Quick answer
If an online lending app threatens, insults, publicly shames, impersonates authorities, contacts people harvested from your phone, or exposes your personal information, preserve the evidence and report the conduct—not merely the app name.
For most online lending platforms operated by financing or lending companies:
- Send a written complaint to the lender’s consumer-assistance unit and data protection officer.
- Report abusive collection practices to the Securities and Exchange Commission (SEC).
- Report unauthorized access, use, or disclosure of personal data to the National Privacy Commission (NPC).
- Report threats, extortion, impersonation, stalking, or defamatory online publication promptly to the police, PNP Anti-Cybercrime Group, NBI Cybercrime Division, or prosecutor, as appropriate.
These remedies may be pursued together because the agencies address different violations. Filing a complaint does not automatically cancel a valid loan, but an unpaid debt does not authorize harassment or privacy abuse.
What conduct may be unlawful?
Under SEC Memorandum Circular No. 18, Series of 2019, financing companies, lending companies, and their collection agents may use reasonable and lawful means to collect amounts due. They may not use unfair collection practices such as:
- Violence or threats of harm to a person, reputation, or property;
- Threats to take action that cannot legally be taken;
- Obscene, insulting, or profane language that abuses the borrower or amounts to an offense;
- Publication or disclosure of borrowers’ names and personal information outside lawful exceptions;
- Communicating false loan information, including failing to say that a debt is disputed when that fact should be disclosed;
- False representations or deceptive methods used to collect a debt or obtain information;
- Contact before 6:00 a.m. or after 10:00 p.m., subject to the circular’s narrow exceptions; and
- Contacting people taken from the borrower’s phone contact list who were not named guarantors or co-makers—even if the borrower supposedly consented.
The hours rule has an exception when the account has been past due for more than 15 days or when the borrower expressly agreed, through written, electronic, or recorded means, that the otherwise restricted hours are the only reasonable or convenient times for contact. That exception does not permit threats, insults, deception, public shaming, or privacy violations.
The Financial Products and Services Consumer Protection Act, or Republic Act No. 11765, separately prohibits financial service providers from using abusive collection or debt-recovery practices. A provider is responsible for its employees and agents and may be solidarily liable with an accredited third-party service provider involved in debt collection.
When collection becomes a privacy violation
The Data Privacy Act of 2012 requires personal data to be processed transparently, for a legitimate purpose, and in a proportionate manner. Data must be relevant, not excessive, and retained only as long as legally necessary.
The NPC’s Circular No. 2020-01 on loan-related transactions specifically provides that online lending apps must not:
- Require permissions involving personal or sensitive personal information when those permissions are unnecessary;
- Retain access to a camera or photo gallery after the limited purpose for which access was needed has been completed;
- Use a borrower’s photograph to harass or embarrass the borrower;
- Access, harvest, copy, or save phone contacts, email contacts, or social-media contacts for debt collection or harassment; or
- Use personal data for unfair collection practices.
An app should instead provide a separate interface where the borrower can voluntarily identify character references or co-makers. A character reference should be told how the lender obtained the person’s details and, when feasible, given an option to have the data removed. Merely being a reference does not make someone liable for the loan. Liability depends on whether the person actually entered into a valid guaranty, co-making arrangement, or other enforceable undertaking.
Granting an app permission during installation is not an unlimited license to harvest contacts or publicly disclose loan information. Consent under the Data Privacy Act must be freely given, specific, and informed. In some situations, a lender may process limited data without consent because it is necessary to perform a contract, comply with law, or pursue a legitimate interest. Those grounds still do not excuse processing that is excessive, incompatible with its stated purpose, or overridden by the borrower’s rights.
Lawful collection is still allowed
Not every reminder or demand is harassment. Subject to the contract and applicable law, a legitimate lender may ordinarily:
- Contact the borrower through lawful channels;
- Make a truthful demand for payment;
- Contact a properly identified guarantor or co-maker;
- Refer an account to an authorized collection agency or lawyer;
- Disclose necessary information under a court order, legal requirement, or properly regulated credit-reporting process; and
- File an appropriate civil action.
A collector may be firm without being abusive. The important questions are what was said, when and how often contact occurred, who received the information, what personal data was used, and whether the collector had a lawful and proportionate reason for using it.
Nonpayment of an ordinary debt does not by itself allow imprisonment. Separate criminal liability may arise from distinct conduct, however, such as proven fraud or another offense. Do not ignore an authentic court summons or prosecutor’s subpoena simply because a collector previously made false threats.
What to do immediately
1. Preserve evidence before blocking or uninstalling the app
Keep the original evidence wherever possible:
- Screenshots showing the entire message, sender, number or account, date, and time;
- Call logs, voicemail messages, emails, chat exports, and collection letters;
- URLs and screenshots of public posts, comments, group messages, or altered photographs;
- The app-store page, developer name, privacy notice, terms, permission screens, and app version;
- The loan agreement, disclosure statement, repayment schedule, receipts, payment history, and account statement;
- Names or aliases used by collectors and the company they claimed to represent;
- Screenshots or statements from relatives, coworkers, or contacts who received messages;
- Proof of any payment account or personal e-wallet to which the collector instructed you to send money; and
- A chronological incident log stating what happened, who was involved, and when you discovered each disclosure or publication.
