Quick answer
Report abusive collection by most online lending apps to the Securities and Exchange Commission (SEC) through the SEC iMessage Portal, directing the complaint to the Financing and Lending Companies Department (FinLenD). Report unauthorized access, use, or disclosure of contacts, photos, IDs, employment details, or other personal data separately to the National Privacy Commission (NPC).
Go immediately to law enforcement when the incident involves a credible threat of physical harm, blackmail, account takeover, fraudulent transfers, impersonation, or another possible crime. Dial 911 if anyone is in immediate danger.
One incident may properly be reported to several agencies because they address different issues:
| Main issue | Proper channel |
|---|---|
| Harassment, debt-shaming, deceptive collection, contacting unrelated people, or an unauthorized lending company | SEC–FinLenD |
| Misuse or disclosure of contacts, photos, IDs, loan details, or other personal data | NPC |
| Loan from a bank, e-money issuer, or another BSP-supervised institution | Institution first, then BSP if unresolved |
| Threats, hacking, blackmail, fraud, identity misuse, or immediate danger | Police, NBI, or other appropriate law-enforcement authority |
A complaint does not automatically cancel a valid loan, erase the balance, or suspend payment. It asks the proper authority to investigate the lender’s conduct. Continue requesting a written statement of account and dispute only the charges or practices you genuinely contest.
What conduct may be unlawful?
A lender may send reasonable payment reminders, demand an amount actually due, negotiate repayment, and pursue lawful collection or court remedies. An unpaid account does not authorize humiliation, threats, deception, or indiscriminate disclosure of the debt.
Harassment and unfair debt collection
SEC Memorandum Circular No. 18, Series of 2019 prohibits lending companies, financing companies, and their collection service providers from engaging in practices such as:
- Threatening violence or other criminal means against a person, reputation, or property.
- Threatening an action that cannot legally be taken.
- Using obscenities, insults, or profane language that abuses the borrower or amounts to an offense.
- Publishing or disclosing the names and personal information of borrowers who allegedly refuse to pay, except when disclosure is legally allowed.
- Communicating loan information known, or which should be known, to be false—including failing to state that a debt is disputed.
- Using false representations or deceptive means to collect a debt or obtain information.
- Contacting a borrower before 6:00 a.m. or after 10:00 p.m., subject to the circular’s limited exceptions where the account is more than 15 days past due or the borrower expressly agreed that those are the only reasonable contact times.
- Contacting people found in the borrower’s contact list who were not named guarantors or co-makers, even if the borrower supposedly consented to contact-list access.
The company remains responsible for collection work it outsources. The Financial Products and Services Consumer Protection Act also prohibits abusive debt-recovery practices and makes a financial service provider responsible for its personnel and solidarily liable with accredited third-party providers for covered acts or omissions, including debt collection. See SEC Memorandum Circular No. 18 and Republic Act No. 11765.
The time-of-contact rule above applies specifically to SEC-regulated financing and lending companies. Different product-specific rules may apply to banks, credit cards, and other BSP-supervised institutions.
Contact blasting and debt-shaming
The following are strong reasons to report an online lender:
- It messaged your relatives, friends, co-workers, employer, neighbors, or social-media contacts about your debt.
- It sent group messages containing your name, photograph, ID, balance, alleged offenses, or insulting statements.
- It falsely told contacts that they were guarantors or legally required to pay.
- It posted your photograph or loan information online.
- It threatened to contact everyone in your phone or workplace unless you paid immediately.
- It used a fake court notice, police identity, law-office name, or government logo to frighten you.
- It threatened immediate arrest solely for nonpayment of an ordinary debt.
The Constitution states that no person may be imprisoned for debt. That does not prevent liability for an independently committed criminal act, so conclusions still depend on the actual facts—not merely on the existence of an unpaid loan. See Article III, Section 20 of the Constitution.
