Quick answer
Usually, no. A lending app, lending company, financing company, or collection agency generally cannot contact a borrower’s relatives, employer, coworkers, friends, or former partner to collect the debt merely because their details appear in the borrower’s phone, social-media contacts, application, or records.
For debt collection, the lender may contact a person who validly agreed to be a guarantor. A true co-maker or co-borrower may also be contacted about an obligation that person actually undertook. A character reference, relative, employer, or former partner does not become liable simply because the borrower supplied their name or number.
Limited contact may be permissible for a legitimate purpose—such as verifying a character reference during the loan application—but it must be necessary, proportionate, and confined to that purpose. It must not become debt collection, disclosure of the borrower’s loan, harassment, or public shaming.
These restrictions do not erase a valid debt. The lender may still contact the borrower through lawful channels, negotiate payment, report information as authorized by law, or pursue a proper court case.
The rule for relatives, employers, and former partners
The decisive issue is not the person’s relationship to the borrower. It is the person’s documented legal role.
| Person contacted | General rule |
|---|---|
| Parent, sibling, child, or other relative | Cannot ordinarily be contacted to collect the borrower’s debt unless that person is a valid guarantor, co-maker, or co-borrower |
| Employer, HR officer, supervisor, or coworker | Employment information may sometimes be verified during an application, but the borrower’s debt should not be disclosed or collection pressure routed through the workplace |
| Former spouse or former partner | Has no collection role merely because of the former relationship; contact may be proper only if the person separately undertook liability or another lawful basis clearly applies |
| Character reference | May be contacted to verify the borrower’s identity and the truthfulness of application information—not to demand payment or pressure the borrower |
| Guarantor | May be contacted for collection if the person expressly and validly consented to the guaranty |
| Co-maker or co-borrower | May be contacted regarding the obligation that person actually signed or accepted |
| Random phone contact | Cannot be contacted for debt collection merely because the lender’s app found the number in the borrower’s device |
A collector should not tell an unauthorized third party that the borrower has a loan, is overdue, is “delinquent,” is supposedly avoiding payment, or may face a case. Even asking the third party to pressure the borrower can reveal the existence of the debt and turn the third party into an unauthorized collection channel.
Why access to the borrower’s contacts is restricted
The Data Privacy Act of 2012 requires personal data to be processed transparently, for a legitimate purpose, and proportionately. Information must be adequate and relevant but not excessive.
Under NPC Circular No. 2022-02, an online lending application may not engage in unrestricted or excessive processing of contact lists. Prohibited “unbridled processing” includes processing that:
- leads to harassment;
- is used to collect a debt from people other than the borrower’s guarantors; or
- results in unfair collection practices.
If an app uses a phone contact list to let the borrower choose a character reference or guarantor, its access must be limited to the minimum necessary for that selection. It cannot lawfully treat the entire address book as a ready-made collection list.
Granting the app a device permission does not give it unlimited authority. Permission to access contacts is not the same as permission to message every contact, expose a loan, or shame the borrower. Consent under the Data Privacy Act must be freely given, specific, informed, and evidenced by written, electronic, or recorded means. Processing must also remain consistent with law and the purpose disclosed to the data subject.
A character reference is not a guarantor
A character reference helps verify the borrower’s identity or the truthfulness of information submitted with a loan application. Under NPC Circular No. 2022-02:
- the borrower should inform the person that they were named as a character reference;
- the lender must tell the person that they were selected as a reference and explain how it obtained their contact details;
- the person must be given the option to have their data removed as a character reference; and
- the lender cannot contact the reference for unrelated purposes such as collection, marketing, cross-selling, or offering other products.
Naming someone as a “reference” does not make that person responsible for repayment. A lender cannot convert a character reference into a guarantor through its own records or through a clause accepted only by the borrower.
When is someone really a guarantor?
A guarantor is a person who expressly binds themselves to fulfill the borrower’s obligation if the borrower fails to do so. NPC Circular No. 2022-02 requires the lender to obtain the guarantor’s separate consent, consistent with the Civil Code rules on guaranty and the guarantor’s data-privacy rights.
