Quick answer
If an online lending app or its collector is threatening you, publicly shaming you, contacting people from your phone for debt collection, or misusing your personal data, you can report the conduct to the government agency that has jurisdiction over the particular violation.
For lending and financing companies, unfair debt collection practices may be reported to the Securities and Exchange Commission (SEC), Financing and Lending Companies Department (FINLEND). Privacy violations may be complained of before the National Privacy Commission (NPC). Threats, fraud, scams, impersonation, hacking, and other potentially criminal conduct may also be reported to the DICT Cyber Hotline, NBI Cybercrime Division, or PNP Anti-Cybercrime Group. The DICT, NPC, and SEC expressly identified these channels in their joint advisory dated 18 March 2026.
A borrower does not lose the protection of the law simply because a loan is unpaid. The Financial Products and Services Consumer Protection Act expressly prohibits abusive collection or debt-recovery practices. At the same time, harassment or a privacy violation does not automatically cancel a valid loan. The debt and the manner of collecting it are separate issues. (Lawphil)
For an NPC privacy complaint, there is an important procedural rule: ordinarily, you must first notify the lender, collector, personal information controller, or other respondent in writing about the privacy violation and give it an opportunity to act. If it takes no timely or appropriate action, or gives no response within 15 calendar days from receipt, you may proceed with the NPC complaint. The NPC may waive this requirement for good cause or sufficiently serious cases, including situations involving grave and irreparable harm, lack of an adequate remedy from the respondent, or patently illegal conduct. (National Privacy Commission)
What online lending practices may violate Philippine law?
Not every collection message is unlawful. A creditor may make legitimate efforts to collect an actual debt. The problem arises when collection methods become abusive or when personal information is processed beyond what is lawful, necessary, and proportionate.
The March 2026 DICT-NPC-SEC advisory specifically states that unnecessary processing of personal data and unnecessary app permissions are prohibited. It also prohibits unauthorized, excessive, or disproportionate processing of borrowers' contact lists, including processing that results in harassment or unfair collection practices. Threats of violence or other criminal means, and threats to take action that cannot legally be taken, are specifically identified as prohibited conduct.
Contacting your relatives, friends, co-workers, or other phone contacts
One of the clearest current rules concerns phone contacts.
The 2026 joint advisory states that contacting persons on a borrower's contact list other than persons named as guarantors is prohibited for debt-collection purposes. For debt collection under the advisory, lending companies, financing companies, and persons acting as such may contact the guarantor.
NPC rules also distinguish a character reference from a guarantor. A character reference is provided for verification of the borrower's identity and the truthfulness of information supplied for the loan. Being named as a character reference does not automatically make that person liable for the loan. A guarantor, by contrast, must expressly bind himself or herself to answer for the borrower's obligation, and the lender must obtain the guarantor's separate consent. (National Privacy Commission)
This means an online lender cannot simply treat everyone found in your phone as a legitimate collection target.
A genuine co-maker, guarantor, or other person who actually signed loan documents may have a different legal position. If the lender claims that another person is legally liable for the debt, the signed loan documents should be examined rather than relying on the collector's description of that person.
Accessing your entire contact list
Access to contacts is not absolutely forbidden in every circumstance. The 2026 advisory allows limited processing, such as allowing the borrower to select character references or guarantors and, where justified, deriving proportionate metadata for a specified and legitimate purpose. What is prohibited is unbridled, excessive, or disproportionate processing.
Accordingly, pressing “Allow Contacts” when installing an app is not a blanket legal authorization to copy your address book, message everyone in it, shame you before your family or employer, or use the information for purposes unrelated to the legitimate loan transaction.
Using other phone permissions
The same principle applies to permissions involving your camera, photographs, and other device data. Permissions must be necessary for a specified and legitimate purpose. The 2026 advisory gives identity verification and know-your-customer procedures as examples of legitimate reasons for temporary camera or gallery access and states that permissions should be turned off or revoked once their purpose has been fulfilled and no other lawful basis applies.
The Data Privacy Act likewise requires personal-data processing to comply with transparency, legitimate purpose, and proportionality. Personal information should be adequate and relevant without being excessive and should generally be retained only as long as necessary for its lawful purpose, legal claims, legitimate business purposes, or requirements of law. (Lawphil)
Public shaming and disclosure of your loan
Posting your name, photograph, loan information, identification documents, accusations, or other personal information on social media or sending such material to unrelated third persons can raise serious privacy and collection issues.
