Image

What Intellectual Property Risks Should Companies Consider When Outsourcing AI Training Data to the Philippines?

Image

By: Ralf Ellspermann
25-Year, Multi-Awarded BPO Veteran
Published: 17 September 2026

Image

Reviewed By: John Maczynski
Former EVP, World's Largest Contact Center
Updated: 17 September 2026

The principal exposures are copyright that does not vest where buyers assume it does, trade secret protection that rests on documented controls rather than a dedicated statute, and vendor reuse of client data. Under Section 178.4 of the Intellectual Property Code, copyright in a commissioned work stays with the creator unless assigned in writing.

Key Takeaways

  • Philippine law does not give copyright to the party that pays. Under Section 178.4 of Republic Act 8293 the commissioning party owns the work, but copyright remains with the creator unless there is a written stipulation to the contrary.
  • Work made for hire is a United States doctrine. Reciting it in a contract governed by Philippine law does not by itself effect an assignment. The Code asks for an express written stipulation.
  • Copyright is the wrong battleground for most of the asset. Labels and coordinates are data as such and fall outside copyright entirely; a dataset is protected only for the originality of its selection and arrangement.
  • There is no standalone Philippine trade secrets statute. Protection is assembled from contract, civil liability, unfair competition doctrine, labour law and computer misuse provisions, so a claim turns on documented secrecy.
  • Your security controls are also your legal evidence. Virtual desktop restrictions, access logs and a classification policy are not only risk reduction. They are what demonstrates that reasonable steps were taken.
  • Monitoring the workforce is itself regulated processing. Behavioural and keystroke monitoring engages the Data Privacy Act, and must be proportionate, disclosed to staff and documented to be defensible.

What Is Actually at Risk, and What Protects Each Part?

Five distinct layers: the raw corpus, the individual labels, the curated dataset, the annotation guidelines and any fine-tuned outputs. Copyright covers some of these partially and one of them not at all. Trade secret and contract cover all five, which is where most protective work belongs.

Discussions of intellectual property in annotation outsourcing tend to collapse into a single question about who owns the data. That framing obscures the fact that an engagement produces several different kinds of asset, and that Philippine law treats them differently.

Figure 1. The five asset layers in an annotation engagement and the protection available to each.

The Intellectual Property Code excludes from copyright protection ideas, procedures, systems, methods, concepts, discoveries and mere data as such. A bounding box coordinate, a sentiment tag or an entity span is data in precisely that sense. A compilation of such material is protectable, but only by reason of the originality of the selection, coordination or arrangement of its contents — not the contents themselves. A buyer whose entire protective strategy rests on copyright assignment has therefore secured the thinnest of the five layers.

The annotation guidelines and taxonomy are the exception worth noting. These are written works, they carry clear copyright protection, and they are frequently the most valuable and most portable thing in the engagement. They encode how the client thinks about its problem, and they travel easily to a competitor. They deserve the same handling as source code.

Who Owns the Copyright by Default Under Philippine Law?

The creator. Section 178.4 of Republic Act 8293 provides that where a work is commissioned and paid for, the commissioning party owns the work but copyright remains with the creator unless there is a written stipulation to the contrary. That stipulation is the entire protection.

This is the single most consequential difference between Philippine and United States practice, and it runs opposite to the intuition most buyers bring. Paying for commissioned work does not transfer copyright. Absent an express written assignment, a buyer can find itself owning the delivered output while the provider retains the copyright in it.

Figure 2. Default copyright ownership in a commissioned annotation engagement, with and without an express assignment.

Two layers have to land, not one. Section 178.3 governs the relationship between the provider and its own employees: the employer holds copyright where the work results from regularly-assigned duties, but the employee retains it where the creation falls outside those duties, even if the employee used the employer’s time, facilities and materials. Section 178.4 then governs the relationship between the provider and the client. A buyer needs the provider to hold rights cleanly from its staff, and to have assigned them onward in writing.