A name and number typed by the borrower are not enough by themselves. If a collector says a relative or former partner is a guarantor, ask for:
- the signed or electronically accepted guaranty;
- the date and method of acceptance;
- the terms identifying the obligation guaranteed;
- the privacy notice and consent record given to the alleged guarantor; and
- proof that the person—not merely the borrower—accepted the undertaking.
The precise liability of a guarantor, co-maker, or co-borrower depends on the wording and validity of the documents. Labels used by an app are not conclusive.
Can the app contact an employer?
A lender may have a legitimate reason to verify employment or income while evaluating an application, provided the processing is disclosed, necessary, lawful, and not excessive. That does not normally authorize the lender to tell HR, a supervisor, a receptionist, or coworkers about an unpaid loan.
Contact becomes particularly problematic when the collector:
- announces that the employee is in debt or overdue;
- asks HR to deduct payment without lawful authority;
- repeatedly calls the workplace to embarrass or disrupt the borrower;
- threatens the borrower’s employment;
- sends loan details, photographs, IDs, or insulting messages to coworkers; or
- asks an employer or supervisor to pressure the borrower into paying.
A collector may try to reach the borrower using contact information the borrower provided, including a workplace number in an appropriate case. But speaking directly with the borrower is different from disclosing the debt to other people at work. Any wage deduction or garnishment also requires a valid legal basis; a collector’s demand alone is not a court order.
What if the borrower agreed to contact-list access?
A broad clause in the app’s terms does not automatically make mass contact lawful. SEC rules treat contacting people in the borrower’s contact list—other than persons who actually undertook the relevant obligation—as an unfair collection practice even where the collector invokes the borrower’s consent.
The NPC’s rules independently require necessity, proportionality, transparency, and purpose limitation. An app must provide appropriate information when it requests personal data or device permissions, and access should not continue after its legitimate purpose has been fulfilled without another lawful basis.
Borrowers may turn off unnecessary permissions through the phone’s settings. Doing so does not delete data the lender has already copied, so a written privacy request may also be necessary.
Other collection conduct that can be unlawful
SEC Memorandum Circular No. 18, Series of 2019 requires lending and financing companies—and collection providers acting for them—to use reasonable, legally permissible means and to avoid unfair practices. Prohibited conduct includes:
- threats of violence or other criminal harm;
- threats to take action that cannot legally be taken;
- obscenities, insults, or profane and abusive language;
- disclosure or publication of borrowers’ personal information as a shaming tactic;
- false or deceptive representations;
- communicating loan information known, or reasonably expected, to be false;
- contacting unauthorized people in the borrower’s contact list; and
- contact at unreasonable or inconvenient hours, subject to the circular’s stated exceptions.
As a general rule under the circular, contact before 6:00 a.m. or after 10:00 p.m. is considered unreasonable or inconvenient. The circular states exceptions where the account has been past due for more than 15 days or the borrower expressly agreed—through written, electronic, or recorded means—that those hours are the only reasonable or convenient times for contact. Even then, threats, disclosure, harassment, and other unlawful methods remain prohibited.
Lawful exceptions and important qualifications
Third-party contact is not automatically unlawful in every situation. The result may differ where:
- the person validly became a guarantor, co-maker, or co-borrower;
- contact is genuinely limited to application-stage identity, character, employment, or income verification;
- disclosure is required by a court order, subpoena, or applicable law;
- information is lawfully supplied to a credit-information entity or another authorized recipient;
- the borrower gave valid, specific consent to a particular disclosure that the law does not otherwise prohibit; or
- a sheriff, process server, court, or lawyer communicates as part of a genuine legal proceeding.
These exceptions are narrow. They do not authorize mass messaging, humiliation, false accusations, or using relatives and employers as collection agents.
