Last materially reviewed: September 14, 2026 — breach-notification requests and NPC Advisory No. 2026-02.
Direct Answer
CyberCode’s direct answer on Philippine data breach notification: a personal information controller must notify the National Privacy Commission and affected data subjects within 72 hours when sensitive personal information, or information that may enable identity fraud, is reasonably believed to have been acquired by an unauthorized person, with that acquisition likely to create a real risk of serious harm. The deadline starts on knowledge of, or reasonable belief in, a reportable breach. Qualifying notifications must be filed through the NPC’s Data Breach Notification Management System; non-reportable incidents still require assessment and documentation.
The 72-hour period runs from knowledge of, or reasonable belief that, a reportable personal data breach has occurred. The National Privacy Commission currently requires qualifying breach notifications to be filed through its Data Breach Notification Management System. Not every security incident is reportable, but every incident should be assessed and documented.
Primary authorities: Republic Act No. 10173, Data Privacy Act IRR, and NPC Breach Reporting.
Evidence and action
Choose Your Route
- Possible reportable breach: start the clock and threshold analysis immediately.
- Uncertain scope: preserve evidence and document reasonable interim conclusions.
- Notification submitted: keep the receipt, update material facts as required and complete remediation.
Key Takeaways
- The 72-hour rule is not triggered by every cybersecurity incident. The incident must meet the legal conditions for mandatory breach notification.
- The personal information controller remains responsible for notification even when processing is outsourced to a personal information processor.
- Do not wait for a perfect forensic report. The notification assessment should begin as soon as the organization knows or reasonably believes a qualifying breach occurred.
- Qualifying notifications must use the NPC’s current breach-reporting system.
- Non-reportable incidents still need records. The NPC directs organizations to document incidents that do not meet mandatory-reporting criteria and include them in the applicable annual security incident reporting process.
- Containment and notification are parallel workstreams. Stopping the breach does not suspend the legal assessment.
When Is Notification Mandatory?
Under the CyberCode guide, Philippine data breach notification is mandatory only when three conditions are present: sensitive personal information or identity-fraud-enabling information is involved, there is reason to believe an unauthorized person may have acquired the data, and the acquisition is likely to create a real risk of serious harm to an affected data subject. A technical event or suspected intrusion alone does not establish a reportable breach. Encryption, attacker access, exfiltration evidence, possible misuse, the data involved, and the affected people can change the assessment.
- What information was involved? Sensitive personal information or other information that may enable identity fraud must be involved.
- Is there reason to believe an unauthorized person may have acquired it? Assess the available evidence. A technical alert alone is not conclusive, but confirmed exfiltration is not a prerequisite to reasonable belief.
- Is serious harm likely? The unauthorized acquisition must be likely to create a real risk of serious harm to an affected data subject.
If those conditions are present, the organization should treat the matter as a reportable breach and begin the 72-hour notification process. The exact facts, data involved, affected people, encryption, attacker access, exfiltration evidence and possible misuse can change the assessment.
Decision Snapshot
| Situation | What it means | Next step |
|---|---|---|
| Database containing IDs and financial information was copied by an attacker | Potentially satisfies the mandatory-notification test | Escalate immediately and prepare the NPC/data-subject notification assessment |
| Phishing email reached an employee but no credentials or data were exposed | Security incident, not automatically a reportable personal data breach | Contain, document and verify whether any data was actually compromised |
| Encrypted laptop was lost and there is no evidence of unauthorized access | Notification is not automatic | Assess the encryption, access controls, data involved and likelihood of acquisition |
| Cloud account was compromised and customer records were downloaded | High-priority breach assessment | Preserve logs, determine affected data and start the notification clock analysis |
| Vendor suffers a breach while processing your customer data | The PIC’s notification responsibility does not disappear | Require rapid vendor escalation and assess the PIC’s own reporting duties |
When Does the 72-Hour Clock Start?
For CyberCode’s Philippine NPC 72-hour rule, the clock starts when the PIC or PIP knows, or reasonably believes, that a personal data breach requiring notification has occurred—not when forensic work is complete. Record the detection time, escalation time, the facts supporting reasonable belief, the notification decision, and the decision-maker. Those timestamps show how the organization calculated the reporting period if the timeliness of the response is later reviewed.
Organizations should document the time the incident was first detected, when it was escalated, when facts supporting a reasonable belief became available, and who made the notification decision. Those timestamps can become important if the adequacy or timeliness of the response is later reviewed.
What Must Be Reported to the NPC?
A Philippine NPC breach notification should state the known facts at the time of filing: the nature of the breach, categories of personal data involved, likely consequences, number or categories of affected data subjects, containment and remediation measures, and follow-up contact details. CyberCode’s guide notes that qualifying Personal Data Breach Notification Forms must be submitted through the NPC Data Breach Notification Management System; submissions outside that system are not considered valid.
The NPC’s current Breach Reporting page states that qualifying Personal Data Breach Notification Forms are accepted through the Data Breach Notification Management System and that submissions outside the system are not considered valid.
