NPC Advisory 2026-02: What Philippine Businesses Must Do When a Data Breach Happens

In June 2026, the National Privacy Commission released Advisory No. 2026-02 — a clarification that tightens and formalises the data breach notification rules that have existed under the Data Privacy Act since 2016 but were inconsistently applied. For most Philippine businesses, this is the first time breach notification requirements have been spelled out with this level of operational specificity.
This guide explains what changed, what it means for your day-to-day operations, and what you need to have in place before an incident happens.
What Advisory 2026-02 Actually Says
The advisory addresses three areas that were previously ambiguous:
1. The 5-calendar-day notification window is non-negotiable.
From the moment a personal information controller (PIC) — that is your business — discovers or is reasonably put on notice of a breach, the clock starts. You have five calendar days to notify the NPC. Not five business days. Not five days from investigation completion. Five calendar days from discovery.
This matters because most organisations previously treated breach notification as something that happened after investigation was complete. Advisory 2026-02 is explicit: initial notification must happen within the window even if the investigation is still ongoing. You file with what you know, then provide a follow-up report.
2. All notifications go through the DBNMS.
The Data Breach Notification Management System (DBNMS) at privacy.gov.ph is now the mandatory channel. Emails, letters, and phone calls to NPC do not satisfy the notification requirement. Your designated Data Privacy Officer (DPO) must have a registered DBNMS account before an incident occurs — not after.
3. Affected individuals must also be notified — directly, in plain language.
Where a breach "may give rise to a real risk of serious harm," your organisation must also notify the individuals whose data was compromised. The advisory specifies that notification must be in plain language (not legal boilerplate), through a channel reasonably likely to reach the individual, and without undue delay after notifying the NPC.
Who Is Required to Comply
Any organisation that processes personal information of Philippine residents — regardless of where the organisation is headquartered — is covered under the DPA and this advisory.
This includes:
- Philippine-registered companies of any size
- Foreign companies with Philippine operations or customers
- Government agencies (separate rules under Circular 2023-01 apply, but Advisory 2026-02 is the baseline)
- Subprocessors and third-party service providers who handle personal data on behalf of a PIC
The advisory does not exempt micro or small enterprises. Size affects how the NPC responds to and penalises breaches, but it does not affect whether you must report.
What Triggers Notification
Not every security incident requires NPC notification. The threshold is a breach that:
- Involves personal information (name, address, contact details, national ID numbers, financial data, health records, etc.)
- Is reasonably likely to give rise to a real risk of harm — including identity theft, fraud, discrimination, or reputational damage — to the data subjects
A test: if the compromised data could be used to impersonate, defraud, or harm someone whose information you hold, you are almost certainly within reporting territory.
Common triggering events in Philippine businesses:
- Ransomware attacks that encrypt or exfiltrate employee or customer records
- Phishing compromises that expose email accounts containing client data
- Lost or stolen laptops containing unencrypted personal data
- Misconfigured cloud storage (S3-style buckets, SharePoint, Google Drive) exposing records publicly
- Insider exfiltration of HR or payroll data
The 5-Day Notification Checklist
When a breach is discovered, your DPO needs to move through these steps within five calendar days:
| Day | Action |
|---|---|
| Day 0 (discovery) | Confirm breach scope, activate incident response plan, preserve logs |
| Day 1–2 | Contain the breach, assess what data was involved, identify affected individuals |
| Day 3–4 | DPO drafts NPC notification via DBNMS; legal and management review |
| Day 5 | Submit DBNMS notification; begin direct notification to affected individuals if harm risk is confirmed |
| Day 15–30 | Submit full investigation report to NPC (follow-up filing) |
If you do not yet have an incident response plan or a registered DBNMS account, those gaps are your first priority — not something to address mid-incident.
What the DBNMS Notification Must Include
The initial DBNMS filing requires:
- Name and contact details of the organisation and DPO
- Date and time of discovery
- Nature of the breach (what happened)
- Categories and approximate number of affected records
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate harm
You will not have all answers on Day 5 if the breach is complex. File what you know and mark fields as preliminary. The follow-up report completes the picture.
Sanctions for Non-Compliance
Advisory 2026-02 reinforces existing DPA penalties, which include:
- Failure to notify NPC within 5 days: up to ₱500,000 per violation
- Failure to notify affected individuals when required: up to ₱2,000,000
- Negligence in safeguarding personal data: 1–3 years imprisonment plus fines up to ₱2,000,000 for responsible officers
Sanctions are assessed per violation, not per incident. A breach that affects 1,000 individuals and triggers both notification failures can result in penalties that quickly exceed the cost of a proper compliance programme.
What Philippine Businesses Should Put in Place Now
If you have not done this yet, do it this week:
-
Register your DPO on DBNMS. Go to privacy.gov.ph and create the account. This takes under 30 minutes and there is no reason not to have it ready.
-
Write a one-page breach response playbook. It does not need to be a 40-page document. It needs to answer: who declares a breach, who notifies the NPC, who notifies affected individuals, and where the DBNMS login is stored.
-
Encrypt laptops and portable storage. Most breach-triggering events in Philippine SMEs involve lost or stolen devices. BitLocker (Windows) and FileVault (macOS) are built into your existing OS licences — there is no cost reason not to use them.
-
Audit cloud storage permissions. Misconfigured SharePoint and Google Drive sharing is the second most common source of reportable incidents. A quarterly permissions audit catches most exposure before it becomes a breach.
-
Brief your department heads. The 5-day window is tight. If a department head discovers an incident on a Friday and does not know to escalate immediately, you may already be non-compliant by Monday.
How This Connects to Your Cloud Infrastructure
The highest-risk surface for most Philippine businesses is their Microsoft 365 or Google Workspace environment — email, file storage, and identity in one place. A compromised account can expose years of personal data in minutes.
Controls that directly reduce breach probability and scope:
- Multi-factor authentication on all user accounts — not SMS OTP (see BSP Circular 1213 on SMS OTP phase-out), but authenticator app or hardware key
- Conditional Access policies in Microsoft Entra ID that restrict sign-in to compliant devices and known locations
- Microsoft Defender for Office 365 or Google Workspace's advanced phishing protection
- Microsoft Purview or Google Vault for data classification and DLP — so you know where personal data lives before an incident
Related Reading
- Zero-Trust Security for Philippine Businesses
- Data Loss Prevention in Microsoft 365
- Conditional Access Policies for Philippine M365 Tenants
- Ransomware Protection for Philippine SMEs
Talk to our Cloud & I.T. team about data privacy compliance


