CyberCode.ph · Philippines

DBNMS Breach Notification: What the NPC’s Advisory Requires

Last updated September 20, 2026 · Practical privacy, cybersecurity and technology-law guidance

The short answer

The Data Breach Notification Management System (DBNMS) is the National Privacy Commission’s online portal for reporting personal data breaches, and it is now the only valid channel — the NPC states that any notification form submitted outside it “shall not be considered as valid.” Two clocks start the moment you know or reasonably believe a breach has occurred: 72 hours to notify the Commission and the affected data subjects, and five days to file the full breach report. NPC Advisory No. 2026-02 confirms that asking for relief pauses neither one.

Two clocks, one starting gun

Almost every mistake Philippine organisations make with breach reporting comes from collapsing two different deadlines into one. They are separate obligations, they are measured in different units, and they both run from the same event — the moment of knowledge or reasonable belief that a personal data breach has occurred.

Obligation Deadline Where it comes from How it is filed
Notify the National Privacy Commission Within 72 hours of knowledge or reasonable belief NPC Circular 16-03, Sec. 17(A); IRR of RA 10173, Rule IX, Sec. 38 Personal Data Breach Notification Form (PDBNF) through the DBNMS — and nowhere else
Notify the affected data subjects Within 72 hours of knowledge or reasonable belief NPC Circular 16-03, Sec. 18(A) Directly to each affected individual, unless the Commission approves alternative means
Submit the full breach report Within five (5) days of the date of discovery NPC Circular 16-03, Sec. 17(C); restated in NPC Advisory No. 2026-02, Sec. 2(C) By email to admindbnms@privacy.gov.ph, subject line FBR_NameofPIC_NameofDPO
Annual Security Incident Report (ASIR) 1 January to 31 March, covering the previous calendar year NPC Circular 16-03, Sec. 22 Through the DBNMS — submissions outside it are not valid
The 72-hour and five-day clocks run in parallel from the same moment, not one after the other.

Note what the five-day clock is not. It is not an extension of the 72-hour deadline and it is not a grace period. It is the deadline for the detailed report that follows the initial notification. If you file nothing in the first 72 hours and then file a full report on day five, you have missed a deadline, not met one.

Does this breach need reporting at all?

Not every security incident is a notifiable personal data breach. NPC Circular 16-03, Sec. 11 makes notification mandatory only when all three of the following are present at once. The NPC’s own breach reporting page repeats the same three-part test.

# Element What it means in practice
1 The breach “involves sensitive personal information or any other information that may be used to enable identity fraud” Health records, government identifiers and financial account details clearly qualify. So does an ordinary-looking combination — full name plus date of birth plus mother’s maiden name — if it would let someone impersonate the data subject.
2 There is “reason to believe that the information may have been acquired by an unauthorized person” Certainty is not required. A reasonable belief is enough, and the absence of proof that data was exfiltrated is not proof that it was not.
3 The unauthorised acquisition “is likely to give rise to a real risk of serious harm to any affected data subject” This is the judgement call. Encrypted data with the keys intact points one way; a plain-text customer list posted to a forum points the other.
All three must be present. If one is genuinely absent, mandatory notification is not triggered — but the incident is still documented.

Two cautions before you conclude that a breach falls outside the test. First, an incident that fails the three-part test is still a security incident, and Sec. 22 of Circular 16-03 requires that “all security incidents and personal data breaches shall be documented through written reports.” It goes into your records and into the Annual Security Incident Report even if no 72-hour notification is due. Second, the decision to treat a breach as non-notifiable is one you will have to defend to the Commission later, with the documents you created at the time. For the wider question of what counts as a reportable breach, see our guide to when the NPC must be notified and the working definition in what counts as a data privacy violation.

