What It Means
- The NPC’s draft circular on data subject rights would replace NPC Advisory 2021-01 with fixed response periods, written reasons for every refusal, and records of every request handled.
- Controllers would carry the burden of proving a lawful basis for continued processing or retention after an objection or erasure request (Sec. 8F, 11H).
- Access would reach inferences, scores and profiling logic, and the right to be informed would cover machine learning and AI use (Sec. 7, 9A).
- Processors would be pulled in through service agreements that must carry request roles and timelines, while the controller stays liable (Sec. 6D).
- The text is a draft. The comment window ends October 5, the in person consultation is October 19, and compliance would fall due 135 days after publication if adopted.

The National Privacy Commission‘s draft circular on data subject rights is being read as a deadline story. Fifteen days to acknowledge a request, thirty days to resolve it. That reading is accurate, and the clocks are also the cheapest part of the draft for a company to absorb. The costly parts are the burden of proof placed on the controller and the reach of the access right into data the company generated about a person, not data the person handed over.
Everything below describes draft text published for consultation. Nothing in it binds anyone yet. Where this piece interprets, it says so.
The draft turns data subject rights into a timed process
The draft sets the clocks in Section 6F. A controller must acknowledge a request within 15 calendar days and resolve it within 30. If clarification is needed, the controller must ask within seven days of receipt, and only then does the 30 day period pause. A controller that misses the seven day window cannot pause the period on that ground.
One extension is allowed, capped at 30 more days, and the written notice with reasons must go out inside the first 15 days. Large volume access requests can run to 60 days in total (Sec. 9H). Each request, the action taken, the grounds relied on, and the dates of receipt and resolution must be recorded (Sec. 15D).
The interpretation is that the structure punishes late administrative moves, not only late answers. A company that realizes on day 20 that it needs more time has already lost the extension. And the clock does not start at the privacy office. A request is deemed received when it reaches any person, office, channel or platform the controller designated to receive it, and the controller cannot shift the date by forwarding the request to its Data Protection Officer (Sec. 6F). A request landing at a branch, a customer service inbox or a social media page starts the 30 days there.
Standardizing data subject rights this way also means standardizing intake. Companies that run requests through several unconnected channels will find that the draft treats every channel as the front door.
The burden of proof moves to the controller
Section 8A lists when a person may object under the draft rules on data subject rights. The grounds are processing based on consent or legitimate interest, further processing beyond what the person reasonably expected, direct marketing, and AI or profiling used as the sole basis for a decision that significantly affects the person.
On a valid objection, the controller and any engaged processor must stop the processing. The draft carves out four exceptions, including a subpoena, obvious purposes tied to a contract, a legal obligation, or another lawful basis under the Data Privacy Act. For those exceptions the controller bears the burden of demonstrating the basis and must tell the person in writing (Sec. 8F). Erasure follows the same logic. The controller must show why retention continues, name what it keeps and for what purpose, and a general assertion of business necessity is declared insufficient (Sec. 11H).
The same rule appears in every response section. A denial needs a specific factual or legal basis, and an unsupported statement does not count (Sec. 8I, 9E, 10E).
The interpretation is that legitimate interest has worked as a quiet default for marketing lists, analytics and customer segmentation because nobody asked a company to defend it on a deadline. Under this draft, one objection forces the defense within 30 days, in writing. A company that cannot point to a documented basis for each processing activity has two choices. It stops the processing, or it answers a complaint with no paper behind it. For data subject rights, that is the point where policy becomes cost.
Access now reaches what companies infer about people
Of all the data subject rights in the draft, access has the widest reach. Section 9A extends it to personal data generated through analysis, inference, modeling or profiling, and to information about its source, recipients, retention period, metadata, profiling logic and automated decision making. The right to be informed in Section 7 separately covers whether data is used for machine learning or processed through an AI system.
