Quick answer
Online lenders may demand payment through lawful, respectful methods, but they may not threaten, insult, publicly shame, or misuse your contacts, photos, messages, or other personal data. Contacting people in your phonebook to pressure or embarrass you—unless the person separately consented to be a guarantor—is prohibited.
Preserve the evidence first. Then:
- Report unfair collection by a lending or financing company, its online platform, or its collection agency through the SEC iMessage portal.
- For unauthorized access, disclosure, or misuse of personal data, send the lender a written privacy complaint and ordinarily allow 15 calendar days for an appropriate response. If unresolved, file a formal complaint with the National Privacy Commission.
- Report threats, extortion, hacking, identity theft, fake legal documents, or other possible crimes to the PNP Anti-Cybercrime Group, NBI Cybercrime Division, or the government’s Cyber Hotline. Call 911 if anyone is in immediate danger.
These remedies may be used together because harassment, privacy violations, and possible crimes fall under different authorities. Reporting misconduct does not automatically cancel a valid loan, but owing money never gives a collector permission to abuse or publicly shame anyone.
What online lenders are prohibited from doing
The Financial Products and Services Consumer Protection Act prohibits financial service providers from using abusive collection or debt-recovery practices. Providers are also responsible for their employees and agents and may be solidarily liable with accredited third-party service providers involved in collection.
For lending and financing companies, SEC Memorandum Circular No. 18, series of 2019 prohibits unfair practices such as threats of violence or other criminal means, threats to take action that cannot legally be taken, insults or profane language, false or deceptive representations, improper disclosure of borrower information, and unreasonable or abusive communications.
Privacy rules provide additional protection. Under NPC Circular No. 20-01, as amended by NPC Circular No. 2022-02, an online lending app must not:
- Require or use app permissions that are unnecessary, excessive, or disproportionate to a legitimate purpose.
- Use a borrower’s photo to harass or embarrass the borrower.
- Engage in unrestricted or “unbridled” processing of phone, email, or social-media contact lists.
- Process contact information in a way that causes harassment or unfair collection.
- Contact people from the borrower’s contact list to collect the debt, except persons who validly consented to be guarantors.
- Treat a character reference as a guarantor. A character reference is for identity or information verification; a guarantor must separately consent to assume responsibility for the loan.
- Keep personal data indefinitely without a lawful and necessary retention purpose.
A lender may have limited access to a contact list so the borrower can select a character reference or guarantor, or to derive proportionate metadata for a legitimate purpose. That narrow allowance does not permit the lender to copy the entire list and message relatives, co-workers, friends, or employers to shame the borrower.
The government reaffirmed these rules in its March 2026 joint DICT-NPC-SEC advisory on online lending platforms.
What lawful collection can look like
A lender may generally:
- Contact the borrower privately and identify the creditor and the obligation.
- Send accurate account statements, payment reminders, and demand letters.
- Offer restructuring or settlement, subject to agreement.
- Report information through a lawful and properly regulated credit-information process.
- File an appropriate civil collection case and serve genuine court documents through lawful channels.
- Contact a valid guarantor concerning the guaranteed obligation.
Firm collection is not automatically harassment. The important questions are what the collector said, how often and when the collector communicated, whether the information was accurate, who received it, and whether personal data was used beyond a lawful and proportionate purpose.
Preserve evidence before blocking or uninstalling the app
Do this as soon as it is safe:
- Take screenshots showing the complete message, sender’s number or profile, date, time, and surrounding conversation. Avoid cropped images that remove identifying details.
- Export chats and emails when the platform permits it. Save original files as well as screenshots.
- Preserve SMS messages, voicemail files, call logs, email headers, social-media posts, comments, and notifications.
- Record the exact app name, developer, app-store link, website, package name if visible, and the legal company name shown in the loan agreement or privacy notice.
- Save the loan agreement, disclosure statement, promissory note, repayment schedule, receipts, payment history, and account statement.
- Screenshot the app’s permission settings and privacy notice before changing or uninstalling anything.
- Ask relatives, colleagues, or other contacted persons to preserve the messages they received. Their screenshots or written statements may establish third-party disclosure and harassment.
- Create a simple chronology listing every incident, the collector’s number or account, what was said or disclosed, and who witnessed it.
- Keep copies in a secure location outside the affected phone, such as encrypted storage or a trusted device.