What the DBNMS actually is

The DBNMS is a web portal operated by the National Privacy Commission at dbnms.privacy.gov.ph. The NPC describes it as “a user-friendly interface that facilitates easy notification and tracking of reports.” In practice it does three things: it accepts the Personal Data Breach Notification Form, it accepts the Annual Security Incident Report, and it is the channel through which a personal information controller submits requests for exemption, postponement or alternative means of notifying data subjects.

The single most important thing to understand about it is exclusivity. In the Commission’s words: “Following the launch of the DBNMS, the Commission accepts submission of PDBNFs through the System ONLY. Any PDBNF submitted outside of the DBNMS shall not be considered as valid.” The same sentence is applied to Annual Security Incident Reports.

That is stronger than a procedural preference. A breach notification emailed to a Commission officer, handed over at a meeting, or posted by courier is not a late notification — it is no notification at all, and the 72-hour clock keeps running past it. If your incident response plan still names an email address as the primary reporting route, it is out of date. Our incident response plan guide and the data breach response checklist both assume the DBNMS route.

The 72-hour clock: notifying the Commission

NPC Circular 16-03, Sec. 17(A) sets the deadline in one sentence: “The Commission shall be notified within seventy-two (72) hours upon knowledge of or the reasonable belief by the personal information controller or personal information processor that a personal data breach has occurred.” The NPC’s breach reporting page applies the same period to the form itself — PDBNFs “should be accomplished and submitted within seventy-two (72) hours upon knowledge of or reasonable belief” that a breach has occurred.

The trigger is knowledge or reasonable belief, not confirmation. The clock does not wait for your forensic vendor’s report, it does not wait for the board to be briefed, and it does not restart when you learn the breach was larger than you thought. It starts when a person in your organisation who is in a position to know first has reasonable grounds to believe personal data was compromised.

Sec. 17(D) of Circular 16-03 sets out what the notification must contain: the nature of the breach, the personal data involved, the measures taken, and the “name and contact details of the data protection officer or any other accountable persons.” The IRR of RA 10173, Rule IX, Sec. 39 requires the same categories, adding the remedial measures and the assistance being provided to affected data subjects.

What you need in front of you before you open the form

  • The date of discovery — this is the single most consequential entry on the form, because both clocks run from it.
  • A description of the incident and, so far as known, its cause.
  • The categories and approximate volume of personal data involved, and whether any of it is sensitive personal information.
  • The approximate number of affected data subjects, with a note that the figure is provisional if it is.
  • The measures already taken to contain the breach and to mitigate harm.
  • The name and contact details of your Data Protection Officer, who is the accountable person on the form.

Where a figure is genuinely unknown at hour 70, say so on the form rather than guessing. Advisory 2026-02 expressly contemplates that numbers will move: “A change in circumstance, including but not limited to change in the number of affected data subjects or the data elements involved, must be included in the full breach report.” A provisional figure corrected in the full report is compliance. A confident figure invented to fill a box is a misrepresentation to a regulator.

The 72-hour clock: notifying the data subjects

This is the obligation most often overlooked, because organisations read the deadline as a reporting duty owed only to the regulator. It is not. Sec. 18(A) of Circular 16-03 is worded in parallel to Sec. 17(A): “The data subjects shall be notified within seventy-two (72) hours upon knowledge of or reasonable belief by the personal information controller or personal information processor that a personal data breach has occurred.” The NPC’s breach reporting page states it in capitals — the PIC must notify the data subject within the same 72 hours.

Section 20(f) of the Data Privacy Act is the statutory root of both duties: the personal information controller “shall promptly notify the Commission and affected data subjects” when sensitive personal information is reasonably believed to have been acquired by an unauthorised person. Two audiences, one statutory sentence, one deadline. If you have told the Commission and not the people whose data it is, you are half-compliant, which under Sec. 18(A) is non-compliant.

Can you delay? Only narrowly, and sometimes not at all

Circular 16-03 allows a limited delay, then removes it for the cases where delay would matter most. Sec. 17(B) permits it only on defined grounds: notification “may only be delayed to the extent necessary to determine the scope of the breach, to prevent further disclosures, or to restore reasonable integrity to the information and communications system.” Rule IX, Sec. 40 of the IRR is drafted to the same effect.

