CyberCode.ph · Philippines

Data Breach Philippines: How to Report One, Step by Step

Last updated September 29, 2026 · Practical privacy, cybersecurity and technology-law guidance

Direct answer: Report a notifiable personal data breach to the National Privacy Commission (NPC) through the Data Breach Notification Management System (DBNMS) within 72 hours of knowing or reasonably believing it occurred, notify the affected data subjects inside the same 72 hours, and submit the full breach report within five days of discovery. A breach is notifiable only if it passes all three parts of the test in NPC Circular No. 16-03, Section 11. A notification filed outside the DBNMS is not valid.

Key Takeaways

  • Not every security incident is a notifiable breach. Section 11 of NPC Circular No. 16-03 sets a three-part test, and all three parts must be met before the notification duty is triggered.
  • There are two 72-hour clocks, not one. One runs to the Commission (Sec. 17(A)), one runs to the affected data subjects (Sec. 18(A)). Both start at the same moment of knowledge or reasonable belief.
  • The five-day rule is a different deadline. It is the deadline for the full breach report under Sec. 17(C), not a notification deadline.
  • Delay is narrowly permitted and has two hard stops. There is no delay at all if the breach involves at least 100 data subjects, or the disclosure of sensitive personal information.
  • The DBNMS is the only valid channel. The NPC states that a Personal Data Breach Notification Form submitted outside the system “shall not be considered as valid.”
  • Asking for an exemption does not pause the clock. Under NPC Advisory No. 2026-02, Sec. 2(C), a pending request does not relieve the controller of its Circular 16-03 obligations, and Sec. 2(D) states that the Commission’s silence is never an approval.
  • New this month: NPC Advisory No. 2026-03, issued 8 September 2026, reopened the window for the 2025 Annual Security Incident Report until 10 November 2026.
  • Concealing a breach is a criminal offence that reaches natural persons, and it can be committed by omission.

Jump to a Section

Decision Snapshot

Question Practical answer
Does every security incident have to be reported to the NPC? No. Only a breach that satisfies all three limbs of Circular 16-03, Sec. 11.
How long do I have to notify the Commission? 72 hours from knowledge or reasonable belief (Sec. 17(A)).
Do I have to tell the affected people too? Yes, and within the same 72 hours (Sec. 18(A)).
Can I notify the NPC by email or letter instead? No. The NPC states a form submitted outside the DBNMS is not valid.
Is the deadline five days or 72 hours? Both. 72 hours to notify; five days from discovery for the full report (Sec. 17(C)).
Can I delay notification while I investigate? Only within Sec. 17(B), and not at all if 100+ data subjects or sensitive personal information are involved.
Does filing a request for exemption stop the clock? No (Advisory 2026-02, Sec. 2(C)).
If the NPC does not reply, is my request granted? No. Inaction is not approval (Advisory 2026-02, Sec. 2(D)).
Can an individual, not just the company, be prosecuted? Yes. RA 10173, Sec. 30 reaches persons who conceal a breach.
Does a vendor’s breach become my problem? Usually yes, where you are the personal information controller.

Step 1: Decide Whether This Is a Personal Data Breach at All

Reporting starts with a classification question, not a form. NPC Circular No. 16-03, Sec. 3(F) defines a personal data breach as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.”

Three things follow from that definition, and each of them decides real cases.

  • Loss and destruction count, not just theft. A ransomware event that encrypts your only copy of a customer database is a breach of availability even if nobody exfiltrated a record. So is a deleted backup.
  • It has to involve personal data. An outage that takes down a marketing site holding no personal data is a security incident, but it is not a personal data breach.
  • Accidental counts. An employee emailing a spreadsheet of client details to the wrong distribution list is squarely inside the definition.

If what happened is a security incident but not a personal data breach, the Commission does not need to be notified of it under Sec. 17 — but Sec. 22 still requires that all security incidents and personal data breaches be documented in written reports, and that a summary be submitted annually. That annual duty is covered further down this page.