Do not secretly record a private call without legal advice. The Anti-Wiretapping Act can apply to unauthorized recordings of private communications. Call logs, lawful voicemails, written messages, and contemporaneous notes are safer forms of evidence.
After preserving the evidence, revoke unnecessary permissions, change reused passwords, enable multi-factor authentication, block abusive accounts, and uninstall the app if appropriate. Uninstalling prevents further access through the device but does not erase data the operator may already have copied.
Identify the company behind the app
An app’s brand name may be different from the company that granted the loan. Check:
- The loan contract and disclosure statement.
- The privacy notice and the named data protection officer.
- Payment receipts and the receiving account.
- The developer information in the app store.
- SEC records and published lists of lending or financing companies.
A lending company must have SEC authority to operate; ordinary corporate registration alone is not enough. Include both the app name and the operator’s legal name in the complaint. If you cannot identify the operator, state every fact that may help regulators trace it, including phone numbers, URLs, payment accounts, screenshots, and app-store information.
Do not send payment to a collector’s personal account merely because of a threat. Verify payment instructions using the lender’s official channel and request a receipt and updated statement.
Send a written complaint to the lender
For a privacy complaint, this step is usually important because the NPC’s rules generally require the complainant to first inform the responsible entity in writing and give it an opportunity to act.
Send the complaint to the lender’s consumer-assistance unit and data protection officer, if identified. Keep proof of delivery. State:
- Your name and loan-account reference, without sending passwords, PINs, or unnecessary identity documents.
- The app and company involved.
- Dates, times, numbers, accounts, and collectors involved.
- The exact conduct complained of.
- What personal data was accessed, used, or disclosed.
- Who received the information and whether that person was ever a guarantor.
- The harm or risk caused.
- The corrective action requested.
Depending on the facts, you may request that the company:
- Stop contacting third parties who are not valid guarantors.
- Stop public disclosure, threats, and abusive communications.
- Identify the source, purpose, legal basis, recipients, and retention period for your data.
- Provide access to personal data held about you.
- Correct inaccurate data.
- Block, delete, or securely dispose of data that no longer has a lawful retention basis.
- Preserve relevant logs, messages, call records, collector assignments, and access records.
- Confirm the lawful amount due and provide a complete account statement.
Erasure is not absolute. A lender may retain data still needed to service a valid loan, comply with law, or establish, exercise, or defend legal claims. It should not retain or use more data than necessary for those purposes.
File an unfair-collection complaint with the SEC
The SEC is the principal regulator for lending companies, financing companies, their online lending platforms, and their collection agencies.
Use the SEC iMessage portal, open a new ticket, and route the concern to the office handling financing and lending companies. The government’s current joint advisory identifies the Financing and Lending Companies Department (FINLEND) for unfair debt-collection complaints.
Prepare:
- Your complete contact details.
- The respondent company’s legal name and the app name.
- A valid government-issued ID, subject to the portal’s current requirements.
- A chronological statement of facts.
- Screenshots, messages, call logs, posts, and witness evidence.
- The loan disclosure statement, agreement, schedule, receipts, and payment records.
- Proof that unrelated contacts were messaged or that information was publicly disclosed.
- The remedy requested.
If using the SEC’s downloadable complaint form, follow its instruction to submit one complaint form per respondent company. The SEC’s published complaint procedure states that incomplete complaints may be dismissed and that supporting evidence and a valid ID should be attached. It also states that the respondent is ordinarily given 10 days from receipt to answer or comment.
The SEC may investigate and impose administrative sanctions where warranted. It cannot automatically rewrite a contract, erase an obligation, or declare a loan or interest provision void merely through the ordinary complaint intake process. Contract validity, disputed charges, and monetary relief may require a separate regulatory adjudication or court remedy depending on the facts.
File a privacy complaint with the NPC
A formal NPC complaint is appropriate when the lender or collector accessed, used, retained, or disclosed personal data unlawfully or excessively—for example, by harvesting contacts, messaging non-guarantors, posting a borrower’s photo, or disclosing the debt to co-workers.
The 15-day prior-notice rule
Under the 2021 NPC Rules of Procedure, a complaint ordinarily will not be given due course unless:
- You informed the respondent in writing of the privacy violation or data breach; and
- The respondent failed to take timely and appropriate action, or did not respond within 15 calendar days from receipt.
