Free tool

The compliance calendar

These are the dates that decide whether a privacy program is real. The 72-hour clock is the one most organizations get wrong — it starts from knowledge or reasonable belief, not from confirmation.

72 hoursOn an incident

Notify the NPC and affected data subjects of a notifiable breach

The clock starts from knowledge or reasonable belief — not from confirmation. An organization that spends four days establishing the facts before notifying has already missed the deadline.

NPC Circular 16-03

5 daysOn an incident

Submit the full breach report through the DBNMS portal

Measured from discovery.

NPC Circular 16-03

31 MarchAnnual

File the Annual Security Incident Report

Covers the preceding calendar year. Due every year, incident or not.

NPC Circular 16-03

20 daysEvent-driven

Register a new personal data processing system

From the date processing commences. Registration is entirely online.

NPC Circular 2022-04

20 daysEvent-driven

Register the DPO designation

From the effectivity of the designation.

NPC Circular 2022-04

10 daysEvent-driven

Notify the NPC of a minor change

Changes to registered details that do not alter the scope of processing.

NPC Circular 2022-04

30 daysEvent-driven

Notify the NPC of a major change

Changes that alter the nature, scope or purpose of processing.

NPC Circular 2022-04

5 daysEvent-driven

Cure deficiencies flagged at registration review

Miss it and the application lapses; you start again.

NPC Circular 2022-04

30 days before expiryAnnual

Renew the Certificate of Registration

The certificate is valid for one year.

NPC Circular 2022-04

Every quarterQuarterly

DPO report to management or the board

Roadmap review and spot checks on controls. Not a statutory deadline, but it is the evidence that the program is actually running.

Good practice

Every monthMonthly

Update the registers

Records of processing, vendor register, data subject request log, incident log, and intake for any new system.

Good practice

Twice a yearSemi-annual

Refresher training, tabletop exercise and notice review

A breach plan that has never been exercised is not a tested plan, and the audit will say so.

Good practice

Every yearAnnual

Internal privacy audit, PIA refresh and Manual review

The evidence base for the following year’s program.

Good practice

This calendar is what a retainer actually takes off your desk

Tracking these dates, filing on them, and telling you first when a new NPC issuance changes one.

Nexthread Solutions is an information technology solutions provider for both hardware and software needs. Current as of July 27, 2026. Reviewed quarterly, and on each new NPC issuance.