·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

Data Breach Notification Deadline in the Philippines: NPC Rules and Requirements

What is the data breach notification deadline in the Philippines? Learn the NPC's 72-hour rule, who must report, and how notification works under the Data Privacy Act.


A personal data breach must be reported to the National Privacy Commission (NPC) and affected data subjects within 72 hours of knowledge of the breach. This deadline comes from NPC Circular No. 16-03, the Commission's issuance on personal data breach management, and applies to personal information controllers and personal information processors covered by the Data Privacy Act of 2012 (Republic Act No. 10173). The 72-hour period is not a grace period for investigation — it is the outer limit for notifying the NPC and data subjects once a breach is confirmed. Missing it exposes an organization to administrative penalties and, in some cases, criminal liability.

What counts as a personal data breach

Under the Implementing Rules and Regulations (IRR) of the Data Privacy Act, a personal data breach is "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed."

The IRR also defines a security incident as an event that affects or tends to affect data protection, or may compromise the availability, integrity, and confidentiality of personal data — including incidents that would have resulted in a breach if not for safeguards already in place.

The distinction matters. Not every security incident triggers the notification requirement. But if the incident results in actual destruction, loss, alteration, unauthorized disclosure of, or access to personal data, it becomes a notifiable breach.

The 72-hour notification deadline

The IRR devotes Rule IX to data breach notification. The rule titles listed in the IRR are "38. Data Breach Notification," "39. Contents of Notification," "40. Delay of Notification," "41. Breach Report," and "42. Procedure for Notification." These provisions are implemented in detail by NPC Circular No. 16-03, which is the issuance that sets the operative timelines.

The rule is straightforward: notification to the NPC and to affected data subjects must be made within 72 hours from the time the personal information controller or personal information processor knows, or reasonably should have known, of the breach.

The 72-hour clock is strict. It runs from knowledge of the breach, not from the completion of an internal investigation. An organization that waits until it has fully traced the cause, scoped the affected records, and prepared a polished report before notifying the NPC risks breaching the deadline.

Who must notify — and who is notified

The duty falls on the personal information controller — the entity that controls the processing of personal data or instructs another to process it on its behalf. A personal information processor, which processes data on the controller's instructions, must notify the controller of any breach.

Two notifications are generally required:

  • Notification to the NPC — a formal breach report submitted through the Commission's prescribed process.
  • Notification to affected data subjects — direct communication informing them of the breach and the steps being taken.

Where a processor is involved, the processor notifies the controller, and the controller carries the obligation to notify the NPC and the data subjects.

What the notification must contain

Under the IRR, the notification must describe the nature of the breach, the personal data possibly involved, the measures taken to address the breach, and the measures to reduce its negative effects. It must also include contact details so data subjects can inquire.

NPC Circular No. 16-03 requires the breach report to the Commission to be submitted using the prescribed form, with supporting documents and a narrative of the incident. The report should cover:

  • The date and time of discovery of the breach;
  • The nature and circumstances of the breach;
  • The personal data possibly involved;
  • The measures taken to address the breach;
  • The measures taken to reduce the harm to data subjects; and
  • The contact details of the data protection officer or responsible officer.

Delayed notification and exceptions

The IRR recognizes that notification may be delayed in limited circumstances — Rule IX includes a provision titled "Delay of Notification." Notification to data subjects may be delayed only when it would impede an ongoing investigation by authorities, or when the breach involves data that is encrypted or otherwise unintelligible, provided the encryption keys remain secure.

Even then, the NPC must still be notified within the 72-hour period. The delay applies to the notification to data subjects, not to the report to the Commission.

Penalties for late or missing notification

The IRR's Rule XIII lists penalties for violations, including Concealment of Security Breaches Involving Sensitive Personal Information under Section 57. Concealing a breach involving sensitive personal information is treated more seriously than an ordinary breach.

The NPC may impose administrative fines, issue compliance or enforcement orders, and award indemnity to affected data subjects. Under Section 9 of the IRR, the Commission's enforcement powers include issuing cease and desist orders and recommending prosecution to the Department of Justice.

Frequently asked questions

Is the data breach notification deadline in the Philippines really 72 hours? Yes. Under NPC Circular No. 16-03, notification to the NPC and affected data subjects must be made within 72 hours of knowledge of the breach.

What happens if a company fails to report a data breach within 72 hours? The NPC may impose administrative fines and other sanctions. Concealment of a security breach involving sensitive personal information is a specific violation under Section 57 of the IRR.

Does a small business need to report a data breach? The obligation applies to personal information controllers and processors covered by the Data Privacy Act, regardless of size. If the entity processes personal data and suffers a notifiable breach, the 72-hour rule applies.

Practical takeaways

  • Start the clock at knowledge. The 72-hour period runs from when the breach is known or reasonably should have been known — not from the end of the investigation.
  • Notify the NPC and data subjects. Both notifications are generally required, and both are subject to the 72-hour deadline.
  • Processors report to controllers. A personal information processor must notify the controller, who then notifies the NPC and affected data subjects.
  • Document everything. Keep a record of the breach, the investigation, and the notifications sent, as the NPC may require these in a compliance check.
  • Delay is narrow. Delayed notification to data subjects is allowed only in limited cases, and never excuses the report to the NPC.

Primary sources

The rules discussed above are drawn from the following primary sources, as published in the Official Gazette and the national statute book.

  • NPC IRR OF REPUBLIC ACT NO. 10173, August 24, 2016

  • IRR OF REPUBLIC ACT NO. 10173 - IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 10173, KNOWN AS THE “DATA PRIVACY ACT OF 2012”

  • NPC CIRCULAR NO. 2014-014, April 25, 2014

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.