How to Report Online Lending App Harassment and Privacy Violations

Quick answer

If an online lending app is threatening, insulting, publicly shaming, or contacting people who did not guarantee your loan, preserve the evidence and report the conduct through the appropriate channels:

  1. Secure your evidence and device. Save messages, call logs, app permissions, loan documents, payment records, and messages received by your contacts before blocking numbers or uninstalling the app.
  2. Complain in writing to the lender’s consumer-assistance desk and Data Protection Officer (DPO). Demand that the harassment and unlawful use or disclosure of personal data stop.
  3. Report unfair collection by a lending or financing company to the Securities and Exchange Commission (SEC).
  4. File a privacy complaint with the National Privacy Commission (NPC) if the app harvested contacts, disclosed the debt, misused photos or other data, or ignored a valid privacy request.
  5. Contact the police or NBI immediately if there are credible threats of violence, extortion, impersonation, account intrusion, or other possible crimes. Dial 911 if anyone is in immediate danger.

You may use more than one channel because collection abuse, privacy violations, and criminal conduct fall under different authorities. A complaint does not automatically cancel a valid loan, suspend payment obligations, or authorize you to ignore genuine court papers.

Conduct that may be unlawful

The Financial Products and Services Consumer Protection Act, or Republic Act No. 11765, requires financial service providers to treat clients fairly and respectfully, protect client data, maintain a free consumer-assistance mechanism, and refrain from abusive debt-recovery practices.

For SEC-regulated lending and financing companies, SEC Memorandum Circular No. 18, Series of 2019 prohibits practices that include:

  • Using or threatening violence or other criminal means to harm a person, reputation, or property;
  • Threatening action that cannot legally be taken;
  • Using obscene, insulting, or profane language that amounts to abuse or an offense;
  • Publishing a borrower’s name or personal information over an alleged refusal to pay, except for narrowly permitted lawful disclosures;
  • Communicating information known, or which should be known, to be false—including failing to state that a debt is disputed when communicating permitted loan information;
  • Using deception or false representations to collect a debt or obtain borrower information;
  • Contacting a borrower before 6:00 a.m. or after 10:00 p.m., unless the account is more than 15 days past due or the borrower expressly agreed, through written, electronic, or recorded means, that those hours are the only reasonable times for contact; and
  • Contacting people in the borrower’s contact list who were not named as guarantors or co-makers—even if the borrower previously allowed the app to access the contact list.

The exception for certain contact hours does not authorize threats, insults, public shaming, deception, or harassment of third parties.

Privacy rules for contacts, photos, and app permissions

The Data Privacy Act of 2012, or Republic Act No. 10173, requires personal-data processing to be transparent, for a legitimate purpose, and proportionate to that purpose. Consent is not a blank check: even consent written into an app’s terms does not validate processing prohibited by law.

Under NPC Circular No. 2020-01, as amended by NPC Circular No. 2022-02:

  • Lending apps may require permissions only when suitable, necessary, and not excessive for a lawful purpose.
  • The user should receive a clear, just-in-time notice explaining how particular data will be used.
  • Camera or gallery access may be justified at a particular stage for identity verification, fraud prevention, or payment verification, but continued access must still be necessary and lawful.
  • A borrower’s photo may not be used to harass or embarrass the borrower.
  • Unconstrained, excessive, or disproportionate processing of an entire contact list is prohibited, particularly when it leads to harassment, debt collection from people other than guarantors, or another unfair collection practice.
  • Limited contact-list access may be allowed to derive proportionate metadata or to let the borrower select a character reference or guarantor, but it must be limited to the minimum necessary.
  • A character reference may be contacted to verify the borrower’s identity or information. The reference must be told how the contact details were obtained and must be given the option to have the data removed as a character reference.
  • A character reference is not automatically a guarantor. A guarantor must separately and expressly agree to undertake the borrower’s obligation in accordance with the law.
  • For debt collection, the lender may contact the guarantor—not unrelated people in the borrower’s phonebook.

Not every app permission is automatically unlawful. The decisive questions include why it was requested, what data was actually collected, whether the access was necessary and proportionate, what the privacy notice disclosed, and how the data was later used.