If you are still working out which category of data was touched, our guide to personal information versus sensitive personal information draws the line that the rest of this procedure turns on.

Step 2: Run the Three-Part Test in Section 11

Section 11 of Circular 16-03 is the provision that decides whether the 72-hour clock starts. All three limbs must be present. If any one of them is absent, the mandatory notification duty in Sec. 17 is not triggered.

Limb What Sec. 11 requires The question to ask
(A) The breach involves sensitive personal information, or any other information that may be used to enable identity fraud Could someone use what leaked to impersonate the data subject or open something in their name?
(B) There is reason to believe the information may have been acquired by an unauthorized person Is there a basis to think someone who should not have it now has it?
(C) The unauthorized acquisition is likely to give rise to a real risk of serious harm to any affected data subject Is serious harm to at least one person a realistic prospect, not a theoretical one?

Two practical notes on this test.

Limb (A) is broader than “sensitive personal information.” The second half of it — information that may be used to enable identity fraud — catches combinations that are not sensitive personal information on their own. A file of full names with mothers’ maiden names, dates of birth and mobile numbers is ordinary personal information item by item, and an identity-fraud enabler taken together.

Limb (C) says “any affected data subject,” singular. A breach touching one person can meet the test if the harm to that one person is serious and realistic. The number of records is not the threshold; it is only relevant later, at the delay stage.

Write the assessment down. If you conclude that the test is not met and you therefore do not notify, that conclusion is the thing a regulator will ask you to justify. Record who decided, when, on what facts, and against which limb the analysis failed.

The Clocks That Actually Bite

Philippine practice talks about “the 72-hour rule” as though there were one. There are at least five distinct clocks, they have different sources, and more than one can run at the same time over a single incident.

Clock Source Runs from Who it applies to
72 hours to notify the Commission NPC Circular 16-03, Sec. 17(A); IRR Rule IX, Sec. 38 Knowledge of, or reasonable belief in, the breach Every personal information controller
72 hours to notify affected data subjects NPC Circular 16-03, Sec. 18(A) The same moment of knowledge or reasonable belief Every personal information controller
Five days for the full breach report NPC Circular 16-03, Sec. 17(C); Advisory 2026-02, Sec. 2(C) The date of discovery Every personal information controller
2 hours, then 24 hours BSP Manual of Regulations for Banks, Sec. 148 Discovery of a reportable major cyber-related incident BSP-supervised financial institutions only
72 hours to disclose on a warrant RA 10175, Sec. 14 Service of a court-issued disclosure order Any person or service provider served with one

The first two run in parallel from the same trigger. The third runs from discovery, which in most incidents is the same day but is not defined identically. If you are a bank, an e-money issuer or another BSP-supervised institution, the two-hour clock is the first one you will hit — it is covered in more detail in our guide to cybersecurity legal duties in the Philippines.

The Reporting Sequence, in Order

This is the order the instruments imply. Steps 1 to 4 usually happen inside the first few hours; steps 5 and 6 are the 72-hour deadlines; step 8 is the five-day deadline.

  1. Contain first, then classify. Stop the bleeding — revoke the credential, pull the server off the network, disable the share link. Containment is not a reason to delay notification, but an uncontained breach keeps enlarging the thing you are about to report.
  2. Convene the breach response team. Sec. 5 of Circular 16-03 requires that a controller or processor “shall constitute a data breach response team, which shall have at least one (1) member with the authority to make immediate decisions regarding critical action.” If you are constituting it for the first time during the incident, you are already behind.
  3. Fix the moment of knowledge and write it down. Every deadline on this page runs from it. Record the date, the time, who knew and what they knew. This single entry is the most contested fact in any later assessment.
  4. Run the Sec. 11 three-part test and record the result either way.
  5. Notify the Commission through the DBNMS within 72 hours. See below.
  6. Notify the affected data subjects within the same 72 hours. See below.
  7. If you need an exemption, postponement or alternative means, file that request — and keep complying meanwhile. See below.
  8. Submit the full breach report within five days of discovery. See below.
  9. Preserve the evidence and the decision trail. See below.
  10. Log the incident for the Annual Security Incident Report. See below.