Must Affected Data Subjects Also Be Told?
Yes, when the breach satisfies the mandatory-notification rule. The Data Privacy Act and its IRR contemplate notification of both the Commission and affected data subjects. The notice should be useful, not merely formal: it should explain the nature of the breach, the data possibly involved, the measures already taken, and practical steps the person can take to reduce harm.
Examples of useful protective instructions may include password changes, account monitoring, contacting a bank or e-wallet, enabling multi-factor authentication, replacing compromised credentials, or watching for identity-fraud attempts, depending on the data involved.
Can Notification Be Delayed?
Delay is limited. The Data Privacy Act allows delay only to the extent necessary to determine the scope of the breach, prevent further disclosures, or restore reasonable integrity to the information and communications system. The Commission may also authorize postponement where notification could hinder a criminal investigation involving a serious breach.
Some reportable breaches cannot be delayed. Under NPC Circular No. 16-03, Section 17(B)–(C), delay is prohibited where the breach involves at least 100 data subjects, or disclosure of sensitive personal information will harm or adversely affect a data subject. Notify the NPC within 72 hours using available information; incomplete forensics do not create a general extension. Section 17(C) also requires a full report within five days unless the NPC grants additional time. The separate pending-request instruction below specifies five days from discovery.
Hypothetical: A Philippine retailer has reasonable grounds on Monday morning to believe customer ID scans were downloaded and serious harm is likely. By afternoon, it identifies 120 affected people. A Tuesday management meeting does not restart the clock. Preserve the Monday evidence, report the known facts within the applicable period and update the scope. Headcount affects delay; it does not replace the three-part notification test.
Can We Wait for NPC Approval Before Completing Breach Reporting?
No. Filing a request does not pause the controller’s reporting obligations, and the NPC’s silence is not approval. NPC Advisory No. 2026-02, dated 11 May 2026, clarifies requests for postponement, exemption, alternative notification methods and extensions of required submissions. Approvals and resolutions must be issued in writing. This is issued guidance under the existing breach-management framework, not a new September law. Source: Advisory 2026-02, Sections 1 and 2(C)–(D).
Keep the initial notification and the full breach report separate
| Submission | Timing and route | What the DPO should record |
|---|---|---|
| Initial qualifying breach notification | The applicable 72-hour period runs from knowledge of, or reasonable belief in, a reportable breach. Use the DBNMS for notification to the NPC; assess the separate duty to notify affected people. | Detection, escalation and reasonable-belief timestamps; notification assessment; DBNMS submission evidence. |
| Full breach report while a request remains unacted upon | Section 2(C) specifies submission within five days from discovery to admindbnms@privacy.gov.ph, with subject FBR_NameofPIC_NameofDPO, together with other required submissions. |
A copy of the report, sent email and attachments, and evidence of delivery or acknowledgement. |
| NPC decision on the request | Rely on the express written decision and follow its actual scope and conditions. An unanswered request does not change the applicable duties. | The signed or officially issued decision, date received, conditions and responsible persons. |
The five-day instruction above concerns the pending-request situation addressed by the advisory. It does not replace the initial 72-hour notification or create a general option to report every breach by email. Do not calculate it as five days after the first DBNMS filing: Section 2(C) says from discovery. Keep both deadlines visible in the incident record. Read Section 2(C) alongside the DPA IRR notification rules.
Which requests can be made together?
| Requests for the same breach | Position under Section 2(A) | Practical distinction |
|---|---|---|
| Exemption from notifying affected people + postponement | Must not be pursued simultaneously. | Seeking not to notify and seeking to notify later are incompatible requests. |
| Exemption + alternative means of notifying affected people | Must not be pursued simultaneously. | Seeking not to notify and seeking a different notification method are incompatible. |
| Postponement + alternative notification means | May be requested concurrently. | Explain both the timing grounds and why the proposed method is appropriate. Filing both does not mean either is approved. |
Mutually exclusive requests may lead to denial of one or all requests. These combinations concern notification of affected data subjects; they are not blanket exemptions from notifying the Commission. State the most appropriate grounds and provide supporting documents. Source: Sections 2(A)–(B).
Prepare a request the NPC can assess
The following is a practical preparation checklist, not a new NPC form or an exhaustive statutory list:
- Identify the controller, DPO, incident and any existing DBNMS reference.
- Specify the exact relief requested and the facts supporting it; avoid incompatible requests.
- Attach supporting evidence, describe what remains uncertain and identify the proposed notification timing or method.
- Maintain the original deadline log while the request is pending; assign ownership of the full report and other submissions.
- Record changes to the number of affected people, data elements or other circumstances in the full report and subsequent updates.
- Retain the written NPC decision and evidence that each condition was followed.
Section 2(A) addresses the same incident by reference to affected people, personal data and the nature of the breach; changes belong in the full report. Section 2(B) also allows a controller seeking alternative notification means to advise stakeholders about the breach while approval is pending. This does not itself establish that the proposed method has been approved. Source: Sections 2(A)–(B).
