[{"data":1,"prerenderedAt":479},["ShallowReactive",2],{"insights-index":3},[4,176,309],{"id":5,"title":6,"author":7,"body":8,"category":159,"date":160,"description":161,"draft":162,"extension":163,"legalContent":164,"meta":165,"navigation":164,"path":166,"readingMinutes":167,"seo":168,"stem":169,"tags":170,"updated":174,"__hash__":175},"insights\u002Finsights\u002Fthe-72-hour-breach-clock.md","What the 72-hour breach clock actually starts from","Jotham Mosuela Hernandez",{"type":9,"value":10,"toc":150},"minimark",[11,15,20,28,31,34,38,41,66,69,72,76,112,115,119,122,126,129,147],[12,13,14],"p",{},"Most organizations know there is a 72-hour deadline. Fewer know what starts it,\nand that is where the failures happen.",[16,17,19],"h2",{"id":18},"it-starts-from-belief-not-proof","It starts from belief, not proof",[12,21,22,23,27],{},"The clock begins at ",[24,25,26],"strong",{},"knowledge or reasonable belief"," that a notifiable personal\ndata breach has occurred. Not at confirmation. Not when the investigation\nconcludes. Not when the forensic report lands.",[12,29,30],{},"That distinction decides most cases. An organization that spends four days\ncarefully establishing the facts before notifying has already missed the\ndeadline — and will have to explain a delay that felt, internally, like\ndiligence.",[12,32,33],{},"If you reasonably believe a notifiable breach has happened, the obligation is\nlive. You notify on what you know, and you supplement as you learn more.",[16,35,37],{"id":36},"notifiable-is-a-three-part-test","Notifiable is a three-part test",[12,39,40],{},"Not every incident is notifiable. All three conditions have to be present:",[42,43,44,52,59],"ol",{},[45,46,47,48,51],"li",{},"The breach involves ",[24,49,50],{},"sensitive personal information",", or information that\ncould be used to enable identity fraud",[45,53,54,55,58],{},"There is ",[24,56,57],{},"reason to believe"," the information was acquired by an unauthorised\nperson",[45,60,61,62,65],{},"The acquisition is ",[24,63,64],{},"likely to give rise to a real risk of serious harm"," to\nthe affected data subjects",[12,67,68],{},"A laptop lost in a locked bag with full-disk encryption and no evidence of access\nmay well fail the second test. An exposed database of borrower records fails\nnone of them.",[12,70,71],{},"The point of running the test is that you document having run it. An\norganization that decided not to notify and can show the reasoning is in a very\ndifferent position from one that simply did not think about it.",[16,73,75],{"id":74},"two-deadlines-not-one","Two deadlines, not one",[77,78,79,92],"table",{},[80,81,82],"thead",{},[83,84,85,89],"tr",{},[86,87,88],"th",{},"Obligation",[86,90,91],{},"Deadline",[93,94,95,104],"tbody",{},[83,96,97,101],{},[98,99,100],"td",{},"Notify the NPC and affected data subjects",[98,102,103],{},"72 hours from knowledge or reasonable belief",[83,105,106,109],{},[98,107,108],{},"Submit the full report through the DBNMS portal",[98,110,111],{},"5 days from discovery",[12,113,114],{},"And if you are in a regulated sector, there may be a third. Notifying the\nNational Privacy Commission does not discharge a separate obligation to notify a\nsector regulator, and the two deadlines are rarely the same.",[16,116,118],{"id":117},"concealment-is-a-separate-offense","Concealment is a separate offense",[12,120,121],{},"Deciding not to notify because notifying looks bad is not a strategy. Concealing\na breach is its own criminal offense under the Data Privacy Act, carrying\nimprisonment and a fine — entirely separately from whatever the underlying breach\nattracts.",[16,123,125],{"id":124},"what-actually-makes-the-deadline-achievable","What actually makes the deadline achievable",[12,127,128],{},"Nothing about 72 hours is difficult if the work was done beforehand. What makes\nit impossible is starting