If the incident is a live attack rather than a discovered exposure, run this sequence alongside the technical response rather than after it. Our incident response plan guide covers the technical track, and there are scenario-specific guides for a ransomware attack, a malware infection, business email compromise and unauthorised account access.

Step 5: Notify the Commission Through the DBNMS

The channel is not optional. The NPC’s own breach-reporting page states that following the launch of the system, the Commission accepts submission of Personal Data Breach Notification Forms (PDBNFs) through the DBNMS only, and that any PDBNF submitted outside of the DBNMS “shall not be considered as valid.” A notification emailed to a general NPC inbox, posted, or hand-delivered does not count as having been made.

The system is at dbnms.privacy.gov.ph.

Set the account up before you need it

The NPC’s breach-reporting page instructs personal information controllers to use the Data Protection Officer’s dedicated office email address as the account username, so that access survives a change of DPO. That is an administrative detail with a sharp edge: an organisation whose DBNMS account is registered to a personal address, or to a DPO who has left, can lose three of its 72 hours to a password reset. Register the account now, while nothing is on fire. Technical problems with the system go to dbnms@privacy.gov.ph.

If you have not yet appointed a DPO, or you are unsure whether your organisation must register with the Commission at all, start with our guides to the National Privacy Commission and to NPC registration and seal requirements.

What the notification has to contain

Section 17(D) of Circular 16-03 requires the notification to state the nature of the breach, the personal data possibly involved, the measures taken to address the breach, and the “name and contact details of the data protection officer or any other accountable persons.”

You will not have complete answers at hour 20, and the circular does not demand them. Describe what is known, describe what is still being established, and say so plainly. An incomplete notification filed on time is a better position than a complete one filed late.

The mechanics of the system itself — account setup, the form, what the NPC does with a submission — are covered in depth in our dedicated guide to DBNMS breach notification. This page is the procedure; that page is the system.

Step 6: Notify the Affected Data Subjects

This is the step organisations most often miss, because it feels like a second thing that can wait for the first. It cannot. Section 18(A) gives the affected individuals the same 72 hours as the Commission, running from the same moment of knowledge or reasonable belief.

The statutory root of both duties is a single provision. RA 10173, Sec. 20(f) requires the personal information controller to “promptly notify the Commission and affected data subjects” where sensitive personal information, or information that may enable identity fraud, is reasonably believed to have been acquired by an unauthorized person. One sentence, two audiences.

If individual notice is impractical

Section 18(D) allows for this, but not unilaterally. Where individual notification is not practicable, the controller may seek the approval of the Commission to use alternative means — “such as through public communication or any similar measure through which the data subjects are informed in an equally effective manner.” The approval is part of the mechanism, not a formality to be assumed. See the requests section.

For the reader on the other side of this — someone who has just been told their data was exposed — our guide on what to do when your personal data is leaked sets out the individual’s options and rights.

Step 7: When You May Delay, and the Two Hard Stops

Section 17(B) permits delay, and defines it narrowly. Notification “may only be delayed to the extent necessary to determine the scope of the breach, to prevent further disclosures, or to restore reasonable integrity to the information and communications system.”

Three permitted reasons, and nothing else. Board approval is not one of them. Waiting for outside counsel is not one of them. Managing the announcement is not one of them.

Then the sentence that most compliance teams have not read:

“There shall be no delay in the notification if the breach involves at least one hundred (100) data subjects, or the disclosure of sensitive personal information.”

These are absolute. At 100 affected data subjects, or at any disclosure of sensitive personal information, the Sec. 17(B) discretion disappears entirely — even where scope is genuinely still unknown, even where the investigation is genuinely incomplete. Two of the most common breach profiles in the Philippines, a leaked customer list and an exposed HR file, will usually trip one or both.

Note also that Sec. 40 of the IRR frames the same point from the other direction: delay is permitted “only to the extent necessary to determine the scope of the breach, to prevent further disclosures.”

