Last materially reviewed: September 2, 2026
Direct Answer
After discovering a personal data breach, a Philippine company should contain the incident, preserve evidence, activate its breach-response process, identify affected systems and personal data, assess whether mandatory notification is triggered, and notify the National Privacy Commission and affected data subjects within 72 hours when the legal criteria are met (NPC Circular No. 16-03). The company should then remediate the root cause, document decisions, and strengthen controls to reduce recurrence.
Primary authority: National Privacy Commission — Breach Reporting and NPC Circular No. 16-03.
Key Takeaways
- Containment and evidence preservation come first.
- Escalate promptly to the DPO and incident-response team.
- Determine what data, systems, people, vendors, and accounts are affected.
- Assess mandatory breach-notification criteria immediately.
- Qualifying NPC notifications are submitted through the current Data Breach Notification Management System.
- Do not wait for a perfect forensic picture before starting the 72-hour legal assessment.
- Document every material decision, including why notification was or was not required.
Jump to a Section
What Should Happen First?
- Stop ongoing unauthorized access or disclosure.
- Preserve logs, system images, emails, alerts, and relevant records.
- Notify the DPO and designated incident-response team.
- Identify affected systems, data sets, processors, and third parties.
- Determine whether credentials, sensitive personal information, government identifiers, financial information, or vulnerable data subjects are involved.
Decision Snapshot
| Question | Action |
|---|---|
| Is unauthorized access still occurring? | Contain immediately |
| Could sensitive data or identity-fraud data have been acquired? | Begin mandatory-notification assessment |
| Is a vendor involved? | Coordinate evidence and response, but remember the PIC retains notification responsibility |
| Facts are incomplete but risk is serious | Use available information and supplement later where allowed |
How Should the Company Assess the Breach?
Determine what happened, when it began, when it was discovered, what data was affected, whether data was actually acquired or merely exposed, which individuals are affected, what safeguards were in place, and what likely harm could result. The assessment should be documented, not left as an undocumented verbal conclusion.
When Must the NPC and Data Subjects Be Notified?
Qualifying breaches are subject to the 72-hour notification requirement. For the detailed test, see Data Breach Notification Philippines: When Must the NPC Be Notified?
Where data-subject notification is required, the notice should explain the nature of the breach, affected data, measures taken, risks, recommended precautions, and contact information for further assistance.
What Should Remediation Include?
- reset or revoke compromised credentials;
- patch exploited vulnerabilities;
- remove unauthorized access;
- rotate keys and secrets where appropriate;
- review vendor controls and contracts;
- strengthen monitoring and logging;
- update breach-response procedures; and
- provide practical mitigation support to affected individuals.
What Happens After Containment?
Run a documented post-incident review. Identify the root cause, security-control failures, policy gaps, training issues, vendor weaknesses, and changes needed to the company’s privacy and security program. Feed the lessons into the broader Data Privacy Compliance Checklist for Philippine Businesses.
Frequently Asked Questions
Does every personal data breach need to be reported to the NPC?
No. Mandatory notification depends on the breach meeting the applicable notification criteria. Even when notification is not required, the incident should still be documented and managed under the organization’s incident-response process.
What should a company do first after discovering a breach?
Contain the incident, preserve evidence, identify affected systems and data, determine when the organization became aware of the breach, and begin the notification assessment promptly.