Then comes the hard stop. Sec. 17(B) continues: “There shall be no delay in the notification if the breach involves at least one hundred (100) data subjects, or the disclosure of sensitive personal information.”

Your situation Is delay available?
Breach affects 100 or more data subjects No. No delay is permitted, whatever the investigative reason.
Breach involves disclosure of sensitive personal information, any number of data subjects No. Same hard stop.
Fewer than 100 data subjects, no sensitive personal information, and you genuinely cannot yet determine the scope Delay permitted, but only to the extent necessary and only on one of the three listed grounds.
You would rather brief the executive team first, or wait for legal sign-off No. Neither is a ground under Sec. 17(B).
NPC Circular 16-03, Sec. 17(B). Note that the two hard stops between them cover most breaches a Philippine business will actually face.

Read the two thresholds together and the practical position is stark. A mailing-list leak of 400 email addresses crosses the 100-data-subject line. A single HR file containing one employee’s medical certificate crosses the sensitive-personal-information line. In both cases there is no delay to be had, and the 72-hour clock is the whole of the answer. Our guide on what a company should do after a personal data breach works through the containment steps that have to happen inside that window.

The five-day clock: the full breach report

Sec. 17(C) of Circular 16-03: “The full report of the personal data breach must be submitted within five (5) days, unless the personal information controller is granted additional time by the Commission to comply.” Advisory 2026-02, Sec. 2(C) restates the same period and pins it to discovery — the PIC “shall submit its full breach report within five (5) days from the date of discovery.”

The full breach report is where the provisional becomes definite: the confirmed scope, the confirmed data elements, the confirmed number of affected data subjects, the root cause, the remedial measures completed, and any change in circumstance since the initial notification. It is also where an organisation that behaved well in the first 72 hours gets to demonstrate it.

Two details from Advisory 2026-02 that are easy to miss and easy to get wrong:

What Exactly as the Advisory states it
Where the full breach report goes admindbnms@privacy.gov.ph
The required subject line FBR_NameofPIC_NameofDPO
Where compliance questions go compliancesupport@privacy.gov.ph, the NPC’s Compliance and Monitoring Division
What that second address may not be used for Questions on requests for postponement, exemption, alternative means of notification, or extension of time to submit documents under Circular 16-03
NPC Advisory No. 2026-02, Sec. 2(C).

The carve-out in the last row is worth pausing on. The Commission has deliberately separated its help desk from its decision-making channel. Emailing the compliance support address to ask whether your postponement request is likely to be granted is not a step in the process, and an answer from it would not be an approval. Requests go through the DBNMS; the Commission’s decision comes back in writing, and only in writing.

What NPC Advisory No. 2026-02 changed

NPC Advisory No. 2026-02, dated 11 May 2026, is titled “Clarification on the Submission of Personal Data Breach Notification through Data Breach Notification Management System.” It was approved by Privacy Commissioner Atty. Johann Carlos S. Barcena, CESO III, with Deputy Privacy Commissioners Atty. Jose Amelito S. Belarmino, MSc and Atty. Juan Paolo F. Fajardo.

Sec. 1 states its scope: the Advisory “prescribes guidelines and clarifications for all Personal Information Controllers (PICs) with respect to personal data breach notification to the National Privacy Commission (NPC).” It does not replace NPC Circular 16-03, which remains in force and is still listed as such on the NPC’s advisories and circulars index. It clarifies how three kinds of request — exemption from notifying data subjects, postponement of that notification, and alternative means of making it — behave when they are filed through the DBNMS.

Those three requests come from Circular 16-03 itself. Sec. 18(B) provides that a controller “may be exempted from the notification requirement where the Commission determines that such notification would not be in the public interest,” and that the Commission “may authorize the postponement of notification where it may hinder the progress of a criminal investigation.” Sec. 18(D) provides that where individual notification is impractical, the controller “may seek the approval of the Commission to use alternative means of notification, such as through public communication or any similar measure through which the data subjects are informed in an equally effective manner.”