Excessive or unauthorized access to personal data
Allowing an app permission to access a device is not a blank check. Processing must still be transparent, for a legitimate purpose, and proportionate to that purpose.
Under NPC Circular No. 2020-01, as amended by NPC Circular No. 2022-02:
- Unnecessary or excessive app permissions are prohibited.
- Access should begin only when the information is actually needed.
- The app should prompt the user to revoke a permission after its purpose has been fulfilled.
- Camera or photo-gallery access may be allowed for a legitimate stage such as identity verification, fraud prevention, or payment verification, but the borrower’s photograph must not be used for harassment or embarrassment.
- Unrestrained or excessive processing of contact lists—including processing that leads to harassment or unfair collection—is prohibited.
- Access to a contact list must be limited to the minimum necessary for the borrower to select a character reference or guarantor.
- For debt collection, the lender may not contact people in the borrower’s contact list other than those validly named as guarantors.
A lender may retain or use some information when another lawful basis exists, such as performance of the loan agreement, compliance with law, or establishment of a legal claim. The right to deletion is therefore not absolute. The lender must still justify the particular data, purpose, recipients, and retention period. See the NPC’s amended loan-data guidelines and NPC Circular No. 2022-02.
A character reference is not automatically a guarantor
A character reference supplies information for identity or application verification. A guarantor expressly agrees to answer for the borrower’s obligation if the borrower defaults.
The lender must inform a character reference that the person was selected, explain how the contact details were obtained, and offer an option to have the data removed as a reference. The reference cannot automatically be treated as a guarantor. A guarantor’s separate consent must be obtained.
A co-maker may already be a party to the loan document. Whether someone is genuinely a co-maker or guarantor depends on the agreement and evidence—not on what a collector calls that person in a text message.
Preserve evidence before blocking or uninstalling
Evidence can disappear when an app is removed, an account is disabled, or messages are deleted. If it is safe to do so, preserve the following first:
Messages and posts. Capture the sender’s number or account, date, time, full message, and enough surrounding conversation to show context. Save links and screen-record disappearing content when lawful.
Evidence from people who were contacted. Ask each recipient to keep the original message, call log, voicemail, envelope, or social-media notification. Obtain their own screenshots rather than forwarding a cropped copy. A signed affidavit may later be useful.
App identity. Save the app-store page, developer or publisher name, download link, website, privacy notice, permission requests, customer-service details, and the corporate lender named in the agreement.
Loan records. Keep the application, promissory note, disclosure statement, amount represented, amount actually released, due date, payment schedule, statement of account, receipts, and payment instructions.
Collector identity. Record the collection agency, caller’s claimed name, numbers, email addresses, social-media accounts, and payment accounts used.
Your written objection. Keep the complaint sent to the lender or its data protection officer, proof of delivery, ticket number, response, and follow-ups.
Device and account records. Preserve permission screens, security alerts, login notices, unauthorized-transaction records, and relevant email headers.
Keep originals and make a backup. Do not edit the files or rely only on heavily cropped screenshots. In Trimillos v. FCash Global Lending, Inc., the Supreme Court addressed electronic messages submitted in an NPC case and held that the lender could not raise an evidentiary objection for the first time on appeal after failing to object during the administrative proceedings. The ruling does not mean every screenshot is automatically sufficient; careful preservation and authentication remain important. See G.R. No. 271360, August 13, 2025.
Be cautious about secretly recording calls. Republic Act No. 4200 generally prohibits recording a private communication without authorization from all parties. Preserve call logs, text messages, emails, and voicemails, and seek legal advice before making a covert recording. See the Anti-Wiretapping Act.
Secure your phone and accounts
After preserving what you need:
- Revoke unnecessary permissions for contacts, photos, files, camera, microphone, SMS, phone, and location.
- Uninstall the app if it is no longer needed or appears unsafe.
- Change the passwords for your email, social-media, banking, and e-wallet accounts if compromise is possible.
- Use unique passwords and enable multi-factor authentication.
