Quick answer
Online lending harassment should usually be reported through more than one channel because different agencies handle different violations:
- Report abusive collection by an SEC-regulated lending or financing company to the Securities and Exchange Commission (SEC) through its official iMessage ticketing system. Select Financing and Lending Companies Department → Complaints on Financing and Lending Companies.
- Report unauthorized contact-list access, debt shaming, disclosure of loan information, misuse of photos, or other unlawful processing of personal data to the National Privacy Commission (NPC). Ordinarily, you must first notify the lender or its data protection officer in writing and allow 15 calendar days from receipt for an appropriate response.
- If the provider is supervised by the Bangko Sentral ng Pilipinas (BSP)—for example, a bank or other BSP-supervised financial institution—complain first to the provider, then escalate an unresolved complaint through the BSP Consumer Assistance Mechanism.
- For credible threats, extortion, impersonation, account intrusion, or other possible crimes, promptly approach the nearest police station, the PNP Anti-Cybercrime Group, or the NBI CyberCrime Division. Call 911 if anyone is in immediate danger.
A lender may pursue a valid debt through lawful means, but it may not use harassment, deception, public shaming, unnecessary surveillance, or unlawful disclosure of personal information. Filing a complaint does not automatically cancel the loan, suspend an actual court case, or erase an otherwise valid payment obligation.
What collection conduct may violate the law?
Unfair debt-collection practices
Under SEC Memorandum Circular No. 18, Series of 2019, financing companies, lending companies, and the collection providers they hire must use reasonable and legally permissible collection methods. Prohibited practices include:
- Using or threatening violence or other criminal means against a person, reputation, or property.
- Threatening an action that cannot legally be taken.
- Using obscenities, insults, or profane language that abuses the borrower or amounts to an offense.
- Disclosing or publishing the borrower’s name or other personal information because of alleged nonpayment, except where a lawful disclosure is allowed.
- Communicating loan information known—or that should be known—to be false, including failing to disclose that a debt is disputed when communicating it in circumstances allowed by the circular.
- Using false representations or deceptive means to collect a debt or obtain information about the borrower.
- Contacting the borrower before 6:00 a.m. or after 10:00 p.m., unless the account is more than 15 days past due or the borrower has expressly agreed, through written, electronic, or recorded means, that those are the only reasonable or convenient times for contact.
- Contacting people in the borrower’s phone contact list who were not named as guarantors or co-makers. The circular treats this as unfair collection notwithstanding the borrower’s consent.
The rules do not prevent every disclosure connected with collection. SEC MC No. 18 permits specified disclosures, including those made with written or recorded consent, pursuant to a lawful government or court order, to authorized collection agencies or counsel, and for certain legitimate credit or service-provider purposes. These exceptions do not authorize public shaming, harassment, false statements, or indiscriminate messaging of a borrower’s contacts.
A lender cannot avoid responsibility simply by blaming an outside collection agency. SEC MC No. 18 leaves ultimate responsibility for collection practices with the financing or lending company. The Financial Products and Services Consumer Protection Act, or Republic Act No. 11765, also prohibits abusive debt-recovery practices and makes a financial service provider solidarily liable with its accredited third-party service provider for relevant acts or omissions, including debt collection.
Privacy violations by a lending app
The Data Privacy Act of 2012 requires personal-data processing to be lawful, fair, transparent, proportionate, and limited to a legitimate purpose. Consent is not a blanket permission: it must be freely given, specific, and informed, and another lawful basis may be required when data is used for a different purpose.
NPC Circular No. 2020-01, which specifically covers loan-related data processing, provides that:
- Lending apps must not require permissions involving personal or sensitive personal information when those permissions are unnecessary or excessive.
- Permissions must be suitable and necessary for legitimate purposes such as identity verification, creditworthiness assessment, fraud prevention, or lawful debt collection.
- Once a permission is no longer needed, the app should turn it off by default or prompt the user to disable it.
- Camera or gallery access may be justified at the identity-verification stage, but a borrower’s photograph must never be used to harass or embarrass the borrower.
