CyberCode.ph · Philippines

Data Breach Notification Philippines: When Must the NPC Be Notified?

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 2, 2026

Direct Answer

In the Philippines, a Personal Information Controller must notify the National Privacy Commission and affected data subjects within 72 hours after knowledge of, or reasonable belief that, a personal data breach requiring notification has occurred (NPC Circular No. 16-03). Mandatory notification generally applies when sensitive personal information or other information usable for identity fraud is reasonably believed to have been acquired by an unauthorized person and the unauthorized acquisition is likely to create a real risk of serious harm.

Not every security incident is automatically reportable. Organizations must assess the facts, document the incident, and determine whether the mandatory-notification criteria are met.

Primary authority: National Privacy Commission — Breach Reporting and NPC Circular No. 16-03.

Key Takeaways

  • The 72-hour rule applies to qualifying personal data breaches.
  • The notification duty remains with the PIC even when processing is outsourced.
  • Qualifying breach notifications are submitted through the NPC’s Data Breach Notification Management System.
  • Non-reportable incidents should still be documented and handled under the organization’s security-incident process.
  • Affected data subjects may also need to be notified when the legal criteria are met.

Jump to a Section

  1. When notification is mandatory
  2. How the 72-hour rule works
  3. When affected people must be told
  4. What if the incident is not reportable?
  5. What to do after discovery

When Is NPC Notification Mandatory?

Under the Data Privacy Act implementing rules and NPC breach-management rules, notification is required when the statutory conditions for mandatory breach reporting are present. The assessment should consider the type of information involved, whether it was reasonably acquired by an unauthorized person, and whether the incident creates a real risk of serious harm.

Decision Snapshot

Incident Likely reporting question
Unauthorized party obtains sensitive personal information Assess mandatory notification immediately
Lost encrypted device with strong protections and no evidence of access Assess facts; notification is not automatic
Phishing email received but no data accessed Security incident; document and assess
Database exposed with identity-fraud risk High-priority mandatory-notification assessment

How Does the 72-Hour Rule Work?

The clock runs from knowledge of, or reasonable belief that, a reportable breach has occurred. The NPC allows initial notification based on available information, with supplemental information provided later as the investigation develops. Organizations should not wait for every forensic detail before starting the legal assessment.

When Must Affected Data Subjects Be Notified?

Affected individuals must also be notified within the applicable 72-hour period when the breach is likely to give rise to a real risk to their rights and freedoms. The notice should help people understand what happened and what precautions they can take.

What If the Incident Does Not Meet the Mandatory Criteria?

The absence of mandatory notification does not mean the incident can be ignored. The organization should document the facts, preserve evidence, contain the incident, determine the root cause, assess affected data, record the decision on notification, and include incidents in required reporting processes where applicable.

What Should a Company Do Immediately?

  1. Contain unauthorized access or disclosure.
  2. Preserve logs and forensic evidence.
  3. Notify the DPO and incident-response team.
  4. Identify the affected systems and data subjects.
  5. Assess the mandatory-notification criteria.
  6. Prepare and submit the required NPC notification through the current reporting system.
  7. Notify affected individuals when required.
  8. Document remediation and lessons learned.

See What Should a Company Do After a Personal Data Breach?

Related Guides

For the individual side, read My Personal Data Was Leaked: What Should I Do?. For the broader legal framework, see Data Privacy Act of 2012 Philippines.

Frequently Asked Questions

Is the 72-hour rule triggered by every security incident?

No. The 72-hour notification timeline applies when the breach meets the applicable mandatory-notification criteria. Organizations still need to assess and document incidents that do not meet those criteria.

When does the 72-hour period start?

It runs from the point at which the organization has knowledge of, or reasonable belief that, a qualifying personal data breach has occurred, based on the applicable NPC rules and guidance.

Official Sources