The Davao City Council passed a measure on Tuesday, September 1, establishing the Davao City Government Centralized Data Center to reinforce cybersecurity defenses, protect public records, and ensure seamless online government operations.
First District Councilor Bonz Andre Militar, who chairs the Committee on Information Technology, explained that the policy addresses existing systemic vulnerabilities within the local government’s digital infrastructure.
”The initiative aims to address weaknesses in the city government’s decentralized information and communications technology system, including inconsistent security, limited system connectivity, and duplicated ICT resources across offices,” said Militar.
Under the legislation, the City Information Technology Center (CITC) will assume primary responsibility for designing, establishing, operating, and managing the centralized facility. The new installation will serve as the core nexus for hosting, linking, and maintaining the municipality’s digital platforms, databases, and electronic services.
The law explicitly designates the hub as critical government ICT infrastructure, prioritizing its funding, maintenance, security, and safeguards against cyber threats, systemic failures, and disasters.
Committee findings highlighted that the city’s fragmented setup caused isolated databases, uneven security protocols, weak inter-agency compatibility, and redundant resource allocation.
The centralized architecture will enable integrated networks, unified backups, disaster redundancy, and secure shared storage without forcing municipal departments to scrap their active operational systems.
Built to meet Tier 3 data center specifications, the facility will emphasize high system availability, operational resilience, and robust threat protection. The ordinance mandates the CITC to formulate data governance guidelines, conduct routine vulnerability audits, and implement standardized incident response protocols.
In the event of a security compromise, all municipal offices must follow a uniform procedure covering swift reporting, containment, investigation, notification, recovery, and post-incident review. The city will also strictly adhere to national privacy and archiving statutes, including the Data Privacy Act of 2012 and the National Archives of the Philippines Act of 2007.
System migration into the hub will occur in phases, giving priority to essential public services. Beyond hosting, the center will support live threat monitoring, disaster recovery, continuous digital access, and future network integration.
Local authorities will select a final site for the installation, explicitly excluding locations prone to flooding, soil liquefaction, or tsunamis.
Funding will depend on resource availability under standard procurement and auditing rules, with the CITC tasked to issue the implementing rules and regulations within 90 days of the ordinance’s effectivity.
