RT&CO. ADVISORY COMPASS • COMPLIANCE UPDATE

NPC Clarifies DBNMS Breach Notification Procedures

Share this article

At a Glance

NPC Advisory No. 2026-02 clarifies how Personal Information Controllers (PICs) should submit breach-related requests through DBNMS. It also confirms that a pending request does not suspend the PIC’s existing reporting obligations.

On 11 May 2026, the National Privacy Commission (NPC) issued NPC Advisory No. 2026-02, Clarification on the Submission of Personal Data Breach Notification through the Data Breach Notification Management  System (DBNMS).

The Advisory clarifies the procedures for requesting postponement, exemption from notifying affected data subjects, alternative means of notification, and extensions for submitting required documents.

More importantly, the Advisory highlights the value of having a disciplined and documented breach management process in place before an incident occurs, rather than developing the response only after a breach.

1. GOVERN THE RESPONSE

A breach response must be governed—not improvised

Breach-related requests must follow the prescribed process and be supported by appropriate grounds and relevant documentation. Organizations should not rely on informal coordination as a substitute for formally submitting the appropriate request.

The Advisory also clarifies which requests may be submitted together for the same personal data breach incident:

Requests involving the same incidentPermitted together?
Exemption and postponement×
Exemption and alternative notification×
Postponement and alternative notification

Organizations should therefore develop a Breach Decision Tree before an incident occurs. This should define notification thresholds, decision-makers, escalation procedures, documentation requirements, and the circumstances under which each type of request may be submitted.

2. PREPARE IN ADVANCE

Organizations must be “notification-ready”

Submitting a request through the DBNMS does not suspend the PIC’s obligations under NPC Circular No. 16-03. Pending requests do not stop the compliance clock, and the NPC’s inaction cannot be treated as approval or justification for noncompliance.

Organizations should therefore have clear escalation procedures, assigned decision-makers, secure DBNMS access, and ready-to-use notification templates to support timely and defensible action during a breach.

3. RETAIN ACCOUNTABILITY

Accountability remains with the PIC

Engaging external counsel, cybersecurity specialists, or other service providers does not relieve the PIC of its obligations under the Data Privacy Act of 2012 and applicable NPC issuances. Although these external advisers may assist with the investigation, assessment, and preparation of reports, the PIC remains responsible for making notification decisions, substantiating requests submitted to the NPC, and ensuring compliance with applicable regulatory requirements.

As a sound governance measure, the PIC should maintain appropriate oversight and control over its DBNMS account and regulatory submissions.

  • breach reporting responsibilities;
  • escalation and reporting timelines;
  • preservation of evidence;
  • investigation support;
  • coordination with the NPC; and
  • assistance in notifying affected data subjects.

Practical next steps

Review breach management policies

Confirm DBNMS access and users

Review third-party provisions

Validate the Breach Decision Tree

Prepare notification templates

Conduct a tabletop exercise

Continuing the conversation

RT&Co. can provide guidance on the implications of NPC Advisory No. 2026-02 and support your organization in reviewing its breach management policies, decision-making procedures, notification templates, third-party obligations, and DBNMS submissions.

For further questions or assistance in assessing your organization’s breach response readiness, please contact:

Author

Caesar “Boboy” Parlade

Managing Partner
cparlade@reyestacandong.com

Kate S. Cabañero

Senior Manager
kscabanero@reyestacandong.com

Mariell G. Peñaroyo

Associate Manager
mgpenaroyo@reyestacandong.com

Author

Caesar “Boboy” Parlade

Kate S. Cabañero

Mariell G. Peñaroyo

Related official references

Informational Disclaimer

This material is intended for general informational purposes only and should not be considered legal advice. The appropriate response to a personal data breach depends on the specific facts and circumstances of each incident.

Contact us today. We’ll schedule a complimentary assessment of your company.

Contact us

Let RT&Co help your business. Send your request for a proposal of services here.

Submit RFP