from nothing at 2am:",[130,131,132,135,138,141,144],"ul",{},[45,133,134],{},"A named response team, with deputies, who know they are on it",[45,136,137],{},"A written notifiability test someone can apply under pressure",[45,139,140],{},"Draft notification templates for the NPC and for data subjects",[45,142,143],{},"A current record of processing, so you can say what data was involved",[45,145,146],{},"At least one tabletop exercise, so the first time you run the plan is not live",[12,148,149],{},"A breach response plan that has never been exercised is not a tested plan, and an\naudit will say so.",{"title":151,"searchDepth":152,"depth":152,"links":153},"",2,[154,155,156,157,158],{"id":18,"depth":152,"text":19},{"id":36,"depth":152,"text":37},{"id":74,"depth":152,"text":75},{"id":117,"depth":152,"text":118},{"id":124,"depth":152,"text":125},"data-privacy","2026-07-28","The most common breach-notification mistake in the Philippines is not lateness. It is misreading when the clock starts.",false,"md",true,{},"\u002Finsights\u002Fthe-72-hour-breach-clock",4,{"title":6,"description":161},"insights\u002Fthe-72-hour-breach-clock",[171,172,173],"breach","NPC","incident response",null,"0vBJAyC3cfPwNbJEIF3B2UwE3-U_2FtRk8u5VeJ2ReM",{"id":177,"title":178,"author":7,"body":179,"category":159,"date":298,"description":299,"draft":162,"extension":163,"legalContent":164,"meta":300,"navigation":164,"path":301,"readingMinutes":302,"seo":303,"stem":304,"tags":305,"updated":174,"__hash__":308},"insights\u002Finsights\u002Fdoes-a-dpo-need-certification.md","Does a Data Protection Officer need a certification?",{"type":9,"value":180,"toc":291},[181,188,191,195,202,213,217,220,223,227,230,256,260,267,270,274,277],[12,182,183,184,187],{},"Short answer: ",[24,185,186],{},"no",". There is no certification, license or accreditation that an\nindividual must hold to act as a Data Protection Officer in the Philippines.",[12,189,190],{},"This gets asked constantly, usually by an organization that has been quoted a\nprice for one.",[16,192,194],{"id":193},"what-the-rule-actually-says","What the rule actually says",[12,196,197,198,201],{},"NPC Circular 2023-02 establishes the Data Privacy Competency Program. It is worth\nreading the relevant part carefully, because it says the opposite of what people\nassume: completing a course or examination under the program is ",[24,199,200],{},"in no case"," a\nprofessional certification, and no certification is necessary to act as a data\nprivacy professional — including as a DPO.",[12,203,204,205,208,209,212],{},"The Commission accredits ",[24,206,207],{},"training providers",". It does not license\n",[24,210,211],{},"individuals",".",[16,214,216],{"id":215},"why-the-confusion-is-profitable","Why the confusion is profitable",[12,218,219],{},"Because \"NPC-accredited\" is true of the provider and gets read as true of the\ngraduate. A private credential from an accredited trainer is a private\ncredential. It may represent real learning. It is not a government license, and\ndescribing it as one is a misrepresentation.",[12,221,222],{},"If a vendor tells you your DPO must be certified before they can be designated,\nthat vendor is either mistaken or selling you something.",[16,224,226],{"id":225},"what-the-role-does-require","What the role does require",[12,228,229],{},"Competence is still required — it is just not evidenced by a card. NPC Advisory\n2017-01 is concerned with matters that actually determine whether the role\nfunctions:",[130,231,232,238,244,250],{},[45,233,234,237],{},[24,235,236],{},"Independence."," The DPO must be able to report without a conflict of\ninterest, and must not hold a role that determines the purposes and means of\nthe processing they supervise. This is why the head of IT or the head of\nmarketing is usually the wrong choice.",[45,239,240,243],{},[24,241,242],{},"Resources."," A