State Borders Extend to a Chip, a Cloud, and a Tax Rule: The Philippines in the Age of Economic (IN)Security

By: Jef Mitzel B. Paran

3 August 2026

States are no longer limited to controlling physical borders because enforcement expands into the technological systems through which States exercise power and protect their interests, from something as complex as cloud and data servers to something as simple as our phones’ app stores. Interestingly, this expansion reflects a deeper transformation in the relationship between technology and sovereignty. The same technologies that power the digital economy also sustain intelligence-gathering, military systems, public services, financial networks, and industrial competitiveness. As a result, cybersecurity can no longer be treated solely as a matter of network defense or cybercrime enforcement, but it has also become a core concern of national security, trade policy, and industrial strategy.

Moving forward, bear in mind that the Philippines’ security need not mean retreating from the global economy. The better approach is to make openness more secure and more strategic. This means investing in digital systems that can be trusted, cybersecurity rules that businesses can follow with confidence, infrastructure that can withstand disruption, and fiscal incentives that build real domestic capability rather than simply reducing the tax bills of investors.

For the Philippines, this changing environment requires a more serious understanding of economic security. To cite an example, the United States has used export controls to restrict access to advanced computing chips, semiconductor manufacturing equipment, and supercomputing-related items on national security grounds. Meanwhile, the European Union has adopted the Chips Act to strengthen its semiconductor ecosystem, while its data-transfer regime after Schrems II has made privacy, surveillance, and foreign access to data embedded in the cloud and digital trade.

These developments show that globalization has not disappeared, but the rules of the game have significantly changed, and the Philippines needs to keep up with it. Trade cannot be appreciated in the modern sense as limited to tariffs, cheaper goods, or access to markets, but it has become more complicated by being increasingly about control over strategic chokepoints such as chips, data, compute capacity, telecommunications, cloud infrastructure, and software systems. A single policy measure can now serve several purposes at once. To put things into perspective, a State’s stricter regulation of its export of semiconductor chips has an incidental effect of reducing military risk and redirecting supply chains to support its domestic industry. A State may also limit the storage of its constituents’ data to local cloud servers to protect sensitive data, conveniently favoring local providers. More relatable, nationality restrictions when it comes to who can be given a franchise for operating a telecommunication network may reduce foreign influence in what the State includes as critical infrastructure. However, this has the effect of excluding foreign competitors from the domestic market, having the incidental [and unintended] effect of allowing monopolies and oligopolies to thrive. Politically, these objectives are often intertwined, and politicians may use them as a convenient justification for protectionism, in the guise of upholding the country’s national security.

However, we should not be preoccupied with asking whether a government invokes “security,” because obviously, almost every government will conveniently do so. We should focus on what is important and ask whether the measure actually responds to an identified and legitimate risk. Like any other sound national policy, a credible cybersecurity measure should be targeted, evidence-based, proportionate, and reviewable. It should fairly and adequately define critical functions, high-risk end uses, or sensitive systems. Such an approach is better compared to one that is broad, indefinite, unsupported by a concrete threat model, and conveniently designed to shield domestic firms from competition globally.

The Philippines should not choose between two lesser evils, being (a) naïve openness and (b) heavy-handed techno-nationalism. When we say naïve openness, it is a policy that would allow critical digital infrastructure, government data systems, and semiconductor-linked supply chains to develop without serious security planning on the part of the State. On the other hand, heavy-handed techno-nationalism imposes broad data localization, excludes foreign providers mainly on nationality grounds, and treats every digital dependency as a reason to close the market. Both approaches are bad economic policies because the first ignores real vulnerabilities in the digital sector and the second risks weakening the openness that makes the Philippines attractive to foreign tech investors.

Moving forward, the better course for the Philippines is strategic openness by remaining open to trade and investment, and simultaneously strengthening its capacity to manage real cybersecurity risks. Fortunately, Philippine domestic law already directs toward this balance. For example, the Data Privacy Act does not treat privacy and openness as mutually exclusive. Still, it declares, as State policy, the protection of privacy while ensuring the free flow of information to promote innovation and growth, and it holds personal information controllers accountable for data transferred to third parties, whether the processing occurs domestically or internationally. The statute also reaches certain cross-border arrangements and extraterritorial processing involving Philippine citizens or residents, which shows that the Philippines has not chosen to respond to digital risk by simply territorializing all data.

It is relevant to include in the discussion that the National Privacy Commission Advisory No. 2024-01 affirms that the Data Privacy Act is not a barrier to cross-border transfers of personal data and instead encourages lawful transfer mechanisms that preserve accountability and comparable protection. In other words, and fortunately, the Philippines does not start from the position that all data must stay within the country, but it allows data to move, only under rules that adequately protect end-users. The National Cybersecurity Plan 2023–2028 (NSCP) builds on this by treating cybersecurity as important to both peace and security and economic development by emphasizing critical information infrastructure protection and a risk-based method of identifying high-risk entities.

