CyberCode.ph · Philippines

Data Scraping in the Philippines: What the NPC’s 2026 Guidelines Require

Last updated October 1, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: October 1, 2026 — verified NPC Advisory No. 2026-01 status and added an evidence-and-action layer plus lead-generation, recruitment, social-listening and AI-training decisions.

Direct Answer

Scraping publicly available personal data in the Philippines is not automatically lawful. Under NPC Advisory No. 2026-01, issued 13 April 2026, the fact that data is public does not amount to consent. An organisation that scrapes personal data must identify a lawful basis under Section 12 or 13 of the Data Privacy Act, notify the people concerned, limit the purpose, minimise what it takes, secure it, delete it when the purpose ends — and conduct a Privacy Impact Assessment covering the activity.

Evidence and Action

Scraping Decision Matrix by Use Case

Use case Main privacy question Minimum action before use Reason to pause
B2B lead generation from public directories Do names, roles, work emails or phone numbers identify people, and what Section 12 basis supports collection and outreach? Limit fields, document the basis and purpose, give notice at the required time, and provide an objection or rights route. The list was bought without source evidence, includes unnecessary personal fields, or will be used for an undisclosed purpose.
Recruitment sourcing from public profiles Is the candidate reasonably expecting the profile to be collected, combined or scored for this hiring purpose? Record the source and criteria, avoid collecting sensitive details, disclose the sourcing at the next practical opportunity, and review profiling for unfairness. The workflow infers health, religion, politics or other sensitive information, or cannot explain an automated score.
Social listening and sentiment analysis Are usernames, posts, images or audience attributes personal data, even when the dashboard shows aggregates? Define queries and retention, minimize raw identifiers, control access, assess profiling and bias, and preserve a rights-request path. The tool silently builds individual dossiers, monitors vulnerable people, or keeps identifiable posts indefinitely.
AI training or fine-tuning Does the corpus contain personal data, and is the training purpose compatible with what people were told or could reasonably expect? Verify dataset origin, lawful basis and notices; update the PIA; apply NPC Advisory No. 2024-04; review bias, security, retention and cross-border transfers. The provider cannot prove collection compliance, the purpose has changed materially, or personal data cannot be removed or rights cannot be honored.
Prices, product codes or other non-personal facts Does the collection truly exclude identifiable people? Document that conclusion and separately review website terms, access controls, database rights and copyright where relevant. Seller names, reviews, account IDs or contact details enter the dataset, or technical safeguards must be bypassed.

Important: The table is a practical screening tool, not an automatic lawful-basis determination. A use case that appears acceptable can still fail if its scale, data fields, notice, source restrictions or downstream profiling create a different risk.

Key Takeaways

  • The governing issuance is NPC Advisory No. 2026-01, “Guidelines on Data Scraping of Publicly Available Personal Data” (13 April 2026).
  • Public availability is not consent. A separate lawful basis is required.
  • Data subjects must be told before processing, or at the next practical opportunity.
  • A Privacy Impact Assessment is mandatory for scraping activities, and must be kept current.
  • Circumventing technical measures on a website counts as unauthorised scraping.
  • Scraping sensitive personal information needs a valid lawful basis plus enhanced security; data on minors, the elderly and persons with disabilities attracts heightened scrutiny.
  • Named prohibited uses include identity fraud, doxxing, unauthorised surveillance, malicious profiling and credential theft.

Jump to a Section

Decision Snapshot

Question Practical Answer
Is scraping public personal data automatically allowed? No. DPA obligations apply in full.
Does public availability count as consent? No. The Advisory states it expressly.
Do I need a lawful basis? Yes — under Section 12 or 13 of the DPA.
Do I have to tell the people whose data I scraped? Yes, before processing or at the next practical opportunity.
Is a Privacy Impact Assessment required? Yes, covering the scraping activity, reviewed on material change.
Can I bypass a paywall, login or anti-bot measure? No. That is unauthorised scraping.
Does breaching a site’s terms of service matter? Yes. The Advisory treats it as part of unauthorised conduct.
Can I scrape sensitive personal information? Only with a valid lawful basis and enhanced security measures.
Can I keep the data indefinitely? No. Only as long as necessary for the declared purpose.

Why This Matters

Scraping had been treated by many Philippine businesses as a grey area: if a profile, a listing or a review was visible without logging in, collecting it felt like fair game. Advisory 2026-01 closes that reasoning. It does not ban scraping. It says that scraped personal data is personal data like any other, and that the ordinary duties of a personal information controller attach the moment you collect it.

The exposure is broader than it looks. Lead-generation lists, competitor price monitoring that incidentally captures seller names, recruitment sourcing, sentiment monitoring, academic datasets and machine-learning corpora all involve personal data at some point in the pipeline.

Applicable Law

NPC Advisory No. 2026-01

“Guidelines on Data Scraping of Publicly Available Personal Data,” issued 13 April 2026. It defines publicly available personal data as information “readily available and accessible to the public without restrictions or the need for authorization.”

Republic Act No. 10173, Sections 12 and 13

Section 12 lists the lawful criteria for processing personal information; Section 13 governs sensitive personal information. The Advisory requires controllers to “determine the most appropriate lawful basis for processing personal data obtained through data scraping.” See our guide to the Data Privacy Act and to sensitive personal information.

Related NPC issuances

Where scraped data feeds an AI system, NPC Advisory No. 2024-04 on artificial intelligence systems processing personal data also applies — see AI and data privacy in the Philippines. Where data moves offshore, NPC Advisory No. 2024-01 on model contractual clauses for cross-border transfers is relevant.

Who Does This Apply To?

