NPC Clarifies DBNMS Breach Notification Procedures
At a Glance
NPC Advisory No. 2026-02 clarifies how Personal Information Controllers (PICs) should submit breachrelated requests through DBNMS. It also confirms that a pending request does not suspend the PIC’s existing reporting obligations.
On 11 May 2026, the National Privacy Commission (NPC) issued NPC Advisory No. 2026-02, Clarification on the Submission of Personal Data Breach Notification through the Data Breach Notification Management System (DBNMS).
The Advisory clarifies the procedures for requesting postponement, exemption from notifying affected data subjects, alternative means of notification, and extensions for submitting required documents.
More importantly, it reinforces the need for organizations to maintain a disciplined and documented breach management process—not an ad hoc response developed only after an incident occurs.
1. A breach response must be governed—not improvised
Breach-related requests must follow the prescribed process and be supported by appropriate grounds and relevant documentation. Organizations should not rely on informal coordination as a substitute for formally submitting the appropriate request.
The Advisory also clarifies which requests may be submitted together for the same personal data breach incident:
| Requests involving the same incident | Permitted together? |
|---|---|
| Exemption and postponement | No |
| Exemption and alternative notification | No |
| Postponement and alternative notification | Yes |
Organizations should therefore develop a Breach Decision Tree before an incident occurs. This should define notification thresholds, decision-makers, escalation procedures, documentation requirements, and the circumstances under which each type of request may be submitted.
2. Organizations must be “notification-ready”
Submitting a request through the DBNMS does not suspend or remove the PIC’s existing obligations under NPC Circular No. 16-03.
For a personal data breach meeting the mandatory-notification criteria, the NPC and affected data subjects must generally be notified within seventy-two (72) hours from knowledge of, or reasonable belief that, the breach occurred. Notification may initially be based on available information and supplemented as the investigation progresses.
Unless the NPC has acted on the request, the PIC must continue complying with the applicable reporting requirements. The NPC’s inaction cannot be interpreted as approval or used as justification for noncompliance.
To support timely and defensible decisions, organizations should maintain a Breach Response Pack containing:
- DBNMS account information and secure access procedures;
- designated authorized users;
- DPO and incident response team contact details;
- incident assessment and escalation forms;
- notification templates;
- documentation and evidence checklists; and
- internal review and approval protocols.
Security note: Passwords and authentication credentials should remain in an approved secure credential-management system and should not be included in an ordinary shared document.
3. Accountability remains with the PIC
Consistent with the accountability principle under the Data Privacy Act of 2012, engaging external counsel, cybersecurity specialists, or other service providers does not remove the PIC’s responsibility for regulatory compliance.
External advisers may assist with the investigation, assessment, and preparation of reports. However, the PIC remains accountable for making notification decisions, supporting requests submitted to the NPC, and ensuring that its regulatory obligations are fulfilled.
As a sound governance measure, the PIC should retain control over its DBNMS account and regulatory submissions. Organizations should also review their third-party agreements to ensure that they clearly address:
- breach reporting responsibilities;
- escalation and reporting timelines;
- preservation of evidence;
- investigation support;
- coordination with the NPC; and
- assistance in notifying affected data subjects.
Practical next steps
Organizations may use the Advisory as an opportunity to:
- review their breach management policies and procedures;
- develop or validate their Breach Decision Tree;
- confirm DBNMS access and authorized users;
- prepare notification templates and document checklists;
- review breach-related provisions in third-party agreements; and
- conduct a breach simulation or tabletop exercise.
Continuing the conversation
RT&Co. can provide guidance on the implications of NPC Advisory No. 2026-02 and support your organization in reviewing its breach management policies, decision-making procedures, notification templates, third-party obligations, and DBNMS submissions.
For further questions or assistance in assessing your organization’s breach response readiness, please contact:
Author

Ceasar Octavius “Boboy” Parlade
Managing Partner
cparlade@reyestacandong.com

Kate S. Cabañero
Senior Manager
kscabanero@reyestacandong.com

Mariell G. Peñaroyo
Associate Manager
mpenaroyo@reyestacandong.com
Author

Ceasar Octavius “Boboy” Parlade
Managing Partner
cparlade@reyestacandong.com

Kate S. Cabañero
Senior Manager
kscabanero@reyestacandong.com

Mariell G. Peñaroyo
Associate Manager
mpenaroyo@reyestacandong.com
Related official references
- NPC Advisory No. 2026-02
- NPC Circular No. 16-03: Personal Data Breach Management
- NPC Breach Reporting page
- Republic Act No. 10173: Data Privacy Act of 2012
- NPC Circular No. 2022-01: Guidelines on Administrative Fines
Informational Disclaimer
This material is intended for general informational purposes only and should not be considered legal advice. The appropriate response to a personal data breach depends on the specific facts and circumstances of each incident.
Contact us today. We’ll schedule a complimentary assessment of your company.
Let RT&Co help your business. Send your request for a proposal of services here.