Rules may also differ according to the lender’s regulator. Lending and financing companies are generally supervised by the SEC under the Lending Company Regulation Act and related laws. Banks, digital banks, credit-card issuers, and other BSP-supervised financial institutions may also be governed by BSP financial-consumer-protection rules. The Data Privacy Act can apply regardless of which financial regulator has primary supervision.
What to do if other people are being contacted
1. Preserve the evidence immediately
Save original copies of:
- texts, chat messages, emails, and social-media messages;
- screenshots showing the sender, number, account name, date, and time;
- call logs and lawful recordings, if any;
- voicemails;
- posts, comments, group messages, or edited borrower photographs;
- the app’s name, developer, download page, privacy notice, permissions, and terms;
- the loan agreement, disclosure statement, receipts, and account history;
- messages received by relatives, coworkers, HR personnel, or a former partner; and
- any report showing when app permissions were granted or revoked.
Ask each recipient to preserve the message on their own device and write a short factual account of what was said. Do not edit the screenshots or crop out information needed to identify the sender.
2. Identify the actual lender
The app’s brand may be different from the corporation that issued the loan. Check the agreement, disclosure statement, privacy notice, payment instructions, and SEC records for:
- the corporate name;
- SEC registration and Certificate of Authority details;
- the app or online lending platform name;
- the collection agency, if one was used; and
- the company’s data protection officer or privacy contact.
A collector’s outsourcing arrangement does not ordinarily remove the lender’s accountability for personal data processed on its instructions.
3. Send a written cease-and-desist and privacy request
Write to the lender and its data protection officer. Identify the account without sending unnecessary IDs or sensitive data. State:
- which unauthorized people were contacted;
- when and how contact occurred;
- what loan information was disclosed;
- that collection through relatives, employers, coworkers, references, or a former partner must stop;
- that unnecessary access to the contact list must cease;
- that inaccurate information is disputed, if applicable; and
- the specific remedy requested.
You may also request access to information about the personal data processed, its source, recipients, the reasons for disclosure, and the identity of the responsible personal-information controller. Ask the lender to preserve call recordings, collector notes, access logs, consent records, and messages relating to the incident.
Keep proof of delivery and any response. A written complaint to the company is important because the NPC ordinarily requires exhaustion of remedies before accepting a formal privacy complaint.
4. Secure the phone and accounts
After preserving evidence:
- revoke unnecessary contacts, storage, camera, microphone, location, and social-media permissions;
- review whether the app has device-administrator or accessibility access;
- change passwords if credentials may have been exposed;
- enable multifactor authentication;
- warn recipients not to click payment links or reveal personal information; and
- avoid reinstalling a suspicious app merely to capture additional evidence.
Do not send payment to a new account or personal e-wallet solely because a caller threatens immediate arrest, public exposure, or a workplace visit. Verify payment instructions directly with the legitimate lender.
5. File with the proper regulator
For unfair collection by an SEC-regulated lending or financing company, use the SEC’s official lending-and-financing-company complaints information and verify the company and platform through the SEC’s official records.
For unlawful access, excessive processing, or unauthorized disclosure of personal data, follow the NPC’s formal complaint instructions. The NPC currently instructs complainants to complete its complaint-assisted form, have it notarized, attach supporting documents, and submit it in person, by courier, or by scanned email to complaints@privacy.gov.ph.
The NPC’s complaint mechanics generally require the complainant first to notify the respondent in writing and allow it to address the violation. Proof should be attached showing that the respondent failed to take timely or appropriate action, or did not respond within 15 calendar days after receiving the written notice.
If the lender is a bank or another BSP-supervised institution, first use the institution’s consumer-assistance channel and, if unresolved, consult the Bangko Sentral ng Pilipinas consumer-assistance resources.
The correct forum depends on the regulated entity and the conduct complained of. The same incident may raise both unfair-collection and data-privacy issues.
