Law note · Philippines
Data Privacy Act of 2012, breach notification
cite Republic Act No. 10173 (2012), Section 20(f)
stage IN FORCE in force since 2012-08-15
kind Breach notification
binds public and private bodies
reviewed 2026-08-29
What it requires
- An app that reasonably believes sensitive personal information or identity-fraud-enabling information of an individual in the Philippines has been acquired by an unauthorized person, in a way likely to cause serious harm, must promptly notify the National Privacy Commission and the affected individuals.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_web
What we found
Section 20(f) requires a personal information controller to promptly notify the National Privacy Commission and affected data subjects when sensitive personal information, or other information that may enable identity fraud, is reasonably believed to have been acquired by an unauthorized person, where the controller or the Commission believes the acquisition is likely to give rise to a real risk of serious harm.
The Act itself sets no fixed numeric deadline; a fixed 72-hour operational deadline is commonly cited as set by a subordinate NPC Circular, which was not read this pass.