Step 8: The Five-Day Full Breach Report

This is where the “five-day rule” belongs, and it is worth stating clearly because the two deadlines are routinely conflated.

Point of comparison The 72-hour notification The five-day report
Source Circular 16-03, Secs. 17(A) and 18(A) Circular 16-03, Sec. 17(C)
Runs from Knowledge or reasonable belief The date of discovery
Goes to The Commission and the data subjects The Commission
What it is Alerting notification The full account of the incident
Extendable? Only within Sec. 17(B), with two hard stops Yes, if the Commission grants additional time

Section 17(C) reads: the full report “must be submitted within five (5) days, unless the personal information controller is granted additional time by the Commission to comply.” NPC Advisory No. 2026-02, Sec. 2(C) restates it as running “within five (5) days from the date of discovery,” and gives the submission address for it: admindbnms@privacy.gov.ph, with the subject line formatted FBR_NameofPIC_NameofDPO.

The same advisory directs general compliance questions to compliancesupport@privacy.gov.ph, and expressly excludes from that channel any question about postponement, exemption, alternative means, or extension of time — those belong in the request itself.

Exemption, Postponement and Alternative Means

Three different requests exist, they are made through the DBNMS, and NPC Advisory No. 2026-02 governs how they interact. Getting this wrong can cost you all three.

The mutual-exclusivity matrix

Section 2(A) of the advisory provides that a controller shall not simultaneously avail of certain combinations in relation to the same incident.

Combination Allowed together?
Exemption from notifying data subjects + postponement of that notification No
Exemption from notifying data subjects + alternative means of notification No
Postponement + alternative means of notification Yes — these “may, however, be availed of concurrently”

The consequence of getting it wrong is set out in the same section: invoking mutually exclusive requests “may be a ground for the denial of one or all such requests.” Filing both an exemption and a postponement as a belt-and-braces measure can therefore lose you the one you actually needed.

What counts as one incident

Because the matrix operates per incident, the advisory defines the unit. A personal data breach is treated as a single incident where it involves the same affected data subjects, the same personal data involved, and the same nature of the breach. Change any one of those three and you are, for these purposes, looking at a different incident.

Three rules that catch people out

  • State your ground and document it. Section 2(B) requires the controller to determine and clearly state the most appropriate ground for the request, and to submit the corresponding supporting documents.
  • A pending request does not pause anything. Section 2(C): submitting a request through the DBNMS “shall not relieve the PIC of its obligation pursuant to NPC Circular No. 16-03.” Unless the request is acted upon, the five-day full breach report is still due.
  • Silence is not approval. Section 2(D) is unusually direct: all approvals or resolutions “shall be expressly issued in writing by the Commission,” and the Commission’s inaction “shall not be construed as an approval, implied consent, or automatic grant,” nor serve as a justification for noncompliance.

One permissive note worth knowing: where alternative means have been requested, Sec. 2(B) records that nothing prevents the controller from advising stakeholders of the fact of the breach, or other relevant information, while the request is pending. You are not gagged by your own application.

The Commission also has its own power to relieve or postpone. Section 18(B) of Circular 16-03 allows exemption from the notification requirement where the Commission determines that notification would not be in the public interest, and allows the Commission to authorise postponement where notification may hinder the progress of a criminal investigation.

Finally, Sec. 3 of Advisory 2026-02 sets the interpretive rule for the whole instrument: any doubt “shall be liberally interpreted in a manner mindful of the rights and interests of data subjects.” If a borderline reading favours the organisation over the people affected, it is probably the wrong reading.

Step 9: What to Preserve and Document

Two separate record-keeping duties attach to a breach, and they serve different readers.

Section 22 of Circular 16-03 requires that all security incidents and personal data breaches “shall be documented through written reports,” and that a summary of all reports be submitted to the Commission annually. That is the regulator-facing record.

The second is evidential. If the breach turns out to be a crime — and unauthorised access, data interference and computer-related identity theft all are, under the Cybercrime Prevention Act — the material you keep in the first days is what an investigation will have to work from. Preserve, do not clean up.