The practical drafting point follows directly. A clause reciting that deliverables are a “work made for hire” imports an American term of art into a statute that does not use it, and may accomplish nothing. What the Code contemplates is an express written stipulation assigning copyright, executed by a party that holds the rights to assign. The governing law and forum clauses matter here too: a New York governing law clause does not necessarily displace the Philippine analysis if enforcement is ultimately sought locally, and this is a question for Philippine counsel rather than for a template.

How Does the Philippines Protect Trade Secrets?

Through a patchwork rather than a dedicated statute: contract, civil liability for acts contrary to morals or good customs, unfair competition doctrine, labour law and computer misuse provisions. A claim requires showing the information had commercial value because it was secret and that reasonable steps were taken to keep it secret.

The absence of a standalone trade secrets act is often reported as a weakness in the Philippine framework. It is better understood as a shift in where the burden falls. Remedies are available — injunctive relief, damages, specific performance, and criminal liability where conduct amounts to theft, fraud or unauthorised access — but establishing the claim depends on the claimant’s own documentation rather than on a statutory presumption.

Figure 3. What a trade secret claim requires, and the control that produces each piece of evidence.

This produces a conclusion that buyers consistently miss. Security controls and legal protection are not two separate workstreams. The virtual desktop configuration that prevents download is also the evidence that reasonable secrecy measures were in place. The access register is also the proof that disclosure was limited to those who needed it. The classification banner on screen is also what establishes that the recipient knew the material was confidential. An organisation that implements these controls but does not retain the documentation has bought the risk reduction and thrown away the legal position.

Retention periods deserve specific attention. Access logs that are purged on a ninety-day cycle will not be available when a misappropriation surfaces two years later, which is the usual timescale. The retention obligation belongs in the contract alongside the destruction obligation, and the two need to be drafted so they do not contradict each other.

What Operational Vulnerabilities Arise During Large-Scale Annotation?

Insider access, endpoint weakness and unmanaged home or hybrid working. When large cohorts touch raw enterprise data daily, the exposures are unauthorised screen capture, exfiltration and local caching. Zero-trust streaming with no local download permission addresses all three at once.

Scale changes the risk profile rather than merely amplifying it. A team of twenty can be supervised directly; a floor of five hundred cannot, and the controls have to be structural rather than behavioural. The move that matters is architectural: data is streamed into an environment the annotator can see but cannot extract from, rather than distributed to endpoints and governed by policy.

Figure 4. Standard BPO practice against the standard appropriate to proprietary training data.

One point of caution belongs alongside the monitoring column. Behavioural analytics and keystroke logging are themselves processing of the workforce’s personal data, and Philippine annotators are data subjects under Republic Act 10173 in the same way the client’s customers are. Monitoring that is disproportionate, undisclosed or undocumented creates a fresh compliance exposure while purporting to close one. Measures should be proportionate to the sensitivity of the material, disclosed to staff, and recorded — which is also, conveniently, what makes the resulting logs usable as evidence.

Personal data embedded in a training corpus raises a separate obligation. Where a dataset contains identifiable information about individuals, the processing must have a lawful basis and appropriate safeguards; redaction or synthetic substitution before transfer is the practical route, and it also narrows the blast radius of any incident.

How Should Vendor Agreements Be Structured?

Across three instruments: a master services agreement carrying the express copyright assignment, warranties and liability; a statement of work fixing processing boundaries and permitted uses; and a data processing agreement carrying privacy terms and destruction obligations. Confidentiality, assignment and audit rights must survive termination.

The instruments overlap deliberately. What matters is that no obligation falls into the gap between them, and that the ones which need to outlive the engagement sit in the agreement that does.

Figure 5. Three contractual instruments mapped across the data lifecycle.

Three provisions are worth singling out. First, an express prohibition on using client-supplied data, prompt artefacts or outputs to train generalised models or to serve other clients — a term that has become materially more important as providers develop their own model assets. Second, destruction on termination evidenced by cryptographic erasure, a signed certificate of destruction and a right of independent audit, rather than an assurance. Third, survival: confidentiality, the assignment itself and audit rights are worthless if they expire with the term.