Whether a particular disclosure constitutes a specific offense under the Data Privacy Act depends on the information disclosed, the legal basis for processing it, the identity and role of the person who disclosed it, the purpose, consent if any, and the surrounding evidence. The DPA contains separate offenses involving matters such as unauthorized processing, processing for unauthorized purposes, malicious disclosure, and unauthorized disclosure. Criminal liability should therefore be assessed from the actual evidence rather than assumed merely from the label “harassment.” (National Privacy Commission)
The main laws that protect borrowers
Data Privacy Act of 2012
Republic Act No. 10173 regulates the collection, use, storage, disclosure, and other processing of personal information. Even where a lender has a legitimate reason to process some information to evaluate or administer a loan, that does not eliminate the requirements of lawful, fair, proportionate, and purpose-limited processing. (Lawphil)
Consent is also not necessarily the only legal basis for processing. A lender may process information when another lawful basis under the DPA applies, such as when processing is necessary for a contract or legal obligation. Conversely, merely obtaining a click or permission does not automatically make excessive processing lawful.
NPC rules specifically governing loan-related data
NPC Circular No. 20-01, as amended by NPC Circular No. 2022-02, addresses personal-data processing in loan-related transactions. Among other safeguards, the amended rules restrict unnecessary app permissions, excessive contact processing, debt collection through persons other than guarantors, and misuse of character-reference information. (National Privacy Commission)
Financial Products and Services Consumer Protection Act
Republic Act No. 11765 requires financial service providers to treat clients fairly and respectfully, protect client data, and maintain a consumer-assistance mechanism for complaints. It expressly prohibits abusive collection and debt-recovery practices. A consumer who is dissatisfied with the provider's handling of a complaint may elevate the matter to the appropriate financial regulator. (Lawphil)
The law also prevents lenders from escaping responsibility merely by outsourcing collection. A financial service provider is responsible for acts or omissions of its directors, officers, employees, and agents in dealings with financial consumers and is solidarily liable with accredited third-party service providers for acts or omissions in activities that may include debt collection. (Lawphil)
Step 1: Preserve the evidence before blocking or uninstalling the app
Evidence often determines whether a regulator can act on a complaint. Before deleting the app, blocking every number, resetting the phone, or clearing messages, preserve what happened.
Keep the original material whenever possible. Screenshots are useful, but avoid keeping only heavily cropped or edited versions. Record dates, times, account names, phone numbers, URLs, and the sequence of events.
Useful evidence commonly includes:
- screenshots and screen recordings of threatening, insulting, shaming, or deceptive messages; call logs, voice messages, emails, and collection notices; screenshots of the app's permissions and privacy notice; the app-store listing, developer name, and legal company name; loan agreements, disclosure statements, account statements, payment receipts, and proof of disbursement; copies of messages sent to relatives, friends, co-workers, or character references; statements or screenshots supplied by those recipients; evidence of social-media posts or group messages; the names or identifiers used by collectors; your written complaint to the lender or its data protection officer and proof that it was received; and every SEC, NPC, DICT, NBI, PNP, or other government ticket or reference number.
If another person's account or phone received the harassment, ask that person to preserve the original message as well. A forwarded screenshot may be helpful, but the original recipient's copy and testimony can provide important context.
Step 2: Protect your device and accounts
After preserving evidence, review the app's permissions and revoke permissions that are unnecessary or no longer required. If you believe passwords, PINs, email credentials, social-media accounts, or financial accounts may have been compromised, secure them through their official providers.
Do not give a collector an OTP, password, recovery code, or remote access to your device. If there are unauthorized financial transactions, report those transactions separately to the relevant bank, e-wallet, or financial service provider.
The 2026 government advisory specifically reminds borrowers to review permissions and states that an OLP should prompt users to turn off or revoke a permission after its purpose has been achieved when no other lawful basis remains.
Step 3: Send a written complaint to the lender or responsible entity
This step is particularly important if you intend to file with the NPC.
Address the written complaint to the lending company, financing company, app operator, collector, data protection officer, or other responsible entity as the facts require. Use an official channel that gives you reliable proof of transmission or receipt.