When police or legal help is urgent
Seek prompt assistance from law enforcement or a Philippine lawyer if the collector:
- threatens violence, kidnapping, sexual harm, arrest without legal basis, or damage to property;
- extorts money or threatens to publish intimate images or confidential information;
- impersonates a police officer, court employee, lawyer, or government agency;
- gains unauthorized access to accounts or devices;
- publishes personal data or fabricated accusations online;
- contacts a child or threatens a child’s safety;
- appears at a home or workplace in a threatening manner; or
- sends an authentic summons, subpoena, demand from counsel, or other court document with a response deadline.
Do not ignore genuine court papers. A collector’s threat of “immediate arrest,” however, is not itself proof that a criminal case or warrant exists. Ordinary nonpayment of a debt does not automatically establish a crime, although fraud or other independently unlawful conduct may present a different issue.
Common mistakes to avoid
- Deleting the app or messages before preserving evidence.
- Assuming every loan threat is fake. Verify genuine court notices and the lender’s identity.
- Posting unredacted screenshots. This may expose account numbers, IDs, phone numbers, or other people’s data.
- Arguing only by telephone. Follow up in writing so there is a usable record.
- Treating a character reference as automatically liable. Ask for the actual undertaking signed or accepted by that person.
- Paying an unknown collector without verification. Confirm the payee and obtain an official receipt.
- Assuming a privacy violation cancels the loan. Collection misconduct and the underlying payment obligation are separate questions.
- Filing a bare complaint without documents. Identify the lender, app, collector, dates, recipients, statements made, and requested relief.
Frequently asked questions
Can a lending app call my mother or sibling because I missed a payment?
Not merely because the person is related to you or appears in your phone. Debt-collection contact is generally limited to you and persons who validly undertook liability, such as a guarantor. A relative who did not agree to the obligation is not responsible for paying it.
Can the app ask a relative to tell me to call?
Even a message framed as a “callback request” can be improper if it uses a person from the borrower’s contact list for collection or reveals the debt. The exact content, source of the number, recipient’s role, and surrounding conduct matter.
I named my friend as a character reference. Can the collector demand payment from them?
No. A character reference may be contacted for identity and application-information verification. The reference is not automatically a guarantor and should not be used for debt collection.
Can my employer deduct the loan from my salary?
Not simply because a collector demands it. A lawful deduction requires an applicable legal basis, valid authorization, or enforceable legal process. The underlying documents and labor-law rules should be reviewed before any deduction is made.
Can the lender contact my ex-partner?
Only if there is a separate lawful basis—for example, the former partner validly became a guarantor, co-maker, or co-borrower. A past romantic or marital relationship alone does not authorize collection contact or create liability.
What if the relative or former partner signed as a co-maker?
Then the person may have their own contractual liability and may be contacted regarding that obligation. Whether the person is truly a co-maker, guarantor, or merely a reference depends on the document they personally signed or validly accepted.
Can a collection agency do what the lending app cannot?
No. Outsourcing collection does not create broader collection or data-processing rights. SEC rules expressly cover relevant third-party service providers, and the lender remains accountable for personal data processed on its behalf.
Does harassment make the debt disappear?
No. A borrower may challenge unlawful collection and still owe a valid balance. Request an account statement, dispute errors in writing, and discuss a realistic payment arrangement without surrendering privacy rights.
Should a contacted relative reply?
They may state once, in writing, that they are not a guarantor, co-maker, or borrower; demand that contact and processing of their data stop; and request removal of their details. They should preserve the exchange and avoid supplying the borrower’s location, workplace, new number, or other personal information.
Official legal sources
- Republic Act No. 10173 — Data Privacy Act of 2012
- NPC Circular No. 2022-02 — Loan-related personal-data processing amendments
- NPC circulars and advisories
- SEC Memorandum Circular No. 18, Series of 2019 — Unfair debt collection practices
- Republic Act No. 9474 — Lending Company Regulation Act of 2007
- NPC formal complaint instructions
- NPC complaint mechanics
This article provides general Philippine legal information, not legal advice or a prediction of how a regulator or court will decide a particular case. Liability may depend on the loan documents, consent records, recipient’s role, lender’s regulator, communications, and other facts. Official sources and procedures were checked as of September 2, 2026.