- Contact your bank or e-wallet immediately about unauthorized transactions.
- Warn contacts not to click links, send money, provide OTPs, or engage with the collector.
- Report the app to the relevant app store as an additional step.
Removing the app may stop future device access, but it does not necessarily delete information already transmitted to the operator.
Complain to the lender in writing
Send a concise written notice to the lender, collection agency, and—if available—the company’s data protection officer or consumer-assistance unit.
State:
- Your name and loan or account reference.
- The app and legal company name.
- The dates and substance of the collection conduct.
- Who was contacted and whether that person was a guarantor or co-maker.
- What personal data was accessed, used, or disclosed.
- What information was false or disputed.
- The action you want taken.
You may request that the company:
- Stop contacting people who are not valid guarantors or co-makers.
- Stop threats, shaming, and prohibited disclosures.
- Preserve collection logs, access logs, messages, and recordings.
- Identify the source, purpose, recipients, and retention period of your personal data.
- Correct false information and notify recipients of the correction.
- Block or delete data that has no continuing lawful basis.
- Provide the loan agreement, disclosure statement, complete statement of account, and computation.
- Confirm its response in writing.
Do not include passwords, PINs, OTPs, or unnecessary copies of unrelated private records.
How to report the lender to the SEC
1. Identify the correct respondent
Name both the app and the legal company, if known. Include:
- App or website name.
- Corporate lender or financing company.
- Collection agency.
- App developer or publisher.
- Telephone numbers, email addresses, websites, and payment accounts.
- SEC registration or Certificate of Authority information, if available.
Check whether both the company and the specific app appear in the SEC’s list of recorded online lending platforms. Appearance in an app store is not proof of SEC authority. A company’s incorporation alone also does not necessarily mean it has authority to operate as a lending company.
2. Prepare a factual chronology
Explain, in date order:
- When you applied and what terms were shown.
- The amount represented and the amount actually received.
- The due date, payments, and amount now demanded.
- When harassment began.
- What each collector said or did.
- Which third parties were contacted.
- What personal data appears to have been used.
- When you complained to the company and how it responded.
- The relief you are requesting.
Separate what you personally witnessed from what another recipient told you. Attach the recipient’s original screenshot or statement where possible.
3. File through SEC iMessage
Current SEC guidance routes complaints against financing and lending companies, including their online platforms, through the SEC iMessage Portal.
Register or sign in, select Open New Ticket, identify the concern as involving a financing or lending company or online lending platform, and direct it to FinLenD. Upload the requested complaint information, valid identification, chronology, and supporting evidence. Do not upload passwords, PINs, or OTPs.
Save the ticket number, acknowledgment, submission date, and an exact copy of every attachment. Monitor the portal and answer requests for clarification promptly. FinLenD may also be contacted at (02) 8818-5990 for procedural inquiries.
The SEC may investigate and impose appropriate regulatory sanctions, but filing a complaint does not itself void the contract, settle the debt, or establish damages.
How to file a privacy complaint with the NPC
1. Observe the 15-day prior-notice rule—unless an exception applies
As a general rule, you must first notify the lender, processor, or concerned entity in writing and allow it to address the privacy violation. You may proceed with an NPC complaint when it fails to take timely and appropriate action or does not respond within 15 calendar days from receipt of your written notice.
The NPC may waive this requirement for proven good cause or a serious violation, including grave and irreparable harm, absence of an adequate remedy from the respondent, or patently illegal conduct. If prior notice was unsafe, impossible, or plainly inadequate, explain and support that reason in the complaint. See the 2021 NPC Rules of Procedure and the NPC’s complaint guidance.
Do not wait 15 days to call the police, secure compromised accounts, or obtain emergency assistance.
2. Use the current Complaint-Affidavit
Download the current NPC Complaint-Affidavit and questionnaire. Complete it accurately, sign it, have it notarized, and attach:
- A valid government-issued ID.
- A clear chronological narration.
