Quick answer
If an online lending app is threatening, insulting, publicly shaming, repeatedly contacting unrelated people, or misusing your contacts, photos, messages, social-media information, or other personal data, document everything and report the conduct to the proper agencies:
- Report unfair collection practices by a lending or financing company to the Securities and Exchange Commission (SEC) through SEC iMessage.
- Report unauthorized collection, use, or disclosure of personal data to the National Privacy Commission (NPC). Ordinarily, first send the lender a written privacy complaint and allow 15 calendar days for an appropriate response before filing a formal NPC complaint.
- If the lender is a bank, digital bank, e-wallet provider, or another BSP-supervised financial institution, complain first to the institution, then escalate an unresolved complaint through the BSP Consumer Assistance Mechanism.
- For threats, extortion, fraud, impersonation, account compromise, or immediate safety concerns, contact law enforcement without waiting for an agency complaint to finish. The government’s 2026 online-lending advisory identifies the DICT Cyber Hotline at 1326@dict.gov.ph and the NBI Cybercrime Division at ccd@nbi.gov.ph.
You may use more than one route because harassment, privacy misuse, and criminal conduct can raise different legal issues. Filing a complaint does not automatically erase a legitimate loan, but owing money does not authorize abuse, public shaming, unlawful threats, or indiscriminate disclosure of your personal information.
Conduct you can report
Collection contact is not automatically unlawful. A lender may send legitimate payment reminders, explain the amount due, propose restructuring, or pursue lawful collection remedies. The problem is the method used.
SEC Memorandum Circular No. 18, Series of 2019 prohibits lending and financing companies—and collection agencies, counsels, agents, and other representatives acting for them—from using unfair debt-collection practices. Report conduct such as:
- threats of violence or other criminal means against you, another person, your reputation, or property;
- threats to take an action that cannot legally be taken;
- insults, obscenities, profane language, or statements intended to shame or abuse;
- false representations or deceptive means used to collect or obtain information;
- communicating or threatening to communicate false credit information;
- disclosing or publishing a borrower’s identity and personal information to shame the borrower;
- contacting people in the borrower’s contact list who are neither guarantors nor co-makers;
- unreasonable or excessive contact, including prohibited collection contact at unreasonable hours, subject to the circular’s limited exceptions; and
- other oppressive conduct by the lender or its collection representative.
The lender cannot avoid responsibility merely by saying that an outside collection agency, employee, or “field officer” sent the messages. The SEC rules cover persons acting on behalf of a regulated lending or financing company.
Privacy violations involving lending apps
The Data Privacy Act of 2012 requires personal-data processing to have a lawful basis and to comply with transparency, legitimate purpose, and proportionality. It also gives data subjects rights that include being informed, accessing and correcting data, objecting in appropriate cases, and seeking blocking, removal, or destruction when the legal conditions are met.
More specific rules apply to loan-related transactions under NPC Circular No. 20-01, as amended by NPC Circular No. 2022-02.
Access to contacts is tightly limited
An online lending platform may provide a limited interface that lets a borrower select a character reference or guarantor. It may also process proportionate contact-list metadata when necessary for a specified and legitimate purpose. It may not have unconstrained, excessive, or disproportionate access to the entire contact list.
For debt collection, a lender may contact only a person who was named and validly accepted as a guarantor. Contacting other people found in the borrower’s phone, email, or social-media contact lists for collection is prohibited.
A person does not become a guarantor simply because:
- the borrower entered the person’s name or number;
- the person appears in the borrower’s contacts;
- the lender labels the person a “co-maker” in a message; or
- the person was identified only as a character reference.
A guarantor must expressly consent to undertake the obligation in accordance with the law on guaranty. Separate consent must be obtained by the lender.
Character references have limited roles
A character reference may be contacted to verify the borrower’s identity or the truth of information supplied during the loan application. The lender must tell the reference that they were selected, explain how the contact details were obtained, and provide an option to have the data removed as a character reference.
