Quick answer
An online lender may collect and use only the personal data that is lawful, relevant, necessary, and proportionate to a specific loan-related purpose. Applying for a loan does not give the lender unlimited permission to copy your contacts, monitor your device, disclose your debt to unrelated people, or use your photograph or personal details to shame you.
A lending app may temporarily access a camera or photo gallery for a legitimate purpose such as identity verification, know-your-customer checks, fraud prevention, or payment verification. Contact-list access is much narrower: it may be used only to let you select a character reference or guarantor, or to derive proportionate metadata when genuinely necessary for a specified legitimate purpose. Unrestricted copying or use of contacts—and contacting people other than a properly designated guarantor to collect your debt—is prohibited.
You may ask the lender to explain its processing, give you access to your data, correct inaccurate information, stop unauthorized uses, and erase or block data when the legal requirements are met. If the lender does not act appropriately, you may file a privacy complaint with the National Privacy Commission (NPC). Harassment or unfair collection may also be reported to the Securities and Exchange Commission (SEC), while threats, fraud, extortion, impersonation, or account compromise should be reported promptly to law-enforcement or cybercrime authorities.
These privacy remedies do not automatically cancel a valid loan. A lender may still process data genuinely necessary to administer or collect a lawful obligation, comply with regulatory duties, or establish or defend legal claims.
What law protects your loan-related personal data?
The principal law is the Data Privacy Act of 2012, Republic Act No. 10173. It requires processing to be transparent, for a legitimate purpose, and proportionate. Personal data must be:
- collected for specified and legitimate purposes;
- processed fairly and lawfully;
- accurate, relevant, and kept up to date when necessary;
- adequate but not excessive;
- retained only as long as necessary for the stated purpose, legitimate business needs, legal claims, or a period required by law; and
- protected by reasonable organizational, physical, and technical safeguards.
For loan transactions, the more specific rules are in NPC Circular No. 2020-01, as amended by NPC Circular No. 2022-02. They apply to lending companies, financing companies, and other persons acting as lenders, including entities using mobile applications, websites, or other online platforms.
The DICT, NPC, and SEC summarized the current requirements in their 2026 Public Advisory on Online Lending Platforms.
What information may an online lender process?
Depending on the transaction, lawful processing may include information reasonably necessary to:
- verify identity and comply with know-your-customer or anti-fraud requirements;
- assess a loan application and creditworthiness;
- prepare, perform, or administer the loan agreement;
- release and receive payments;
- communicate directly with the borrower;
- collect a lawful unpaid obligation within legal limits;
- comply with reporting, recordkeeping, court, or regulatory requirements; and
- establish, exercise, or defend legal claims.
The lawful basis is not always consent. Processing may also be necessary to take steps requested before entering a contract, perform the loan agreement, comply with a legal obligation, or pursue a legitimate interest that is not overridden by the borrower’s fundamental rights.
This distinction matters. Withdrawing consent can stop processing that depends on consent, but it does not necessarily require the lender to delete records that must still be kept or used under another valid legal basis. The lender must be able to identify its purpose and lawful basis; a broad statement such as “for business purposes” is not a blank check.
Sensitive personal information—such as government-issued identifiers, health information, education records, marital status, or information about legal proceedings—receives stricter protection and may be processed only under the conditions allowed by law.
App permissions must be necessary and properly timed
A lender should not demand every available phone permission at installation merely because the app might use it later. The amended loan-data rules require consent at the point when the particular data becomes necessary, supported by a “just-in-time” notice explaining how that data will be processed.
For example, camera or gallery permission may be justified while the borrower is taking or selecting an identification photograph. Once that purpose is completed, the app should turn off the permission by default or tell the borrower that it may be revoked.
The same principle applies throughout the account’s life. A permission that was necessary during identity verification does not automatically remain necessary during repayment or after account closure.