- Accessing, harvesting, copying, or saving phone contacts, email contacts, or social-media contacts for debt collection or harassment is prohibited.
- The app must instead provide a separate interface where the borrower can choose character references or co-makers.
- Personal data must not be retained indefinitely for an undefined possible future use.
- The lender remains accountable for personal data handled by its collectors and other service providers.
A character reference may be contacted under appropriate procedures, but the lender should explain that the person was named as a reference and how the contact details were obtained. Where feasible, the reference should be allowed to request removal of their data as a character reference.
What to do immediately
1. Address any immediate danger
If a collector threatens physical harm, publishes your home address, threatens your children or workplace, demands money through extortion, or appears to have compromised your accounts, do not wait for the administrative complaint process. Contact law enforcement and, if danger is imminent, call 911.
Do not meet a threatening collector alone. Do not send identification documents, passwords, one-time PINs, or additional personal information merely because a caller claims to represent a lender, lawyer, court, police unit, or government agency.
2. Preserve the evidence before blocking or uninstalling
Keep the original device and original electronic records where possible. Save:
- Full screenshots showing the sender’s number, account name, date, time, and complete message—not only the insulting sentence.
- Screen recordings showing how the conversation, post, app profile, or account was reached.
- Original SMS, email, Messenger, Viber, WhatsApp, or other message threads and exported chat files where available.
- Call logs, voice messages, recordings lawfully obtained, and the collector’s stated name or agency.
- URLs, usernames, profile identifiers, post links, and screenshots of public comments or debt-shaming posts.
- The app-store listing, developer name, privacy policy, app permissions, and version number.
- Screenshots from the phone’s privacy dashboard showing when contacts, photos, camera, microphone, SMS, location, or storage were accessed.
- The loan agreement, disclosure statement, repayment schedule, account statement, proof of disbursement, receipts, and payment history.
- Emails or tickets sent to the lender, its consumer-assistance unit, or data protection officer, together with proof of receipt.
- Messages received by family members, friends, co-workers, or other contacts. Ask each recipient to retain the original and write a dated account of what happened.
- Evidence identifying the corporate operator behind the app, such as the company name in the contract, privacy notice, payment instructions, website footer, or app-store page.
Keep an incident log listing each date, time, phone number or account, channel, words or conduct used, person contacted, data disclosed, and resulting harm. Back up the files without editing them. Cropped or annotated copies may be convenient, but preserve the originals and metadata.
3. Secure the phone and accounts
After preserving evidence:
- Revoke unnecessary permissions for contacts, photos, camera, microphone, SMS, location, and storage.
- Change passwords for email, social media, cloud storage, and financial accounts if compromise is possible.
- Enable multi-factor authentication and review active sessions or logged-in devices.
- Ask contacted friends and relatives not to engage, click links, or disclose information.
- Report and request removal of public posts through the platform’s reporting tools.
- Block abusive numbers if needed for safety, while retaining the evidence first.
Uninstalling an app may stop future access from the device, but it does not delete data the operator has already copied or shared.
Identify the company and the correct regulator
The app’s brand name may differ from the legal name of the lender. Check the loan contract, disclosure statement, privacy policy, app-store developer details, and payment recipient.
The appropriate regulator generally depends on the provider:
- SEC: Lending companies and financing companies, including their online lending platforms.
- BSP: Banks and other BSP-supervised financial institutions.
- CDA: Cooperatives offering financial services, except cooperative banks and other BSP-supervised cooperative financial institutions.
- NPC: Privacy violations by any covered person or organization, including entities that lack the required lending authority.
- Law enforcement: Possible criminal conduct, regardless of the provider’s regulatory status.
A lending company must be a stock corporation registered and licensed by the SEC and must hold a Certificate of Authority under the Lending Company Regulation Act. If the operator is unregistered, revoked, unidentified, or appears to be operating from abroad, report that fact and attach the documents that connect the app to the operator. Do not abandon the complaint merely because the app has disappeared from an app store.