A character reference cannot automatically be treated as a guarantor. The lender may not use the reference’s details for debt collection, marketing, cross-selling, or unrelated product offers.
Photos, camera access, and other permissions
Camera or gallery access may be justified for a limited purpose such as identity verification, know-your-customer checks, fraud prevention, or payment verification. Once that purpose is complete, the permission should be turned off or the borrower should be prompted that it may be revoked.
A borrower’s photograph cannot be edited, posted, or circulated to harass or embarrass the borrower. Permissions do not give the lender unlimited authority to copy, retain, publish, or repurpose personal data.
Consent obtained through deceptive design—such as pre-ticked permissions, hidden privacy-protective choices, or a process that makes consent easy to give but unreasonably difficult to withdraw—may be invalid. The joint DICT-NPC-SEC advisory on online lending platforms summarizes these current restrictions.
What to do immediately
1. Protect your safety and accounts
If a message contains a credible threat of violence, doxxing, sexual violence, kidnapping, or harm to your family, contact the nearest police station or emergency services immediately. Do not arrange an in-person meeting with a collector who is threatening you.
Then secure your phone and accounts:
- revoke the lending app’s access to contacts, phone, camera, photos, location, files, microphone, and social media;
- change passwords for email, banking, e-wallet, and social-media accounts if compromise is possible;
- enable multi-factor authentication;
- review logged-in devices and terminate unfamiliar sessions;
- warn affected contacts not to pay, disclose information, or click links sent by the collector; and
- contact your mobile provider or financial institution if your SIM, wallet, or account may have been compromised.
Revoking app permissions does not cancel a lawful payment obligation. It limits future access to device data.
2. Preserve evidence before blocking or uninstalling
Do not rely only on cropped screenshots. Preserve enough context to identify the sender, recipient, date, time, account, and conversation.
Keep copies of:
- the app’s exact name, developer, download-page URL, and app-store listing;
- the lender’s corporate name, business address, website, customer-service details, and SEC registration or certificate-of-authority information;
- loan agreements, disclosure statements, payment schedules, receipts, and account statements;
- screenshots and screen recordings of messages, posts, caller profiles, altered photos, threats, and collection notices;
- complete SMS, chat, email, and call logs;
- phone numbers, email addresses, usernames, URLs, and social-media profile links used by collectors;
- the app’s privacy notice, terms, consent screens, and permission requests;
- proof showing which device permissions were granted;
- messages received by relatives, co-workers, employers, or other contacts;
- written statements or affidavits from affected contacts when available;
- your written complaint to the lender and proof that it was delivered;
- the lender’s response, ticket number, or proof that no response arrived; and
- evidence of actual harm, such as employment consequences, medical expenses, unauthorized transactions, or costs incurred responding to the incident.
Export original files where possible. Keep an untouched backup. Avoid editing, annotating, or forwarding the only copy because this can remove metadata or make authenticity harder to establish.
3. Identify the company behind the app
The app’s brand name may differ from the legal name of the lender. Check the loan contract, disclosure statement, privacy notice, payment destination, and app-store developer details.
Use the SEC’s Check with SEC service and its published lists of lending and financing companies. Record whether the entity appears to have both corporate registration and the necessary authority to operate as a lending or financing company. Registration as an ordinary corporation alone is not necessarily authority to engage in lending.
If you cannot identify the operator, include all available identifiers in your complaint. An unknown or overseas collector can make enforcement more difficult, but it should not stop you from reporting threats, fraud, or privacy misuse.
How to complain to the lender
Send a concise written complaint through a traceable channel listed in the contract, privacy notice, app, or official website. Address privacy issues to the company’s data protection officer when that information is available.
State:
- your name and account or loan reference;
- the dates and methods of the offending conduct;
- the phone numbers, accounts, or collectors involved;
- which personal data was accessed, used, or disclosed;
- who received the disclosure;
- why the processing or collection method was unauthorized, excessive, or abusive;
- the action you want taken; and
- a reasonable request to preserve relevant records.
