03 · What You Need to Know
Different Notifications Serve Different Purposes
The first notification is usually internal
When a researcher discovers that personal research data may have been lost, disclosed, altered, destroyed, or accessed without authorization, the first step is normally to activate the institution's incident-response process.
Depending on the organization, the relevant contact may be a data protection officer, privacy office, information-security team, incident-response team, research governance office, or another designated unit.
The researcher should not wait until the event has been fully investigated. External notification deadlines can be short, and the institution needs enough time to determine what happened, assess the risk, and decide which reporting obligations apply.
This is why the immediate response to a suspected research data breach emphasizes rapid internal escalation even when the final legal classification remains uncertain.
The privacy regulator is notified only when the applicable threshold is met
Data protection laws use different tests for regulatory notification.
Under the EU GDPR, a controller must notify the competent supervisory authority of a personal data breach unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Where notification is required, it must occur without undue delay and, where feasible, within 72 hours after the controller becomes aware of the breach.
The Philippine framework uses a different test. The Data Privacy Act implementing rules require notification to the National Privacy Commission and affected data subjects when specified information is reasonably believed to have been acquired by an unauthorized person and the unauthorized acquisition is likely to give rise to a real risk of serious harm.
The NPC explicitly states that not all personal data breaches require notification. Its current breach-reporting guidance identifies mandatory notification criteria and requires qualifying notifications through its Data Breach Notification Management System.
In the Philippines, the personal information controller carries the notification obligation
The NPC states that the obligation to notify remains with the personal information controller even where processing has been outsourced or subcontracted to a personal information processor.
This matters in research involving cloud providers, survey platforms, transcription companies, laboratories, and other service providers. A vendor may be required to alert the institution quickly, but researchers should not assume the vendor will take over the institution's regulatory obligations.
Internally, this reinforces the importance of knowing who is responsible for protecting personal research data and who has authority to make breach-notification decisions.
Affected participants may have to be told
Regulatory notification and participant notification are related but separate questions.
Under the EU GDPR, affected individuals generally must be informed without undue delay when a personal data breach is likely to result in a high risk to their rights and freedoms, subject to the Regulation's conditions and exceptions.
Under the Philippine breach framework, affected data subjects must be notified when the applicable mandatory-notification requirements are met. NPC guidance states that qualifying notifications should be made individually through written or electronic means and should explain how affected individuals can obtain further information and what they can do to minimize resulting risks.
Participant notification is therefore not simply an apology email. Its content and timing may be regulated.
Participants should receive useful information, not institutional fog
When notification is required, affected people need enough information to understand what happened and what they can do.
Depending on the governing law, relevant information may include the nature of the breach, the types of information involved, likely consequences, actions already taken, protective steps the participant can take, and how to contact the responsible organization or data protection officer.
If credentials were exposed, participants may need to change passwords. If financial or identity information was compromised, different protective measures may be appropriate. If highly sensitive research information was disclosed, the institution may need to consider context-specific safety or confidentiality risks.
Good notification should help participants act. A paragraph explaining that the organization "takes privacy very seriously" is not, by itself, a mitigation strategy.
The ethics committee may need to know even when the privacy regulator does not
A research data incident can raise ethical issues independently of whether it meets a statutory privacy-notification threshold.
Loss of confidentiality may expose participants to psychological, social, economic, physical, or other harms that were not previously anticipated. It may also reveal that the study's approved privacy protections are inadequate.
Under U.S. HHS human-subject protections, unanticipated problems involving risks to participants or others must be reported promptly through the relevant institutional process. OHRP guidance specifically gives the example of an unencrypted laptop containing identifiable sensitive research data being stolen and treats the event as an unanticipated problem requiring reporting because it increased participants' risk of harm.
OHRP has also treated inadvertent disclosure of research participants' email addresses as a confidentiality breach constituting an unanticipated problem in a specific enforcement case.
The exact reporting requirements depend on the ethics framework governing the study. Researchers should therefore check the conditions of their own ethics approval rather than assuming that regulator notification and ethics reporting use the same threshold.
