including the technology partners behind each capability.
Data Classification & Handling — Forcepoint, Netskope
Protects sensitive data across users, devices, applications, and cloud platforms through data loss prevention (DLP), a cloud access security broker (CASB), insider risk management, and secure web gateway capabilities.
Identity & Access Management — JumpCloud, Yubico
Ensures only authorized users access the right resources at the right time through zero trust access, multi-factor authentication (MFA), device and user management, and least-privilege access.
Cybersecurity & Threat Protection — CrowdStrike, WithSecure, Sophos
Prevents, detects, and responds to advanced threats across endpoints and servers using next-gen endpoint protection (EDR/XDR), threat intelligence, managed detection & response (MDR), and automated threat hunting.
Network Security — Fortinet
Secures government networks with advanced visibility and control through next-gen firewalls (NGFW), intrusion prevention (IPS), VPN & SD-WAN, and application control.
Network Detection & Response — DAS Security
Detects threats in real time across the network with network detection & response (NDR), encrypted traffic analysis, real-time threat detection, and behavioral analytics.
Network Forensics & Investigation — NetDem (by Datapatrol)
Investigates, visualizes, and responds to cybersecurity incidents through full packet capture, forensic analysis, incident investigation, and evidence preservation.
Data Protection, Backup & Disaster Recovery — Arcserve
Protects critical data and ensures fast recovery and business continuity with backup & replication, instant VM recovery, ransomware protection, and offsite/off-cloud copies.
Secure & Resilient Infrastructure — MAIPU HCI, Archeros HCI
Runs secure, high-performance, compliant workloads on modern hyperconverged infrastructure (HCI), with high availability, data redundancy, and centralized management.
Secure Email & Collaboration — Mimecast
Protects communication from email-borne threats, data leaks, and impersonation through advanced email security, phishing protection, email continuity & archiving, and data leak protection.
Managed Security Services — Antarex (Managed Security Operations Center)
Provides 24/7 monitoring, threat detection, and incident response for government environments through SOC monitoring, MDR, threat intelligence, and incident handling & reporting.
Why Choose Bequik for EO 119 Compliance?
- End-to-end security portfolio — a single partner covering every EO 119 requirement, not a patchwork of disconnected vendors
- Strong vendor partnerships & support — direct relationships with global security leaders backing every deployment
- Proven industry experience & expertise — track record delivering government-grade technology solutions
- Tailored solutions for government agencies — architecture designed around public-sector compliance needs, not repurposed enterprise tooling
- Local presence, rapid response & service — on-the-ground support in the Philippines when agencies need it
Business Outcomes of EO 119 Compliance
Agencies that approach EO 119 strategically — rather than as a last-minute checklist — can expect to:
- Ensure compliance with EO 119
- Strengthen data security & privacy
- Improve operational resilience
- Reduce risk & financial impact
- Enable secure digital transformation
Frequently Asked Questions About EO 119
What is Executive Order No. 119 (2026)? EO 119 is a Philippine government executive order that updates the government's data classification rules, establishes a data residency framework, and modernizes how government agencies classify, store, process, and protect their data.
What are the key requirements of EO 119? EO 119 has five key requirements: data classification, data residency, security controls, governance & accountability, and business continuity & disaster recovery.
Does EO 119 require government data to stay in the Philippines? EO 119 establishes a data residency framework where data location — within or outside the Philippines — is determined by the data's classification level, rather than applying a single blanket rule to all government data.
Who needs to comply with EO 119? Philippine government agencies that manage government data and information systems fall under EO 119, along with the technology and service providers that support those systems.
What technology is needed for EO 119 compliance? In practice, EO 119 compliance requires a layered security architecture spanning data classification and DLP, identity and access management, endpoint and network security, network detection and forensics, backup and disaster recovery, secure infrastructure, secure email, and 24/7 managed security monitoring.
How can Bequik help my agency comply with EO 119? Bequik provides an end-to-end compliance and solution framework mapped to each EO 119 requirement, combining data protection, identity management, threat detection, network security, backup and disaster recovery, resilient infrastructure, secure email, and managed SOC services from established global technology partners.
What are the data classification tiers under EO 119? EO 119 divides government data into Restricted Access Data — graded Top Secret, Secret, Confidential, or Restricted based on the potential harm from unauthorized disclosure — and Open Access Data, which carries no access restrictions.
How long do agencies have to comply with EO 119? Agencies have a three-year phased transition period: Year 1 covers data inventories and initial classification, Year 2 requires full compliance for Top Secret and Secret data, and Year 3 requires full compliance for all remaining data classifications.
Who oversees EO 119 implementation? The Joint Oversight Committee for Data Classification (JOC-DC), co-chaired by the DICT and the National Security Council, oversees EO 119 implementation. It is required to issue implementing guidelines within 120 days of the order's effectivity.
What policy did EO 119 replace? EO 119 replaces Memorandum Circular No. 78 (s. 1964), a paper-era government data classification policy that had been in place for roughly six decades.
Is your agency ready for EO 119? Bequik Information Solutions helps Philippine government agencies design and deploy the risk-based, integrated security architecture EO 119 requires. Contact Bequik at sales@bequik.com.ph or 0917-164-4726 to discuss your agency's compliance roadmap.
Bequik Information Solutions, Inc. — Secure. Compliant. Resilient. Powering a Safer Digital Government.
Note on the solution mapping: The EO 119-to-solution mapping in this article (Forcepoint, Netskope, JumpCloud, Yubico, CrowdStrike, WithSecure, Sophos, Fortinet, DAS Security, NetDem, Arcserve, MAIPU HCI, Archeros HCI, Mimecast, Antarex) reflects Bequik's own published compliance and solution framework rather than an independent EO 119 requirement — the executive order itself does not name specific vendors or products. Agencies should confirm final architecture decisions against the implementing guidelines once issued by the JOC-DC.
References:
1. Official Gazette of the Republic of the Philippines, "Executive Order No. 119, s. 2026" 2. Presidential Communications Office, "PBBM Orders Update, Modernization of Gov't Data Classification Structure" 3. Philippine Information Agency, "President Marcos Signs EO 119, Unlocking Digital Infrastructure Growth and Strengthening Philippine Data Security" 4. Philippine News Agency, "DICT: EO 119 to Boost Data Security, Attract Digital Investments" 5. Rappler, "What Marcos' New Data Rules Mean for Gov't Information, Cloud Storage" 6. Manila Bulletin, "Government Updates 60-Year-Old Data Policy for the Cloud and AI Era" 7. The Manila Times, "Marcos Orders Government Data Overhaul" 8. Philstar Tech, "Government Updates Data Rules for Cloud and AI" 9. Baker McKenzie, "Philippines: New Data Classification and Residency Rules" 10. Bequik Information Solutions, Company Website 11. Bequik Information Solutions, About Us
Is your agency ready for EO 119?
Bequik Information Solutions helps Philippine government agencies design and deploy the risk-based, integrated security architecture EO 119 requires.