- The identity and address of the respondent, if known.
- The personal data affected.
- Your written notice to the respondent and proof of receipt.
- Its response, if any.
- Messages, screenshots, documents, and witness affidavits.
- The specific relief requested.
- Information about related cases or complaints as required by the certification against forum shopping.
Failure to attach evidence or satisfy the form requirements can result in outright dismissal.
3. Submit the complaint
The NPC’s formal filing page permits submission:
- Personally;
- By courier; or
- By scanning and emailing the notarized complaint and attachments to complaints@privacy.gov.ph.
The NPC is currently located at 25th–27th Floors, The Upper Class Tower, Quezon Avenue corner Scout Reyes Street, Barangay Paligsahan, Quezon City 1103.
Keep proof of filing. Electronic submissions must be legible and complete, and the NPC may require original or printed documents later.
4. Pay the applicable fee
Under the current NPC Schedule of Fees:
- Basic complaint filing fee: ₱500
- Legal research fee: 1% of the filing fee, but not less than ₱10
- Additional fee for damages not exceeding ₱20,000: ₱150
- Additional fee for damages over ₱20,000 up to ₱100,000: ₱500
- For every succeeding ₱100,000 or fraction: ₱500
Qualified indigent litigants may be exempt. The published criteria require that the combined gross income of the litigant and immediate family not exceed twice the applicable monthly minimum wage and that they not own real property with a fair market value exceeding ₱300,000, together with the required certificate and affidavits.
Follow the NPC’s assessment and current payment instructions rather than sending money to an unofficial account.
When to use the BSP complaint process
Use the BSP route when the lender is a BSP-supervised financial institution, such as a bank, non-bank electronic-money issuer, pawnshop, money-service business, or another institution under BSP supervision. The BSP Verifier can help determine whether an institution is BSP-supervised.
Complain to the institution’s consumer-assistance unit first. If unresolved, escalate through the BSP Online Buddy or submit the BSP Complaints, Inquiries and Requests form to consumeraffairs@bsp.gov.ph. Include your requested resolution, contact details, the complaint sent to the institution, its response, and supporting records. See the BSP Consumer Assistance channels.
An ordinary non-bank lending company is generally regulated by the SEC, not the BSP.
When law-enforcement help is urgent
Seek immediate help when the evidence shows:
- A credible death threat or threat of physical injury.
- Stalking, an announced visit to your home or workplace, or display of a weapon.
- Blackmail or extortion.
- Hacking, account takeover, unauthorized transfers, or identity misuse.
- Falsified court, police, prosecutor, or government documents.
- Malicious distribution of photographs or other highly sensitive material.
- A fake lender collecting payments through changing personal accounts.
- Threats against children, elderly relatives, or other vulnerable people.
Dial 911 for immediate danger. The Unified 911 system connects callers to police, fire, medical, and other emergency services.
For computer-related offenses, the NBI accepts an online complaint. A complainant may also proceed to the NBI Cybercrime Division or a regional cybercrime center for an interview, sworn statement, device examination when relevant, and submission of supporting evidence. See the NBI procedure for victims of computer crimes.
Bring original messages, devices if requested, URLs, sender accounts, transaction references, recipient account details, and witness information. Do not alter evidence, threaten the suspected offender, or attempt to enter someone else’s account.
A practical complaint summary
Respondent: [App name and legal company] Loan/account reference: [Reference] Loan date: [Date] Amount represented: ₱[amount] Amount received: ₱[amount] Amount demanded: ₱[amount] as of [date]
On [date], I obtained or applied for a loan through [app]. The app requested access to [permissions/data]. The loan terms shown to me were [brief facts].
Beginning on [date], persons using [numbers/accounts] sent the attached messages. On [date], they contacted [person and relationship], who was not my guarantor or co-maker, and disclosed [information]. They also stated or threatened [accurate description].
I complained to the respondent in writing on [date]. It [did not respond/responded as follows]. My notice, proof of receipt, and its response are attached.