The NPC may waive these requirements for properly shown good cause or a serious violation, including circumstances involving grave and irreparable harm, lack of a plain and adequate remedy, or patently illegal conduct. If immediate intervention is needed, explain the danger and provide supporting evidence instead of merely omitting the prior notice.
Formal requirements
Use the NPC’s current Complaint-Affidavit form. A formal complaint generally must be:
- Written and signed.
- Verified under oath.
- Clear about the complainant and respondent.
- Supported by a chronological narration and documentary or testimonial evidence.
- Accompanied by the correspondence sent to the respondent.
- Specific about the relief requested.
- Accompanied by a certification against forum shopping.
- Filed by the affected data subject or by a representative with a special power of attorney.
The current form also asks the complainant to identify the affected personal information and the possible privacy violation, such as unauthorized processing, processing for an unauthorized purpose, malicious disclosure, or unauthorized disclosure.
Complaints may be filed at an NPC office through the modes authorized by the NPC’s rules. Consult the NPC complaint page immediately before filing for the current submission address, electronic channel, payment process, and office details.
The current NPC schedule of fees lists a ₱500 filing fee, plus applicable fees depending on the relief sought. Qualified indigent litigants may apply for exemption by submitting the required proof. Confirm the amount and payment instructions before filing because fee schedules can be amended.
Where necessary to protect data-subject rights, a complainant may also ask the NPC about applying for a temporary ban on the respondent’s processing of personal data. This is a separate remedy with evidentiary, hearing, fee, and possible bond requirements; legal assistance is advisable.
Report threats, fraud, or other possible crimes
Do not wait for the SEC or NPC process if the collector threatens physical harm, extorts money, hacks an account, impersonates a police officer or court, uses stolen identity documents, or creates an immediate safety risk.
The March 2026 government advisory identifies these channels:
- DICT Cyber Hotline:
1326@dict.gov.ph - NBI Cybercrime Division:
ccd@nbi.gov.ph; trunk line(02) 8523-8231 to 38 - PNP Anti-Cybercrime Group:
acg@pnp.gov.ph;(02) 8723-0401, local7491
The NBI also provides an online complaint page and accepts requests for investigative assistance for computer crimes. The Cybercrime Investigation and Coordinating Center may be reached through 1326 or report@cicc.gov.ph.
Bring or attach the evidence, a concise chronology, the collector’s identifiers, payment-account details, and any proof of immediate risk. Ask for a complaint or reference number and keep it.
If there is an immediate threat to life or safety, call 911 or go to the nearest police station. Tell trusted family members, building security, or your employer’s security office when the threat identifies your home or workplace.
Use the correct financial regulator
The regulator depends on the entity behind the loan:
| Provider | Primary financial regulator or channel |
|---|---|
| SEC-registered lending or financing company, online lending platform, or its collection agency | SEC iMessage |
| Bank, digital bank, e-money issuer, or another BSP-supervised institution | Provider’s consumer-assistance mechanism first, then the BSP Consumer Assistance Mechanism |
| Cooperative lender | Cooperative Development Authority, subject to the entity’s actual registration and activities |
| Unauthorized or unidentified app | SEC and law enforcement; NPC as well if personal data was misused |
| Privacy violation by any lender, including an entity regulated elsewhere | National Privacy Commission |
For a BSP-supervised institution, first complain to its Financial Consumer Protection Assistance Mechanism. If unresolved, escalate through the BSP Online Buddy or send the BSP’s complaint form and proof of the first-level complaint to consumeraffairs@bsp.gov.ph. BSP guidance specifically directs complaints about ordinary financing and lending companies, online lending platforms, and their collection agencies to the SEC.
Common mistakes that weaken a complaint
- Deleting the app, messages, or account before preserving evidence.
- Submitting cropped screenshots that hide the sender, date, time, or surrounding conversation.
- Naming only the app and not the legal company or payment recipient.
- Combining several unrelated companies in one SEC complaint form.
- Filing an NPC complaint without proof of written prior notice or without explaining why the requirement should be waived.
- Leaving the complaint unsigned, unverified, or without the certification against forum shopping.
- Describing conduct only as “harassment” without quoting or attaching what was actually said or disclosed.
- Posting unredacted IDs, loan documents, phone numbers, or contact lists publicly while seeking help.
- Sending PINs, passwords, one-time passwords, or complete card details to someone claiming to be a regulator.
- Paying an unverified personal account because a collector threatens immediate arrest.