What to do immediately

1. Preserve evidence before blocking or uninstalling

Keep the original files wherever possible. Create a dated folder containing:

  • Screenshots showing the complete message, sender’s number or account, date, and time;
  • Exported chat or email threads;
  • Call logs and voicemails already left for you;
  • The app’s name, developer, version, download-page URL, privacy notice, and permission screens;
  • Screenshots showing access to contacts, photos, camera, microphone, location, storage, or social-media accounts;
  • The loan agreement, disclosure statement, repayment schedule, account statement, receipts, and proof of payment;
  • The corporate name, SEC registration number, Certificate of Authority number, customer-service details, and collection agency named in the app or documents;
  • Messages sent to relatives, friends, coworkers, employers, or other contacts;
  • Statements or affidavits from affected contacts, together with their screenshots;
  • Your written complaints to the company, delivery or read receipts, replies, and ticket numbers; and
  • A chronological log describing each incident and its effect.

Preserve an untouched copy and a separate working copy. Do not crop out identifying details or edit the original messages. Back up the evidence to a secure account or drive.

Secretly recording a private conversation can create issues under the Anti-Wiretapping Act, Republic Act No. 4200. Preserve voicemails and written communications you received, but obtain legal advice before secretly recording live private calls.

2. Identify the company behind the app

The app’s brand name may differ from the lender’s corporate name. Check the loan agreement, disclosure statement, privacy notice, billing details, app-store developer page, receipts, and payment instructions.

An online lending platform should conspicuously disclose its corporate name, SEC registration number, and Certificate of Authority number. If those details are absent or inconsistent, include that fact and supporting screenshots in the SEC report. Do not assume that an app is licensed merely because it appears in an app store.

3. Revoke unnecessary permissions—after preserving evidence

After capturing the app and permission screens:

  • Turn off access to contacts, photos, camera, microphone, location, and storage when no longer necessary;
  • Change passwords for accounts that may have been exposed;
  • Enable multi-factor authentication;
  • Review logged-in devices and revoke unfamiliar sessions;
  • Warn contacts not to open links, disclose information, or send money to collectors; and
  • If serious account intrusion or identity theft is suspected, preserve the phone and consult investigators before wiping or replacing it.

Revoking a permission or uninstalling the app does not necessarily delete information already copied to the lender’s systems.

Send a written complaint to the lender first

Financial service providers must maintain a free consumer-assistance mechanism. Send the complaint to the company’s official customer-service channel and DPO—not merely to the collector who is harassing you. Ask for a ticket number or written acknowledgment.

A concise complaint may say:

I am reporting unfair debt-collection and personal-data processing connected with account [reference number]. On [dates], your company or collection agent [describe the messages, calls, disclosure, contact-list use, or public post]. I dispute [identify any incorrect amount or statement, if applicable].

Please immediately stop contacting persons who are not my guarantors, stop publishing or disclosing my loan information, and restrict all lawful communications to [email/address]. Please identify the company and collection agency responsible, the source and categories of personal data used, the recipients to whom my information was disclosed, the lawful basis and purpose for the processing, and the applicable retention period.

Please preserve all relevant call records, messages, access logs, collection instructions, and disclosure records. Correct any false information and block, remove, or delete unlawfully processed data where legally required. This request does not require deletion of records that the law permits or requires you to retain.

Please provide your written action on this complaint. For purposes of the NPC complaint process, I request a response within 15 calendar days from receipt.

Attach copies, not your only originals. Redact unrelated personal information and never send an OTP, password, PIN, or unnecessary identification document.

How to file with the National Privacy Commission

Use the NPC route when the complaint concerns contact harvesting, unauthorized or excessive permissions, disclosure of a debt, public shaming, misuse of photos, failure to honor data-subject rights, or another privacy violation.

The 15-calendar-day pre-complaint requirement

Under the 2021 NPC Rules of Procedure, as amended, you generally must prove that:

  1. You informed the company, DPO, data processor, or other concerned entity of the privacy violation in writing; and
  2. It failed to take timely and appropriate action, or did not respond within 15 calendar days after receiving your written notice.

Keep proof showing when the company received the complaint.

The NPC may waive this requirement for proven good cause or a serious violation, including circumstances involving grave and irreparable harm, lack of a plain and adequate remedy, or patently illegal action. Waiver is discretionary. If continuing disclosure or harassment makes waiting dangerous, state the facts, attach proof, and expressly ask the NPC to waive the requirement.