designation with no time, no budget and no access to\nleadership is a designation on paper.",[45,245,246,249],{},[24,247,248],{},"Accessibility."," The DPO must be reachable — by data subjects and by the\nCommission — at a dedicated address that is not a personal or general-purpose\nmailbox.",[45,251,252,255],{},[24,253,254],{},"Registration."," The designation itself is registered with the NPC, within 20\ndays of taking effect.",[16,257,259],{"id":258},"can-the-role-be-outsourced","Can the role be outsourced?",[12,261,262,263,266],{},"Yes, with conditions. Where the DPO function is outsourced, NPC Advisory 2017-01\nexpects the engagement to run for ",[24,264,265],{},"at least two years",", so the function is\nstable rather than rotating. That is a regulatory requirement, not a vendor\npreference — and it is why credible outsourced DPO arrangements carry a\n24-month minimum term.",[12,268,269],{},"The defensible structure is: the provider is engaged on a term of at least two\nyears, a named individual at the provider is designated as DPO, and the\norganization separately designates an internal Compliance Officer for Privacy as\nthe day-to-day point of contact.",[16,271,273],{"id":272},"what-to-ask-instead","What to ask instead",[12,275,276],{},"Not \"are you certified?\" but:",[130,278,279,282,285,288],{},[45,280,281],{},"Who specifically will be designated, by name?",[45,283,284],{},"What conflicts do they have with our systems and vendors?",[45,286,287],{},"How many hours a month, and what happens when there is an incident?",[45,289,290],{},"What happens at the end of the term — how does the designation transfer?",{"title":151,"searchDepth":152,"depth":152,"links":292},[293,294,295,296,297],{"id":193,"depth":152,"text":194},{"id":215,"depth":152,"text":216},{"id":225,"depth":152,"text":226},{"id":258,"depth":152,"text":259},{"id":272,"depth":152,"text":273},"2026-07-26","No. And anyone selling you an \"NPC license\" for a person is selling something that does not exist.",{},"\u002Finsights\u002Fdoes-a-dpo-need-certification",3,{"title":178,"description":299},"insights\u002Fdoes-a-dpo-need-certification",[306,172,307],"DPO","training","vL1kF1zdY4p_KRs1XY79oF1NbxCycy-QNTMzWJkmSYE",{"id":310,"title":311,"author":7,"body":312,"category":159,"date":469,"description":470,"draft":162,"extension":163,"legalContent":164,"meta":471,"navigation":164,"path":472,"readingMinutes":167,"seo":473,"stem":474,"tags":475,"updated":174,"__hash__":478},"insights\u002Finsights\u002Fa-privacy-manual-is-not-a-program.md","A Privacy Manual is not a compliance program",{"type":9,"value":313,"toc":462},[314,317,320,323,327,330,333,337,340,372,375,378,382,389,397,401,404,411,414,418,421,459],[12,315,316],{},"There is a particular failure mode we see often enough that it is worth naming.",[12,318,319],{},"An organization becomes aware of the Data Privacy Act. It buys a Privacy Manual\nfrom a template vendor. The manual arrives, it is signed, it goes into a folder,\nand nothing else happens.",[12,321,322],{},"Two years later, that folder is a problem.",[16,324,326],{"id":325},"why-it-is-worse-than-nothing","Why it is worse than nothing",[12,328,329],{},"An organization that never engaged with the Act at all can at least argue it did\nnot understand its obligations. An organization holding a signed, dated Privacy\nManual cannot. The manual is documentary evidence that you knew what was\nrequired — and, since nothing in it was implemented, that you chose not to do it.",[12,331,332],{},"You have not bought compliance. You have bought an exhibit.",[16,334,336],{"id":335},"what-the-commission-actually-looks-for","What the Commission actually looks for",[12,338,339],{},"The National Privacy Commission expects an organization to be able to\ndemonstrate five things:",[42,341,342,348,355,361,366],{},[45,343,344,345],{},"That