On May 11, the National Privacy Commission (NPC) issued NPC Advisory No. 2026 – 02 with the subject “Clarification on the Submission of Personal Data Breach NotificationOn May 11, the National Privacy Commission (NPC) issued NPC Advisory No. 2026 – 02 with the subject “Clarification on the Submission of Personal Data Breach Notification

On making requests for exemption, postponement, or to use alternative means of notification

2026/06/03 00:01
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

On May 11, the National Privacy Commission (NPC) issued NPC Advisory No. 2026 – 02 with the subject “Clarification on the Submission of Personal Data Breach Notification Through Data Breach Notification Management System.”

Under Section 20(f) of Republic Act No. 10173 (the Data Privacy Act), personal information controllers (PICs) are obligated to quickly notify the NPC and data subjects who are affected when an unauthorized person acquires “sensitive personal information or other information that may, under the circumstances, be used to enable identity fraud” and the PIC or NPC believes that the acquisition “is likely to give rise to a real risk of serious harm to any affected data subject.”

The provision states that PICs “shall at least describe the nature of the breach, the sensitive personal information possibly involved, and the measures taken by the entity to address the breach.” Further, the provision also lists the acceptable reasons for delay: determining the breach’s scope, preventing additional disclosures, or restoring “reasonable integrity to the information and communications system.”

In 2016, pursuant to this provision in the Data Privacy Act, as noted in one of the preambular clauses, the NPC issued NPC Circular 16 – 03 regarding Personal Data Breach Management. Rule V of the Circular lays out, among others, the conditions that would trigger notification (Sec. 11), the guidelines on determining if there is a necessity to notify (Sec. 13), who is obligated to make such a notification (Sec. 15), the process and form of notification to the NPC (Sec. 17) and data subjects (Sec. 18), and some factors to consider in exempting a personal information controller from notification (Sec. 19).

Section 18 of the Circular requires that, when the PIC or personal information processor has knowledge or even a reasonable belief of the existence of a data breach, the notification of the data subjects must be done within 72 hours. The Circular provides that exemptions from notification requirements or postponements should be requested by the PIC from the NPC. (Sec. 18(B)). Further, the PIC may also ask the NPC for approval “to use alternative means of notification, such as through public communication or any similar measure through which the data subjects are informed in an equally effective manner[.]” (Sec. 18(D)).

Through the recent Advisory, the NPC has made clarifications to the procedure for submitting requests for postponement, exemption, the use of alternate means for notifying data subjects, and extension to submit documents required by the Circular (Sec. 2).

PICs are expressly prohibited from simultaneously making two pairs of requests: first, an exemption to notify affected data subjects request alongside a postponement of the notification request, or, second, an exemption to notify request and an alternative means of notification request (Sec. 2(A)). Intuitively, this can be explained by the fact that a request for postponement and/or alternative means of notification may presuppose that the PIC is obligated to notify in the first place. Thus, it may be contradictory to a request for exemption.

Meanwhile, the same provision permits concurrent requests for postponement and to use alternative means of notification. Compliance with these rules is important as the provision also states that invoking mutually exclusive requests may lead to any or all requests being denied.

In addition, the Advisory provides that requests must contain the supporting documents and “clearly state the most appropriate grounds for the justification of its requests.” (Sec. 2(B)).

It is further clarified by the Advisory that submitting “any request in relation to personal data breach notification to the Commission through the Data Breach Notification Management System (DBNMS) shall not relieve the PIC of its obligation pursuant to NPC Circular No. 16-03.” (Sec. 2(C)). In addition, inaction by the NPC is not equivalent to consent or approval of any request, which is required to be express and in writing the Commission. (Sec. 2(D)). In other words, if a PIC is unable to secure the approval of the NPC regarding any of its requests, its obligations under the Circular are still in force and the mere filing of a request does not stay such.

Ultimately, this Advisory not only clarifies but also tightens the procedure for Personal Data Breach Notification as provided by the Circular. Citing NPC Circular No. 2022 – 01, the Advisory also reiterates the possibility of administrative fines for violations of the Data Privacy Act, its Implementing Rules and Regulations and certain issuances of the NPC. (Sec. 2(E)).

The views and opinions expressed in this article are those of the author. This article is for general informational and educational purposes only and not offered as and does not constitute legal advice or legal opinion.

Ignacio Lorenzo D.c. Villareal is an associate of the Litigation and Dispute Resolution Department of the Angara Abello Concepcion Regala & Cruz Law Offices (ACCRALAW).

(632) 8830-800

ldvillareal@accralaw.com

시장 기회
Non-Playable Coin 로고
Non-Playable Coin 가격(NPC)
$0.005283
$0.005283$0.005283
+0.64%
USD
Non-Playable Coin (NPC) 실시간 가격 차트

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel