Quick answer
Doxxing—publishing or circulating someone’s identifying information to expose, intimidate, shame, threaten, impersonate, or mobilize others against that person—is not named as one stand-alone crime under Philippine law. It can nevertheless violate one or more laws depending on what information was disclosed, how it was obtained, why it was shared, who was targeted, and what harm or risk followed.
Possible violations include:
- unauthorized processing or disclosure under the Data Privacy Act;
- computer-related identity theft under the Cybercrime Prevention Act;
- gender-based online sexual harassment under the Safe Spaces Act;
- cyberlibel, grave threats, unjust vexation, or another offense under the Revised Penal Code;
- psychological violence under the Anti-Violence Against Women and Their Children Act; and
- civil violations of a person’s dignity, privacy, and peace of mind.
Not every publication of personal information is unlawful. Information may sometimes be disclosed with consent, under a legal duty, to protect lawful rights, for legitimate journalism, or for another purpose recognized by law. Even information found online, however, is not automatically free to weaponize. The complete facts and the original source of the data matter.
If the post reveals a home address, daily routine, workplace, children’s details, identification numbers, financial information, medical information, or live location—and especially if it includes threats or encourages confrontation—preserve the evidence and seek police or legal help immediately.
What counts as doxxing?
“Doxxing” usually means identifying or locating a person online by publishing or assembling information such as:
- a home or work address;
- telephone numbers or private email addresses;
- a full birth date or family details;
- photographs of identification documents;
- government-issued identification numbers;
- school, employer, vehicle, or travel information;
- financial, health, or sexual information;
- real-time or frequently visited locations; or
- information identifying children or relatives.
The information may be genuine, partly inaccurate, or taken from several sources and combined into a profile. A typical doxxing incident also has a harmful context: threats, public shaming, demands for others to contact the victim, false accusations, impersonation, or invitations to visit the victim’s home or workplace.
The label “doxxing” does not decide the case. Investigators and courts examine the acts that can be proved and the elements of the particular offense alleged.
When doxxing may violate the Data Privacy Act
Republic Act No. 10173, or the Data Privacy Act of 2012, governs the processing of personal information. “Processing” is broad and includes collecting, recording, organizing, storing, using, modifying, retrieving, consulting, blocking, erasing, or destroying personal data. Posting, forwarding, or compiling personal information can therefore amount to processing.
Personal information is information from which a person is apparent or can reasonably and directly be identified, or which, when combined with other information, would directly and certainly identify that person.
The Act gives stricter protection to sensitive personal information, including information about a person’s health, education, sexual life, marital status, race, age, religious or political affiliations, government-issued identifiers, tax returns, and certain information specifically classified by law.
The basic privacy rule
Processing must have a lawful basis and must comply with transparency, legitimate purpose, and proportionality. For ordinary personal information, lawful grounds can include consent, contractual or legal necessity, protection of vital interests, public authority, or a legitimate interest that is not overridden by the person’s fundamental rights.
Sensitive personal information is generally prohibited from processing unless a specific exception applies. These exceptions are narrower and include consent specific to the purpose, authorization by law, protection of life or health in limited circumstances, medical treatment, or information necessary to establish or defend legal claims.
Accordingly, a person or organization that obtains private contact details for one purpose and then publishes them to shame or endanger someone may face liability for:
- unauthorized processing under Section 25;
- processing for an unauthorized purpose under Section 28;
- malicious disclosure under Section 31, where its specific requirements apply; or
- unauthorized disclosure by a personal information controller, processor, officer, employee, or agent under Section 32.
The precise provision depends on the accused person’s role, the nature of the data, the authority or consent claimed, and the purpose of processing. Criminal liability must be proved under the elements of the applicable section; an offensive or harmful post does not automatically establish every Data Privacy Act offense.
The National Privacy Commission (NPC) has also reminded the public that sharing photos and videos containing personal data must have a lawful basis and comply with the privacy principles of transparency, legitimate purpose, and proportionality. Its official guidance warns that irresponsible sharing can expose people to identity theft, fraud, harassment, and stalking. See the NPC’s reminder on sharing photos and videos containing personal data.
Does the Act cover information already available online?
Personal information does not necessarily lose all legal protection merely because it appeared on a public page, directory, or earlier post. The later user must still consider the source, purpose, context, applicable lawful basis, and whether the new use is fair and proportionate.
But public availability is legally significant. In Disini v. Secretary of Justice, the Supreme Court stated that acquiring and disseminating information made public by the user cannot be treated as computer-related identity theft. That ruling does not create a general license to harass, threaten, defame, impersonate, or unlawfully process a person’s data. It addresses the elements of identity theft under the Cybercrime Prevention Act. Read the Supreme Court’s decision in Disini.
Computer-related identity theft
Section 4(b)(3) of Republic Act No. 10175, the Cybercrime Prevention Act of 2012, punishes the intentional acquisition, use, misuse, transfer, possession, alteration, or deletion of another person’s identifying information without right.
The Supreme Court explained in Disini that the offense concerns specific acts involving another person’s identifying data and that the theft of identity information must be intended for an illegitimate purpose. Damage affects the applicable penalty, but the statute provides for a penalty one degree lower if no damage has yet occurred.
This provision may be relevant when identifying information is taken without right and used for impersonation, fraudulent accounts, fabricated documents, targeted attacks, or another illegitimate purpose. A bare allegation that someone “stole my identity” is insufficient; the acquisition or use, absence of right, intent, and other statutory elements must be supported by evidence.
When the Safe Spaces Act applies
Section 12 of Republic Act No. 11313, or the Safe Spaces Act, defines gender-based online sexual harassment broadly. It includes certain online threats, sexist or anti-LGBTQ remarks, cyberstalking, incessant messaging, impersonation, reputation-harming lies, and unauthorized sharing of a victim’s photos, videos, or information online.
Doxxing may fall under this law when it is gender-based and sexual in character or context. The statute does not convert every non-consensual disclosure into gender-based online sexual harassment; the surrounding words, conduct, motive, and relationship must bring the act within the statutory definition.
The prescribed penalty for gender-based online sexual harassment is prision correccional in its medium period, a fine of ₱100,000 to ₱500,000, or both, at the court’s discretion. The next higher penalty applies in specified qualified cases, including when the offended person is a minor, senior citizen, person with disability, or a breastfeeding mother, and in certain cases involving uniformed personnel or government frontline-service premises.
The PNP Anti-Cybercrime Group is identified by the Act as the primary body to receive complaints involving gender-based online sexual harassment.
Other laws that may apply
Cyberlibel
If the post contains a public and malicious accusation or imputation that tends to dishonor or discredit an identifiable person, cyberlibel may be considered under Article 355 of the Revised Penal Code in relation to Section 4(c)(4) of the Cybercrime Prevention Act.
Truth alone is not a universal defense to every libel allegation. Privilege, good motives, justifiable ends, malice, identification, publication, and the exact language and context may all matter. Sharing or reacting to a post does not create automatic liability in every instance, but adding a defamatory caption, independently republishing content, or deliberately widening its circulation can materially change the analysis.
Threats, coercion, or unjust vexation
A doxxing post may be evidence of grave threats, light threats, grave coercion, unjust vexation, or another Revised Penal Code offense when it is accompanied by threats of harm, demands backed by intimidation, repeated harassment, or conduct causing annoyance or distress. The correct offense depends on the words used, whether a condition or demand was imposed, the seriousness and immediacy of the threatened harm, and the whole course of conduct.
Under Section 6 of the Cybercrime Prevention Act, crimes under the Revised Penal Code and special laws committed by, through, and with information and communications technology may carry the consequences specified in that section. Charging and sentencing questions should be assessed by a prosecutor or lawyer from the actual evidence.
Violence against women and their children
Republic Act No. 9262, the Anti-Violence Against Women and Their Children Act, may apply when the perpetrator is the victim’s spouse, former spouse, dating or former dating partner, sexual partner, or a person with whom she has a common child.
The law covers psychological violence, harassment, stalking, intimidation, public ridicule, humiliation, and conduct causing substantial emotional or psychological distress. Victims may seek barangay, temporary, or permanent protection orders when the legal requirements are met. Available relief can include prohibiting the respondent from contacting, threatening, or approaching the victim.
Civil liability for invasion of privacy
Articles 19, 20, 21, and 26 of the Civil Code protect human dignity, privacy, and peace of mind and provide possible bases for damages.
Article 26 specifically requires every person to respect the dignity, personality, privacy, and peace of mind of others. Depending on the proof, a victim may seek damages or injunctive relief. A civil claim requires proof of its legal elements, including actionable conduct, injury, and a sufficient connection between the conduct and the loss claimed.
Writ of habeas data
A writ of habeas data is an extraordinary remedy—not a general remedy for every offensive post. It may be available when an unlawful act or omission by a public official, employee, private individual, or entity engaged in gathering, collecting, or storing data violates or threatens a person’s privacy in relation to life, liberty, or security.