A company cannot refuse access to a whole record because part of it holds a trade secret. It must redact that part and release the rest (Sec. 9B, 9E). Where it withholds or redacts anything, it must identify each item and cite the specific legal basis for each (Sec. 9D).
The draft also leaves room. Information whose disclosure would compromise fraud prevention mechanisms or information security can be withheld (Sec. 9B). Portability is narrower than access. Data created solely by the controller through scoring or inference is outside a portability request except where the access right already covers it (Sec. 12B).
The interpretation is that credit scores, risk tiers, propensity models, fraud flags and segment tags move from internal assets to something a customer can ask to see. Annex A of the draft lists financial services, healthcare, education, employment and online services as illustrative sectors. Lenders and insurers that score applicants, and platforms that profile users, hold the most inferred data per person. The NPC already treated scraped public data as regulated processing in its Advisory 2026-01 on data scraping. This draft applies the same logic to data a company derives itself.
Processors inherit the problem through contracts
Section 6D requires service and outsourcing agreements to define roles, procedures and timelines for handling requests. Processors must give reasonable assistance, and engaging one does not relieve the controller of its responsibility. On erasure, the controller must also notify recipients who previously received the data (Sec. 11F), disclose whether copies remain in backup or archive systems (Sec. 11H), and keep auditable records of the erasure (Sec. 11J).
The interpretation is that the controller’s 30 days are partly spent waiting on vendors, because each of the data subject rights the draft lists eventually lands on a system someone else runs. A CRM provider, an outsourced contact center or a marketing platform now needs a contract term that fixes how fast it responds, and many existing agreements have none. Renegotiation is the likely result, and some cost will pass back to the controller in pricing. Processors with mapped data and a clean request interface become the vendors controllers keep. The rest become the weak link in a deadline the controller owns. The NPC’s earlier warning on sharing breach data already showed that liability follows the data across organizational lines.
Relief valves limit the cost for companies with records
The draft on data subject rights contains real relief, and overstating the burden would be inaccurate. A controller may deny requests that are manifestly unfounded, excessive, vexatious or repetitive (Sec. 15A). It may decline an access request when it already gave substantially the same data within the previous six months, except where something changed (Sec. 9C). It need not build a new system or interface to answer an individual portability request (Sec. 12E). Notarization of a representative’s authority is not required as a matter of course (Sec. 4B). Fees are generally barred, with a reasonable charge allowed only for the actual cost of copies and for repeated portability requests (Sec. 6E, 12F). A controller also may not hold data just to be ready for future requests (Sec. 6I).
The interpretation is that every one of these valves needs paperwork to use. A denial must be in writing, state its basis, and tell the person they may complain to the Commission (Sec. 15C). A company that logs its requests and decisions can use the relief, and its data subject rights process doubles as its evidence file. A company that does not has relief on paper and none in practice.
A 135 day window opens after adoption
The draft takes effect 45 days after publication in the Official Gazette or a newspaper of general circulation, and controllers then get 90 calendar days to comply (Sec. 18, 21). That is roughly 135 days from publication. The draft repeals NPC Advisory 2021-01 and overrides inconsistent parts of the 2024-02 rules on CCTV access. Violations carry criminal, civil or administrative liability under the Data Privacy Act, and administrative fines under NPC Circular 2022-01 (Sec. 17).
The final text on data subject rights can still change after October 19. The interpretation is that 135 days is short against the real work. Mapping where personal data sits, documenting a lawful basis per activity, rewriting vendor contracts and training intake staff each run on their own cycles, and most of them cannot start in earnest until the final text is out.
Legitimate interest has carried marketing lists, behavioral scoring and customer segmentation without ever being tested on a clock. The draft puts the test on a 30 day clock and hands the burden to the company. Firms with undocumented bases will face that question for the first time in a written request from a customer, with the Commission named as the place to take a complaint. Processors without contract terms for request handling carry the same exposure one step down, and the controller who signed their contract answers for it.
Track more regulatory shifts that affect your business in Policy & Regulation section of Hemos PH.