How to complain to the lender first
Send a written complaint to the company’s consumer-assistance unit and data protection officer using the addresses in the contract, privacy notice, official website, or app. State:
Your name, loan or account reference, and contact details.
The collector’s number, account, name, or agency, if known.
A chronological description of each incident.
The personal data accessed, copied, used, or disclosed.
The people who received messages and what they were told.
Which information is false or disputed.
The action you require, such as:
- Stop contacting people who are not named guarantors or co-makers.
- Stop abusive or deceptive communications.
- Remove public posts and notify recipients of any correction.
- Identify the source and recipients of your personal data.
- Preserve relevant call recordings, access logs, messages, and collection instructions.
- Restrict or erase unlawfully obtained or unnecessary data, subject to lawful retention requirements.
- Provide the company’s written findings and corrective action.
Ask for a ticket number and written acknowledgment. For an NPC complaint, retain proof that the company received this notice because the 15-calendar-day period ordinarily runs from receipt.
Do not demand deletion of every loan record without qualification. A lender may retain information that remains necessary to service a valid loan, comply with law, or establish or defend legal claims. The complaint should focus on unlawful collection, excessive permissions, unauthorized disclosure, inaccurate data, or information no longer necessary for a lawful purpose.
How to file with the SEC
Use the SEC’s iMessage system, which the SEC identifies as its official centralized platform for public inquiries and complaints. The current iMessage user guide requires an eSECURE account.
After signing in:
- Open a new ticket.
- Select Financing and Lending Companies Department.
- Choose Complaints on Financing and Lending Companies.
- Identify both the app name and the legal company name.
- Describe each collection incident with dates, numbers, accounts, and affected third parties.
- Upload the loan documents, full screenshots, call logs, proof of payment, communications with the company, and a valid government-issued ID.
- Use one complaint submission for each respondent company where practicable.
- Save the ticket number and monitor the ticket for requests, replies, or additional filing requirements.
The SEC’s complaint guidance for financing and lending companies warns that incomplete complaints or complaints lacking evidence may be dismissed. It also explains that the SEC does not, through the ordinary complaint process, rewrite the payment terms, declare the contract void, or cancel the debt.
For violations of SEC MC No. 18, the stated administrative penalties are:
- Lending companies: ₱25,000 for a first offense and ₱50,000 for a second offense.
- Financing companies: ₱50,000 for a first offense and ₱100,000 for a second offense.
- Third offense: Depending on the facts and gravity, a fine of at least twice the second-offense fine but not more than ₱1 million, a 60-day suspension of lending or financing activities, or revocation of the Certificate of Authority.
For unfair-collection violations, the circular counts violations per loan transaction per complainant rather than treating every message concerning the same loan as a separate count. The progression of offenses lapses three years after the last order of payment. Other sanctions under Republic Act No. 11765 or other applicable laws may also apply.
How to file a privacy complaint with the NPC
First satisfy the 15-day requirement
Under the 2021 NPC Rules of Procedure, a privacy complaint ordinarily will not be given due course unless you show that:
- You informed the company, its personal information processor, or the concerned entity in writing about the privacy violation or data breach; and
- It failed to take timely or appropriate action, or did not respond within 15 calendar days from receiving your written notice.
The NPC may waive either requirement for proven good cause or a serious violation, including grave and irreparable harm that requires NPC action, the absence of a plain and adequate remedy from the respondent, or conduct that is patently illegal. If you cannot safely wait, expressly request a waiver and attach evidence showing the urgency.
Prepare the formal complaint
Use the NPC’s official complaint-assisted form and filing instructions. A formal complaint should be written, signed, verified, and notarized. It should include:
- Your identity and service address, including an email address if available.
- The respondent’s legal identity and contact information, if known.
- A clear statement of material facts.
- The acts or omissions alleged to violate the Data Privacy Act, its rules, or NPC issuances.
- The relief you are requesting.
- Copies of all correspondence with the respondent and proof of the response or nonresponse.
- Documentary evidence and witness affidavits, where available.
