LabanPHLabanPH — home
LABAN Answers · Know your rights. Fight back.
19 answers

Data Privacy

Contact-list scraping, unauthorized data use, and how to file with the NPC.

How do I report a data privacy violation in the Philippines?

File with the National Privacy Commission (NPC) — primarily through its online eComplaint Portal at complaints.privacy.gov.ph, which issues an instant docket number; e-mail to complaints@privacy.gov.ph is a fallback if the portal is down. The Data Privacy Act of 2012 (RA 10173) gives the NPC authority to investigate, order data deletion, fine controllers, and refer criminal cases to the DOJ. The complaint must be a sworn/verified statement identifying the data controller, describing the alleged violation, and attaching documentary evidence.

Read the full answer, sources & FAQ →

A lending app messaged my contacts about my debt — what can I do?

It is illegal, and you can report it to the National Privacy Commission (NPC). When a lending app pulls the contacts from your phone and messages your friends, family, or co-workers about your loan, it commits unauthorized processing and unauthorized disclosure of your personal data under the Data Privacy Act (RA 10173), and it breaches NPC Circular No. 20-01 (2020), which bars lending and financing companies from harvesting a borrower's contact list for debt collection. The same conduct is also an unfair collection practice under SEC Memorandum Circular 18 (2019). Screenshot every message, then file with the NPC (privacy.gov.ph) and the SEC — both can order the lender to delete your data and can fine or suspend it. LabanPH builds both complaints for free.

Read the full answer, sources & FAQ →

Did I really consent to a lending app's data collection just by installing it?

Not necessarily. Under the Data Privacy Act (RA 10173), consent must be freely given, specific, and informed — a blanket in-app "Allow" that forces you to surrender your entire contact list, photos, or location before you can borrow is not valid consent for excessive data. RA 10173 §11 requires processing to follow transparency, legitimate purpose, and proportionality, and NPC Circular No. 20-01 (2020) says a lender may only collect data that is adequate, relevant, and not excessive for assessing your loan. Harvesting your whole phone to pressure you later fails that test, and the NPC has repeatedly struck it down.

Read the full answer, sources & FAQ →

How do I file an NPC complaint against a lending app?

File with the National Privacy Commission — primarily through its online eComplaint Portal at complaints.privacy.gov.ph, which issues an instant docket number and handles Data Privacy Act (RA 10173) violations by lending apps such as contact-list scraping and debt-shaming; e-mail to complaints@privacy.gov.ph is a fallback for when the portal is down. Under the NPC's 2021 Rules of Procedure (NPC Circular 2021-01, as amended by NPC Circular 2024-01), it's recommended — not mandatory — to notify the lender (its Data Protection Officer) first and give it a chance to respond; keep that written notice as an exhibit if you send one. Your complaint must be a sworn/verified statement identifying the lending company (the data controller), describing the violation, the relief requested, and a Certification against forum shopping, plus evidence — screenshots of the messages, the app's permission screen, and your loan record. Filing is free for data subjects, needs no lawyer, and can be done online.

Read the full answer, sources & FAQ →

Can I demand that a lending app delete my data?

Yes. The Data Privacy Act (RA 10173) §16(e) gives every data subject the right to suspend, withdraw, or order the blocking, removal, or destruction of their personal data when it is incomplete, outdated, false, unlawfully obtained, used for an unauthorized purpose, or no longer needed. NPC Circular No. 20-01 (2020) separately orders lending and financing companies to securely dispose of any borrower contact lists they hold in violation of the rules, and bars keeping your data in perpetuity. Send a written erasure demand; if the lender refuses or ignores it, file with the NPC, which can order deletion.

Read the full answer, sources & FAQ →

Is 24/7 GPS tracking of my financed vehicle a privacy violation?

It can be. Your continuous location is personal data, so a lender that tracks a financed vehicle 24/7 must satisfy the Data Privacy Act (RA 10173): a lawful basis, and processing that is transparent, for a legitimate purpose, and proportional (§11). Round-the-clock tracking that goes beyond what is needed to secure the loan — for example, logging your movements when you are not in default — can be excessive processing you may challenge before the National Privacy Commission. The device's legality as a repossession tool is a separate question governed by the Civil Code and courts.

