In the digital age, a phone number or an email address is more than just a string of characters; it is a gateway to a person’s identity. In the Philippines, the unauthorized sharing of this information is not just a breach of social etiquette—it is a violation of the Data Privacy Act of 2012 (Republic Act No. 10173).
Below is a comprehensive guide on the legal framework, rights, and procedures involved when your contact information is shared without your consent.
1. The Legal Framework: R.A. 10173
The Data Privacy Act (DPA) was enacted to protect the fundamental human right to privacy while ensuring the free flow of information. Under this law, contact information (mobile numbers, home addresses, personal email addresses) is classified as Personal Information.
Key Principles of Processing
For the sharing of contact info to be legal, it must adhere to three principles:
- Transparency: You must be informed that your data is being collected.
- Legitimate Purpose: There must be a valid reason for sharing it.
- Proportionality: Only necessary information should be shared.
The Core Rule: Generally, personal information cannot be shared with third parties unless the Data Subject (you) has given explicit consent, or the sharing falls under specific legal exemptions (e.g., a court order or public safety).
2. When is Sharing a Violation?
Sharing contact information without consent typically falls under Unauthorized Processing or Malicious Disclosure. Common scenarios include:
- Adding someone to a messaging group (Viber, WhatsApp) for marketing without asking.
- Posting a person’s phone number on social media to incite harassment (doxing).
- Selling "leads" or contact lists to telemarketers.
- A company sharing your details with an affiliate without a clear privacy agreement.
3. Remedies and the NPC
The National Privacy Commission (NPC) is the regulatory and quasi-judicial body that enforces the DPA. If your rights are violated, you have the right to file a formal complaint.
Prerequisites for Filing
Before the NPC takes cognizance of a complaint, the law usually requires you to:
- Notify the Violator: Inform the person or entity (the Personal Information Controller) of your grievance.
- Request Redress: Ask them to stop sharing the info or delete it.
- Wait for a Response: If they ignore you or provide an unsatisfactory explanation, you may then proceed to the NPC.
4. How to File a Formal Complaint
The process is governed by the NPC Rules of Procedure.
| Step | Action | Description |
|---|---|---|
| 1 | Prepare the Complaint | Write a "Complaints-Affidavit" detailing the "who, what, when, and where" of the violation. |
| 2 | Gather Evidence | Attach screenshots, links, witness statements, or copies of the unauthorized communication. |
| 3 | Submission | Submit the complaint via the NPC’s online portal or physically at their office (PICC Complex, Manila). |
| 4 | Mediation | The NPC often mandates a mediation conference to see if the parties can reach an amicable settlement. |
| 5 | Adjudication | If mediation fails, the NPC will review the merits and issue a Decision or Sua Sponte order. |
5. Penalties for Violators
The DPA carries heavy penalties to deter "data leakers." If found guilty of Unauthorized Processing, the penalties may include:
- Imprisonment: Ranges from 1 to 3 years.
- Fines: Ranges from ₱500,000 to ₱2,000,000.
If the act is deemed Malicious Disclosure (sharing info with intent to cause harm or for profit), the imprisonment can extend up to 5 years, and fines can reach ₱1,000,000.
6. Practical Tips for Data Subjects
- Keep Records: Always save screenshots of the unauthorized post or the message where your info was shared.
- Check Privacy Notices: Before giving your number to a mall raffle or a website, read the fine print.
- Exercise Your "Right to Object": You have the right to demand that a company stop using your data for marketing.
Would you like me to draft a template for a Demand Letter that you can send to a person or company that shared your contact information without consent?