The Supreme Court requires a real connection between the privacy violation and a threat to life, liberty, or security. The writ may be important in serious cases involving organized data collection, surveillance, targeting, or credible danger. See Gamboa v. Chan on the scope of habeas data.
What to do immediately
1. Address physical danger first
If the post reveals where you live or are presently located, contains a credible threat, invites others to confront you, or identifies a child:
- contact the police or emergency services;
- move temporarily to a safer location if necessary;
- alert household members, building security, school officials, or workplace security;
- avoid meeting or confronting the poster; and
- ask law enforcement about preserving subscriber and traffic data before it is routinely deleted.
The Cybercrime Prevention Act generally requires service providers to preserve specified traffic data and subscriber information for at least six months from the transaction. Content data may be preserved upon a proper law-enforcement order. Access, disclosure, or seizure of protected data ordinarily requires lawful process, including the applicable cybercrime warrant. A private complainant should not attempt to obtain restricted account data through hacking, deception, or another unlawful method.
2. Preserve evidence before requesting removal
Save evidence in a way that shows context and authenticity:
- take full-screen screenshots showing the post, account name, date, time, and platform;
- copy the exact URL of each post, profile, image, video, and comment;
- record the username, display name, profile URL, account ID if visible, and any prior names;
- capture the entire conversation, not only selected messages;
- download original emails, messages, photographs, videos, or account archives where available;
- retain files in their original format with metadata intact;
- note when and how you discovered the disclosure;
- preserve platform notices, report numbers, takedown responses, and account-security alerts;
- list witnesses who saw the material and ask them to preserve their own copies;
- document calls, visits, threats, lost work, relocation costs, medical treatment, and other consequences; and
- keep at least two secure copies, with one stored away from the affected device.
Do not edit the only copy, crop away identifying details, annotate the original file, or repeatedly forward sensitive material. Create a working copy if redactions are necessary.
3. Reduce immediate exposure
After preserving evidence:
- report the content through the platform’s privacy, harassment, impersonation, or personal-information channel;
- request removal from group administrators, website operators, or the responsible organization;
- change exposed passwords and enable multi-factor authentication;
- change account-recovery questions if the answers were disclosed;
- review active sessions and revoke unknown devices or applications;
- warn banks or mobile providers if financial or identity information was exposed; and
- consider changing a compromised phone number or email address.
A takedown can reduce harm, but it does not guarantee deletion from screenshots, mirrors, search caches, or other users’ devices.
Where to report or file a complaint
Different remedies may be pursued at the same time, but each has its own jurisdiction and requirements.
PNP or NBI
For threats, identity theft, cyberlibel, gender-based online sexual harassment, hacking, impersonation, or another possible crime, report promptly to the PNP Anti-Cybercrime Group or the NBI Cybercrime Division. Bring identification, a chronological statement, original devices if requested, printed evidence, electronic copies, URLs, and witness information.
The Cybercrime Prevention Act designates both the PNP and NBI as cybercrime law-enforcement authorities. The NBI provides an official online complaint page and information on investigative assistance for victims of computer crimes.
An initial report is not the same as a filed criminal case. Investigators gather evidence, and the proper prosecution office determines whether probable cause exists based on the complaint-affidavit, counter-affidavit, and supporting records.
National Privacy Commission
For a possible Data Privacy Act violation, first notify the responsible person, business, agency, personal information controller, processor, or concerned entity in writing and ask for specific corrective action. Keep proof that the notice was received.
Under the 2021 NPC Rules of Procedure, a complaint ordinarily will not be given due course unless:
- the complainant informed the respondent in writing of the privacy violation or personal data breach; and
- the respondent failed to take timely or appropriate action, or did not respond within 15 calendar days after receiving the notice.
The NPC may waive these requirements for good cause or a serious violation, including circumstances involving grave and irreparable harm, the absence of a plain and adequate remedy, or patently illegal action.
A formal NPC complaint must generally be written, signed, verified, supported by the relevant facts and evidence, and accompanied by a certification against forum shopping. If a related case is later discovered, the complainant must report it to the NPC within five calendar days. Current filing modes, forms, fees, exemptions, and instructions are available on the NPC’s formal-complaint page.
Workplace or school
If the conduct occurred in a workplace or educational institution and is gender-based sexual harassment, report it to the employer’s or school’s internal mechanism or Committee on Decorum and Investigation. The Safe Spaces Act requires these bodies to observe due process, protect complainants from retaliation, and decide complaints within ten days or less from receipt.
An internal complaint does not necessarily replace police, prosecution, NPC, or court remedies.