Which requests can be combined, and which cannot

This is the operative new rule, and it is the reason the Advisory exists. Sec. 2(A) prohibits two specific pairings outright and expressly permits a third.

Combination, for the same breach incident Permitted? Source
Exemption from notifying data subjects + postponement of that notification Not permitted Sec. 2(A)(1)
Exemption from notifying data subjects + alternative means of notification Not permitted Sec. 2(A)(2)
Postponement + alternative means of notification Permitted, concurrently Sec. 2(A)
NPC Advisory No. 2026-02, Sec. 2(A). The logic is internally consistent: exemption says the notification should not happen, so it cannot be combined with a request about how or when it happens.

The Advisory’s words on the two prohibited pairings: the PIC “shall not simultaneously avail of: (1) a request for exemption to notify affected data subjects and a request for postponement of such notification; or (2) a request for exemption to notify affected data subjects and a request to use alternative means of notification, in relation to the same personal data breach incident.” On the permitted pairing: “A request for postponement and a request to use alternative means of notification may, however, be availed of concurrently.”

There is a consequence attached, and it is not a warning about form-filling. Where a PIC invokes multiple mutually exclusive requests arising from the same incident, the Advisory states that such requests may be a ground for the denial of one or all such requests. Filing both an exemption request and a postponement request as a hedge does not double your chances. It can lose you both.

What counts as one incident

The prohibition above applies “in relation to the same personal data breach incident,” which makes the definition of a single incident load-bearing. Sec. 2(A) supplies it: “For purposes of this Advisory, a personal data breach shall be treated as a single incident where it involves the same affected data subjects, the same personal data involved, and the same nature of the breach.”

Test element Same? Result
Affected data subjects All three the same One incident. The mutual-exclusivity rule applies across everything you file about it.
Personal data involved
Nature of the breach
Any one of the three differs Not the same incident on this test — but do not treat that as a licence to file contradictory requests. The Commission assesses the facts and circumstances.
NPC Advisory No. 2026-02, Sec. 2(A).

The Advisory adds that a change in circumstance — it names a change in the number of affected data subjects or in the data elements involved — “must be included in the full breach report,” and that nothing precludes the PIC from submitting information or requests relating to that change. So a growing breach is not handled by opening a second file; it is handled by reporting the growth within the existing one.

Silence from the Commission is not a yes

If you take one line away from Advisory 2026-02, take Sec. 2(D). It disposes of the most dangerous assumption in breach management — that a request filed on time and met with silence has bought you room.

“All approvals or resolutions of requests shall be expressly issued in writing by the Commission.” … “The Commission’s inaction shall not be construed as an approval, implied consent, or automatic grant of any request submitted by the PIC, nor shall serve as a justification for noncompliance.”

NPC Advisory No. 2026-02, Sec. 2(D)

Sec. 2(C) makes the same point from the other direction: submitting a request through the DBNMS “shall not relieve the PIC of its obligation pursuant to NPC Circular No. 16-03.” Unless and until the Commission acts on the request, the underlying duties stand — including the full breach report within five days of discovery.

Put plainly: a pending request is not a deadline extension. If you have asked for postponement of data subject notification and heard nothing by hour 71, the correct action is to notify the data subjects. If the Commission later grants the postponement, you have over-complied. If it refuses, or simply never answers, you have complied. The only route that produces a breach of Sec. 18(A) is waiting.

Make the request properly the first time

Sec. 2(B) tells you how the Commission will read a request: the PIC “shall determine and clearly state the most appropriate grounds for the justification of its requests and shall submit corresponding supporting documents.” The Commission assesses them under Circular 16-03, “taking into account the supporting documents, as well as the facts and circumstances surrounding the personal data breach incident.”