The framework described here is general information about the Philippine statutory position rather than legal advice, and the drafting should be settled with counsel qualified in the Philippines before execution.

What Strategic Guidance Do Industry Leaders Offer on Protecting AI Assets Offshore?

Treat AI training data as a different category of work from standard business process outsourcing. Move past non-disclosure agreements to express assignment, zero-trust technical environments and contractual carve-outs covering every annotated data point and derivative output.

The recurring failure is one of classification rather than diligence. Buyers apply a customer-service outsourcing template to a workload whose output is a proprietary asset, and discover the mismatch only when they want to enforce something.

The Philippine BPO sector possesses unmatched linguistic dexterity and cultural nuance, making it the premier destination for complex AI data annotation and semantic alignment. However, executive buyers often stumble by treating AI training data like standard customer service workflows. Protecting enterprise intellectual property requires moving beyond basic NDAs to implement zero-trust technical environments and precise contractual carve-outs that guarantee absolute ownership of every annotated data point.

John Maczynski, CEO, Cynergy BPO

  • Get the assignment express and written. Do not rely on payment, on a work-for-hire recital or on any statutory default to move copyright to the client.
  • Document the secrecy, not just the security. Retain the classification policy, access register and logs, because the claim later depends on them rather than on the controls alone.
  • Contract for destruction and for retention. Both are needed, and drafted carelessly they conflict: erase the data, keep the access records.

How Did One Enterprise Scale RLHF Operations Securely?

A generative AI enterprise scaling multilingual annotation and reinforcement learning from human feedback to 500 personnel had fourteen Philippine delivery centres audited against ISO 27001, SOC 2 Type II and zero-trust capability. Throughput rose several-fold within 90 days with no reported security incidents.

The blocking issue was internal rather than commercial. The enterprise could not verify technical security readiness for custom large language model training through conventional broker channels, and its own stakeholders would not approve offshore scaling without that verification. The diligence, not the sourcing, was the constraint.

Figure 6. Reported outcomes from a secured 500-person annotation and RLHF deployment.

Fourteen centres were audited against certification status and demonstrated zero-trust virtual desktop capability, and the selected provider operated an isolated facility with biometric access control, dedicated connectivity and locked-down workstations. Reported outcomes were a substantial multiple in annotation throughput over the first ninety days, no security incidents recorded, and operational overhead roughly 42% below the domestic scaling alternative.

One caveat is worth stating plainly, because it applies to every security claim of this kind. Zero reported incidents is a favourable result, not proof that none occurred. The statement carries weight only in proportion to the detection capability behind it, which is a further reason to specify logging and retention in the agreement rather than to accept the headline.

Why Do Organizations Work with Cynergy BPO on Secure AI Outsourcing?

Cynergy BPO is an independent BPO advisory firm representing more than 100 vetted Philippine providers. It verifies technical security readiness and certification status directly rather than relying on provider representations, and matches buyers on objective criteria instead of vendor commission.

Who Is Cynergy BPO?

Cynergy BPO is a BPO advisory and consultancy firm connecting global enterprises with vetted call centre, back-office and data operations providers across Manila, Cebu and emerging Philippine technology hubs. Its work spans provider assessment, security and compliance diligence, commercial structuring and the local market visibility buyers rarely have themselves.

How Does Cynergy BPO Differ from Traditional Outsourcing Brokers?

Traditional brokers are compensated by the providers they place, which makes their assessment of a provider’s security posture a function of commission structure. Cynergy BPO operates on an advisory basis, so the judgement of whether a delivery centre genuinely operates zero-trust infrastructure is not shaped by which provider pays more to be recommended. Where the subject is intellectual property exposure, that independence is the substance of the service.

How Does Cynergy BPO’s Network of 100+ Vetted Philippine BPO Providers Benefit Organizations?

The network converts an opaque market into a verified shortlist. Rather than accepting certification claims at face value, buyers start from providers already assessed on physical and cyber infrastructure, compliance credentials, financial stability and operational history — so the diligence question narrows from whether a provider is credible to whether it fits the workload.