Preserve Why it matters later
System, access and authentication logs Establishes who got in, when, and from where. Often the first thing overwritten by retention settings.
Firewall, VPN and email gateway logs Shows the route in and any exfiltration.
Forensic images of affected machines Rebuilding a server destroys the evidence on it. Image before you rebuild.
Ransom notes, phishing emails with full headers, attacker messages Headers carry routing information that a screenshot does not.
The incident timeline, with the moment of knowledge fixed Every deadline on this page is measured from it.
The Sec. 11 assessment and who made it The document that justifies notifying, or not notifying.
Copies of the DBNMS submission and any acknowledgement Your proof that the 72-hour duty was met.
The data subject notice as sent, with the send list and timestamps Proof of the parallel Sec. 18(A) duty.
Vendor contracts, data processing agreements and breach clauses Determines who owed what if a processor was involved.
Board or management minutes recording decisions Shows the accountability trail, and the absence of concealment.

Do not alter, crop, delete or overwrite original material while you assemble it. Our electronic evidence checklist covers preservation in more detail, and our guide to reporting cybercrime in the Philippines explains the separate criminal route to the NBI and the PNP Anti-Cybercrime Group. Notifying the NPC and filing a criminal complaint are different acts with different destinations — doing one does not do the other.

Step 10: The Annual Security Incident Report, and the 2026 Extension

Section 22 of Circular 16-03 makes the annual summary a standing obligation, separate from any individual notification. The Annual Security Incident Report (ASIR) covers the preceding calendar year and, like the breach notification, is submitted through the DBNMS.

NPC Advisory No. 2026-03, issued 8 September 2026, reopened the window for the 2025 ASIR. Its subject is the “GRANT OF ADDITIONAL PERIOD TO SUBMIT ANNUAL SECURITY INCIDENT REPORTS FOR THE YEAR 2025,” and it was signed by Privacy Commissioner Atty. Johann Carlos S. Barcena, CESO III, with Deputy Privacy Commissioners Atty. Jose Amelito S. Belarmino, MSc and Atty. Juan Paolo F. Fajardo.

Item What the advisory provides
Which reports Annual Security Incident Reports for the year 2025
New deadline On or before 10 November 2026
Original deadline 31 March 2026
Channel Exclusively through the DBNMS online platform
When the window reopened “The period for the submission of 2025 ASIRs shall be reopened upon the issuance of this Advisory.”
Effect on breach clocks None. It does not touch the 72-hour or five-day deadlines

If your organisation missed the March deadline for its 2025 ASIR, this is the window, and it closes on 10 November 2026.

One caution about the deadline for other years. The NPC’s breach-reporting page states the ASIR window as running “from 1 January 2023 to 31 March of the current year.” Read against Sec. 22, the operative rule is an annual 1 January to 31 March window for the preceding calendar year; the fixed “2023” appears to be a stale literal left on the page rather than a rule. We do not publish it as a deadline. Check the current year’s position in the DBNMS itself.

If Another Regulator Also Has a Clock

The NPC deadlines are not exclusive. A single incident can carry two or three reporting duties running in parallel to different bodies, and the fastest one is often not the privacy one.

  • BSP-supervised institutions. Section 148 of the BSP Manual of Regulations for Banks requires notification to the Bangko Sentral within two hours of discovering a reportable major cyber-related incident, with a follow-up report within twenty-four hours. For a bank, that clock expires long before the privacy clock does.
  • Criminal reporting. There is no general legal duty to report a breach to law enforcement, but where the breach is an offence, a complaint to the NBI Cybercrime Division or the PNP Anti-Cybercrime Group is how an investigation starts. See how to report cybercrime.
  • Court-ordered disclosure. Separately, RA 10175, Sec. 14 requires any person or service provider served with a court warrant to disclose subscriber information, traffic data or relevant data within seventy-two hours. That is a disclosure duty on a warrant, not a breach-notification duty, and the two should not be confused.
  • Contractual clocks. Many processing agreements and cyber-insurance policies impose notice periods shorter than 72 hours. Those are contractual, not regulatory, but breaching them has its own consequences.

