Law note · Philippines

Data Privacy Act of 2012, breach notification

cite Republic Act No. 10173 (2012), Section 20(f) stage IN FORCE in force since 2012-08-15 kind Breach notification binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that reasonably believes sensitive personal information or identity-fraud-enabling information of an individual in the Philippines has been acquired by an unauthorized person, in a way likely to cause serious harm, must promptly notify the National Privacy Commission and the affected individuals.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web

What we found

Section 20(f) requires a personal information controller to promptly notify the National Privacy Commission and affected data subjects when sensitive personal information, or other information that may enable identity fraud, is reasonably believed to have been acquired by an unauthorized person, where the controller or the Commission believes the acquisition is likely to give rise to a real risk of serious harm.

The Act itself sets no fixed numeric deadline; a fixed 72-hour operational deadline is commonly cited as set by a subordinate NPC Circular, which was not read this pass.

← Back to the example  ·  Lint your app →