I respectfully request [investigation, cessation of prohibited collection, explanation of data processing, correction or blocking of information, verification of authority to operate, complete account computation, or other appropriate relief].
Attachments: [Numbered index]
Describe the conduct and let the regulator determine the legal violations. Avoid exaggeration, personal attacks, and unsupported accusations.
Common mistakes
- Naming only the app. Include the corporate lender, developer, collector, payment recipient, and other identifying details.
- Deleting evidence before saving it. Preserve the app listing, permissions, agreement, account history, and messages first.
- Submitting cropped screenshots. Show the sender, date, time, and surrounding context, and retain the original file.
- Treating a character reference as a guarantor. Check whether the person separately and expressly agreed to guarantee the loan.
- Assuming reporting cancels the debt. Collection conduct and the validity or amount of the debt are separate questions.
- Ignoring a real official notice. Verify court or government documents directly with the issuing office and comply with the stated deadline.
- Paying through an unexplained personal account. Verify the official payment channel and preserve the registered account name and receipt.
- Publishing unredacted evidence online. Public posts can expose IDs, account numbers, contact lists, and other people’s data.
- Using different factual stories in different complaints. Keep the chronology consistent and disclose related proceedings when required.
- Giving collectors an OTP, PIN, or password. No legitimate collection process requires these credentials.
Frequently asked questions
Can I report harassment even if I really owe the money?
Yes. A valid debt does not authorize threats, insults, public shaming, deception, or unauthorized disclosure of personal data. Reporting the collection method does not excuse nonpayment or automatically remove the balance.
Can a lender call my relatives or employer?
Not merely because their numbers appeared in your phone. A lender may communicate with an actual borrower, valid guarantor, or co-maker as permitted by law and the agreement. A relative, employer, friend, or character reference does not become liable simply because the collector contacts or labels that person.
Can a character reference file a complaint?
Yes, concerning the processing or misuse of that reference’s own personal data. The person may ask how the lender obtained the information and request removal as a character reference. The person should preserve every message and demand addressed to them.
Must I contact the lender before filing?
For a formal NPC complaint, prior written notice and a 15-calendar-day opportunity to respond are the general rule, subject to the NPC’s waiver for good cause or serious violations. An SEC report or request for emergency law-enforcement assistance should not be delayed when immediate action is necessary.
Can I file with the SEC, NPC, and police at the same time?
Yes, when the incident involves separate regulatory, privacy, and possible criminal issues. Each body determines its own jurisdiction. Keep the facts consistent and disclose related filings when a form requires it.
Should I uninstall the app immediately?
Preserve evidence first if it is safe. Then revoke unnecessary permissions and uninstall the app when appropriate. If financial or email accounts appear compromised, prioritize account security and contact the relevant provider immediately.
How soon should I file?
File as soon as reasonably possible. Electronic evidence, app listings, accounts, and transaction records may disappear. Claims under the Financial Products and Services Consumer Protection Act generally prescribe five years from consummation of the transaction or discovery of deceit or nondisclosure, subject to an ultimate ten-year limit from the violation. That rule does not govern every privacy, civil, administrative, or criminal remedy, which may have different periods.
What can the agencies order?
Depending on jurisdiction and proof, the SEC may impose regulatory or administrative measures; the NPC may order compliance, blocking or cessation of processing, administrative fines, indemnity, or referral for prosecution; and law-enforcement authorities may investigate possible crimes. A court, not a collector, determines criminal guilt and imposes criminal penalties.
Disclaimer
This article provides general Philippine legal information, not advice for a particular loan, complaint, or court case. Outcomes depend on the agreement, messages, identity of the lender, evidence, and applicable regulator. Seek individualized legal assistance when threats are serious, substantial damages are involved, several victims are affected, or you receive a subpoena, prosecutor’s notice, or court document. Laws, procedures, official channels, and published forms were checked against official sources as of August 25, 2026.