RT&CO. ADVISORY COMPASS • COMPLIANCE UPDATE
NPC Clarifies DBNMS Breach Notification Procedures
At a Glance
NPC Advisory No. 2026-02 clarifies how Personal Information Controllers (PICs) should submit breach-related requests through DBNMS. It also confirms that a pending request does not suspend the PIC’s existing reporting obligations.
On 11 May 2026, the National Privacy Commission (NPC) issued NPC Advisory No. 2026-02, Clarification on the Submission of Personal Data Breach Notification through the Data Breach Notification Management System (DBNMS).
The Advisory clarifies the procedures for requesting postponement, exemption from notifying affected data subjects, alternative means of notification, and extensions for submitting required documents.
More importantly, the Advisory highlights the value of having a disciplined and documented breach management process in place before an incident occurs, rather than developing the response only after a breach.
1. GOVERN THE RESPONSE
A breach response must be governed—not improvised
Breach-related requests must follow the prescribed process and be supported by appropriate grounds and relevant documentation. Organizations should not rely on informal coordination as a substitute for formally submitting the appropriate request.
The Advisory also clarifies which requests may be submitted together for the same personal data breach incident:
| Requests involving the same incident | Permitted together? |
|---|---|
| Exemption and postponement | × |
| Exemption and alternative notification | × |
| Postponement and alternative notification | ✓ |
Organizations should therefore develop a Breach Decision Tree before an incident occurs. This should define notification thresholds, decision-makers, escalation procedures, documentation requirements, and the circumstances under which each type of request may be submitted.
2. PREPARE IN ADVANCE
Organizations must be “notification-ready”
Submitting a request through the DBNMS does not suspend the PIC’s obligations under NPC Circular No. 16-03. Pending requests do not stop the compliance clock, and the NPC’s inaction cannot be treated as approval or justification for noncompliance.
Organizations should therefore have clear escalation procedures, assigned decision-makers, secure DBNMS access, and ready-to-use notification templates to support timely and defensible action during a breach.
3. RETAIN ACCOUNTABILITY
Accountability remains with the PIC
Engaging external counsel, cybersecurity specialists, or other service providers does not relieve the PIC of its obligations under the Data Privacy Act of 2012 and applicable NPC issuances. Although these external advisers may assist with the investigation, assessment, and preparation of reports, the PIC remains responsible for making notification decisions, substantiating requests submitted to the NPC, and ensuring compliance with applicable regulatory requirements.
As a sound governance measure, the PIC should maintain appropriate oversight and control over its DBNMS account and regulatory submissions.
- breach reporting responsibilities;
- escalation and reporting timelines;
- preservation of evidence;
- investigation support;
- coordination with the NPC; and
- assistance in notifying affected data subjects.
Practical next steps
✓Review breach management policies
✓Confirm DBNMS access and users
✓Review third-party provisions
✓Validate the Breach Decision Tree
✓Prepare notification templates
✓Conduct a tabletop exercise
Continuing the conversation
RT&Co. can provide guidance on the implications of NPC Advisory No. 2026-02 and support your organization in reviewing its breach management policies, decision-making procedures, notification templates, third-party obligations, and DBNMS submissions.
For further questions or assistance in assessing your organization’s breach response readiness, please contact:
Author

Caesar “Boboy” Parlade
Managing Partner
cparlade@reyestacandong.com

Kate S. Cabañero
Senior Manager
kscabanero@reyestacandong.com

Mariell G. Peñaroyo
Associate Manager
mgpenaroyo@reyestacandong.com
Author
Related official references
- NPC Advisory No. 2026-02
- NPC Circular No. 16-03: Personal Data Breach Management
- NPC Breach Reporting page
- Republic Act No. 10173: Data Privacy Act of 2012
- NPC Circular No. 2022-01: Guidelines on Administrative Fines
Informational Disclaimer
This material is intended for general informational purposes only and should not be considered legal advice. The appropriate response to a personal data breach depends on the specific facts and circumstances of each incident.
Contact us today. We’ll schedule a complimentary assessment of your company.
Let RT&Co help your business. Send your request for a proposal of services here.