- A certification against forum shopping.
If a representative files for you, a special power of attorney is required. The complaint may be filed personally, by registered mail, by courier, or by electronic mail authorized by the NPC. Follow the current destination and document-format instructions shown on the official filing page. The NPC states that electronic documents should be digitally signed and, where practicable, submitted in PDF format.
The current basic complaint filing fee is ₱500. Additional fees apply when damages are claimed, and the NPC fee schedule should be checked before payment. Qualifying indigent litigants may seek exemption by submitting the required proof of income, property, and indigency.
The NPC rules give the investigating officer 30 calendar days from receipt to give the complaint due course or dismiss it without prejudice. The NPC’s public guidance estimates approximately 10 to 12 months through final adjudication, although actual timing depends on the case.
Possible NPC remedies include orders to correct unlawful processing, cease-and-desist measures, temporary or permanent restrictions on processing, indemnity where legally established, and recommendations to the Department of Justice for prosecution. Criminal liability is not automatic. It depends on proof of the specific offense and the participation of the responsible persons.
When to escalate to the BSP
Use the BSP channel only if the complained-of provider is BSP-supervised. First submit the concern to the institution’s own consumer-assistance mechanism.
If the matter remains unresolved, file through the BSP Online Buddy or another BSP Consumer Assistance channel. Include:
- A summary of the complaint and the resolution requested.
- A copy of the complaint sent to the institution.
- The institution’s response, if any.
- The loan documents and evidence of harassment or disclosure.
- Your daytime contact details.
The BSP Consumer Assistance Mechanism primarily evaluates and refers complaints; it is not a substitute for an NPC complaint concerning unlawful personal-data processing or a police complaint concerning possible crimes.
When a police or NBI report is urgent
Seek immediate investigative assistance when the facts involve:
- Credible threats of bodily injury or property damage.
- Extortion or demands tied to threats of publishing private information.
- Unauthorized access to email, social media, financial accounts, or devices.
- Identity theft or use of your documents to obtain other loans.
- Fabricated court orders, warrants, police notices, or false claims of government authority.
- Publication of intimate images or threats to publish them.
- Stalking, doxxing, or disclosure of a home or workplace address creating a safety risk.
- Repeated conduct continuing despite regulator complaints and preservation demands.
Bring the original device, identification, incident log, complete electronic records, loan documents, URLs, and witness information. The NBI’s official procedure allows members of the public to proceed to its CyberCrime Division or a regional cybercrime center, undergo an initial interview, execute a sworn complaint or statement, and submit the relevant device and supporting documents for examination.
Do not assume that every rude message is automatically a particular criminal offense. Threats, coercion, defamation, unlawful access, privacy offenses, and cybercrime-related liability have different legal elements. Investigators or counsel must assess the exact words, context, intent, publication, identity of the sender, and available evidence.
Does harassment erase the debt?
No. Unlawful collection conduct and the validity or amount of the debt are separate issues.
The 1987 Constitution prohibits imprisonment for debt or nonpayment of a poll tax. A collector therefore cannot truthfully threaten imprisonment merely because a borrower is unable to pay an ordinary loan. This does not prevent lawful civil collection, and it does not bar prosecution for a separate alleged offense whose legal elements are independently established.
Continue communicating only through verified company channels. Ask for an itemized statement showing principal, interest, fees, payments, and the claimed balance. If you can pay, use only a verified payment channel and obtain a receipt. If you cannot, request restructuring or a payment arrangement in writing. Never pay a personal account supplied by an unverified collector merely to stop a threat.
Do not ignore an authentic summons, subpoena, court order, or regulator notice. Verify it directly with the issuing court or agency rather than through the phone number given by the collector.
Common mistakes that weaken a complaint
- Deleting messages or uninstalling the app before preserving evidence.
- Submitting heavily cropped screenshots without the sender, date, time, or surrounding context.
- Naming only the app brand and not the legal company or collection agency.
- Combining unrelated lenders in a single SEC complaint.