You may request that the company:
- stop contacting unrelated persons;
- stop threats, insults, public posts, and other abusive methods;
- remove unlawful posts and correct false statements;
- disclose the source, purpose, recipients, and extent of its processing of your data;
- identify the lender and collection agency responsible;
- block or delete data when the statutory conditions for that remedy are satisfied;
- restrict future communication to a specified lawful channel; and
- provide a written response and complaint-reference number.
Do not admit amounts you genuinely dispute merely to make the harassment stop. Likewise, do not make factual accusations you cannot support. Separate the debt issue—such as the balance, interest, payments, or restructuring—from the collection and privacy violations.
How to report unfair collection to the SEC
For conduct by a lending or financing company or its representatives, submit a complaint through SEC iMessage. Choose the service for the Financing and Lending Companies Department when available. The joint government advisory also lists the SEC hotline 1-4732 (1-4SEC).
Your complaint should identify:
- the app and legal company name;
- the loan or account involved;
- the collector or agency, if known;
- a dated, chronological account of the conduct;
- the people contacted and what was disclosed to them;
- the particular threats, deceptive statements, insults, posts, or repeated calls;
- your efforts to complain directly to the lender; and
- clearly labeled attachments.
Ask for a ticket or reference number and preserve it. The SEC can investigate regulatory violations and impose sanctions within its authority. It does not automatically decide every private dispute about the exact balance or award every form of personal compensation.
How to file a privacy complaint with the NPC
First satisfy the written-notice requirement
Under the NPC’s current complaint mechanics, a complainant ordinarily must first notify the respondent in writing of the privacy violation or personal-data breach. The complaint should show that the respondent failed to take timely or appropriate action, or failed to respond within 15 calendar days after receiving the written notice.
Keep proof of receipt, such as a sent-email record, delivery confirmation, courier receipt, or support-ticket acknowledgment. The formal complaint should explain if prior notice was not possible or if circumstances justify an exception, but the NPC decides whether the procedural requirements are satisfied.
This 15-day period concerns the ordinary prerequisite for an NPC complaint. It does not require you to delay an urgent police report, take-down request, account-security response, or SEC complaint.
Prepare the formal complaint
Use the NPC’s current complaint-assisted form from its formal complaint page. The NPC presently requires a completed and notarized complaint-assisted form or a properly verified complaint, together with supporting evidence and witness affidavits where applicable.
Include:
- the complainant’s and respondent’s identifying details;
- a clear chronology;
- the personal data involved;
- how it was collected, accessed, used, retained, or disclosed;
- the persons who received it;
- the absence or limits of any consent;
- copies of the privacy notice and relevant permission screens;
- the harm caused;
- proof that the respondent received your written complaint;
- the response or proof that 15 calendar days passed without one; and
- the specific relief requested.
The NPC states that filing may be made personally, by registered mail, by courier, or by authorized electronic mail. Its current filing page identifies complaints@privacy.gov.ph for scanned submissions. Check the page and current form immediately before filing because form, fee, signature, PDF, copy, and submission requirements can change.
A complaint that is deficient in form, does not show that the respondent had an opportunity to address the issue, lacks enough supporting information, or fails to identify or trace the parties despite diligent efforts may be dismissed outright.
If the NPC finds a violation, possible outcomes within its authority can include compliance or enforcement orders, administrative fines or other sanctions, and appropriate relief involving personal data. When the evidence warrants possible criminal prosecution under the Data Privacy Act, the NPC may endorse the records to the Department of Justice. A reported violation does not guarantee any particular finding, penalty, or award.
When the BSP is the proper financial regulator
The BSP route applies when the provider is a BSP-supervised financial institution, such as a bank or another entity falling under BSP supervision. A typical SEC-licensed lending company is generally reported to the SEC instead.