Read the full answer, sources & FAQ →

What are the penalties for a lender that abuses my personal data?

The Data Privacy Act (RA 10173) sets criminal penalties. Unauthorized processing of personal information is punished by imprisonment of one to three years and a fine of ₱500,000 to ₱2,000,000, rising to three to six years and up to ₱4,000,000 for sensitive personal information (§25). Malicious disclosure carries one year and six months to five years plus ₱500,000 to ₱1,000,000 (§31), and unauthorized disclosure carries one to three years plus ₱500,000 to ₱1,000,000 (§32). The National Privacy Commission can also impose administrative fines and order deletion, on top of any SEC sanctions for unfair collection.

Read the full answer, sources & FAQ →

My personal data was leaked or breached — what are my rights?

Under the Data Privacy Act (RA 10173), a company that suffers a breach of sensitive personal information that is likely to cause serious harm must promptly notify both the National Privacy Commission and the affected data subjects (§20(f)). As a data subject you have the right to be informed, to access your data, to correct it, to block or erase it, and to be indemnified for damages you suffered from the unlawful or unauthorized processing (§16). If a company hid a breach or was negligent, you can complain to the NPC, which can investigate, fine, and refer the matter for prosecution.

Read the full answer, sources & FAQ →

Can a lending app access my phone photos or camera?

Only if that access is genuinely necessary for the loan — otherwise no. NPC Circular No. 20-01 (2020) prohibits lending and financing apps from demanding unnecessary permissions and limits data collection to what is adequate, relevant, and not excessive for evaluating your loan. A camera permission may be justified for a required selfie or ID verification (KYC), but demanding your whole photo gallery or storage is excessive processing under the Data Privacy Act (RA 10173 §11) that you can challenge before the National Privacy Commission.

Read the full answer, sources & FAQ →

What are my rights as a data subject under the Data Privacy Act?

The Data Privacy Act (RA 10173 §16) gives you the right to be informed that your data is being processed; to access your data, its sources, and who received it; to dispute and correct inaccurate data; to suspend, withdraw, or order the blocking, removal, or destruction of your data; and to be indemnified for damages from inaccurate, unlawfully obtained, or unauthorized use. RA 10173 also gives a right to data portability (§18). Any organization that processes your personal data — a lender, bank, app, or employer — must respect these rights, and the National Privacy Commission enforces them.

Read the full answer, sources & FAQ →

Can a company share my personal information without my consent?

Generally no, unless it has another lawful basis. The Data Privacy Act (RA 10173) allows processing of personal information only where a criterion in §12 is met — such as your consent, performance of a contract you are party to, a legal obligation, or a legitimate interest that is not overridden by your rights. Sharing your data outside those grounds — for example, disclosing your debt to your contacts or selling your details to third parties — is unauthorized disclosure punishable under §32, and you can complain to the National Privacy Commission.

Read the full answer, sources & FAQ →

How do I make a company delete my data (right to erasure)?

You have a legal right to demand deletion. RA 10173 (Data Privacy Act) §16(e) lets any data subject order the blocking, removal, or destruction of their personal data when it is incomplete, outdated, false, unlawfully obtained, used beyond the purpose you agreed to, or no longer necessary. Put the request in writing to the company's Data Protection Officer — every controller must designate one — identify yourself, and specify exactly what to delete. The law sets no fixed day-count, but a controller has a duty to act within a reasonable period; if it refuses, or keeps data it no longer needs, file a complaint with the National Privacy Commission (NPC), which can order deletion, impose fines, and refer the case for prosecution.

Read the full answer, sources & FAQ →

After a data breach exposed my info, must the company notify me — and how fast?

Yes, in the serious cases. NPC Circular No. 16-03 (Personal Data Breach Management) requires a company to notify both the National Privacy Commission and the affected data subjects within 72 hours of knowing, or reasonably believing, that a notifiable breach happened. A breach is notifiable when it involves sensitive personal information or information that could be used for identity fraud, was likely acquired by an unauthorized person, and poses a real risk of serious harm. The company must also submit a full breach report to the NPC (within five days unless the NPC grants more time). If you were not notified when you should have been, that failure is itself a violation you can report.