Do not crop away dates, account names, URLs, or other identifying details. Keep unedited copies and back them up securely.
Be careful with call recording. The Anti-Wiretapping Act generally prohibits secretly recording a private communication without authorization from all parties. Preserve voicemail left for you and make contemporaneous written notes, but obtain legal advice before secretly recording live calls.
2. Secure your phone and accounts
After capturing the necessary evidence:
- Revoke the app’s access to contacts, camera, microphone, location, photos, and storage;
- Change passwords for your email, financial, and social-media accounts;
- Enable multifactor authentication;
- Review logged-in devices and recent account activity;
- Tell affected contacts not to click links, share information, provide an OTP, or send payment to a collector;
- Ask contacts to preserve messages before blocking the sender; and
- Report the app to the relevant app store as an additional safety measure.
Uninstalling the app may stop local access, but it will not necessarily delete data already copied to the lender’s servers. Preserve evidence first and make a written data-rights request.
3. Verify the lender and collector
Identify the corporation behind the brand, not only the app’s display name. Check the contract, privacy notice, disclosure statement, payment instructions, app-store developer information, and the SEC’s Check with SEC system.
Ask the collector in writing for:
- Full name and true identity;
- Collection company and business address;
- Name of the financing or lending company that owns the account;
- Account reference and itemized amount claimed; and
- Written authority to collect.
SEC rules require collection personnel to disclose their full name or true identity. Do not send money to a collector’s personal account without independently confirming the payment channel with the lender.
Send a written complaint to the lender
Address the complaint to the lender’s consumer-assistance unit and data protection officer. Use an email address or ticketing channel published in the contract, app, privacy notice, or official company website.
Include:
- Your name and loan-account reference, with unnecessary ID details masked;
- A short chronological statement of the incidents;
- The numbers, accounts, or collector names involved;
- The personal data accessed, used, or disclosed;
- The names or categories of people contacted;
- Copies of key evidence;
- A statement identifying any amount you dispute and why; and
- The action you want the company to take.
Depending on the facts, request that the company:
- Stop unlawful contact, threats, and disclosures;
- Use only a designated written channel to communicate with you;
- Identify the collector and confirm whether the person is authorized;
- Preserve call, access, disclosure, and collection logs;
- Explain the source, purpose, legal basis, recipients, and retention period for your data;
- Correct inaccurate account or personal information;
- Block, remove, or destroy unlawfully obtained or no-longer-necessary data;
- Notify recipients of a correction when legally required; and
- Give a written resolution.
Keep proof that the company received the complaint. This is especially important for an NPC case.
Report abusive collection to the SEC
The SEC generally regulates financing companies, lending companies, online lending platforms, and their collection agencies. Use the SEC iMessage portal or follow the Commission’s current complaint instructions for financing and lending companies.
The SEC’s complaint guidance requires a completed complaint form, supporting evidence, a valid government-issued ID, and one complaint form for each respondent company. Describe specific acts rather than merely stating “harassment.” Identify the dates, words used, people contacted, disclosures made, and the connection between the app, corporate lender, and collection agent.
The SEC can investigate regulatory violations and take enforcement action. A regulatory complaint does not itself:
- Cancel the loan;
- Rewrite its payment terms;
- Declare the contract void;
- Automatically erase interest or charges; or
- Substitute for a civil or criminal case when that separate remedy is necessary.
If the provider is a bank, digital bank, or another BSP-supervised institution rather than an SEC-regulated lending or financing company, complain first through the institution’s consumer-assistance mechanism. If unresolved, use the BSP’s second-level Consumer Assistance Mechanism described in its official BSP-CAM guide.
File a privacy complaint with the NPC
A borrower—or another person whose data was accessed or disclosed—may complain to the NPC. A relative or coworker contacted through a harvested phone list may have an independent complaint because that person is also a data subject.
Complete the prior written-complaint step
Under the 2021 NPC Rules of Procedure, the complainant ordinarily must first:
- Inform the lender, collection company, or other responsible entity of the privacy violation in writing; and
- Show that the entity failed to take timely or appropriate action or did not respond within 15 calendar days after receiving the written complaint.
The NPC may waive this requirement for proven good cause or a serious violation, including circumstances involving grave and irreparable harm, lack of an adequate remedy, or patently illegal conduct. If waiting would expose you or others to serious harm, explain the urgency and provide evidence supporting a request for waiver.
Prepare the formal complaint
Use the NPC’s current Complaint-Affidavit form. The complaint should be written, signed, verified, and accompanied by a certification against forum shopping. It should identify:
- The complainant and respondent;
- The personal data affected;
- The specific processing, access, use, or disclosure complained of;
- Dates, times, places, accounts, and persons involved;
- A clear chronological narrative;
- The relief requested;
- All supporting documents and witness affidavits, when available;
- Correspondence with the respondent and proof of receipt; and
- A valid government-issued ID.