Two things follow. First, a request with no supporting documents is a request the Commission has no material to grant. Second — and this is a useful relief valve — Sec. 2(B) confirms that where you have asked for alternative means of notification, “nothing prevents the PIC from advising the stakeholders of the fact of the data breach or any other relevant information pending the approval of such request.” You are not gagged while you wait. You can tell people something has happened.

The sequence, hour by hour

The following is the order the two circulars impose, written as a timeline rather than as a list of rules. Hour zero is the moment of knowledge or reasonable belief, not the moment the incident began.

When What has to happen Authority
Hour 0 Record the date and time of discovery, and who discovered it. Convene the data breach response team — Sec. 5 requires one, with “at least one (1) member with the authority to make immediate decisions regarding critical action.” Circular 16-03, Secs. 4–5
Hours 0–24 Contain the breach. Assess the three-part test in Sec. 11. Begin the written record that Sec. 22 requires whatever the outcome. Circular 16-03, Secs. 11, 22
Hours 24–48 Determine whether any delay ground under Sec. 17(B) is even available — it is not if 100 or more data subjects are affected, or if sensitive personal information was disclosed. Prepare the PDBNF. Draft the data subject notification. Circular 16-03, Sec. 17(B)
By hour 72 Submit the PDBNF through the DBNMS. Notify the affected data subjects. If you are requesting exemption, postponement or alternative means, file that through the DBNMS too — and notify anyway unless and until a written approval arrives. Circular 16-03, Secs. 17(A), 18(A); Advisory 2026-02, Secs. 2(C)–(D)
By day 5 from discovery Email the full breach report to admindbnms@privacy.gov.ph with subject FBR_NameofPIC_NameofDPO, including any change in circumstance since the notification. Circular 16-03, Sec. 17(C); Advisory 2026-02, Sec. 2(C)
1 Jan – 31 Mar following File the Annual Security Incident Report through the DBNMS for the previous calendar year. Circular 16-03, Sec. 22

What it costs to get this wrong

There are three distinct exposures, and they are not alternatives to one another.

1. Administrative fines

Advisory 2026-02, Sec. 2(E) states it directly: “Noncompliance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, or any Order, Resolution, or Decision of the Commission shall be subject to administrative fine pursuant to NPC Circular No. 2022-01 or the Guidelines on Administrative Fines.”

Under NPC Circular 2022-01, failure to notify regarding data breaches is classified as a major infraction where it is not otherwise criminally punishable. Major infractions carry a fine of 0.25% to 2% of the annual gross income of the immediately preceding year when the infraction occurred. The circular caps the total imposable fine for a single act of a PIC or PIP at five million pesos (₱5,000,000.00).

Read the base of that calculation carefully. It is a percentage of annual gross income, not of profit, not of the revenue attributable to the affected service, and not a flat schedule. For a mid-sized Philippine company the arithmetic gets uncomfortable quickly. Our guide to Data Privacy Act penalties sets out the full fine and penalty structure.

2. Criminal liability for concealment

This is the exposure most compliance memos leave out. Section 30 of RA 10173 creates a standalone offence of Concealment of Security Breaches Involving Sensitive Personal Information:

“The penalty of imprisonment of one (1) year and six (6) months to five (5) years and a fine of not less than Five hundred thousand pesos (Php500,000.00) but not more than One million pesos (Php1,000,000.00) shall be imposed on persons who, after having knowledge of a security breach and of the obligation to notify the Commission pursuant to Section 20(f), intentionally or by omission conceals the fact of such security breach.”

RA 10173, Sec. 30

Three features of that provision deserve attention. It is directed at persons, not only at the corporate entity. It is satisfied “by omission” as well as by a positive act of concealment. And it requires knowledge of both the breach and the notification obligation — which means that the better your organisation documents its own awareness of the Sec. 20(f) duty, the more squarely a decision not to notify sits inside Sec. 30.