- Filing an NPC complaint without proof of prior written notice or without explaining why the 15-day requirement should be waived.
- Posting unredacted loan documents, IDs, phone numbers, or contact lists publicly while seeking help.
- Treating every contact with a guarantor, co-maker, counsel, credit bureau, or authorized agency as automatically unlawful without examining the purpose and applicable exception.
- Assuming that an app permission authorizes every later use or disclosure of the data.
- Paying an unverified person or account because the collector claims to be a lawyer, police officer, or court employee.
- Stopping payment solely because a harassment complaint was filed.
- Ignoring requests for additional evidence or deadlines shown in an SEC, NPC, BSP, police, or court communication.
Frequently asked questions
Can a lending app contact my family, friends, or co-workers?
It generally may not harvest your contact list and message people who were not specifically named as guarantors or co-makers. Publicly disclosing your debt or using third parties to shame or pressure you may violate SEC and privacy rules. A properly identified character reference, guarantor, or co-maker is different, but communication with that person must still be lawful, accurate, proportionate, and non-abusive.
What if I allowed contact access when I installed the app?
That does not automatically make every use lawful. NPC Circular No. 2020-01 prohibits harvesting or saving contact lists for debt collection or harassment, and SEC MC No. 18 treats contact with people in the borrower’s contact list—other than named guarantors or co-makers—as unfair collection notwithstanding consent.
Can I complain if I am only a friend or relative who received the messages?
Yes, if your own personal data was unlawfully processed or you personally suffered a privacy violation, you may be a data subject with your own NPC complaint. Preserve the original message and record how the sender identified you or obtained your number. You may also provide evidence or an affidavit supporting the borrower’s SEC complaint.
Can I demand deletion of all my data?
You may request blocking, erasure, or destruction of data that was unlawfully obtained, used for an unauthorized purpose, or is no longer necessary. That right is not absolute: the company may retain data still required by law, necessary to administer an existing loan, or needed to establish or defend legal claims. Demand an explanation of the lawful basis, purpose, recipients, and retention period.
What if the app or company is unregistered?
Report it to the SEC and provide every detail connecting the brand, developer, payment account, website, privacy policy, and loan contract. Privacy and criminal laws may still apply even when the operator lacks a Certificate of Authority. The Data Privacy Act may also apply to certain conduct outside the Philippines when it concerns a Philippine citizen or resident and the statutory links to the Philippines exist.
Can the SEC or NPC award me money?
Republic Act No. 11765 gives the SEC authority to adjudicate specified purely civil financial-transaction claims seeking payment or reimbursement of up to ₱10 million, subject to applicable procedures and jurisdiction. The Data Privacy Act authorizes the NPC to award indemnity in matters affecting personal information. Neither remedy is automatic; the agency must have jurisdiction, and liability, causation, damages, and procedural requirements must be established.
How quickly should I act?
Preserve evidence and send the written company complaint immediately. The NPC’s 15-calendar-day exhaustion period is important unless a waiver is justified. Claims under Republic Act No. 11765 generally prescribe five years from consummation of the financial transaction or discovery of deceit or material nondisclosure, subject to an ultimate 10-year limit and other statutory exceptions. Other administrative, civil, privacy, and criminal remedies may follow different limitation periods, so obtain legal advice promptly rather than relying on the longest possible period.
Official references
- SEC iMessage complaint portal
- SEC iMessage user guide
- SEC Memorandum Circular No. 18, Series of 2019
- SEC complaint guidance for lending and financing companies
- NPC Circular No. 2020-01 on loan-related data processing
- NPC formal complaint instructions
- 2021 NPC Rules of Procedure
- Data Privacy Act of 2012
- Financial Products and Services Consumer Protection Act
- BSP Consumer Assistance channels
- NBI CyberCrime Division complaint procedure
This article provides general legal information, not legal advice or a prediction of any complaint’s outcome. The appropriate remedy depends on the lender’s identity, the contract, the exact communications, the data processed, and the available evidence. Official sources and procedures were checked as of 18 August 2026.