When Must Philippine Companies Report Data Breaches?

When Must Philippine Companies Report Data Breaches?

Introduction

A serious corporate data leak can require immediate action under Philippine data privacy law. A personal information controller (PIC) may have as little as 72 hours from knowledge of, or reasonable belief in, a qualifying personal data breach to notify both the National Privacy Commission (NPC) and affected data subjects.

The deadline is not triggered by every cybersecurity incident. It applies when the breach involves sensitive personal information, or other information that may enable identity fraud, and the unauthorized acquisition is likely to create a real risk of serious harm to an affected data subject.

Digital enterprises should therefore maintain a documented incident-response process that identifies the breach, preserves evidence, assesses the risk, prepares an initial notification, and submits the required follow-up report.

Governing Philippine Law

The principal statute is the Data Privacy Act of 2012, particularly Section 20(f). It requires a PIC to promptly notify the NPC and affected data subjects when the statutory conditions for breach notification are present.

The implementing requirements appear in Rule IX, Section 38 of the Implementing Rules and Regulations of Republic Act No. 10173. The rule specifies that notification must generally be made within 72 hours from the PIC’s knowledge of, or reasonable belief that, a personal data breach requiring notification has occurred.

NPC Circular No. 16-03, or the Personal Data Breach Management rules, further describes the timing, content, manner, and reporting requirements for breach notifications. NPC decisions have repeatedly treated notification to the Commission and notification to data subjects as separate obligations.

When Does the 72-Hour Period Apply?

The 72-hour period applies when all material conditions for a reportable breach are present. The breach must involve either:

  • sensitive personal information; or
  • other information that may, under the circumstances, be used to enable identity fraud.

There must also be a reasonable belief that the information was acquired by an unauthorized person. Finally, the PIC or the NPC must believe that the unauthorized acquisition is likely to give rise to a real risk of serious harm to an affected data subject.

The 72-hour period runs from the PIC’s knowledge of, or reasonable belief that, the qualifying breach occurred. The enterprise does not have to complete its entire investigation before making the initial notification. It may notify the NPC and affected data subjects using the information reasonably available at that time, then supplement the notification as additional facts become known.

What Counts as Knowledge or Reasonable Belief?

The period may begin when the PIC has sufficient information to reasonably conclude that a personal data breach has occurred and that notification may be required. This may arise from an internal security alert, a confirmed unauthorized access event, a credible report from a service provider, or evidence that personal data was copied, extracted, or exposed.

An enterprise should not postpone assessment merely because the precise number of affected individuals, the full categories of data, or the identity of the attacker remain unknown. An initial report may be based on available information, provided the PIC continues its investigation and submits the required additional information.

When Is Notification Prohibited from Being Delayed?

NPC Circular No. 16-03 provides that there shall be no delay in notification when the breach involves at least 100 data subjects, or when the disclosure of sensitive personal information will harm or adversely affect a data subject.

In either situation, the NPC must be notified within 72 hours based on available information. The full breach report must generally be submitted within five days, unless the NPC grants additional time.

The five-day full-report period is separate from the 72-hour notification period. Submitting an initial notification does not eliminate the duty to submit the full breach report.

What Must the Notification Contain?

The notification should be sufficiently detailed to allow the NPC and affected individuals to understand the incident and take protective measures. Under Rule IX, Section 39 of the IRR of Republic Act No. 10173, it should at least describe:

  • the nature of the breach;
  • the personal data possibly involved;
  • the measures taken by the PIC to address the breach;
  • the measures taken to reduce harm or negative consequences;
  • the representatives of the PIC and their contact details; and
  • the assistance available to affected data subjects.

The notice should also explain what affected individuals can do, such as changing passwords, blocking accounts, monitoring financial activity, reporting suspicious communications, or securing government and financial records.

How Must Affected Individuals Be Notified?

Notification to data subjects is distinct from notification to the NPC. It is not enough for a PIC to send a report to the Commission while failing to inform the affected individuals.

Notification should generally be made individually through secure written or electronic communication. The PIC must take reasonable steps to verify the recipient’s identity and prevent the notification itself from causing further unnecessary disclosure of personal information.

The PIC should preserve delivery records, confirmation logs, returned messages, and other evidence showing the steps taken to make affected data subjects aware of the breach. NPC issuances have required proof that notifications were actually received or that reasonable mechanisms were used to reach the affected individuals.