Deceptive interface designs may undermine valid consent. Warning signs include pre-ticked permission boxes, a prominent “agree” button paired with a hidden privacy-preserving option, or an easy consent process with no reasonably accessible way to withdraw consent.
Can the lender access your phone contacts?
Only within strict limits.
An online lending platform may provide a separate interface allowing you to select a character reference or guarantor from your contacts. Access must be limited to the minimum necessary for that selection. The rules also recognize proportionate use of contact-list metadata when necessary for a specified legitimate purpose, but this does not permit unrestricted harvesting, copying, saving, or later use of the entire contact list.
“Unbridled” processing is prohibited. This includes processing that:
- is excessive or disproportionate;
- leads to harassment;
- is used to collect a debt from people other than the guarantors identified by the borrower; or
- results in an unfair collection practice.
The lender cannot justify mass messaging your family, friends, co-workers, clients, or social-media contacts merely by pointing to a general permission accepted when the app was installed.
Character references are not automatically guarantors
A character reference is normally supplied to help verify the applicant’s identity or the truthfulness of information in the loan application. The borrower should inform the person before providing the person’s details.
The lender must tell the reference that:
- the borrower selected them as a character reference;
- how the lender obtained their contact details; and
- they may request removal of their personal data as a character reference.
A lender may not use a reference’s details for unrelated marketing, cross-selling, or sharing with third parties to offer other products or services.
Most importantly, a character reference does not become liable for the loan simply because their name and number were supplied. A guarantor must separately and expressly agree to assume the obligation in accordance with the law on guaranty. For debt collection, the lender may contact a valid guarantor, but it may not contact other people in the borrower’s contact list about the debt.
The lender may not use your photograph to shame you
A photograph obtained for identity verification, fraud prevention, payment verification, or another specified legitimate purpose cannot be transformed into a collection weapon.
Editing a borrower’s photo, attaching accusations or humiliating language, creating a “wanted” poster, or sending the image to other people to pressure payment may violate the Data Privacy Act, the NPC’s loan-data rules, and SEC rules against unfair debt collection. Whether a particular act also amounts to a criminal offense or gives rise to civil liability depends on its content, recipients, method, and surrounding facts.
Disclosure to collectors and service providers
A lender may engage a collection agency, cloud provider, identity-verification provider, or other processor. Outsourcing does not erase the lender’s accountability.
The lender remains responsible for personal data under its control and must use contractual and other reasonable safeguards to ensure comparable protection. A service provider may process the data only under lawful instructions and within the authorized purpose. Foreign service providers must likewise be subject to appropriate technical and contractual controls.
If a collector discloses the debt to unrelated people, harvests contacts, threatens the borrower, or uses data to shame them, identify both the collector and the lender in any complaint when the evidence supports doing so.
Your rights as a data subject
Subject to the facts, applicable exceptions, and the lender’s lawful grounds for continued processing, you may exercise the following rights.
Right to be informed
You should receive clear information about:
- what personal data is collected;
- the purposes and lawful bases for processing;
- how the data is processed;
- who receives or may receive it;
- how long it will be retained;
- the lender or controller’s identity and contact details;
- how to contact its data protection officer;
- your data-subject rights; and
- automated processing or profiling that will, or is likely to, be the sole basis of a decision significantly affecting you.
This information should be accessible in the app or platform, not buried where an ordinary borrower is unlikely to find it.
Right of access
You may request reasonable access to your processed personal data, including:
- the data held about you;
- its source;
- recipients and their addresses;
- how it was processed;
- reasons for disclosure;
- information about relevant automated processing;
- when the data was last accessed or modified; and
- the identity and address of the personal information controller.
The right of access does not necessarily require disclosure of another person’s protected information or proprietary material beyond what the law requires.
Right to correction
You may dispute inaccurate or erroneous information and request prompt correction. This is especially important for an incorrect balance, payment status, identity detail, contact number, or credit-related record.