How Does Cynergy BPO’s Advisory-Led Vendor Matching Process Work?

The process begins with the buyer’s requirements — data sensitivity, sovereignty obligations, certification thresholds, volume and timeline — rather than with a provider list. Candidates are audited against those parameters, shortlisted on verified evidence rather than representations, and the engagement is structured so that assignment, confidentiality, audit and destruction terms are settled before signature.

Why Do Organizations Use Cynergy BPO?

Because intellectual property exposure is established at selection and drafting, and is very difficult to remedy afterwards. Organisations use Cynergy BPO to verify security readiness independently, to shortlist providers whose infrastructure matches the sensitivity of the work, and to have the contractual architecture in place before any data moves.

Frequently Asked Questions

What happens to intellectual property rights if a Philippine vendor helps fine-tune our proprietary model?

It depends entirely on what the contract says. Philippine law does not transfer copyright to the paying party by default, so fine-tuned weights, adjustments and derivative outputs remain the client’s only where an express written assignment says so and the provider holds the rights to assign. The agreement should also deny the vendor any co-ownership or reuse rights.

Does copyright protect the labels our annotators produce?

Generally not. The Intellectual Property Code excludes mere data as such from protection, which covers coordinates, tags and spans. The curated dataset may be protected as a compilation, but only for the originality of its selection and arrangement. Trade secret and contract carry most of the weight.

How do Philippine data privacy laws affect international AI training datasets?

Republic Act 10173 aligns closely with international privacy standards. Where a training corpus contains personal data of individuals in other jurisdictions, processors in the Philippines must observe lawful basis, security and cross-border accountability obligations, and redaction or synthetic substitution before transfer is the usual practical route.

Are remote work arrangements safe for handling sensitive AI training data?

Home and hybrid arrangements raise exposure materially unless managed through enterprise virtual desktop infrastructure that blocks local printing, downloading and external device connectivity. The relevant question is not where the annotator sits but whether data can leave the streamed environment.

How can enterprises verify that outsourced training data has been erased?

Specify cryptographic erasure, a signed certificate of destruction and a right of independent third-party audit on completion. Note that the destruction obligation and the log retention obligation must be drafted together, since access records generally need to outlive the data itself.

What is the cost efficiency of outsourcing AI annotation to the Philippines?

Reported savings typically fall between 45% and 60% against United States or Western European operations. That range describes cost realised after retained oversight and transition, and is the appropriate figure for a business case rather than the higher gross labour arbitrage sometimes quoted.

Can Philippine teams handle domain-specific datasets such as legal or medical material?

Yes. The country has a deep pool of degree-holding and licensed professionals, including nurses, accountants and legal practitioners, which makes it practical to staff a pod against a regulated vertical. Regulated material also carries its own privacy and access obligations that should be settled in the data processing agreement before work begins.

How does Cynergy BPO vet its network of Philippine providers?

Through multi-tier audits covering financial stability, physical and cyber security infrastructure, data compliance certifications and historical operational performance, conducted before any provider is recommended to a client.

Share This
Jump to a Section

Unlock cost-efficient growth with expert BPO guidance!

Partner with Cynergy BPO to connect with top outsourcing providers.
Streamline operations, cut costs, and scale your business with confidence.

Book a Free Call
Image

Ralf Ellspermann is the Chief Strategy Officer (CSO) of Cynergy BPO and a globally recognized authority in business process and contact center outsourcing. With more than 25 years of experience advising enterprises and SMEs, he provides strategic guidance on vendor selection, CX optimization, and scalable outsourcing strategies across global markets. His expertise spans fintech, ecommerce and retail, healthcare, insurance, travel and hospitality, and technology (AI & SaaS) outsourcing.

A frequent speaker at leading industry conferences, Ralf is also a published contributor to The Times of India and CustomerThink, where he shares insights on outsourcing strategy, customer experience, and digital transformation.