Common mistakes to avoid
- Arguing publicly with the doxxer. This may increase circulation, reveal more information, or escalate a threat.
- Reporting before preserving evidence. A successful takedown can remove material needed to identify the account or prove publication.
- Saving only cropped screenshots. Preserve URLs, dates, usernames, surrounding comments, and the full conversation.
- Reposting the doxxing content as a warning. This may further expose the victim and create separate legal or privacy issues.
- Assuming an anonymous account cannot be investigated. Platforms and service providers may hold relevant records, although disclosure requires proper legal process and data may not be retained indefinitely.
- Hacking the suspected account. Illegally accessing another account or device can create criminal exposure and undermine the complaint.
- Treating every harmful post as cyberlibel. Privacy, identity theft, threats, harassment, and civil remedies have different elements.
- Waiting for all harm to occur. Early reporting is especially important when a post exposes a location, children, financial credentials, or information capable of enabling violence.
- Missing formal NPC requirements. Prior written notice, verification, supporting evidence, certification against forum shopping, and any applicable fee or exemption should be checked before filing.
- Assuming deletion ends the matter. Preserve proof of the original publication, takedown request, removal, republication, and continuing consequences.
When legal help is urgent
Consult a lawyer or approach the Public Attorney’s Office, if eligible, without delay when:
- there is a credible threat of physical harm, abduction, stalking, or sexual violence;
- the disclosure identifies a child or vulnerable person;
- an intimate image or sexual information is involved;
- government identification, banking, medical, or authentication information was exposed;
- the poster knows the victim’s current location or routine;
- the harassment comes from a spouse, former partner, dating partner, or person with whom the victim has a common child;
- the doxxer is an employer, school, government office, lender, or other organization holding data in confidence;
- copies are spreading across several accounts or platforms;
- urgent injunctive relief, a protection order, or a writ of habeas data may be necessary; or
- a filing deadline may be approaching.
Prescription periods vary with the offense and remedy, and identifying the correct starting date can be fact-sensitive. Do not assume that every cyber-related claim has the same deadline.
Frequently asked questions
Is posting someone’s address automatically a crime?
Not automatically. Liability depends on how the address was acquired, the poster’s right or lawful basis, the purpose and context of publication, accompanying threats or statements, and the resulting harm or danger. Publishing a private home address to facilitate harassment is materially different from using an official business address for a legitimate transaction.
Is doxxing legal if the information came from a public profile?
Public availability may defeat a claim of computer-related identity theft based solely on acquiring and disseminating information the user made public, as explained in Disini. It does not excuse threats, impersonation, defamation, gender-based harassment, disproportionate data processing, or misuse for an unlawful purpose.
Can I file against an unknown or fake account?
Yes, a report may begin even if the real person is unknown. Preserve the profile URL, username, account ID, messages, payment details, email headers, phone numbers, and any facts connecting the account to a person. Law enforcement may seek subscriber or computer data through the required legal process.
Should I message the doxxer before going to the NPC?
Ordinarily, the NPC requires written notice to the respondent or concerned entity and proof that it failed to act appropriately or respond within 15 calendar days. The NPC may waive this requirement in serious or urgent circumstances. Do not contact a dangerous person directly if doing so could increase the risk; explain the danger and request a waiver.
Can I ask for compensation?
Potentially. The NPC may award indemnity under its authority when legally justified, and a civil court may award damages under the Civil Code or another applicable law. Compensation is not automatic; the claimant must prove the legal basis, injury, and causal connection.
Can the police immediately obtain the doxxer’s account records?
Not merely upon request by a private complainant. Subscriber information, traffic data, content, and devices are subject to statutory and constitutional safeguards. Investigators must use the appropriate preservation request, disclosure process, or court-issued cybercrime warrant.
What if the doxxing was done by my former partner?
If you are a woman and the offender is a spouse, former spouse, dating or former dating partner, sexual partner, or person with whom you have a common child, Republic Act No. 9262 may provide criminal and protection-order remedies. Other privacy and cybercrime laws may also apply.
What if the information is false?
False identifying information used to impersonate you, direct hostility toward you, or damage your reputation may support identity-theft, cyberlibel, Safe Spaces Act, civil, or other claims depending on the evidence. Preserve both the false statement and proof of the correct facts.
This article provides general legal information, not legal advice or a prediction of any case’s outcome. Liability and remedies depend on the exact posts, source of the data, parties’ relationship, evidence, and applicable procedure. Primary legal and official government sources were checked as of 7 September 2026.