State your full name and loan or account reference, identify the app and legal company if known, describe each incident with dates and times, identify the numbers or accounts used by the collector, specify which personal information was accessed or disclosed, and identify the people who were contacted.
Ask the respondent to stop the complained-of conduct, investigate the collectors involved, stop unauthorized or unnecessary processing, preserve relevant call logs and collection records, correct inaccurate information where applicable, address any lawful request concerning your data, and provide a written response.
If you are withdrawing consent for optional or unnecessary processing, say so clearly. However, withdrawing consent does not necessarily require deletion of every record immediately. A lender may still have another lawful basis to retain certain information, including legal retention requirements or the establishment, exercise, or defense of legal claims. The 2026 advisory expressly recognizes those retention grounds.
Most importantly for an eventual NPC case, keep proof that the written notice was received.
Step 4: Report unfair debt collection to the SEC
For unfair collection by a lending or financing company, the 18 March 2026 joint government advisory directs complaints to the SEC Financing and Lending Companies Department (FINLEND) through the SEC iMessage system. The advisory also lists the SEC hotline 1-4732 (1-4SEC).
The SEC's current iMessage manual includes a FINLEND Legal and Enforcement Division ticket category for complaints on financing and lending companies. (SEC Philippines)
In the complaint, identify the legal corporate entity if you can. Online lending apps frequently use a brand or app name that differs from the name of the company holding the lending or financing authority. Preserve the app-store page, loan contract, disclosure statement, payment instructions, and privacy notice because these may help connect the brand to the actual operator.
The SEC continues to maintain official information concerning lending and financing companies, including advisories and information concerning recorded online lending platforms. (Securities and Exchange Commission)
Step 5: File the privacy complaint with the NPC
If the misconduct involves misuse, excessive collection, unlawful disclosure, contact-list harvesting, inappropriate retention, or another violation involving personal data, the National Privacy Commission is the principal privacy regulator.
Under the NPC's current complaint mechanics, a complainant generally must first inform the respondent in writing of the privacy violation or personal data breach. If the respondent fails to take timely or appropriate action, or there is no response within 15 calendar days from receipt, the complainant may proceed. Proof of compliance should be attached. (National Privacy Commission)
The NPC may waive that requirement at its discretion when good cause is properly alleged and proved or when the complaint involves a serious DPA violation or breach considering the risk of harm. The rules specifically mention grave and irreparable damage that only NPC action can prevent or mitigate, situations where the respondent cannot provide a plain, speedy, or adequate remedy, and patently illegal conduct. Do not simply assume that a waiver will be granted; explain and document why one is necessary. (National Privacy Commission)
The NPC currently allows a filled-out and notarized Complaint-Assisted Form or a verified complaint, together with supporting evidence and witness affidavits, to be filed personally, by registered mail, by courier, or by electronic mail as authorized by the Commission. Its complaint instructions contain additional requirements for electronic documents. Because complaint forms and administrative instructions can change, download the current form directly from the NPC rather than using an old copy saved elsewhere. (National Privacy Commission)
The NPC's current website identifies complaints@privacy.gov.ph as its complaints email and lists its complaints contact numbers. (National Privacy Commission)
The NPC also states that, from receipt of a complaint, its Complaints and Investigation Division has 30 calendar days to give the complaint due course or dismiss it without prejudice. That is an initial procedural determination, not a guaranteed deadline for final resolution of the entire case. (National Privacy Commission)
Step 6: Report threats, fraud, scams, or cybercrime to the appropriate authorities
Do not treat the NPC's 15-day exhaustion rule as a reason to wait when there is an immediate safety or criminal concern. That requirement concerns the ordinary processing of an NPC privacy complaint; it does not prevent a person from seeking police or other law-enforcement assistance.
The March 2026 joint advisory identifies the following channels for other forms of harassment, threats, fraud, and scams: DICT Cyber Hotline at 1326@dict.gov.ph; NBI Cybercrime Division at ccd@nbi.gov.ph and (632) 8523-8231 to 38; and PNP Anti-Cybercrime Group at acg@pnp.gov.ph, onlinecims.ocs@gmail.com, and (632) 8723-0401 local 7491.
This route becomes particularly important where the facts involve credible threats of physical harm, extortion, account takeover, fraudulent transactions, impersonation, fabricated communications, hacking, or similar conduct requiring immediate investigation.
Preserve the evidence before blocking the sender whenever doing so is reasonably safe.