This waiting period does not prevent an immediate police or NBI report concerning threats or possible crimes.

Prepare and file the formal complaint

Use the current Complaint-Affidavit template on the NPC’s formal complaint page. A new template took effect on July 1, 2025, so an older downloaded form may no longer be accepted.

The complaint should:

  • Identify you and the respondent;
  • Give a clear chronological statement of material facts;
  • Identify the privacy provisions or conduct complained of;
  • Attach the relevant evidence, witness affidavits, and correspondence with the respondent;
  • State the action the respondent took, if any;
  • Specify the relief requested; and
  • Include the required certification against forum shopping.

The completed complaint must be notarized. The NPC currently allows submission in person, by courier, or by emailing a scanned copy to complaints@privacy.gov.ph, subject to the current instructions on its complaint page. Filing fees may apply under the NPC’s linked schedule; exemptions are available in specified cases, including qualifying indigent complainants.

Disclose any related SEC, court, or agency filing in the certification against forum shopping. Do not conceal a parallel complaint simply because it was filed with a different authority.

How to report the lender to the SEC

For a lending or financing company under SEC supervision:

  1. First send the complaint through the lender’s consumer-assistance mechanism.
  2. Gather the complaint, acknowledgment, response or proof of nonresponse, loan documents, screenshots, payment records, and the company’s identifying details.
  3. Create or use an eSECURE account and open a ticket through the SEC’s iMessage portal.
  4. Select “Complaints on Financing and Lending Companies” under the Financing and Lending Companies Department, as shown in the current SEC iMessage public user manual.
  5. Upload the documents and identity or complaint forms requested by the service, then retain the ticket number and monitor the portal for instructions.

State separately each alleged violation—for example, threats, false representations, public disclosure, contact-list harassment, unreasonable contact hours, missing disclosures, or suspected operation without authority. Identify both the lender and collection agency when known.

The SEC can investigate regulatory violations and impose appropriate administrative measures, but an SEC complaint does not itself void the contract, erase the debt, or decide every civil or criminal claim.

If the provider is not SEC-regulated

Check the legal entity named in the agreement:

  • Complaints against a bank, digital bank, e-wallet provider, cooperative bank, or another BSP-supervised institution should first go through that institution’s consumer-assistance channel and may then be escalated through the BSP Consumer Assistance Mechanism.
  • A lending cooperative that is not a cooperative bank is generally subject to the Cooperative Development Authority’s consumer-redress framework. Complain to the cooperative first and then use the appropriate CDA escalation process.
  • Privacy complaints may still fall within NPC jurisdiction regardless of the lender’s financial regulator.

When to involve law enforcement

Report promptly if the conduct includes a credible threat of physical harm, extortion, stalking, account intrusion, identity theft, impersonation, fabricated legal documents, or publication of sensitive material.

  • If danger is immediate, move to a safe location and dial the nationwide 911 emergency hotline. The DILG describes Unified 911 as the integrated emergency channel for police, fire, medical, and disaster response.
  • For computer-related conduct, approach the PNP’s appropriate cybercrime unit or the NBI Cybercrime Division or a regional cybercrime center.
  • The NBI’s official procedure for investigative assistance to victims of computer crimes calls for a complaint or request for investigation, a preliminary interview, supporting documents, sworn statements, and—when relevant—examination of the device. The listed service has no fee.

Bring the original device, government identification, printed chronology, and secured copies of the evidence. Ask for the complaint or blotter reference number. Criminal liability depends on the exact words, conduct, intent, identity of the actor, and available evidence; let investigators or counsel assess the proper offense.

Important points about the debt itself

  • You can report harassment even if the loan is unpaid. A creditor’s right to pursue lawful collection does not include threats, deception, public humiliation, or prohibited disclosure.
  • Reporting does not extinguish the debt. Continue addressing any valid balance separately. Ask for a complete statement of account, dispute errors in writing, and negotiate only through verified official channels.
  • Do not pay a personal account merely because someone threatened you. Confirm payment instructions independently with the lender.
  • Nonpayment of debt alone is not punishable by imprisonment. Article III, Section 20 of the 1987 Constitution prohibits imprisonment for debt. A separate alleged criminal act, such as fraud, is a different matter and requires its own legal basis and process.
  • Do not ignore genuine legal papers. A real summons, subpoena, or court order should be verified directly with the issuing court or office and answered within the applicable period.