Research ethics committees can have authority to require changes or suspend research
The 2024 Declaration of Helsinki states that research ethics committees must have authority to monitor research, recommend changes, withdraw approval, and suspend ongoing research. It also requires researchers to provide relevant monitoring information, particularly regarding serious adverse events, where monitoring is required.
Although the Declaration applies specifically to medical research involving human participants, it illustrates why a confidentiality breach can become more than a privacy-office matter. A serious incident may alter the ethical acceptability of continuing the approved protocol unchanged.
Sponsors and funders may have separate reporting requirements
Research contracts, grant conditions, clinical trial agreements, data-use agreements, or sponsor policies may require notification of security incidents or confidentiality breaches.
The contractual threshold may not be identical to the legal threshold for regulator notification. A sponsor might require notification of any suspected breach affecting sponsored data, even where the incident ultimately does not meet the regulator's mandatory reporting criteria.
Researchers should therefore check project-specific agreements rather than assuming the privacy office's regulator decision resolves every reporting obligation.
Collaborating institutions may need immediate notice
If data originated from another institution, are jointly controlled, or are processed under a collaboration or data-sharing arrangement, the partner organization may need to be informed promptly.
Agreements should ideally specify who reports incidents to whom, within what period, and what information must be provided. This is particularly important because one institution may need information from another to meet its own regulatory deadline.
A collaborator discovering a breach should therefore follow the reporting provisions established when the data-sharing or transfer arrangement was documented.
A processor should tell the controller, not independently improvise the whole response
Where a service provider acts as a processor, it generally needs to notify the controller according to applicable law and contract so that the controller can perform its breach assessment.
Under the GDPR, processors must notify controllers without undue delay after becoming aware of a personal data breach.
Researchers using external services should know the contractual incident-notification route and should immediately escalate any provider notification to the institutional privacy or security team.
Other regulators or authorities may apply in specialized research
Health research, clinical trials, government research, education records, financial data, national-security research, or other regulated areas may involve additional authorities and sector-specific reporting obligations.
For HHS-regulated human-subject research in the United States, institutional procedures must provide for prompt reporting of relevant unanticipated problems, serious or continuing noncompliance, and suspensions or terminations to the IRB, appropriate institutional officials, and, where applicable, agencies such as OHRP or FDA.
Researchers should not generalize those U.S. requirements to studies in other jurisdictions. The useful principle is that privacy regulation may be only one reporting layer.
Law enforcement notification is situation-specific
A breach involving theft, extortion, ransomware, fraud, physical danger, or other suspected criminal activity may justify involvement of law enforcement or cybercrime authorities.
That decision should normally be coordinated through institutional security, legal, privacy, or senior management channels. Researchers should preserve evidence and avoid actions that could interfere with a forensic or criminal investigation.
Do not notify the media simply because the incident feels serious
Public communication may sometimes become necessary, particularly for large incidents or where individual notification is impossible, but media communication is normally an institutional function.
Researchers should not post about an active breach on social media, contact journalists independently, or discuss identifiable details publicly. Apart from creating additional disclosure risk, premature public statements may contain facts that later prove inaccurate.
Notification can be phased when the investigation is incomplete
Short deadlines do not always mean the organization must know everything within 72 hours.
Philippine NPC guidance states that where complete information cannot reasonably be provided within the prescribed period, the PIC should still submit the available information through the breach-notification process and may supplement it later.
GDPR Article 33 similarly allows information to be provided in phases where it cannot all be supplied at the same time.
The practical lesson is important: uncertainty is not a reason to remain silent until day four.
Notification can sometimes be delayed, but researchers should not make that decision alone
Philippine NPC guidance permits limited delay of data-subject notification where necessary to determine the scope of the breach, prevent further disclosure, or restore reasonable integrity to the system, subject to the applicable conditions. It also identifies circumstances in which delay is not allowed and provides a process for requesting postponement.
Other jurisdictions have their own rules and exceptions. Decisions to delay notification should therefore be made through the formal breach-response process, not because the research team would prefer to finish the paper first.
Different Thresholds
A breach can require reporting to an ethics committee without requiring notification to a privacy regulator, or require contractual notice to a partner before the regulator assessment is complete. Never assume that one "not reportable" decision answers every reporting obligation.