For a BSP-supervised provider:
- file the complaint first through the provider’s own consumer-assistance channel;
- preserve its acknowledgment and reference number; and
- if the response is absent or unsatisfactory, escalate through the BSP Online Buddy or Consumer Assistance Mechanism.
The BSP also accepts its Complaints, Inquiries and Requests form at consumeraffairs@bsp.gov.ph. Include the financial institution’s complaint-reference number because its internal mechanism is normally the first-level recourse.
When to contact law enforcement
Seek prompt law-enforcement assistance when the facts involve:
- a credible threat of physical harm;
- demands for money backed by threats to harm, expose, or falsely accuse someone;
- impersonation of police officers, courts, prosecutors, lawyers, or government agencies;
- fake arrest warrants, fabricated cases, or false claims that arrest is imminent;
- unauthorized account access, identity theft, SIM compromise, or fraudulent transfers;
- publication of intimate images or sexual threats;
- stalking, doxxing, or disclosure of a home or workplace that creates a safety risk; or
- continuing conduct that may destroy evidence or cause immediate harm.
The exact criminal offense depends on the words used, the surrounding facts, the identity and intent of the sender, and the evidence. Not every rude message is automatically a cybercrime. Bring the original device and preserved records when requested, and ask for the complaint or blotter reference.
The joint government advisory lists:
- DICT Cyber Hotline: 1326@dict.gov.ph
- NBI Cybercrime Division: ccd@nbi.gov.ph
You may also report at the nearest appropriate police or NBI office. Do not pay someone claiming that payment is required to cancel an arrest warrant or prevent immediate imprisonment. Verify official documents directly with the named court or agency.
Does unpaid debt allow arrest or public shaming?
No. The Philippine Constitution provides that no person shall be imprisoned merely for debt or nonpayment of a poll tax. A creditor may use lawful civil remedies, and separate criminal liability may arise from independently unlawful conduct such as fraud when its legal elements are supported by evidence. Mere inability or failure to pay a loan, by itself, is not authority for a collector to threaten arrest.
The lender may accurately communicate with the borrower about the account and use lawful remedies. It may not invent a criminal case, pose as an officer, circulate humiliating material, or disclose the debt indiscriminately to pressure payment.
Practical ways to limit further harm
- Tell family, friends, and co-workers that they are not required to engage with the collector unless they knowingly and validly became guarantors.
- Ask recipients to preserve the original messages before blocking the sender.
- Request removal of abusive posts through the platform’s harassment, privacy, impersonation, or doxxing process.
- Do not post your entire loan agreement, ID, address, phone number, or unredacted screenshots publicly while seeking help.
- If you negotiate payment, use the lender’s verified channel and obtain written terms before sending money.
- Verify the payee. Do not transfer funds to a collector’s personal wallet merely because of a threat.
- Request an updated statement of account and official receipt for every payment.
- Keep complaints factual and consistent across the lender, SEC, NPC, BSP, platforms, and law-enforcement offices.
- Continue preserving new incidents after filing; submit supplementary evidence through the channel and procedure given by the receiving agency.
Common mistakes to avoid
Deleting the app or messages too soon
Uninstalling may stop some access, but it can also remove evidence. Capture the app details, permissions, privacy notice, account page, and offending content first, unless leaving the app installed creates an immediate security risk.
Reporting only the app’s marketing name
Regulators need the legal operator. Include the corporate name, contract, developer, payment account, website, phone numbers, and every other available identifier.
Filing an NPC complaint without prior written notice
Unless an exception applies, failing to notify the respondent and document the 15-day response period may result in dismissal. Use a traceable written channel.
Treating every reference as a guarantor
A reference does not owe the debt merely because the lender says so. Ask for the document showing the person’s express consent to guaranty.
Paying through an unverified personal account
A threat does not prove that the sender is authorized. Confirm payment details through the lender’s official channel and demand a receipt.
Assuming a complaint cancels the loan
A regulatory or privacy complaint addresses misconduct. The validity, computation, or enforceability of the debt may require a separate review of the contract, disclosures, payments, interest, charges, and applicable law.