Where a vendor or cloud provider suffered the breach rather than you, the allocation question is covered in our guides to vendor and SaaS security due diligence and data privacy for SaaS and cloud tools. The short version: accountability generally stays with the personal information controller.

Six Worked Scenarios

For how these tests apply to an unverified leak claim still under investigation, see our report on the possible DICT DTAP data exposure.

1. A staff member emails a client list to the wrong recipient

A spreadsheet with 240 clients’ names, mobile numbers and dates of birth goes to an external address by autocomplete error. Sec. 11 analysis: limb (A) is met — that combination enables identity fraud even though none of it is sensitive personal information; limb (B) is met, an unauthorised person has it; limb (C) is realistic. Notify both audiences within 72 hours. With 240 data subjects, the Sec. 17(B) hard stop applies and no delay is available at all, however incomplete the picture. Ask the recipient to delete it and record the response, but do not treat a deletion promise as removing the breach.

2. Ransomware encrypts the customer database, with no sign of exfiltration

Availability has been destroyed, which is squarely inside the Sec. 3(F) definition. Whether limb (B) is met turns on evidence of acquisition, and in most modern ransomware the safer working assumption is that data was taken. Assess honestly and document the reasoning. If the database holds sensitive personal information, the hard stop applies. The separate question of paying is covered in our guides on responding to a ransomware attack and ransomware payment and reporting.

3. A cloud vendor tells you on day four that it was breached on day one

Your 72 hours run from your knowledge or reasonable belief, not from the vendor’s incident. The clock starts when the vendor tells you. That does not excuse the delay commercially, and it is exactly the gap that a notification clause in a data processing agreement exists to close. As controller, the accountability for notifying the Commission and the data subjects is yours.

4. A misconfigured storage bucket, publicly readable for two months, no evidence anyone opened it

Limb (B) asks whether there is reason to believe the information may have been acquired — not whether you can prove it was. Two months of public exposure, with indexing and scanning being what they are, usually supplies that reason. Absence of access logs is not evidence of absence of access, and an organisation that disabled its own logging is not in a stronger position for it.

5. A single HR file containing one employee’s medical records is taken

One data subject. Limb (C) says “any affected data subject” and the harm here is serious and realistic, so the test can be met on one person. Health information is sensitive personal information, so the second hard stop applies and no delay is available — the 100-person threshold is irrelevant.

6. A laptop is stolen, but the disk was fully encrypted and the key was not on it

Limb (B) is where this is decided: whether there is reason to believe the data may have been acquired by an unauthorised person. Properly implemented full-disk encryption with the key held separately is a strong argument that it was not. Document the encryption standard, confirm it was actually enabled on that device, and record who verified it. This is the clearest case on this page for a reasoned decision not to notify — and the one most likely to be tested, so the assessment needs to be written, dated and evidenced.

Common Mistakes

  • Treating the five-day rule as the notification deadline. They are different duties with different sources. Missing 72 hours is not cured by filing at day four.
  • Notifying the NPC and forgetting the data subjects. Sec. 18(A) is a parallel duty on the same clock, not a follow-up task.
  • Emailing the notification. A PDBNF submitted outside the DBNMS is not valid. The submission has not happened.
  • Waiting for a complete investigation. Sec. 17(B) permits delay for three narrow reasons, with two absolute cut-offs. “We wanted the full picture first” is not among them.
  • Assuming a request for exemption buys time. It does not, and silence from the Commission is not a grant.
  • Filing an exemption and a postponement together. Mutually exclusive under Advisory 2026-02, and doing so may sink both.
  • Starting the clock at board sign-off. It starts at knowledge or reasonable belief, which is usually days earlier and held by someone in IT.
  • Rebuilding the affected server before imaging it. Recovery and evidence preservation pull in opposite directions; image first.
  • Deciding not to notify and writing nothing down. A defensible Sec. 11 assessment that exists only in someone’s memory is not a defensible assessment.
  • Skipping the annual report. Sec. 22 applies to all security incidents, including those that never became notifiable breaches.