 The amended Public Service Act adds a further layer of protection for genuinely sensitive sectors. It (a) defines critical infrastructure to include public services so vital that their incapacity would harm national security, expressly including telecommunications; (b) it authorizes national-security review of investments and corporate control in public services; (c) it bars foreign state-owned enterprises from owning capital in critical infrastructure and public utilities, subject to limited exceptions; (d) and it requires telecommunications firms to obtain and maintain information-security certifications tied to relevant ISO standards. It is clear that the Philippines already possesses legal tools to distinguish between ordinary commercial openness and the narrower class of assets that justify heightened security scrutiny.

This matters because international trade law has a heavy hand in disciplining and directing the design of cybersecurity regulations. If the Philippines regulates goods such as chips, telecommunications equipment, or other digital hardware, the World Trade Organization (WTO) rules under the General Agreement on Tariffs and Trade may be implicated, particularly the rules on non-discrimination, national treatment, and import or export restrictions. If it regulates services such as cloud computing, data processing, or telecommunications services, the relevant disciplines may fall under the General Agreement on Trade in Services (GATS), including market access and national treatment where the Philippines has undertaken relevant commitments. Product-based cybersecurity standards may also fall within the Agreement on Technical Barriers to Trade (ATBT) when they operate as technical regulations affecting the entry or use of digital products in the market.

These agreements recognize that Member-States may pursue legitimate privacy and security objectives. For example, the GATS allows measures necessary to protect the privacy of individuals in relation to the processing and dissemination of personal data. Meanwhile, the ATBT recognizes national security requirements as a legitimate objective, provided that the measure is not more trade-restrictive than necessary and is not applied as a disguised restriction on trade. Relevant to this is the ruling of the WTO panel in Russia—Measures Concerning Traffic in Transit, which clarified that the invocation of national security under GATT Article XXI is not wholly beyond review, even if States retain substantial discretion in defining their essential security interests.

Therefore, given that the enactment of cybersecurity policies is the trend, the important question is whether the Philippines’ cybersecurity measures are designed in a way that is relevant and strategic to current threats. So, such a design must respond to an identified risk in a clearly defined critical sector, which is easier to defend than one that imposes economy-wide data localization, excludes foreign providers based mainly on nationality, or operates as a convenient shield for domestic oligopolies.

With all these in mind, it seems that the most viable solution is a risk-tiered economic security framework, where the design would not blanketly place every digital activity in the same legal category. For example, at the first tier, ordinary commercial data flows and digital services should remain open, subject to minimum cybersecurity rules. At the second tier, sectors that are sensitive but not system-critical may be subjected to enhanced obligations such as requiring regular audit rights, regulation of data cross-border transfers, and reliable incident reporting made available to end-users. At the third tier, critical infrastructure, as defined by the amended Public Service Act, and high-risk chokepoints as determined by the National Security Council of the Philippines (NSC) may justify the hardest interventions requiring Congressional oversight in the issuance of permits and possible procurement standards. This tiered matching of the intensity of regulation based on the gravity of the risk mirrors what the NCSP and WTO agreements point toward.

This is also where fiscal policy complements such a framework. In the past, countries often competed for investment by offering business-friendly tax regimes. Now, foreign investors also look for places that are conducive to growth, and this could be seen in a country’s digital infrastructure, reliable energy that can power demanding operations, competent regulators who understand and justly implement clear cybersecurity rules, and predictable treatment of capital that is insulated from politics. In that sense, cybersecurity is an important component of the investment climate itself. Philippine tax law has already moved in the direction of a more disciplined incentives regime. The CREATE Act sought to make incentives to local and foreign investors more performance-based, targeted, time-bound, and transparent. Furthermore, the CREATE MORE Act refined the system by broadening the Value-Added Tax (VAT) zero-rating, introducing the Registered Business Enterprise (RBE) local tax, and creating a dedicated taxpayer service for registered business enterprises.

However, though these tax policies are fairly recent, the international tax law has changed, and continues to change, and may have rendered these initiatives obsolete. For example, as provided under the Organisation for Economic Co-operation and Development (OECD) Pillar Two, large multinational enterprise groups are generally subject to a 15 percent global minimum effective tax rate on a jurisdictional basis, and where domestic incentives push the effective rate below that threshold, another State may collect a top-up tax instead. This poses a policy mismatch in the Philippines.

As Santos et al. (2026) explain, traditional income-based incentives such as income tax holidays and special corporate income tax rates may become less valuable to in-scope multinationals because part of the benefit can be neutralized abroad. By contrast, incentives that do not simply reduce income tax may prove more durable under the global minimum tax rules, including VAT zero-rating, customs duty exemptions, and carefully designed refundable tax credits. A familiar example can be found in the tourist VAT refund, where, when travelers buy goods abroad, they may claim back the VAT at the airport because the tax is not meant to burden goods that will ultimately be consumed outside that country. The same principle helps explain why some forms of tax relief operate differently from ordinary income-tax reductions.