Posting all evidence publicly
Public exposure can spread your own personal data, disclose other people’s information, complicate take-down efforts, and create additional legal issues. Give complete evidence to the authorities; share only carefully redacted material elsewhere.
When legal help is urgent
Consult a Philippine lawyer or the appropriate legal-aid office promptly if:
- a collector has made a credible threat or appeared at your home or workplace;
- private images, identification documents, or sensitive information have been published;
- your employer or livelihood is being targeted;
- you received an authentic summons, subpoena, court order, demand letter, or notice of a filed case;
- money was taken from an account without authorization;
- the lender claims you signed a guaranty or loan document that you dispute;
- you need an injunction, damages, or another court remedy;
- several agencies or companies are involved; or
- the amount, interest, fees, or payment history is materially disputed.
Do not ignore genuine court papers. Verify them with the issuing court and observe the stated deadline even if you have already complained to a regulator.
Frequently asked questions
Can a lender call my family, friends, employer, or co-workers?
Not merely because they appear in your contacts. For debt collection, the NPC’s loan-related rules permit contact with a validly designated guarantor—not unrelated contacts or a person who was only a character reference. A reference may be contacted for limited identity or application-verification purposes, not to pressure payment.
I gave the app permission to access contacts. Does that make the harassment legal?
No. Permission is not unlimited consent. Processing must still be transparent, lawful, necessary, proportionate, and confined to a specified legitimate purpose. Unbridled contact-list processing, harassment, and collection from people who are not guarantors remain prohibited.
Can a collector post my photograph and label me a scammer?
Using a borrower’s photograph to harass or embarrass the borrower is expressly prohibited by the NPC’s loan-related guidelines. False or malicious public statements may raise additional legal issues depending on their exact content and publication.
Can I complain even if the loan is overdue?
Yes. Default does not remove your privacy rights or authorize unfair collection. Be truthful about the account and distinguish the overdue debt from the unlawful method used to collect it.
Can a character reference be forced to pay?
Not solely because they were named as a reference. A guarantor must expressly consent to undertake the obligation. Whether a particular document creates an enforceable guaranty depends on its contents and the surrounding facts.
Should I block the collectors?
Preserve the evidence first. You may then block abusive accounts or restrict communication to one documented channel. If there is a credible threat, report it immediately rather than continuing the exchange.
Can I file with the SEC and NPC at the same time?
Potentially, yes. The SEC addresses unfair collection and regulatory violations by lending and financing companies, while the NPC addresses unlawful personal-data processing. Disclose related filings when a complaint form or agency rule requires it, and avoid seeking inconsistent relief.
What if the app is unregistered or has disappeared?
Report all known identifiers, including screenshots, contracts, developer details, payment accounts, phone numbers, URLs, and messages. Also report threats, fraud, or account compromise to law enforcement. An unidentified operator can complicate the case but does not make the conduct lawful.
Will the agencies erase my debt or award damages automatically?
No. The agencies act only within their legal powers, and outcomes depend on jurisdiction, evidence, procedure, and the particular violation. A separate civil action or contract review may be necessary for some remedies.
Official references
- Data Privacy Act of 2012
- NPC implementing rules for the Data Privacy Act
- NPC Circular No. 2022-02 amending the loan-related data-processing guidelines
- NPC formal complaint instructions
- NPC complaint mechanics
- SEC Memorandum Circular No. 18, Series of 2019
- SEC iMessage
- Financial Products and Services Consumer Protection Act
- BSP consumer-assistance channels
- Joint DICT-NPC-SEC Public Advisory on Online Lending Platforms
This article provides general legal information, not legal advice. The proper remedy and possible liability depend on the actual messages, permissions, contracts, parties, and evidence. Official sources and procedures were checked as of September 3, 2026; confirm the latest forms, addresses, fees, and filing requirements with the relevant agency before submitting.