WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Data Privacy Act of 2012 — personal data breach notification

PH DPA s. 20(f)

Philippines · September 8, 2012 (Act); NPC Circular 16-03 issued December 15, 2016

The statutory trigger is narrow and specific: notification is owed where sensitive personal information, or information that could enable identity fraud, is reasonably believed to have been acquired by an unauthorized person AND the acquisition is likely to give rise to a real risk of serious harm. Where it applies, NPC Circular 16-03 gives 72 hours from knowledge or reasonable belief to notify BOTH the National Privacy Commission and the affected data subjects — the Philippines does not split the two onto different clocks or different thresholds the way the GDPR does. Delay is permitted only to determine scope, prevent further disclosure, or restore system integrity, and is not permitted at all where at least 100 data subjects are affected or where disclosing the sensitive personal information will harm the data subject.

Republic Act No. 10173, s. 20(f); NPC Circular 16-03 on Personal Data Breach ManagementRead regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.