If information has been corrected, the lender may also have to make the corrected and retracted information available and, upon reasonable request, inform previous recipients of the correction.
Right to object or withdraw consent
You may object to processing or withdraw consent where consent is the legal basis. The lender must stop that processing unless another lawful basis permits or requires it.
Withdrawal does not undo processing that was lawful before withdrawal, erase the loan contract, extinguish an unpaid obligation, or prevent retention needed for legal claims or statutory duties.
Right to blocking, removal, erasure, or destruction
You may seek suspension, blocking, removal, or destruction when there is substantial proof that the data is incomplete, outdated, false, unlawfully obtained, used for an unauthorized purpose, or no longer necessary.
Deletion is not absolute. The lender may retain particular records that remain necessary for legal compliance, legitimate business purposes, or the establishment, exercise, or defense of legal claims. It should not use this exception to retain every permission or every copied contact indefinitely.
Right to damages and to complain
A person who suffers damage because of inaccurate, incomplete, outdated, unlawfully obtained, or unauthorized use of personal data may seek indemnification as allowed by law. Compensation is not automatic: the claimant must establish the legal basis, injury, and causal connection.
You may also bring a complaint before the NPC for misuse, malicious disclosure, improper disposal, inadequate security, denial of data-subject rights, or another violation of the Data Privacy Act and related NPC issuances.
What to do if your data is being misused
1. Stop unnecessary access without destroying evidence
Review the app’s permissions in your phone settings. Turn off contacts, camera, gallery, location, microphone, storage, or other permissions that are no longer necessary.
Before uninstalling the app, preserve the evidence you may need. Uninstalling can remove notifications, local records, or information identifying the app and operator.
Change passwords if the same password was used elsewhere. Enable multi-factor authentication on email, banking, social-media, and messaging accounts. If you suspect SIM or account takeover, immediately contact the relevant provider.
2. Preserve complete evidence
Keep original electronic files where possible, not only cropped screenshots. Preserve:
- the app name, icon, download page, developer name, website, and package identifier;
- the lender’s corporate name, SEC registration or authority details, address, and contact information;
- the privacy notice, permission screens, consent prompts, and relevant terms;
- dates and times when each permission was requested;
- screenshots or screen recordings showing the app’s access;
- messages, emails, call logs, voice recordings lawfully obtained, and voicemail;
- names, numbers, account names, and profiles used by collectors;
- messages received by references, relatives, co-workers, or other third parties;
- copies of posts or group messages showing public disclosure;
- the loan agreement, disclosure statement, payment schedule, receipts, and account ledger;
- your written request to the lender and proof that it was received; and
- the lender’s response, or proof that no response arrived.
Ask third-party recipients to preserve the original message and provide their own screenshots or affidavit. Do not ask anyone to fabricate, edit, or exaggerate evidence.
3. Write to the lender or its data protection officer
Identify the conduct precisely. A useful request should state:
- your full name and account reference;
- the data or permission involved;
- what happened, when, and how you discovered it;
- why you believe the processing was excessive, inaccurate, unauthorized, or no longer necessary;
- the names or numbers contacted, if applicable;
- the specific relief requested; and
- a request to preserve relevant logs and records while the dispute is pending.
Possible relief includes stopping disclosure, correcting data, identifying recipients, providing an access report, removing a character reference, blocking unauthorized processing, revoking unnecessary access, and confirming appropriate deletion.
Send the request through a channel that produces proof of transmission and receipt. Keep the language factual. Do not include passwords, one-time PINs, or unrelated sensitive information.
4. Allow the required response period unless the case is urgent
Before an ordinary NPC complaint is given due course, the complainant generally must first inform the lender, processor, or concerned entity in writing and allow it to take appropriate action. If it does not respond within 15 calendar days from receipt, or its action is not timely or appropriate, the complainant may proceed.
