The National Privacy Commission (NPC) has issued NPC Advisory No. 2026-02 dated 11 May 2026, providing clarifications to Personal Information Controllers (PICs) on requests concerning the notification of affected data subjects following a personal data breach. The Advisory specifically addresses requests for postponement, exemption, alternative means of notification, and extensions for required submissions through the Data Breach Notification Management System (DBNMS).
The Advisory clarifies how PICs should submit and manage requests relating to personal data breach notifications under NPC Circular No. 16-03, on the Personal Data Breach Management. It emphasizes that certain requests cannot be made simultaneously for the same breach. A PIC may not concurrently request an exemption from notifying affected data subjects and either postponement or alternative means of notification. However, requests for postponement and alternative means of notification may be made together.
For purposes of the Advisory, a breach is treated as a single incident when it involves the same affected data subjects, personal data, and nature of the breach. Changes in circumstances, such as an increase in affected individuals or changes in the data elements involved, must be reflected in the full breach report.
The Advisory requires PICs to clearly identify the appropriate grounds for their requests and submit the necessary supporting documents. The NPC will evaluate each request based on the applicable rules, supporting documents, and circumstances of the breach.
Importantly, filing a request through the DBNMS does not suspend the PIC’s existing breach-reporting obligations. Unless the NPC has acted on the request, the PIC must still submit its full breach report to the designated NPC email address, within five (5) days from discovery, together with the other required submissions.
The NPC also makes clear that approval of any request must be expressly issued in writing. The Commission’s silence or inaction cannot be treated as approval, implied consent, or a basis for noncompliance.
Noncompliance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, or relevant NPC orders, resolutions, or decisions may result in administrative fines under NPC Circular No. 2022-01.
PICs should carefully distinguish among the different types of requests available when responding to a personal data breach and ensure that requests are supported by appropriate grounds and documentation. They should also avoid filing mutually exclusive requests for the same incident, as doing so may result in the denial of one or all of the requests.
Most importantly, a pending request should not be treated as a substitute for compliance with the applicable breach-reporting requirements. PICs should continue preparing and submitting the full breach report within the prescribed five-day period unless the NPC has expressly acted otherwise.
Organizations should likewise maintain clear documentation of their breach incidents, requests, supporting documents, and communications with the NPC to ensure that their compliance position can be properly demonstrated.
NPC Advisory No. 2026-02 reinforces that requests concerning data breach notification do not automatically relieve PICs of their existing compliance obligations. The Advisory provides greater clarity on which requests may be made, the documentation required, and the continuing duty to submit the full breach report within the prescribed period. It also emphasizes that only an express written action by the NPC constitutes approval.
PICs should therefore treat DBNMS requests as part of, rather than a replacement for, their broader breach-response and notification obligations under the Data Privacy Act and NPC Circular No. 16-03.
This guide provides a general overview of the above Advisory as of the date of writing and is not intended to constitute comprehensive legal advice or an opinion on the topic. For further details and information, you may coordinate with any GVES Law Partner.
Atty. Beryl Joyce V. Barba is an Associate at GVES Law.