3. Civil claims by data subjects

Separately from anything the Commission does, affected individuals may have their own claims. See whether you can sue a company for leaking your personal information for how that side works, and how a data subject files a complaint with the NPC for the route most of them take first.

The Annual Security Incident Report

Sec. 22 of Circular 16-03 requires that “all security incidents and personal data breaches shall be documented through written reports,” and that “a summary of all reports shall be submitted to the Commission annually.” The NPC’s breach reporting page describes what the summary must contain: the number of incidents and breaches encountered, and the number of incidents classified according to their causes and according to whether they were mandatory notifications, voluntary notifications, or other security incidents.

The ASIR covers the previous calendar year and is filed in the 1 January to 31 March window. Like the PDBNF, it must go through the DBNMS — the NPC states that an ASIR submitted outside the system “shall not be considered as valid.”

The point most organisations miss is that the ASIR is where non-notifiable incidents surface. An incident that failed the Sec. 11 three-part test never generated a 72-hour notification, but it still belongs in the annual summary. An organisation that reports zero incidents for a year in which its help desk logged several is making a statement to the regulator that its own records contradict.

Worked scenarios

Situation What the rules require
Friday 4pm: your IT lead tells you a misconfigured storage bucket exposed a customer list of 6,000 names, emails and mobile numbers. It is unclear whether anyone downloaded it. The clock started Friday 4pm. “Reason to believe” does not require proof of download. With 6,000 data subjects you are far past the 100 threshold, so no delay is available under Sec. 17(B). PDBNF through the DBNMS and data subject notification by Monday 4pm; full breach report by the following Wednesday.
A single HR folder containing three employees’ medical certificates was emailed to the wrong internal distribution list. Small numbers do not help here. Sensitive personal information was disclosed, which removes delay under Sec. 17(B) independently of the headcount. Assess the Sec. 11 test on real risk of serious harm, document the assessment either way, and if the test is met run the full 72-hour and five-day sequence.
You want to postpone notifying data subjects because the PNP has asked you not to tip off the suspect, and you also want to notify by public announcement rather than individually. Both requests may be filed concurrently — this is the one permitted pairing under Sec. 2(A). File through the DBNMS with your grounds clearly stated and the supporting documents, including the law enforcement request. Keep notifying on schedule unless a written approval arrives first.
You file an exemption request, and to be safe you also file a postponement request for the same breach. Prohibited under Sec. 2(A)(1). Worse than useless: invoking mutually exclusive requests “may be a ground for the denial of one or all such requests.” Choose the one your facts actually support.
You filed a postponement request on day two and the Commission has not replied by hour 70. Notify the data subjects. Sec. 2(D) is explicit that inaction is not approval and “nor shall serve as a justification for noncompliance.” The pending request does not move the deadline.
On day four you discover the breach touched 9,000 people, not 900. Do not open a second notification. Same data subjects’ category, same data, same nature of breach means the same incident. The change in circumstance “must be included in the full breach report” under Sec. 2(A) — which is due on day five.
Your DPO emailed the notification to an NPC officer she has worked with before, within 48 hours. Not a valid notification. The NPC accepts PDBNFs “through the System ONLY,” and anything outside it “shall not be considered as valid.” The 72-hour clock never stopped. File through the DBNMS immediately and treat the lapse honestly in the full breach report.
A ransomware attack encrypted your systems but you have no evidence of exfiltration. Encryption without exfiltration may fail element 2 or element 3 of the Sec. 11 test, but that is a documented assessment, not an assumption. Modern ransomware commonly exfiltrates before encrypting. See what to do after a ransomware attack and after a business cyberattack.

A DBNMS readiness checklist

Every item below can be done before a breach, and each one buys back hours you will not have afterwards.