Read the full answer, sources & FAQ →

Is CCTV recording of me legal, and can I get a copy of the footage?

CCTV recording is legal but regulated — footage of an identifiable person is personal data under the Data Privacy Act. NPC Circular No. 2024-02 (CCTV Systems), which replaced the earlier 2020 CCTV advisory, requires operators to post visible notice that CCTV is in use, limit recording to a legitimate purpose, secure the footage, and keep it only for a set retention period. Because you are a data subject in the footage, you can invoke your right of access under RA 10173 §16(c) to request a copy of the parts that show you — the operator may redact or blur other people to protect their privacy, and may refuse where release would defeat a lawful investigation.

Read the full answer, sources & FAQ →

Can my employer monitor my work email, chats, and computer?

Generally yes, but only within limits set by the Data Privacy Act. An employer may process employee data — including monitoring work systems — for a legitimate business purpose, but RA 10173 §11 requires that processing be transparent, for a declared and legitimate purpose, and proportional (no more intrusive than necessary). In practice that means monitoring should be disclosed in advance in a written policy you were told about; secret, blanket, or excessive surveillance of your private communications can violate the DPA. Intercepting private voice calls without consent can also breach the Anti-Wiretapping Act (RA 4200), which is separate and criminal.

Read the full answer, sources & FAQ →

How do I stop spam texts and marketing I never signed up for?

You have a right to object. Under the Data Privacy Act and its Implementing Rules (IRR Rule VIII §34(b)), a data subject may object to processing for direct marketing — and that objection is absolute: once you object, the company must stop and can no longer use your data for marketing without fresh consent. The NPC holds that contact details collected for one purpose (like signing up for a service) cannot be reused for marketing without your separate, informed consent. Reply with the opt-out keyword (e.g., STOP), send a written objection to the sender's Data Protection Officer, and if it continues, file a complaint with the NPC.

Read the full answer, sources & FAQ →

How long do I have to file a data-privacy complaint with the NPC?

Don't wait — file promptly, and take a required first step. Under the NPC's 2021 Rules of Procedure (NPC Circular No. 2021-01), before the Commission takes up your complaint you are generally expected to have first brought the matter to the company (the personal information controller), usually to its Data Protection Officer, and given it a reasonable chance to respond. Data-privacy claims are also subject to prescriptive limits, so both administrative action and criminal prosecution under RA 10173 can be time-barred if you delay. Because the exact window depends on the nature of the violation, the safest course is to complain internally as soon as you discover it and file with the NPC without unnecessary delay.

Read the full answer, sources & FAQ →

How do I request a copy of all the data a company has on me?

Two rights let you do this. Your right of access under RA 10173 §16(c) lets you demand, in reasonable form, the contents of the personal data a company holds on you, its sources, who it was disclosed to, and how it was processed. Your right to data portability under RA 10173 §18 goes further: where your data is processed electronically in a structured, commonly used format, you can obtain a copy in an electronic format you can reuse or move to another provider. Send a written request to the company's Data Protection Officer identifying yourself; the controller has a duty to respond within a reasonable period.

Read the full answer, sources & FAQ →

Can a company require my fingerprint or face scan (biometric data)?

Only on a lawful basis, and it usually needs your consent. Biometric data — fingerprints, face scans, iris — is personal information the NPC treats as sensitive, so its collection is tightly regulated. Under RA 10173 §12 (and §13 for sensitive personal information), a company needs a valid lawful basis, most commonly your freely given, informed consent, and under §11 the collection must be for a legitimate purpose and proportionate. That means a company generally cannot force biometrics on you if a less-intrusive alternative (like an ID card or PIN) would achieve the same purpose; you can ask for that alternative and refuse blanket biometric capture.

Read the full answer, sources & FAQ →

Facing this yourself?

We pre-fill the BSP, SEC, DTI, and small-claims letters for you — and route you to the right regulator.

More answer topics

Editorial policy: Educational content, not legal advice. Every answer cites primary sources only. Rules and rates change; verify against the cited source before you act.