Common mistakes to avoid

  • Deleting chats, wiping the device, or uninstalling the app before saving evidence;
  • Keeping only cropped screenshots that omit the sender, date, or surrounding conversation;
  • Complaining only to an anonymous collector instead of the lender’s official assistance desk and DPO;
  • Failing to preserve proof that the lender received the written privacy complaint;
  • Filing the NPC complaint before the 15-calendar-day requirement is met without explaining and proving grounds for waiver;
  • Naming only the app brand and not the corporate operator;
  • Posting accusations, phone numbers, IDs, or collectors’ personal information publicly instead of sending evidence to authorities;
  • Secretly recording private calls without first considering the Anti-Wiretapping Act;
  • Sending more IDs, selfies, OTPs, passwords, or banking credentials to an unverified collector;
  • Assuming that an SEC or NPC report automatically suspends payment or cancels the loan; and
  • Hiding related proceedings despite the NPC’s certification-against-forum-shopping requirement.

When legal help is urgent

Consult a lawyer or seek immediate law-enforcement assistance when:

  • A threat names your home, workplace, children, or planned physical action;
  • The collector has published your address, identification documents, intimate material, or other sensitive information;
  • Your accounts, SIM, email, or financial services have been accessed or taken over;
  • Someone is impersonating you or applying for loans in your name;
  • An employer, client, or business relationship has been materially affected;
  • You receive a real summons, subpoena, warrant, or prosecutor’s notice;
  • A large amount, multiple lenders, or disputed identity is involved; or
  • Continuing harassment is causing a serious safety or mental-health crisis.

The Public Attorney’s Office may be an option for qualified indigent persons. Bring the complete evidence file and disclose all pending complaints and proceedings.

Frequently asked questions

Can a collector contact my family, friends, or employer?

Not merely because their numbers appeared in your contact list. Debt-collection contact is generally limited to the borrower and a person who expressly became a guarantor or co-maker. A genuine character reference may be contacted for identity or information verification, but is not automatically liable for the debt and should not be used as a collection target.

Does clicking “Allow contacts” make third-party harassment legal?

No. Permission must still be necessary, proportionate, transparent, and used only for a lawful purpose. SEC rules expressly treat contact with unrelated people in the borrower’s contact list as an unfair collection practice notwithstanding the borrower’s consent.

Can the lender post my name, photo, or debt on social media?

Public disclosure intended to shame a borrower is generally prohibited. Whether a particular disclosure is lawful depends on its recipient, purpose, legal basis, accuracy, and necessity; narrow lawful disclosures should not be confused with public posting or mass messaging.

Can I complain if I am only a contacted friend or character reference?

Yes, if your own personal data was processed or you were directly affected by a privacy violation. An affected data subject may file a separate NPC complaint. Preserve the message, explain how the sender obtained your number, and ask the company to remove your information as a character reference when applicable.

Should I uninstall the app immediately?

Preserve the app details, permission screens, messages, and documents first. Then revoke unnecessary permissions. If serious cybercrime is suspected, ask investigators before wiping the phone because the device may contain evidence.

Can I demand deletion of all my information?

You may request blocking, removal, erasure, or destruction when the legal conditions are met, particularly for unlawfully obtained or unlawfully used data. The right is not absolute: a lender may retain data needed for an active contract, a legal obligation, or the establishment, exercise, or defense of legal claims. Ask the lender to identify the legal basis and retention period for anything it refuses to delete.

Must I wait 15 days before seeking help?

The 15-calendar-day rule generally applies before the NPC gives due course to a formal privacy complaint. It does not prevent an immediate SEC report, app-platform report, police complaint, NBI request, or emergency call. The NPC may also waive the requirement for proven good cause or a serious violation.

Will reporting stop all collection calls?

Not automatically. You may demand that unlawful conduct stop and that future lawful communications use a designated written channel. The lender may continue reasonable, truthful, and lawful collection while a valid obligation remains.

Official sources

This article provides general legal information, not advice for a particular case. Rights, filing requirements, and the proper forum can depend on the lender’s identity, the documents, and the exact conduct involved. Official sources and procedures were checked as of August 6, 2026.

Disclaimer: This content is not legal advice and may involve AI assistance. Information may be inaccurate.