Under the NPC’s 2021 Rules of Procedure, as amended, the NPC may waive this exhaustion requirement for good cause or a serious violation—for example, where immediate NPC action is needed to prevent grave and irreparable harm, the respondent cannot provide a plain and adequate remedy, or the challenged action is patently illegal. Explain and prove the urgent circumstances rather than simply omitting the prior written notice.
5. File a formal NPC complaint
The NPC’s current instructions require a completed and notarized complaint form or a properly verified complaint, together with supporting evidence and witness affidavits, if any. The complaint should identify the complainant and respondent, narrate the material facts, state the violations and requested relief, attach the prior correspondence, and include the required certification against forum shopping.
The NPC warns that incomplete complaints may be dismissed. If a related case has already been filed before a court, tribunal, or another quasi-judicial agency, disclose it accurately. If you later learn of a similar proceeding, the rules require you to report that fact to the NPC within five calendar days.
Use the NPC’s current complaint-filing instructions and form. The official page lists filing in person, by courier, or by scanning and emailing the notarized complaint to the stated NPC complaints address. Check the page before filing for the current form, address, filing fee, and submission requirements.
6. Report unfair collection to the SEC
For unfair collection by a lending or financing company, submit a complaint through the SEC iMessage system under the service for complaints on financing and lending companies. The 2026 joint advisory also identifies the SEC Financing and Lending Companies Department and hotline 1-4732 (1-4SEC).
A privacy complaint and an SEC complaint address different regulatory issues. The NPC focuses on personal-data processing and data-subject rights; the SEC regulates lending and financing companies and their collection conduct. The same incident may justify reports to both agencies.
Neither complaint automatically settles the account balance, rescinds the contract, or suspends payment duties. Keep any legitimate payment dispute separate and supported by the agreement, disclosure statement, ledger, and receipts.
7. Escalate threats, fraud, or account compromise immediately
Do not wait 15 days if there is an immediate threat to safety, ongoing extortion, impersonation, unauthorized access, or active fraud. Preserve the evidence and contact the appropriate authorities.
The 2026 government advisory lists:
- DICT Cyber Hotline:
1326@dict.gov.ph - NBI Cybercrime Division:
ccd@nbi.gov.ph
For imminent physical danger, contact local law enforcement or emergency services at once. A lawyer can help determine whether the facts support a criminal complaint, an application for urgent judicial relief, or another remedy.
If the lender reports information to a credit system
A lender may have lawful duties or grounds to submit credit data. The Data Privacy Act does not create a right to erase accurate adverse credit information merely because it is unfavorable.
You may, however, dispute information that is wrong, incomplete, misleading, or attributed to the wrong person. Request the exact record, identify each error, and attach contracts, receipts, settlement documents, account statements, or identity records. A dispute about credit data may involve both the lender and the relevant credit-information entity, depending on where the error originated.
Personal-data breaches
A personal-data breach is different from an intentional collection or disclosure dispute. It may involve unauthorized access caused by hacking, lost devices, exposed databases, misdirected messages, or inadequate security.
A lender must maintain reasonable security measures and remains accountable for processors acting on its behalf. When sensitive personal information or information capable of enabling identity fraud is reasonably believed to have been acquired by an unauthorized person, and the unauthorized acquisition is likely to create a real risk of serious harm, the controller must notify the NPC and affected data subjects under the applicable breach-notification rules.
If you receive a breach notice, follow its protective instructions but independently secure your email, mobile number, financial accounts, and identification records. Ask what data was affected, when the breach occurred, what containment was performed, and what assistance is available.
Common mistakes to avoid
- Assuming that every requested permission is lawful because the borrower tapped “Allow.”
- Treating a character reference as responsible for the debt without a separate guaranty.
- Deleting the app, messages, or call logs before preserving evidence.
- Posting unredacted IDs, contracts, phone numbers, or screenshots publicly while seeking help.
- Making only a telephone complaint and keeping no proof that the lender received written notice.
- Filing an incomplete, unsigned, unverified, or unnotarized NPC complaint.