  • Register your organisation’s DBNMS access now, not during an incident. A portal you have never logged into is not a reporting channel.
  • Name the individuals authorised to submit, and give at least two people working credentials.
  • Put admindbnms@privacy.gov.ph and the subject-line format FBR_NameofPIC_NameofDPO into your incident runbook verbatim.
  • Remove any instruction in existing documentation that tells staff to email a breach notification to the NPC. It is no longer a valid route.
  • Constitute the data breach response team required by Sec. 5, and identify in writing which member holds authority for immediate critical decisions.
  • Pre-draft the data subject notification. Seventy-two hours is not enough time to write, review and approve one from nothing.
  • Decide in advance who records the date and time of discovery and where that record lives.
  • Pre-assemble the evidence you would attach to a postponement or alternative-means request, so a request is filed with grounds and documents rather than a bare assertion.
  • Build the wider compliance baseline and security measures that make the three-part test in Sec. 11 easier to answer honestly.
  • Keep the incident log that feeds the Annual Security Incident Report running all year, not reconstructed each January.

Five assumptions that cause the damage

The assumption What is actually true
“We have five days to report a breach.” You have 72 hours to notify, and five days for the full report. Two clocks, both from discovery.
“Telling the NPC is the obligation.” Sec. 18(A) imposes a parallel 72-hour duty to the affected data subjects.
“We filed a request, so we are covered while we wait.” Sec. 2(D): inaction is not approval and is not a justification for noncompliance.
“We can pause while we investigate.” Only on three narrow grounds, and not at all at 100+ data subjects or where sensitive personal information was disclosed.
“We emailed it, so it is filed.” PDBNFs outside the DBNMS “shall not be considered as valid.”

Where this fits

Breach notification sits at the end of a chain of duties that start long before an incident. The security measures required under the Data Privacy Act and its IRR are what reduce the chance of ever filing a PDBNF; a privacy impact assessment is what tells you which systems would trigger one; and the first 72 hours checklist is the operational companion to this page. If the breach is at a supplier rather than in your own systems, the duties still land on the controller — see vendor and SaaS due diligence and data privacy for SaaS and cloud tools. If you are on the receiving end rather than the reporting end, start with what to do when your personal data is leaked. The full set of instruments is indexed in our NPC issuances database.

Verification note

Everything quoted on this page was read from a primary government source on 20 September 2026: NPC Circular 16-03 and NPC Advisory No. 2026-02 from the National Privacy Commission’s own document library, the Commission’s breach reporting page, its advisories and circulars index, and the text of RA 10173 published by the Commission. Section numbers are given with each quotation so that any statement here can be checked against the source.

Three limits on what this page asserts. First, no Philippine case law is cited. The Supreme Court’s e-library could not be reached during the preparation of this guide, and we do not cite cases from memory. Second, NPC Advisory No. 2026-02 contains no effectivity clause — its Sec. 3 addresses interpretation only — so this page states its date of issue rather than asserting a date on which it took effect. Third, the NPC’s breach reporting page renders the ASIR filing window with a fixed opening year (“from 1 January 2023 to 31 March of the current year”). Read against Sec. 22 of Circular 16-03, the operative rule is an annual 1 January to 31 March window for the preceding calendar year; the fixed year on the page appears to be an artefact rather than a live deadline, and we have not asserted it as one.

Frequently asked questions

Is the DBNMS the only way to notify the NPC of a data breach?

For the Personal Data Breach Notification Form, yes. The Commission states that following the DBNMS launch it accepts PDBNFs “through the System ONLY,” and that any PDBNF submitted outside it “shall not be considered as valid.” The same applies to the Annual Security Incident Report. The full breach report is the exception — Advisory 2026-02, Sec. 2(C) directs it by email to admindbnms@privacy.gov.ph.

Is the deadline 72 hours or five days?

Both, for different things. Seventy-two hours to notify the Commission and the affected data subjects; five days from the date of discovery for the full breach report. Neither is an alternative to the other, and both run from the same moment of knowledge or reasonable belief.

When exactly does the 72-hour clock start?