What It Costs to Get This Wrong

Two distinct exposures, criminal and administrative.

The criminal offence of concealment

RA 10173, Sec. 30 imposes “imprisonment of one (1) year and six (6) months to five (5) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than One million pesos (Php1,000,000.00)” on persons who, after having knowledge of a security breach and of the obligation to notify the Commission under Sec. 20(f), intentionally or by omission conceal the fact of the breach.

Three features of that provision deserve attention. It reaches natural persons, not only the organisation. It can be committed by omission — no active cover-up is required. And it requires knowledge of both the breach and the duty, which is why the moment-of-knowledge record cuts both ways.

Administrative fines

NPC Circular No. 2022-01 sets the administrative scale. Failure to notify regarding data breaches is expressly listed among the major infractions, unless the conduct is criminally punishable.

Tier Fine
Grave infractions 0.5% to 3% “of the annual gross income of the immediately preceding year when the infraction occurred”
Major infractions (includes failure to notify) 0.25% to 2% of the same base
Other infractions ₱50,000 to ₱200,000, and up to ₱50,000
Overall cap “The total imposable fine for a single act of a PIC or PIP … shall not exceed Five Million Pesos (Php 5,000,000.00)”

NPC Advisory No. 2026-02, Sec. 2(E) points back to the same circular: noncompliance with the advisory “shall be subject to administrative fine pursuant to NPC Circular No. 2022-01.”

Because the major and grave tiers are percentages of annual gross income rather than flat sums, the exposure scales with the size of the business. For a small organisation the cap is unlikely to bind; for a large one it may be the operative number.

Frequently Asked Questions

Do I have to report every data breach to the NPC?

No. Only a breach that satisfies all three limbs of NPC Circular No. 16-03, Sec. 11 triggers the mandatory notification duty. But Sec. 22 requires that every security incident and personal data breach be documented in a written report, and summarised to the Commission annually, whether or not it was notifiable.

Is the deadline 72 hours or five days?

Both, for different things. 72 hours to notify the Commission (Sec. 17(A)) and the affected data subjects (Sec. 18(A)). Five days from discovery for the full breach report (Sec. 17(C)). There is no five-day notification rule.

When exactly does the 72 hours start?

On knowledge of, or reasonable belief in, the breach — not on confirmation, not on the completion of an investigation, and not on management being briefed. Fix that moment in writing on day one, because every deadline is measured from it.

Can I notify the NPC by email?

No. The NPC states that it accepts Personal Data Breach Notification Forms through the DBNMS only, and that a form submitted outside the system “shall not be considered as valid.” The five-day full breach report is a separate submission, sent to admindbnms@privacy.gov.ph with the subject line FBR_NameofPIC_NameofDPO.

What if I do not yet know how many people are affected?

Notify anyway, and say what you do not yet know. Sec. 17(D) asks for the nature of the breach, the data possibly involved, the measures taken and the DPO’s contact details. Incomplete and on time beats complete and late.

Can I delay while I investigate?

Only within Sec. 17(B), and only to determine scope, prevent further disclosures, or restore system integrity. There is no delay at all if the breach involves at least 100 data subjects or the disclosure of sensitive personal information.

Does asking the NPC for an exemption stop the clock?

No. NPC Advisory No. 2026-02, Sec. 2(C) states that submitting a request does not relieve the controller of its Circular 16-03 obligations, and the five-day full report remains due unless the request is acted upon.

If the NPC does not respond to my request, is it granted?

No. Section 2(D) of the same advisory states that all approvals must be expressly issued in writing, and that the Commission’s inaction is not an approval, implied consent, or automatic grant, nor a justification for noncompliance.

Our vendor had the breach, not us. Do we still have to report?

Generally yes, where you are the personal information controller. Accountability for the processing does not transfer to the processor. Your clock starts when you learn of it, which is why notification timing belongs in the data processing agreement.

Can a person be prosecuted, or only the company?