- Omitting a related complaint or court case from the certification against forum shopping.
- Believing that a privacy complaint automatically cancels the principal, interest, or payment schedule.
- Stopping all payments solely because a collector violated privacy rules, without obtaining advice on the separate contractual consequences.
- Paying a person who promises guaranteed deletion, regulator approval, or immediate cancellation of the debt.
- Threatening collectors, editing screenshots, or using another person’s account to obtain evidence.
When legal help is urgent
Consult a Philippine lawyer promptly when:
- personal data, photographs, or accusations are being posted publicly;
- the lender is repeatedly contacting an employer, clients, children, or unrelated relatives;
- messages contain threats of violence, arrest without lawful basis, property damage, or exposure of intimate information;
- identity documents or financial credentials appear to have been compromised;
- money was transferred through an unauthorized transaction;
- you receive a subpoena, summons, court order, or formal demand with a deadline;
- several complaints concerning the same events may create a forum-shopping issue;
- you seek damages, an injunction, or criminal prosecution; or
- the identity of the actual lender, app operator, collector, or data controller is unclear.
Deadlines and the proper respondent can depend on the cause of action, date of discovery, documents, and forum. Do not rely on an agency complaint to pause a court deadline.
Frequently asked questions
Can a lender message everyone in my contacts?
No. Unrestricted processing of a contact list and contacting people other than designated guarantors for debt collection are prohibited. A lender may use limited access to let you select a reference or guarantor, or proportionate metadata for a specified legitimate purpose, but that is not authority to broadcast your debt.
Can the lender call my character reference about payment?
A character reference is for identity or information verification and is not automatically a guarantor. The reference’s data cannot be repurposed for debt collection merely because the borrower supplied the number.
Does naming someone as a guarantor make that person liable?
No. The person must separately and expressly consent to become a guarantor in accordance with applicable law. The label entered by the borrower alone is insufficient.
Can I demand immediate deletion after paying the loan?
You may request deletion of data that is no longer necessary, but immediate deletion of every record is not guaranteed. The lender may retain information required by law or reasonably necessary for legal claims and legitimate business purposes. It should explain the applicable purpose, legal basis, and retention period.
Can I withdraw permission while the loan is active?
You may revoke unnecessary device permissions and withdraw consent-based processing. The lender may continue processing data genuinely necessary to perform the contract, comply with law, collect a lawful debt, or protect legal claims.
Can the lender use my photo in collection messages?
Not to harass or embarrass you. A photograph collected for verification or a similar legitimate purpose cannot lawfully be turned into a shaming poster or circulated as pressure for payment.
Can a person contacted by the lender complain even if they are not the borrower?
Potentially, yes. A reference, relative, co-worker, or other individual whose own personal data was improperly obtained or used may exercise their own data-subject rights and may file a complaint based on the facts affecting them.
Is an unregistered online lender exempt from privacy law?
No. Processing personal data for loan-related transactions does not become lawful merely because the operator lacks the required lending authority. Give the NPC and SEC all available information that may identify the app, developer, company, payment recipient, website, and collectors.
Will an NPC or SEC complaint cancel my loan?
Not automatically. Privacy and collection violations are distinct from whether a loan obligation is valid and how much remains payable. Contractual disputes may require a separate complaint, negotiation, defense, or court proceeding.
Official sources
- Data Privacy Act of 2012
- NPC Circular No. 2022-02 amending the loan-data guidelines
- 2021 NPC Rules of Procedure, as amended
- NPC formal complaint instructions
- 2026 DICT-NPC-SEC Public Advisory on Online Lending Platforms
- SEC iMessage complaint system
This article provides general Philippine legal information, not legal advice for a particular loan, privacy incident, or case. Rights and remedies depend on the documents, parties, dates, type of information, lawful basis for processing, and available evidence. Official sources and procedures were last checked on September 5, 2026.