If individual notification is impossible or would require disproportionate effort, the PIC may seek NPC approval to use an alternative method, such as public communication, provided the alternative is equally effective in informing the affected data subjects.

What Delays or Exceptions May Apply?

The Data Privacy Act permits limited delay only to the extent necessary to determine the scope of the breach, prevent further disclosures, or restore reasonable integrity to the information and communications system.

The NPC may also exempt a PIC from notification when, in its reasonable judgment, notification is not in the public interest or is not in the interest of the affected data subjects. In addition, the NPC may authorize postponement when notification could hinder a criminal investigation involving a serious breach.

These provisions are not a general license to wait until the investigation is complete. Any delay must be limited, justified, and consistent with the purpose of protecting affected individuals. Where the breach involves at least 100 data subjects or disclosure of sensitive personal information that may harm or adversely affect a data subject, the applicable rules expressly prohibit delay in notifying the Commission.

What Is the Five-Day Full Breach Report?

The full breach report is a separate compliance requirement. It should provide a more complete account of the incident, including the facts established after the initial notification, the categories and approximate number of affected data subjects, the data involved, the security measures in place, the remedial actions taken, and the measures adopted to prevent recurrence.

Under NPC Circular No. 16-03, the full report must generally be submitted within five days after the initial report, unless the NPC grants additional time. A PIC should request an extension before the deadline and explain why the additional period is necessary.

What Are the Consequences of Concealing a Breach?

Section 30 of the Data Privacy Act of 2012 penalizes a person who, after acquiring knowledge of a security breach and the obligation to notify the NPC, intentionally or by omission conceals the breach.

The penalty is imprisonment of one year and six months to five years, and a fine of not less than ₱500,000 but not more than ₱1,000,000. The provision specifically concerns concealment of security breaches involving sensitive personal information.

A company should therefore avoid suppressing, minimizing, or informally handling a serious incident without creating a written record. Deliberate concealment can create separate criminal exposure apart from possible administrative sanctions, civil claims, contractual consequences, and reputational damage.

Incident-Response Steps for Digital Enterprises

  1. Record the time of discovery. Identify when the PIC first knew, or reasonably believed, that a qualifying breach occurred. This timestamp should be documented.
  2. Contain the incident. Disable compromised credentials, isolate affected systems, preserve logs, and prevent further unauthorized access without destroying relevant evidence.
  3. Assess the affected information. Determine whether sensitive personal information or information capable of enabling identity fraud was exposed or acquired.
  4. Assess the risk of serious harm. Consider the nature of the information, the number of affected individuals, the likelihood of misuse, and the consequences of identity theft, fraud, discrimination, or other harm.
  5. Prepare the initial notifications. Submit the NPC notification and notify affected data subjects within the applicable 72-hour period when the breach is reportable.
  6. Submit the full report. Complete and submit the full breach report within five days, unless the NPC authorizes additional time.
  7. Preserve proof of compliance. Keep copies of notices, delivery records, confirmation logs, incident reports, forensic findings, and communications with the NPC.

Common Mistakes to Avoid

A frequent mistake is treating the 72-hour deadline as beginning only after the forensic investigation is finished. The rules allow notification based on available information; uncertainty about the complete scope of the breach does not automatically suspend the period.

Another mistake is notifying the NPC but not the affected individuals. These are separate duties. The PIC should also avoid relying solely on a general website announcement when individual notification is reasonably possible.

Enterprises should not assume that outsourcing information processing transfers responsibility. A PIC remains accountable for personal information processed on its behalf and should ensure that contracts with processors contain incident-reporting, cooperation, evidence-preservation, and notification provisions.

Conclusion

For a qualifying personal data breach, the Philippine rule is immediate and demanding: the NPC and affected data subjects should generally be notified within 72 hours from the PIC’s knowledge of, or reasonable belief in, the breach. The initial notice may rely on available information, but it must be followed by a fuller report, generally within five days.

Digital enterprises should maintain a tested breach-response plan, designate responsible officers, preserve an accurate discovery timeline, and prepare notification templates in advance. Prompt reporting, accurate communication, evidence preservation, and continuing cooperation with the NPC are the most reliable means of reducing legal and operational exposure.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH