NPC Clarifies DBNMS Breach Notification Procedures

Share this article

At a Glance

NPC Advisory No. 2026-02 clarifies how Personal Information Controllers (PICs) should submit breachrelated requests through DBNMS. It also confirms that a pending request does not suspend the PIC’s existing reporting obligations.

On 11 May 2026, the National Privacy Commission (NPC) issued NPC Advisory No. 2026-02, Clarification on the Submission of Personal Data Breach Notification through the Data Breach Notification Management  System (DBNMS).

The Advisory clarifies the procedures for requesting postponement, exemption from notifying affected data subjects, alternative means of notification, and extensions for submitting required documents.

More importantly, it reinforces the need for organizations to maintain a disciplined and documented breach management process—not an ad hoc response developed only after an incident occurs.

1. A breach response must be governed—not improvised

Breach-related requests must follow the prescribed process and be supported by appropriate grounds and relevant documentation. Organizations should not rely on informal coordination as a substitute for formally submitting the appropriate request.

The Advisory also clarifies which requests may be submitted together for the same personal data breach incident:

Requests involving the same incidentPermitted together?
Exemption and postponementNo
Exemption and alternative notificationNo
Postponement and alternative notificationYes

Organizations should therefore develop a Breach Decision Tree before an incident occurs. This should define notification thresholds, decision-makers, escalation procedures, documentation requirements, and the circumstances under which each type of request may be submitted.

2. Organizations must be “notification-ready”

Submitting a request through the DBNMS does not suspend or remove the PIC’s existing obligations under NPC Circular No. 16-03.

For a personal data breach meeting the mandatory-notification criteria, the NPC and affected data subjects must generally be notified within seventy-two (72) hours from knowledge of, or reasonable belief that, the breach occurred. Notification may initially be based on available information and supplemented as the investigation progresses.

Unless the NPC has acted on the request, the PIC must continue complying with the applicable reporting requirements. The NPC’s inaction cannot be interpreted as approval or used as justification for noncompliance.

To support timely and defensible decisions, organizations should maintain a Breach Response Pack containing:

  • DBNMS account information and secure access procedures;
  • designated authorized users;
  • DPO and incident response team contact details;
  • incident assessment and escalation forms;
  • notification templates;
  • documentation and evidence checklists; and
  • internal review and approval protocols.

Security note: Passwords and authentication credentials should remain in an approved secure credential-management system and should not be included in an ordinary shared document.

3. Accountability remains with the PIC

Consistent with the accountability principle under the Data Privacy Act of 2012, engaging external counsel, cybersecurity specialists, or other service providers does not remove the PIC’s responsibility for regulatory compliance.

External advisers may assist with the investigation, assessment, and preparation of reports. However, the PIC remains accountable for making notification decisions, supporting requests submitted to the NPC, and ensuring that its regulatory obligations are fulfilled.

As a sound governance measure, the PIC should retain control over its DBNMS account and regulatory submissions. Organizations should also review their third-party agreements to ensure that they clearly address:

  • breach reporting responsibilities;
  • escalation and reporting timelines;
  • preservation of evidence;
  • investigation support;
  • coordination with the NPC; and
  • assistance in notifying affected data subjects.

Practical next steps

Organizations may use the Advisory as an opportunity to:

  • review their breach management policies and procedures;
  • develop or validate their Breach Decision Tree;
  • confirm DBNMS access and authorized users;
  • prepare notification templates and document checklists;
  • review breach-related provisions in third-party agreements; and
  • conduct a breach simulation or tabletop exercise.

Continuing the conversation

RT&Co. can provide guidance on the implications of NPC Advisory No. 2026-02 and support your organization in reviewing its breach management policies, decision-making procedures, notification templates, third-party obligations, and DBNMS submissions.

For further questions or assistance in assessing your organization’s breach response readiness, please contact:

Author

Ceasar Octavius “Boboy” Parlade

Managing Partner
cparlade@reyestacandong.com

Kate S. Cabañero

Senior Manager
kscabanero@reyestacandong.com

Mariell G. Peñaroyo

Associate Manager
mpenaroyo@reyestacandong.com

Author

Ceasar Octavius “Boboy” Parlade

Managing Partner
cparlade@reyestacandong.com

Kate S. Cabañero

Senior Manager
kscabanero@reyestacandong.com

Mariell G. Peñaroyo

Associate Manager
mpenaroyo@reyestacandong.com

Related official references

Informational Disclaimer

This material is intended for general informational purposes only and should not be considered legal advice. The appropriate response to a personal data breach depends on the specific facts and circumstances of each incident.

Contact us today. We’ll schedule a complimentary assessment of your company.

Contact us

Let RT&Co help your business. Send your request for a proposal of services here.

Submit RFP