How to Check If an Online Raffle Is Legitimate and SEC-Compliant (Philippines)
For general information only; not legal advice. Philippine law changes and sectoral regulators issue new circulars. Consult counsel for a specific promotion.
1) Why this matters
Online “raffles” can be perfectly lawful sales promotions—or they can be illegal lotteries or fronts for investment solicitation. In the Philippines, several regulators may have a say, and compliance is layered: business registration, raffle/lottery authority, consumer-protection rules, data privacy, advertising standards, and tax.
2) The legal & regulatory map (Philippine context)
Think of compliance in five layers:
Legal existence of the organizer
- Sole proprietors: DTI Business Name registration.
- Corporations/partnerships: SEC registration and ongoing reporting (as applicable).
- BIR registration (ATP/ORs, TIN), and LGU business permits.
Authority to run the chance-based promotion
- Raffles as sales promotions (e.g., “buy X, get a raffle entry”) generally require a DTI Sales Promotion Permit (SPP).
- Lotteries/sweepstakes (pure games of chance offered to the public for consideration) are the domain of the PCSO; private entities may not run lotteries unless specifically authorized.
- Charity/fund-raising raffles may require additional approvals (e.g., from LGUs and/or the relevant social welfare authority) and must not resemble unauthorized lotteries.
- Gambling laws (e.g., PD 1602 and related statutes) penalize unauthorized games of chance.
Securities & investments angle (SEC)
- If the “raffle” is bundled with soliciting funds with an expectation of profits (investment contracts, profit-sharing, returns, “double your money”), that’s securities offering requiring SEC registration/permit (unless exempt).
- Common red flag: “buy a slot” or “package” not tied to a real product/service, with payouts sourced from subsequent joiners (pyramids/ponzis) thinly veiled as “raffles.”
Consumer & e-commerce compliance
- Consumer Act sales promotion rules (mechanics, fairness, disclosure, draw supervision, prize fulfillment, complaint handling).
- E-Commerce Act obligations (online disclosures, electronic documentation).
- Platform policies (marketplaces, social media) are not law but are enforceable terms that often mirror regulatory requirements.
Cross-cutting regimes
- Data Privacy Act (NPC): lawful basis, privacy notice, security measures, data sharing agreements with couriers/prize partners, retention/deletion.
- Advertising & endorsements: truth-in-advertising; influencer disclosures; no deceptive claims; respect for vulnerable audiences.
- Tax (BIR): organizer’s income tax/VAT consequences; prize withholding and reporting; documentary stamp tax in some cases.
3) Raffle vs. lottery vs. illegal gambling—know the line
- Raffle (lawful sales promo): chance-based selection of winners tied to a legitimate sales promotion (e.g., purchase or participation), with a DTI Sales Promotion Permit and compliant mechanics.
- Lottery (PCSO domain): general public pays for a chance to win; only PCSO (or entities expressly authorized by law) can run these.
- Illegal gambling: chance-based games outside permitted regimes (no DTI SPP; not PCSO-authorized), or with wagering elements.
Key test: If the main consideration paid by the public is only to enter a chance game (not to buy a bona fide product/service) and it’s public-facing, you’re likely in lottery territory unless lawfully authorized.
4) When the SEC matters
The SEC is your primary check for:
- Corporate legitimacy: Is the organizer a duly registered corporation/partnership? Are officers real and filings current?
- Investment solicitation risk: If entries are sold as “packages/investments” with promised returns or upline commissions, that is a securities offering (or a pyramid) requiring SEC registration/permits and is often unlawful.
- Public advertising of investments without a registered security or an exempt transaction is prohibited.
Rule of thumb: A genuine sales promo raffle (DTI-permitted) that does not solicit investments is not a “securities” offering. The moment expected financial returns enter the pitch, expect SEC jurisdiction.
5) What a legal online raffle (sales promotion) typically looks like
Before launch
Organizer has DTI/SEC/BIR/LGU registrations as applicable.
DTI Sales Promotion Permit issued before the campaign. (The permit number and validity dates should be published.)
Terms & Conditions (T&Cs) drafted with:
- Title of promotion, campaign dates, participating products/markets.
- Eligibility (age, residency; exclusions such as employees/affiliates).
- “No purchase required” path, where applicable (some formats require a free entry route to avoid lottery characterization—check your mechanics).
- Entry mechanics (how entries are earned/limited), draw schedule, methodology (manual/electronic RNG), and supervision (e.g., witnessed by DTI/independent representative).
