30 September 2026
In brief
The National Privacy Commission (NPC) issued Advisory No. 2026-03 (“Advisory”), granting covered personal information controllers (PICs) and personal information processors (PIPs) an extended period to submit their 2025 Annual Security Incident Reports (ASIRs) until 10 November 2026. The Advisory was issued in response to requests from PICs and PIPs seeking additional time to complete their submissions beyond the original deadline.
PICs and PIPs that have not yet filed their 2025 ASIRs, but are required to do so, should take note of the extended filing period and ensure that their reports are submitted through the Data Breach Notification Management System (DBNMS) on or before the 10 November 2026 deadline.
Key takeaways
- The NPC has extended the deadline for the submission of 2025 ASIRs until 10 November 2026.
- The 2025 ASIR covers security incidents and personal data breaches that occurred during the period of 1 January 2025 to 31 December 2025.
- PICs and PIPs must submit their 2025 ASIRs through the DBNMS. Submissions made through other channels will not be considered valid.
- The NPC clarified that PICs and PIPs are still required to submit an ASIR even if no security incidents or personal data breaches occurred during the reporting period.
In more detail
The requirement to submit ASIRs forms part of the reporting framework established under Philippine data privacy regulations, which require covered PICs and PIPs to document security incidents and personal data breaches and submit an annual report to the NPC.
As the original deadline for the submission of 2025 ASIRs had already lapsed, the NPC issued the Advisory in response to requests from covered PICs and PIPs seeking additional time to comply. In this regard, the Advisory clarifies the scope of the extension, the reporting period, and the manner by which 2025 ASIRs must be submitted, among others.
Scope and coverage
The Advisory applies to all PICs and PIPs covered by NPC Circular No. 16-03 in relation to Section 4 of the Data Privacy Act of 2012. In particular, it is intended to benefit covered organizations that have not yet submitted their 2025 ASIRs.
The 2025 ASIR should cover security incidents and personal data breaches occurring during the period 1 January 2025 to 31 December 2025. The Advisory reiterates the distinction between security incidents and personal data breaches under existing regulations while requiring covered organizations to provide the information prescribed under the applicable reporting framework.
Extended filing deadline
Under the Advisory, the NPC has reopened the filing period for 2025 ASIRs and extended the submission deadline until 10 November 2026.
Contents of the ASIR
The ASIR must contain the information required under the applicable NPC reporting framework, including the number of security incidents and personal data breaches encountered during the reporting period. Such incidents must be classified according to their impact on the availability, integrity, and confidentiality of personal data, as applicable. The specific information required to be disclosed may be accessed through the NPC's DBNMS.
Submission via the DBNMS
The Advisory reinforces that 2025 ASIRs must be submitted exclusively through the DBNMS. The NPC expressly reiterates that submissions made through email, personal filing, ordinary mail, courier services, or any other channel will not be considered valid for compliance purposes.
Reporting requirement even in the absence of security incidents
Importantly, the Advisory confirms that covered PICs and PIPs must submit an ASIR even if they did not experience any security incident or personal data breach during the reporting period. In such cases, organizations should indicate zero (0) incidents in the relevant section of the report.
Failure to submit
Failure to submit the required 2025 ASIR constitutes non-compliance with NPC requirements and may result in the issuance of a compliance order directing the organization to file the required report. Continued non-compliance with such an order may expose the organization to administrative penalties of up to PHP 50,000 (approximately USD 800).
How this affects your business
The Advisory provides organizations that have not yet submitted their 2025 ASIRs with an additional opportunity to comply with their reporting obligations under Philippine data privacy regulations. Organizations subject to the annual reporting requirement should review their incident records for the 2025 reporting period, verify that all relevant information has been properly documented, and ensure that the necessary preparations are completed well ahead of the extended deadline.
The extension may also be relevant to service providers and processors that support compliance and reporting activities on behalf of client organizations. Given that submissions must be made exclusively through the DBNMS, affected organizations should confirm that they have access to the platform and that the relevant stakeholders are prepared to complete the filing process on or before 10 November 2026.
For further information on how this development may affect your organization, please feel free to reach out to our team in Quisumbing Torres, and we will be pleased to assist.