What if the lender is a bank, digital bank, or another BSP-supervised institution?
The SEC FINLEND route is directed primarily at lending and financing companies under SEC jurisdiction. If the creditor is a bank, digital bank, or another BSP-Supervised Financial Institution, use the institution's own financial consumer protection or customer-assistance mechanism first.
If the matter remains unresolved, the Bangko Sentral ng Pilipinas states that its Consumer Assistance Mechanism (CAM) is a second-level recourse for complaints against BSP-supervised institutions. Consumers may escalate through the BSP Online Buddy or, alternatively, submit the BSP Complaints, Inquiries and Requests form to consumeraffairs@bsp.gov.ph. (Bureau of the Treasury)
A privacy violation can still fall within the NPC's jurisdiction even when the financial institution itself is supervised by another financial regulator.
What should your complaint say?
A useful complaint is factual rather than emotional or conclusory.
Start with the identity of the lender, app, and collector. Explain when the loan was obtained and, if relevant, its present status. Then give a chronological account: what the collector said or did, which phone number or account was used, which personal information was accessed or disclosed, who was contacted, and when each incident occurred.
Separate what you personally witnessed from what another person reported to you. Attach the corresponding evidence and label it clearly.
State the relief you want. Depending on the facts, that may include stopping communications to non-guarantors, stopping public disclosure or harassment, correction of inaccurate information, investigation of the collector, appropriate restriction or deletion of unlawfully processed data, preservation of records, and a written explanation of what information was obtained and how it was used.
Do not exaggerate. A precise account supported by messages, records, and identifiable dates is generally more useful than broad accusations that cannot be matched to evidence.
Common mistakes that can weaken a complaint
Deleting the evidence too early
People understandably want to block collectors and uninstall intrusive apps immediately. Capture the relevant messages, permissions, privacy notices, account details, and app information first when it is safe to do so.
Filing an NPC complaint without the required prior written notice
Unless the NPC waives the requirement, failure to show that you first notified the respondent in writing and gave it the required opportunity to act can prevent the complaint from being given due course. (National Privacy Commission)
Complaining only under the app's brand name
Identify the corporation behind the app whenever possible. The loan agreement, disclosure statement, privacy notice, SEC records, app-store information, and payment instructions may reveal the legal entity.
Assuming a character reference is automatically liable
It is not. NPC rules expressly distinguish a character reference from a guarantor. A guarantor must separately and expressly consent to undertake that obligation. (National Privacy Commission)
Assuming “Allow Contacts” authorizes mass collection
It does not give an online lender unrestricted freedom to process or contact everyone in the phone. Current government guidance expressly prohibits unbridled processing and debt-collection contact with persons in the borrower's contact list other than guarantors.
Treating the complaint as proof that the loan disappeared
Collection misconduct and the underlying debt are different questions. Continue to preserve your loan documents and payment records. If the amount, interest, charges, or validity of the obligation is disputed, raise that issue separately and obtain advice based on the actual contract.
Retaliating by publicly posting other people's personal information
Preserve and submit relevant evidence to the proper authorities. Avoid unnecessary publication of collectors' private data, identification documents, telephone numbers, or unrelated personal information merely as retaliation.
What can regulators do?
The exact result depends on the respondent, the regulator's jurisdiction, the evidence, and the violation proved.
The Financial Products and Services Consumer Protection Act authorizes financial regulators to take enforcement measures for violations within their jurisdiction. Depending on the applicable law and proceedings, available measures may include fines, suspension, cease-and-desist measures, and suspension or cancellation of authority relating to a financial product or service. The Act also expressly prohibits abusive collection. (Lawphil)
The Data Privacy Act gives the NPC authority to receive complaints, investigate, adjudicate privacy matters, and exercise statutory enforcement powers. Certain proven acts may also fall within the DPA's criminal provisions, but criminal guilt and the applicable offense cannot be determined from a complaint allegation alone. (National Privacy Commission)
The 2026 DICT-NPC-SEC advisory likewise warns that violations of applicable laws, regulations, and SEC rules may expose financing and lending companies to administrative sanctions, including fines and suspension or revocation of authority to operate, as provided by the applicable law.