- Prizes (description, quantity, SRP, total value), odds (if determinable), claiming and forfeiture periods.
- Notification method (public posting, email/SMS), and prize fulfillment timelines.
- Data privacy notice and consent language aligned to RA 10173.
- Dispute resolution and venue (PH courts), and contact channel for complaints.
Privacy compliance: privacy notice, purpose limitation, security measures, vendor due diligence, DPA (data processing agreements).
During the promo
- Transparent communications: post permit number and T&Cs on the landing page/social posts; avoid misleading claims.
- System integrity: auditable entry logs; anti-bot/anti-fraud measures; server timestamps; immutable draw records.
- Random draw: certified RNG or verifiable method; supervised draw; contemporaneous minutes.
After the promo
- Winner notification per T&Cs; publishing winners if stated.
- Prize release with proper identification and receipts/acknowledgements; compliance with tax withholding/reporting.
- Record retention for regulator inspection.
6) How to independently verify a raffle
Ask for and check:
DTI Sales Promotion Permit number, exact promo title, and validity dates. The permit details should match the public materials (same name, dates, prizes).
Legal identity of the organizer:
- SEC (for corporations/partnerships): exact corporate name, registration number, registered address, names of directors/officers.
- DTI Business Name (for sole proprietors): BN certificate details.
- BIR registration and LGU business permit** (at least copies).
T&Cs: hosted on a stable page; check mechanics, draw method, prize list/value, claiming rules, and complaint channel.
Privacy notice: names the Personal Information Controller, contact details, purpose of processing, retention period, and data subject rights.
Audit trail: commitment to produce draw minutes or RNG certification upon request, and to keep records for a defined period.
Advertising integrity: influencer posts and ads should disclose the sponsor, use consistent mechanics, and not overstate odds.
Practical identity checks
- Organizer’s official email domain matches corporate name.
- Bank account or e-wallet payee name matches the legal entity (avoid paying personal accounts for corporate promos).
- Corporate address is real; phone lines connect to an actual office.
7) Red flags (treat as high risk or potentially unlawful)
- No DTI permit number shown anywhere, or a permit that doesn’t match the promo name/dates.
- “Investment raffle” where you must buy a “slot” or stake primarily for the chance to win; or returns/commissions are promised.
- Prize values that are implausible relative to the organizer’s size; vague stock photos, no brand serials/model numbers.
- Winners never named or all “winners” are anonymous initials with no way to verify.
- Payments routed to personal accounts for what is claimed to be a corporate promo.
- Pressure tactics (“only 10 minutes to pay to lock your entries”), NFT/crypto only, or forced “membership” fees.
- Data hunger beyond necessity (ID selfies + credit card + bank statements) without a clear lawful purpose or privacy notice.
- Terms missing key elements (eligibility, dates, draw method, claim window, taxes).
- Organizer previously flagged for pyramid schemes or unregistered investment solicitations.
8) Online-specific compliance must-haves
- Clear digital disclosures: the first screen/post should display the promo title, dates, and permit number; link to full T&Cs.
- Platform parity: mechanics must not differ materially across Facebook, Instagram, TikTok, official website, or e-commerce store unless clearly disclosed.
- Electronic drawing: if using RNG, document the algorithm, seed/entropy source, and independence of the draw team; keep hashes/logs.
- Cybersecurity: protect entry forms from tampering; rate-limit; CAPTCHA; encrypt PII in transit and at rest.
- Minors: obtain verifiable parental consent or exclude under-18s; no targeting minors for adult products.
- Cross-border: restrict entries to Philippine residents unless you can lawfully ship and tax prizes abroad; be explicit in T&Cs.
9) Data Privacy Act essentials (NPC)
- Lawful basis: typically consent for marketing and raffle participation; contract/legitimate interests may also apply for fulfillment.
- Privacy notice: identity of the controller, purposes (entry administration, winner notification, marketing opt-in), recipients (couriers, auditors), retention, rights, and contact details.
- Data minimization: collect only what you need; separate optional marketing consent from raffle consent (no bundling).
- Cross-border transfers: disclose and protect with appropriate safeguards.
- Security & breaches: adopt organizational, physical, and technical measures; have a breach response plan and notification triggers.
10) Taxes & prize handling (high level)
- Organizer: account for promo costs; observe withholding tax on prizes where applicable; file returns and keep prize release documentation (IDs, claim forms, ORs/ARs).