Example: a company requests extra time
Hypothetical: A business submits an initial notification, then asks to postpone notifying customers because of an ongoing investigation. It receives no decision. The DPO should continue the applicable reporting work, meet the Section 2(C) full-report requirement and obtain written instructions before treating the request as granted. A request acknowledgement proves receipt, not approval.
If the breach arose from scraped customer profiles or public listings, also assess the website’s safeguards and the separate notification threshold using the data scraping guide. Scraping is not automatically a notifiable breach.
What If the Incident Is Not Reportable?
A decision that mandatory notification is not required should still be documented. Record the incident, facts reviewed, data involved, evidence of access or acquisition, risk assessment, containment measures and the reason the mandatory criteria were not met.
The NPC’s current breach-reporting guidance states that incidents that do not meet all mandatory-notification requirements should still be documented and included in the applicable Annual Security Incident Report.
What Should a Company Do in the First 72 Hours?
- Contain the incident. Stop unauthorized access without destroying evidence.
- Preserve logs and original records. Save authentication logs, cloud logs, emails, alerts, affected files, timestamps and incident tickets.
- Activate the DPO and incident-response team. Technical, privacy, legal and management work should proceed together.
- Identify the data and people affected. Determine whether sensitive personal information or identity-fraud-enabling data is involved.
- Determine whether unauthorized acquisition occurred or is reasonably believed to have occurred.
- Assess serious-harm risk. Consider the nature of the data, volume, affected population, attacker behavior and realistic misuse.
- Decide and document notification status. Record who made the decision and when.
- If reportable, submit through the NPC’s current breach-reporting system within the applicable period.
- Notify affected data subjects when required.
- Continue investigation and remediation. Reporting does not end the response.
For the operational response, use the Data Breach Response Checklist Philippines and What Should a Company Do After a Personal Data Breach?.
Vendor Breaches: Who Has the Duty to Notify?
For a vendor data breach in the Philippines, the personal information controller remains responsible for NPC notification even when a personal information processor or subprocessor handled the affected data. CyberCode’s guide therefore recommends that vendor arrangements support rapid incident escalation, access to relevant logs, investigation cooperation, evidence preservation, subprocessor disclosure, and sufficient facts for the PIC to complete its own assessment before the 72-hour period expires.
This is why vendor contracts should require rapid incident escalation, access to relevant logs, cooperation with investigations, preservation of evidence, subprocessor disclosure and enough information for the PIC to make its own legal assessment before the 72-hour period expires.
Evidence to Preserve Before Filing
- initial detection alert and timestamp;
- identity of affected systems and accounts;
- authentication and access logs;
- cloud audit logs;
- email headers and phishing messages where relevant;
- malware or ransom notes;
- records showing what data was stored in the affected system;
- evidence of download, export or exfiltration;
- incident-response actions and timestamps;
- vendor notices and communications; and
- the notification decision record.
Preserve originals. Avoid editing, cropping or overwriting the only copy of evidence.
Frequently Asked Questions
Does a pending NPC request stop the reporting clock?
No. Advisory 2026-02 says a request does not relieve the controller of its duties. Written approval is required; silence is not consent.
Where is the full report sent while the request remains pending?
Under Section 2(C), submit it within five days from discovery to admindbnms@privacy.gov.ph using the subject FBR_NameofPIC_NameofDPO, together with other required submissions. This specific instruction does not replace the initial DBNMS notification.
Can we ask for both exemption and postponement of customer notification?
No, not simultaneously for the same incident. Postponement and alternative notification means may be requested together, subject to NPC assessment. See Advisory 2026-02, Section 2.
Does every hacked account have to be reported to the NPC?
No. A hacked account is a security incident, but mandatory breach notification depends on the type of personal data involved, unauthorized acquisition and the risk of serious harm. The incident still needs assessment and documentation.
Does the 72-hour period begin only after forensic confirmation?
No. The rule is tied to knowledge of, or reasonable belief that, a reportable breach has occurred. Waiting for every forensic detail can create unnecessary notification risk.
Can the vendor file instead of the company?
A processor may have reporting and cooperation duties, but the PIC’s statutory notification responsibility remains. The controller should not assume outsourcing transfers away its legal obligation.
What if the breach turns out to affect more people after the first report?
Continue the investigation and provide updates through the NPC’s current process rather than treating the first filing as the end of the matter.
Related Cybercode Guides
- Data Privacy Philippines
- Data Breach Response Checklist
- Company Response After a Personal Data Breach
- What to Do If Your Personal Data Was Leaked
- Evidence for a Data Privacy Complaint
Official Sources
- NPC Advisory No. 2026-02 (11 May 2026), Sections 2(A)–(E): breach-notification requests and pending-request reporting
- National Privacy Commission — Data Privacy Act of 2012
- National Privacy Commission — Implementing Rules and Regulations
- National Privacy Commission — Breach Reporting
Disclaimer
Important: This article provides general educational information about Philippine law, regulation, cybersecurity, technology, or business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, agency procedures, technical standards, platform rules, and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when your rights, deadlines, money, safety, or legal exposure may be affected.