On “knowledge of or reasonable belief” that a personal data breach has occurred — not on confirmation, not on completion of a forensic investigation, and not on management sign-off. In practice it starts when someone in your organisation first has reasonable grounds to believe personal data was compromised.

Can we delay notification while we investigate?

Only narrowly. Sec. 17(B) of Circular 16-03 permits delay only to the extent necessary to determine the scope of the breach, prevent further disclosures, or restore reasonable integrity to the system. And there is “no delay in the notification if the breach involves at least one hundred (100) data subjects, or the disclosure of sensitive personal information” — which covers most breaches of any size.

We filed a postponement request and the NPC has not replied. Are we protected?

No. Advisory 2026-02, Sec. 2(D) states that all approvals “shall be expressly issued in writing” and that the Commission’s inaction “shall not be construed as an approval, implied consent, or automatic grant,” nor as a justification for noncompliance. Keep notifying on schedule unless a written approval arrives.

Can we ask for exemption and postponement at the same time?

No. Sec. 2(A)(1) of Advisory 2026-02 prohibits that pairing for the same incident, as does Sec. 2(A)(2) for exemption combined with alternative means. Postponement and alternative means may be requested concurrently. Filing a prohibited combination may be a ground for denying one or all of the requests.

The number of affected people grew after we notified. Do we file again?

Not a new notification. Where the affected data subjects, the personal data and the nature of the breach are the same, it is a single incident, and Sec. 2(A) requires that the change in circumstance “must be included in the full breach report.”

Do we have to notify the data subjects as well as the NPC?

Yes. Sec. 18(A) of Circular 16-03 imposes the same 72-hour deadline for notifying data subjects, and Sec. 20(f) of RA 10173 requires the controller to “promptly notify the Commission and affected data subjects.” Notifying only the regulator does not satisfy the duty.

What if the breach does not meet the three-part test?

Then mandatory notification is not triggered — but Sec. 22 still requires the incident to be documented in a written report, and it still belongs in the Annual Security Incident Report. Record the assessment that led you to conclude the test was not met, at the time you make it.

What are the penalties for not reporting?

Administrative fines under NPC Circular 2022-01, where failure to notify is a major infraction attracting 0.25% to 2% of the annual gross income of the immediately preceding year, subject to a ₱5,000,000 cap per single act. Separately, Sec. 30 of RA 10173 makes concealment of a security breach involving sensitive personal information a criminal offence carrying imprisonment of one year and six months to five years and a fine of ₱500,000 to ₱1,000,000 — and it can be committed by omission.

Does NPC Advisory No. 2026-02 replace NPC Circular 16-03?

No. The Advisory clarifies how requests submitted through the DBNMS interact with the Circular’s obligations. Sec. 2(C) states that a request “shall not relieve the PIC of its obligation pursuant to NPC Circular No. 16-03,” and the Commission’s issuances index continues to list Circular 16-03 as in force.

Who inside the company is accountable?

The Data Protection Officer or other accountable person is named on the notification itself under Sec. 17(D). Sec. 5 additionally requires a data breach response team with at least one member holding authority to make immediate decisions on critical action. And Sec. 30 of RA 10173 reaches individual persons, not only the corporate entity.

Official sources

About this guide

Author: Cybercode.ph Editorial Team. Last materially reviewed: 20 September 2026, against NPC Circular 16-03, NPC Advisory No. 2026-02, the NPC breach reporting page and RA 10173 as published by the National Privacy Commission.

This page has not been reviewed by a named external legal reviewer. We say so rather than attaching a credential the site does not have. Every legal proposition on this page is tied to a numbered provision of a named government issuance so that it can be verified independently.

Disclaimer: This guide is general information about Philippine law, not legal advice, and it does not create a lawyer-client relationship. Breach assessment turns on facts that vary from incident to incident, and the consequences of getting the 72-hour and five-day deadlines wrong are significant. If you are inside a live incident, obtain advice from a Philippine lawyer qualified in data privacy, and contact the National Privacy Commission directly through the channels listed above.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.