it has ",[24,346,347],{},"designated a Data Protection Officer",[45,349,350,351,354],{},"That it ",[24,352,353],{},"knows what personal data it holds"," and has assessed the risk",[45,356,344,357,360],{},[24,358,359],{},"written down its rules"," in a Privacy Management Program and a\nPrivacy Manual",[45,362,344,363],{},[24,364,365],{},"implemented real privacy and security measures",[45,367,368,369],{},"That it is ",[24,370,371],{},"prepared for, and regularly exercises, its breach response",[12,373,374],{},"Note where the manual sits: it is one part of item three, out of five. A template\npurchase addresses roughly a fifth of one pillar, and only on paper.",[12,376,377],{},"None of these is a document you buy once. All five are a program you run\ncontinuously, and someone has to be accountable for running it.",[16,379,381],{"id":380},"there-is-no-prescribed-format","There is no prescribed format",[12,383,384,385,388],{},"Worth stating plainly, because it is sometimes sold as a feature: ",[24,386,387],{},"there is no\nNPC-prescribed form for a Privacy Manual."," If a vendor tells you their template\nis \"in the NPC-prescribed format\", they are describing something that does not\nexist.",[12,390,391,392,396],{},"What a manual should do is answer, section by section, every obligation in the\nAct, the Implementing Rules and the circulars — as they apply to ",[393,394,395],"em",{},"your","\noperations. A generic manual cannot do that, because it does not know what you do.",[16,398,400],{"id":399},"evidence-not-intention","Evidence, not intention",[12,402,403],{},"The test that matters is not whether you have a policy. It is whether you can\nshow the policy was followed.",[12,405,406,407,410],{},"An internal audit tests evidence, not intention. ",[24,408,409],{},"An unevidenced yes is a no.","\nThat standard is uncomfortable, and it is the only one that survives contact with\na regulator asking for records.",[12,412,413],{},"Concretely: not \"we train staff on privacy\" but the attendance sheet and the\ndates. Not \"we have a breach plan\" but the tabletop exercise report. Not \"we\nreview our notices\" but the version history showing when and what changed.",[16,415,417],{"id":416},"what-running-it-actually-looks-like","What running it actually looks like",[12,419,420],{},"The manual is the smallest part. The program is:",[130,422,423,429,435,441,447,453],{},[45,424,425,428],{},[24,426,427],{},"Continuously"," — a breach hotline someone answers, data subject requests triaged",[45,430,431,434],{},[24,432,433],{},"Monthly"," — registers updated, new systems assessed before they go live",[45,436,437,440],{},[24,438,439],{},"Quarterly"," — a report to management, roadmap review, spot checks on controls",[45,442,443,446],{},[24,444,445],{},"Twice yearly"," — refresher training, a tabletop exercise, notices reviewed",[45,448,449,452],{},[24,450,451],{},"Annually"," — internal audit, PIA refresh, manual review, registration renewal,\nand the Annual Security Incident Report by 31 March",[45,454,455,458],{},[24,456,457],{},"Whenever something changes"," — a new system, a new vendor, a merger, a new\nNPC issuance",[12,460,461],{},"That calendar is the product. The manual is one output of it.",{"title":151,"searchDepth":152,"depth":152,"links":463},[464,465,466,467,468],{"id":325,"depth":152,"text":326},{"id":335,"depth":152,"text":336},{"id":380,"depth":152,"text":381},{"id":399,"depth":152,"text":400},{"id":416,"depth":152,"text":417},"2026-07-24","Buying a manual and filing it can leave you worse off than doing nothing, because it evidences that you knew what was required.",{},"\u002Finsights\u002Fa-privacy-manual-is-not-a-program",{"title":311,"description":470},"insights\u002Fa-privacy-manual-is-not-a-program",[476,172,477],"compliance","governance","rlY6cCchXJQMrvMFaod3vUpjZ2b2g9BhEz3lAismi58",1785320187282]