Last materially reviewed: September 2, 2026
Direct Answer
For a data privacy complaint in the Philippines, collect evidence that shows what happened, what personal data was involved, who controlled or processed it, when the incident occurred, what you did to resolve it, and what harm or risk followed. The strongest complaint is usually built from contemporaneous records rather than later recollection.
Primary authority: National Privacy Commission — Mechanics for Complaints.
Key Takeaways
- Preserve screenshots, emails, URLs, notices, account alerts, and transaction records.
- Keep proof of your written complaint to the company and its response.
- Save original files where possible instead of relying only on cropped screenshots.
- Document dates, times, names, accounts, and affected data.
- Preserve proof of actual loss, identity misuse, or other harm.
- Witness affidavits may be useful where another person directly observed relevant events.
Jump to a Section
What Evidence Matters Most?
| Evidence | What it can show |
|---|---|
| Breach notice | What the organization admits happened |
| Screenshots with date and URL | Unauthorized publication or disclosure |
| Email or letter to the DPO | Exhaustion of remedies and notice |
| Company response | What action was or was not taken |
| Bank or account records | Financial loss or misuse after exposure |
| Witness affidavit | Firsthand corroboration of disputed facts |
How Should You Preserve Digital Evidence?
- Capture the full screen where useful, including date, time, account name, and URL.
- Save the original email, not only a screenshot of it.
- Keep message headers or metadata when relevant.
- Download breach notices or files in their original format.
- Record the date you discovered the incident.
- Avoid editing original files; work from copies.
Why Is Company Correspondence Important?
The NPC’s complaint process generally requires proof that you informed the PIC, PIP, or concerned entity in writing and gave it an opportunity to take appropriate action, subject to exceptions in serious cases. Keep your original request, proof of delivery, follow-ups, and every response.
How Do You Prove Harm?
If you claim financial or other damage, preserve records that connect the privacy incident to the harm: unauthorized transactions, replacement costs, credit-monitoring expenses, identity-fraud reports, account lockouts, lost income records, or other reliable documentation.
How Should You Organize the Evidence?
- Create a one-page timeline.
- Number each exhibit.
- Keep originals separately.
- Match each allegation to supporting evidence.
- Identify missing evidence and request it through your right of access when appropriate.
For the filing process, see How to File a Data Privacy Complaint With the NPC.
Related Guides
If your data was exposed, start with My Personal Data Was Leaked: What Should I Do?. To request records from a company, see Right to Access Personal Data.
Decision Snapshot
Preparing an NPC complaint? Build a dated timeline, preserve the original evidence, identify the organization involved, and connect each document to the privacy right or incident you are alleging. Missing key records? Request them from the organization where appropriate before filing.
Frequently Asked Questions
Are screenshots enough for a data privacy complaint?
Screenshots can help, but stronger complaints usually combine them with emails, notices, transaction records, privacy requests, responses, account records, or other evidence that establishes what happened and who was responsible.
Should I keep original files?
Yes. Keep original files, full email headers where relevant, timestamps, URLs and uncropped records whenever possible. A preserved original is more useful than a heavily edited copy.