If the respondent’s legal name is unknown, provide facts that may lead to identification, such as the app name, developer, website, payment account, phone numbers, email domains, privacy notice, and app-store URL.
The NPC rules allow filing personally at an NPC office, by registered mail, by courier, or by electronic mail when authorized by the Commission. Check the NPC complaints and contact page immediately before filing for the current address, authorized email, office hours, and payment instructions. A filing fee may apply, subject to the rules on indigent complainants, government complainants, or an NPC waiver for good cause.
When to involve law enforcement
Do not wait for the SEC or NPC process if the conduct includes:
- A credible threat of physical harm;
- Extortion or a demand backed by a threat to expose private material;
- Stalking or threats to visit your home, school, or workplace;
- Impersonation of police officers, courts, prosecutors, or government agencies;
- Account takeover, identity theft, or unauthorized financial transactions;
- Publication of intimate images; or
- Public or online accusations that may constitute defamation.
Report promptly to the nearest police station, the PNP Anti-Cybercrime Group, or the NBI Cybercrime Division. Bring your device, identification, incident timeline, original electronic evidence, URLs, and copies of the loan documents. If someone faces an immediate threat, contact emergency services and move to a safe place.
Criminal classifications depend on the precise words, medium, intent, audience, and evidence. Obtain legal advice quickly. In its April 8, 2026 resolution in Causing v. People, G.R. No. 258524, the Supreme Court confirmed that cyber libel prescribes in one year from discovery by the offended party, authorities, or their agents. Other offenses and civil claims have different periods, so delay can forfeit a remedy even while an administrative complaint remains possible.
For claims specifically accruing under Republic Act No. 11765, the statute generally provides five years from consummation of the financial transaction or discovery of deceit or nondisclosure of material facts, with an outside limit of ten years from the violation. Do not assume those periods govern a privacy, defamation, threat, or other separate claim.
Common mistakes to avoid
- Deleting messages or uninstalling the app before preserving evidence;
- Reporting only the app’s brand name without identifying the corporate lender;
- Sending a vague complaint with no dates, screenshots, or description of the words used;
- Omitting proof that the lender received your written privacy complaint;
- Secretly recording calls without considering the Anti-Wiretapping Act;
- Posting your own loan documents, IDs, phone numbers, or account details publicly;
- Paying a collector’s personal account without verification;
- Treating a character reference as automatically liable for the debt;
- Assuming a complaint cancels the loan or pauses all contractual obligations;
- Ignoring authentic court or prosecutor documents; and
- Waiting until electronic evidence disappears or a short prescriptive period expires.
Frequently asked questions
Can collectors contact my family, friends, or employer?
They cannot freely disclose your debt or shame you. An SEC-regulated financing or lending company may not contact people harvested from your phone contact list unless they were named guarantors or co-makers. A voluntarily named character reference may be contacted under appropriate policies, but unnecessary loan details should not be disclosed and the reference is not automatically responsible for payment.
What if I allowed contact access when installing the app?
That does not necessarily make the later use lawful. NPC Circular No. 2020-01 prohibits harvesting or saving phone, email, or social-media contacts for debt collection or harassment. Permissions must be necessary, proportionate, and tied to a lawful purpose.
Can I demand immediate deletion of all my data?
You may request access, correction, blocking, removal, or destruction when the legal requirements are met. Deletion is not absolute: the lender may retain data still necessary to service the loan, comply with law, or establish, exercise, or defend legal claims. It should not retain or use data indefinitely for an unspecified future purpose.
Does harassment make the debt invalid?
Not automatically. The collection conduct and the enforceability or amount of the debt are separate questions. Continue disputing incorrect charges in writing and obtain legal advice about the contract while pursuing the harassment or privacy complaint.
May I block the collector?
Yes, after preserving evidence. Consider leaving one controlled written channel open so legitimate notices can reach you and communications remain documented. Blocking a number does not replace a complaint or resolve the underlying account.
What if the app or lender is unregistered?
Preserve the app-store listing, developer information, payment instructions, website, phone numbers, and communications. Report the entity through SEC iMessage and state that you could not verify its registration or authority. Criminal or privacy complaints may still be appropriate even if the operator is unidentified or unregistered.
Can both the borrower and contacted relatives complain?
Yes, if each person’s own personal data or rights were affected. The borrower may complain about unlawful collection and use of borrower data. A relative, coworker, or friend whose contact information was harvested or whose data was otherwise unlawfully processed may have a separate NPC complaint.
Official references
- Data Privacy Act of 2012
- NPC Circular No. 2020-01: Loan-Related Transactions
- 2021 NPC Rules of Procedure
- NPC Complaint-Affidavit form
- SEC Memorandum Circular No. 18, Series of 2019
- SEC complaint instructions
- Financial Products and Services Consumer Protection Act
This article provides general legal information, not legal advice for a particular case. Procedures and the proper remedy depend on the lender’s identity, the documents, the exact communications, and the harm involved. Official sources and procedures were checked as of August 11, 2026.