- Winners: certain prizes/winnings may be subject to final tax and/or included in income depending on type and amount; winners should receive the required BIR certificates if withholding applies.
- In-kind prizes: disclose whether taxes/fees are for the organizer’s account or deductible from the prize; reflect this clearly in T&Cs.
(Specific rates and thresholds change; check the latest BIR issuances and the NIRC as amended.)
11) Advertising, endorsements, and consumer fairness
- Truthful, non-deceptive claims about odds, availability, and prize value.
- Influencer/affiliate posts must disclose sponsorship and mirror official mechanics.
- No baiting (promising scarce prizes to drive traffic without intent to award).
- Complaint handling: publish a working hotline/email; respond within a reasonable period; cooperate with DTI mediation where applicable.
12) What solid Terms & Conditions include (template checklist)
- Organizer’s legal name, address, registration numbers (SEC/DTI BN), BIR TIN (optional to display), and contact details.
- DTI SPP number and validity dates (if sales promotion).
- Promo title, territory, start/end times (Philippine Standard Time).
- Eligibility; how to enter; entry limits; disqualification grounds.
- Draw details: date/time, location (virtual/physical), draw method (RNG/manual), supervising party, contingency if force majeure.
- Prizes: description, quantity, SRP, total value; substitution policy; warranty/service handling for goods.
- Notification & claiming: documents required, deadlines, redemption channels, delivery rules.
- Taxes & fees: who shoulders which taxes/charges; any cash alternative (or the absence of one).
- Data privacy: link to full privacy notice; consents; data subject rights.
- Publicity: permission (or separate consent) to use winner’s name/likeness.
- General: fraud prevention, audit rights, amendment/termination conditions (with DTI approval where required), governing law/venue.
13) Due-diligence workflow for consumers (step-by-step)
- Identify the organizer (not just the brand page).
- Request the DTI SPP (or the legal basis if not a sales promotion).
- Confirm SEC/DTI BN registration of the organizer and match exact names.
- Read the T&Cs: do mechanics and timelines make sense? Are taxes explained?
- Assess payments: are you paying for a real product/service? If not, why is this not a lottery?
- Check data practices: is there a privacy notice and an opt-out?
- Scan public history: past promos, posted winners, and fulfillment stories.
- Keep records: screenshots of posts, permit, and your entries.
14) Organizer’s internal controls (to actually be compliant)
- Compliance file: permits, T&Cs, RNG certificate, draw minutes, winner IDs/receipts, prize delivery proofs.
- Segregation of duties: marketing ≠ draw team; independent witness.
- System logs: unalterable entries and draw outputs; versioned T&Cs.
- Vendor contracts: data processing agreements with agencies/couriers; SLAs for prize delivery.
- Post-mortem: close-out report (entries, draw stats, complaints, fulfillment rate) for regulator inspection.
15) Quick FAQ
Q: Is a “comment-to-win” or “like-and-share” raffle allowed? A: Social giveaways still need lawful mechanics and often require a DTI permit if positioned as a sales promotion to the public. Even when small, disclose terms, eligibility, dates, and prize details; avoid misrepresentation.
Q: Can I require a purchase to join? A: Yes for sales promotions, provided you obtain the DTI permit and follow consumer-protection rules. Consider if a free entry route is needed based on your mechanics and risk profile.
Q: My “raffle” is actually a fund-raise where joiners earn from future joiners. Is this okay? A: That’s typically an unregistered investment/pyramid issue, squarely within SEC enforcement—and is likely unlawful even if labeled a raffle.
Q: Do I have to publish winners? A: Follow your T&Cs and applicable rules. Publishing at least names/initials and cities is common practice for transparency, but confirm privacy constraints and consents.
Q: Who pays the taxes on prizes? A: Depends on the T&Cs and tax rules. Many promoters shoulder withholding and disclose “net of taxes” or “taxes for sponsor’s account.” Spell it out.
16) Bottom line
A legit, SEC-compliant, and regulator-ready online raffle in the Philippines is one where:
- The entity is real and registered (SEC/DTI, BIR, LGU);
- The activity fits the correct regime (DTI-permitted sales promotion or PCSO-authorized lottery—not an illegal game);
- No investment solicitation masquerades as a raffle (SEC securities rules);
- Consumer, privacy, advertising, and tax rules are followed end-to-end; and
- The organizer can prove it with permits, T&Cs, draw records, and prize fulfillment evidence.
Use the checklists above—if any core element is missing (especially the DTI permit for a sales promo), treat the raffle as suspect.