Considering all these, the Philippines should structure its strategic openness so that both its cybersecurity policy and its incentive policy continue to produce real value under current international rules. Despite the enactment of some domestic laws, the Philippines has on privacy law and its safeguards for foreign ownership of critical infrastructure, there are still gaps that need fixing.

To name a few, the Philippines still lacks a dedicated Cybersecurity Act and a Critical Information Infrastructure Protection Act. This is worsened by how planning and regulation, when it comes to components of cybersecurity, are governed by different agencies with separate mandates and policy directions. Each performs an important function, and they often operate independently from one another, making it difficult to translate them into a coherent economic security strategy. On the tax side, the Philippines has not yet fully aligned its incentive system with the realities of Pillar Two, including the adoption of a Qualified Domestic Minimum Top-up Tax that would allow it to retain taxing rights over low-taxed profits earned within its own jurisdiction. In short, it becomes important that the openness of the Philippines is more strategic and operational.

It seems that the future of Philippine competitiveness, beyond traditional trade policies, will be decided by whether the country can become a reliable link in global technology networks. As evident in the discussion, a State’s modern border extends to the digital sphere that (a) encroaches on both military and commercial matters, (b) includes cloud servers that store sensitive information, and (c) even includes tax incentives that would either make or break how the Philippines navigates a growing digital global economy. The countries that succeed in this era of digitalization are those that build the most trusted systems, which, at least, the Philippines is working on today. Therefore, for the Philippines, sovereignty should not mean shutting the world out, but having the capacity to engage the world on better terms.

AI Disclosure

I, Jef Mitzel B. Paran, hereby declare that my blog article submission entitled “State Borders Extend to a Chip, a Cloud, and a Tax Rule: The Philippines in the Age of Economic (In)Security” was originally drafted and prepared by me, and that the use of AI-assisted tools was limited to Grammarly for purposes of improving sentence construction and checking grammar, spelling, and punctuation. No generative Artificial Intelligence tool was used to generate the ideas and content of the article.

I further declare that, to the best of my knowledge and due diligence as the author, all sources, references, and materials relied upon in the preparation of the article have been properly cited and acknowledged through the hyperlinks provided in the text.

Disclaimer

Blog articles and discussion papers published by Para Doxa reflect the views of the author alone and not necessarily by the University of the Philippines, University of the Philippines Institute of International Legal Studies, or by Para Doxa. Only articles bearing the University of the Philippines Institute of International Legal Studies signature may be ascribed to the institution.

About the Author

Jef is a third-year law student in the Evening Program of the University of the Philippines College of Law and a Policy Researcher in the House of Representatives. His work focuses on local governance, where he contributes to position papers on relevant House bills and policy proposals. He also works closely with government agencies in gathering and developing research data that support evidence-based and impactful legislation.

Recent Blogs

Comments

.comment-box{ max-width:700px; margin:auto; padding:20px; font-family:Arial,sans-serif; } .comment-box input, .comment-box textarea{ width:100%; padding:12px; margin-bottom:10px; border:1px solid #ddd; border-radius:8px; } .comment-box textarea{ min-height:120px; resize:vertical; } .comment-box button{ padding:12px 20px; border:none; background:#111; color:white; border-radius:8px; cursor:pointer; } .comment-item{ border:1px solid #ddd; padding:15px; margin-top:15px; border-radius:8px; } .comment-header{ display:flex; justify-content:space-between; margin-bottom:10px; } .comment-name{ font-weight:bold; } .comment-time{ font-size:12px; color:gray; } .delete-btn{ margin-top:10px; background:red; color:white; border:none; padding:8px 12px; border-radius:5px; cursor:pointer; } let comments = JSON.parse(localStorage.getItem("comments")) || []; function saveComments(){ localStorage.setItem("comments", JSON.stringify(comments)); } function addComment(){ const name = document.getElementById("commentName").value.trim(); const text = document.getElementById("commentText").value.trim(); if(!name || !text){ alert("Complete all fields."); return; } const newComment = { name, text, time: new Date().toLocaleString() }; comments.unshift(newComment); saveComments(); renderComments(); document.getElementById("commentName").value = ""; document.getElementById("commentText").value = ""; } //function deleteComment(index){ comments.splice(index,1); saveComments(); renderComments(); } function renderComments(){ const list = document.getElementById("commentList"); list.innerHTML = ""; comments.forEach((comment,index)=>{ list.innerHTML += `
${comment.name} ${comment.time}

${comment.text}

`; }); } renderComments();