- Assuming that a regulatory complaint automatically cancels the debt.
- Ignoring a genuine summons, subpoena, or court notice. Verify it directly with the issuing court or agency and obtain legal advice.
When legal help is urgent
Consult a Philippine lawyer, the Public Attorney’s Office if eligible, or a recognized legal-aid clinic promptly when:
- A threat identifies your address, family, children, or workplace.
- Intimate images, altered photographs, identity documents, or medical information are being distributed.
- Your accounts, SIM, email, or e-wallet may have been compromised.
- The lender continues mass disclosure after receiving written notice.
- You need a temporary ban, injunction, damages, or another urgent protective remedy.
- Police, prosecutors, the NPC, SEC, or a court asks for a sworn statement or formal pleading.
- You receive genuine court papers or a formal demand involving a large or disputed amount.
- Several complaints involving the same facts are pending, because the NPC certification against forum shopping must be accurate.
- You are close to a possible prescriptive deadline. Under the Financial Products and Services Consumer Protection Act, claims generally prescribe five years from consummation of the transaction or discovery of deceit or material nondisclosure, subject to an outer limit of ten years from the violation; other causes of action may follow different periods.
Frequently asked questions
Does failure to pay allow the lender to shame me?
No. Default may permit lawful collection and a civil case, but it does not authorize threats, insults, publication of your debt, or misuse of personal data.
May the app contact my family, friends, co-workers, or employer?
Not as a pressure tactic merely because their details appear in your phone. For debt collection, the government’s current guidance permits contact with a person who separately consented to be a guarantor. A character reference is not automatically a guarantor.
Can a collector post my photo or ID online?
A borrower’s photo must not be used to harass or embarrass the borrower. Posting a photo, ID, debt information, or altered image may also constitute unauthorized or malicious disclosure depending on the facts.
Can I complain even if I am not the borrower?
Yes, if your own name, number, messages, photo, or other personal data was accessed or used. You may be a data subject independently of the borrower. Preserve the communication you received and explain that you never consented to be a guarantor, if that is true.
Can a lender have me arrested just for an unpaid loan?
The Constitution provides that no person shall be imprisoned for debt. Nonpayment may lead to civil collection, but a collector cannot create a warrant or order an arrest. Separate conduct that independently satisfies the elements of a criminal offense is different. Verify any claimed case directly with the court or law-enforcement office and never rely solely on the collector’s screenshot. See Article III, Section 20 of the Constitution.
Should I stop paying after filing a complaint?
A complaint does not by itself suspend or erase a valid obligation. Ask for a complete account statement, dispute unauthorized charges in writing, and make payments only through verified channels. Obtain individualized legal advice before withholding an undisputed amount.
Does consent to app permissions make every use of my data lawful?
No. Consent must be informed and tied to a stated purpose, and processing must still be necessary and proportionate. Permission to select a reference or upload an identity photo does not authorize public shaming, mass messaging, or unrelated disclosure.
Will uninstalling the app solve the privacy problem?
It can stop future device access through the app, but it cannot retrieve data already copied. Preserve evidence, revoke permissions, secure affected accounts, and send a written demand addressing retained data.
What can regulators do?
Depending on jurisdiction and proof, regulators may order corrective action, restrict processing, impose administrative fines or other sanctions, suspend or revoke authority, or refer possible crimes for prosecution. The NPC may also award indemnity in an appropriate case. Criminal fines and imprisonment under the Data Privacy Act or Financial Products and Services Consumer Protection Act require the proper proceedings and proof of a specific offense; they are not automatic upon filing a complaint.
Official legal and complaint resources
- Data Privacy Act of 2012
- Implementing Rules of the Data Privacy Act
- NPC Circular No. 20-01 on loan-related personal data
- NPC Circular No. 2022-02 amending the loan-data rules
- 2021 NPC Rules of Procedure
- Current NPC Complaint-Affidavit form
- SEC rules and complaint information for lending and financing companies
- SEC iMessage complaint portal
- Financial Products and Services Consumer Protection Act
- March 2026 DICT-NPC-SEC advisory
- BSP consumer-assistance channels
This article provides general Philippine legal information, not legal advice or a prediction of any complaint’s outcome. Rights, jurisdiction, deadlines, and remedies may depend on the loan documents and the specific conduct involved. Official sources and filing information were checked on 11 August 2026; confirm current forms, addresses, fees, and channels with the relevant agency before filing.