Law / Philippines

Data Privacy Act of 2012, breach notification

Republic Act No. 10173 (2012), Section 20(f)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 15 August 2012.

A breach notification rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app that reasonably believes sensitive personal information or identity-fraud-enabling information of an individual in the Philippines has been acquired by an unauthorized person, in a way likely to cause serious harm, must promptly notify the National Privacy Commission and the affected individuals.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 20(f) requires a personal information controller to promptly notify the National Privacy Commission and affected data subjects when sensitive personal information, or other information that may enable identity fraud, is reasonably believed to have been acquired by an unauthorized person, where the controller or the Commission believes the acquisition is likely to give rise to a real risk of serious harm.

The Act itself sets no fixed numeric deadline; a fixed 72-hour operational deadline is commonly cited as set by a subordinate NPC Circular, which was not read.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web

Read the law

National Privacy Commission's official HTML reproduction of the Act

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app