A person. RA 10173, Sec. 30 reaches persons who, knowing of a breach and of the Sec. 20(f) duty, conceal it intentionally or by omission — one year and six months to five years’ imprisonment and a fine of ₱500,000 to ₱1,000,000.

Does a small business have the same obligations?

The notification duties in Circular 16-03 do not have a size threshold. Related obligations do vary with scale: IRR Rule VI, Sec. 29 judges the adequacy of security measures partly on “the size of the organization and complexity of its operations,” and the administrative fine tiers are percentages of annual gross income.

We missed our 2025 Annual Security Incident Report. Is it too late?

Not yet. NPC Advisory No. 2026-03, issued 8 September 2026, reopened the submission period for 2025 ASIRs until 10 November 2026, exclusively through the DBNMS.

Do I have to report the breach to the police as well?

Reporting to the NPC and filing a criminal complaint are separate acts. There is no general duty to go to law enforcement, but where the breach is an offence under RA 10175, a complaint to the NBI Cybercrime Division or the PNP Anti-Cybercrime Group is what starts an investigation.

Verification Log

What was checked for this guide, where, and what could not be established. Sources were read on 25 September 2026 (Manila) unless stated.

Claim Source Result
DBNMS is the only valid channel for a PDBNF NPC breach-reporting page, privacy.gov.ph Confirmed and re-read this run
DBNMS account username must be the DPO’s dedicated office email NPC breach-reporting page Confirmed this run
NPC Advisory No. 2026-03, 2025 ASIR extension to 10 November 2026 NPC advisory PDF, privacy.gov.ph, dated 8 September 2026 Confirmed this run, read in full
Circular 16-03 still in force; no repeal notation NPC advisories and circulars index Confirmed this run
No 2026 NPC issuance supersedes Advisory 2026-02 on breach notification NPC advisories and circulars index Confirmed this run: 2026-01 (data scraping), 2026-02 (DBNMS), 2026-03 (ASIR extension)
Circular 16-03 Secs. 3(F), 5, 11, 17, 18, 22 verbatim NPC Circular 16-03 full text, privacy.gov.ph Verified previously and reused, not re-fetched
Advisory 2026-02 Secs. 1, 2(A)–(E), 3 verbatim NPC Advisory 2026-02 full text Verified previously and reused, not re-fetched
RA 10173 Secs. 20(c), 20(f), 30; IRR Rule VI Sec. 29, Rule IX Secs. 38–40 privacy.gov.ph full texts Verified previously and reused, not re-fetched
NPC Circular 2022-01 fine tiers and the ₱5,000,000 cap NPC Circular 2022-01 full text Verified previously and reused, not re-fetched
BSP two-hour and twenty-four-hour incident clocks MORB Sec. 148, morb.bsp.gov.ph Verified previously and reused, not re-fetched
RA 10175 Sec. 14’s 72-hour disclosure window Senate copy of RA 10175 Verified previously and reused, not re-fetched
The ASIR window literal on the NPC page reading “1 January 2023” NPC breach-reporting page Still present. Treated as a stale page artefact and not published as a deadline
Case law on breach-notification enforcement sc.judiciary.gov.ph Not established. Every sub-path of the Supreme Court site is unreachable from our research environment, so no decision is cited anywhere on this page
Any published NPC decision imposing a fine for late notification — Not established. We do not state how the Commission has exercised the Circular 2022-01 scale in practice, because we could not read a decision that shows it

Official Sources

Related Cybercode Guides

About This Guide

Author: Cybercode.ph Editorial Team.

Reviewer: This page has not been reviewed by a named external legal reviewer. Cybercode does not attribute review to a person who has not carried it out. In place of a reviewer’s name, we publish the verification log above, which records exactly which primary sources were read for this guide, which were reused from earlier verification rather than re-fetched, and which claims we could not establish at all.

Corrections: if you believe anything here is wrong, check it against the primary source it cites — the NPC issuance or the statute named in the sentence — and tell us what the source says.

Last materially reviewed: 25 September 2026.

Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.