When legal help is urgent
Seek immediate assistance if the collector is making credible threats of physical harm; threatening or attempting extortion; impersonating authorities or using apparently fabricated legal documents; accessing accounts or devices without authorization; making unauthorized financial transactions; publishing sensitive information in a way that is causing continuing serious harm; or repeatedly threatening family members, children, employers, or other third parties.
Urgent legal advice is also appropriate if you have received an actual subpoena, summons, complaint, court document, or formal government notice. Do not assume that every document sent by a collector is genuine, but do not ignore a genuine official document either. Verify it through the issuing court or agency.
Where the danger is immediate, prioritize personal safety and law-enforcement assistance. The ordinary 15-day NPC exhaustion period should not be misunderstood as a requirement to remain exposed to ongoing threats before seeking other lawful protection.
FAQ
Can an online lending app call everyone in my contacts because I have an unpaid loan?
No. Current DICT-NPC-SEC guidance expressly prohibits contacting persons in the borrower's contact list other than guarantors for debt-collection purposes.
I allowed the app to access my contacts. Does that make the collection legal?
Not automatically. Personal-data processing must still have a lawful basis and comply with transparency, legitimate purpose, and proportionality. The 2026 advisory specifically prohibits unbridled, excessive, and disproportionate contact-list processing. (Lawphil)
Can the lender collect from my character reference?
A character reference is not automatically a guarantor. NPC rules define a character reference primarily for identity and information verification. A guarantor must separately and expressly consent to undertake responsibility for the loan. (National Privacy Commission)
Can I report an app even if it appears to be unregistered?
Yes. The March 2026 joint advisory expressly addresses entities offering or facilitating loans through online lending platforms whether recorded or unrecorded. Preserve the app's name, developer details, website, payment instructions, communications, and any information identifying the operator, and report the appropriate conduct to the relevant agency.
Can I file with the NPC immediately?
Ordinarily, first notify the respondent in writing. If it fails to take timely or appropriate action or does not respond within 15 calendar days from receipt, you may proceed with the NPC complaint. The NPC has discretion to waive this requirement for good cause or certain serious violations, but the grounds for waiver should be properly alleged and supported. (National Privacy Commission)
What if a third-party collection agency, not the lending app itself, harassed me?
Preserve evidence identifying both the collector and the financial service provider. Under Republic Act No. 11765, a financial service provider is responsible for acts or omissions of its employees and agents and may be solidarily liable with accredited third-party service providers for conduct that includes debt collection. (Lawphil)
Does reporting harassment mean I no longer have to pay the loan?
No. A complaint about collection methods does not by itself extinguish a legally valid debt. If you contest the loan balance, interest, fees, payments, identity of the creditor, or validity of the agreement, those questions should be addressed separately based on the contract and records.
Can the lender keep my personal information after I repay the loan?
Not indefinitely merely because it wants to. The applicable rule is purpose- and law-dependent. The 2026 advisory says lenders should retain borrowers' personal data only as long as necessary for the purpose for which it was obtained, for the establishment, exercise, or defense of legal claims, or as otherwise provided by law, after which secure disposal should follow.
Where do I complain if the loan came from a bank or digital bank?
First use the bank or other BSP-supervised institution's own consumer-assistance channel. If unresolved, the BSP Consumer Assistance Mechanism is the second-level recourse. Privacy issues may separately be brought to the NPC subject to its procedural rules. (Bureau of the Treasury)
Official sources
DICT-NPC-SEC Public Advisory on Online Lending Platforms, 18 March 2026: Official joint advisory
National Privacy Commission — complaint procedures: NPC Mechanics for Complaints
National Privacy Commission — loan-related privacy rules and 2022 amendments: NPC guidance on amended loan-data rules
Data Privacy Act of 2012, Republic Act No. 10173: Lawphil text of RA 10173
Financial Products and Services Consumer Protection Act, Republic Act No. 11765: Lawphil text of RA 11765
SEC Financing and Lending Companies advisories and notices: SEC lending and financing advisories
SEC complaint portal: SEC iMessage
Bangko Sentral ng Pilipinas — Consumer Assistance Mechanism: BSP Consumer Assistance Mechanism
General-information disclaimer
This article provides general Philippine legal information and is not a substitute for advice based on the particular loan agreement, messages, app permissions, evidence, identities of the parties, and surrounding facts of a specific case. Regulatory procedures and contact channels can change. Official sources and procedures cited here were checked as of 23 August 2026.