  • Controllers and processors involved in extracting public personal data, including manual collection and vendor-operated scraping. Large-scale collection is not a prerequisite for coverage.
  • Controllers hosting public personal data, including directories, profiles and other accessible personal information; see the website-host checklist below.
  • Companies buying scraped datasets — you are processing that data, and the origin does not launder the obligations.
  • AI developers and teams fine-tuning models on web-sourced material.
  • Marketing, recruitment and research teams building contact or profile lists.
  • Vendors and BPOs scraping on a client’s instruction — allocate roles in writing, and see controller versus processor.

What Is Required?

  1. Establish a lawful basis before you collect. Under Section 12 or 13. Do not assume consent from publication.
  2. Give notice. Inform data subjects “before the processing takes place, or at the next practical opportunity.”
  3. Declare and limit the purpose. Processing “shall be limited to such specified and declared purpose” and must not extend to purposes “unrelated or not reasonably expected by data subjects.”
  4. Minimise. Refrain from “excessive or indiscriminate data scraping” and assess whether the scraping is reasonable in the circumstances.
  5. Run a Privacy Impact Assessment. Covering nature, scope, risks and mitigation, “reviewed and updated periodically, or whenever there is a material change.” See how to run a PIA.
  6. Secure the data. Appropriate technical, organisational and physical measures.
  7. Set retention limits. Retain “only for as long as necessary to fulfill the declared purpose.”
  8. Enable data subject rights. People must be able to exercise their rights over scraped data — see data privacy rights.

Checklists for Website Hosts, Scraping Operators and Dataset Buyers

Your duties depend on your role, and one business can have more than one role. Advisory 2026-01 covers controllers and processors engaged in scraping, as well as controllers hosting public personal data. Its definition includes manual collection; a small list is not automatically outside scope. The operational checklists below apply the advisory to common workflows. Source: Sections 1–2.

If your website exposes personal data to scraping

Examples include public member directories, seller profiles, staff listings and reviews that identify individuals. Section 5 addresses the controller hosting that information, even if another company operates the scraper.

  1. Inventory exposed personal data. Record which fields are public, why they are public and whether publication is required or intentionally chosen by the person. Assess aggregation and misuse risks.
  2. Explain the exposure. Tell people that their information is public and may be scraped. Describe accessible categories, whether site terms permit scraping, and known third-party purposes or identities where available.
  3. Provide a rights pathway. Explain how people may object to, disallow or seek termination of scraping in accordance with their DPA rights; identify who handles requests.
  4. Apply appropriate safeguards. Consider rate limits, access restrictions, suspicious-account monitoring and blocking malicious activity. Match controls to the information and risks; not every listed control is mandatory in every case.
  5. Prepare incident handling. Investigate unauthorized extraction and assess whether the separate mandatory breach-notification test is met. Preserve logs and document the decision.

Source: Section 5(A)–(B). For a practical example, a directory can retain useful business information while reconsidering unnecessary personal phone numbers or unrestricted bulk exports. That is an implementation choice to assess, not a statutory requirement to hide every listing. Where extraction may be a breach, follow the NPC notification assessment.

If you collect personal data yourself or through a vendor

  1. Define the purpose and lawful basis before collection. Distinguish ordinary personal information under Section 12 from sensitive information under Section 13. Public visibility is not blanket consent.
  2. Check the source and access conditions. Document applicable terms and restrictions. Do not bypass anti-scraping controls or obtain personal data deceptively.
  3. Complete the PIA. Include the nature, scope and purpose of scraping, risks from combining datasets and planned safeguards. Review periodically and after material changes.
  4. Minimize and give notice. Limit fields and collection to what the purpose needs. Explain the scraping before processing or at the next practical opportunity, using the required privacy information.
  5. Govern outsourced collection. Where a vendor is your processor, use an appropriate agreement covering privacy and security and expressly prohibiting unauthorized scraping and circumvention of safeguards. The controller remains accountable.
  6. Set retention and disposal. Give retained datasets an owner and review date; dispose of personal data when it is no longer needed for the declared purpose.

Source: Sections 3, 4 and 6. A processor collecting on instructions and an independent controller selling an existing dataset have different roles. Determine the actual arrangement before selecting contract terms.

If you buy scraped leads, profiles or training datasets

Buying a dataset does not cure unlawful collection. Section 7(A) calls for procedures to verify compliance when a controller obtains scraped personal data from another independent controller. Further processing of data scraped through the unauthorized practices in Section 4 is also treated as unauthorized.

  1. Request evidence of origin. Ask for sources, collection dates, data categories and the method used. A general claim that the data is public is insufficient to assess the collection.
  2. Assess the lawful-basis explanation. Ask how collection, disclosure to your business and your intended use were justified. Check the basis applicable to any sensitive personal information.
  3. Review notices and restrictions. Establish what affected people were told and whether the access method respected source restrictions. A purchase invoice is not evidence of consent.
  4. Document your own use. Your privacy notice should identify public sources, collection purposes and processing methods. Evaluate bias and unfairness when analyzing or profiling people.
  5. Control changes of purpose. Before a use beyond the originally declared purpose, assess the appropriate lawful basis, sufficient notice, a new PIA and other advisory requirements.
  6. Resolve evidence gaps before activation. As an operational safeguard, do not launch campaigns, profile individuals or train a model using a dataset whose compliance cannot be substantiated. Escalate to the DPO and document the decision.

Source: Sections 7(A)–(E). The suggested evidence requests are ways to carry out verification; the advisory does not prescribe a universal vendor certificate or guarantee that one contract clause proves compliance.

A practical approval record

Decision Evidence to keep Reason to pause
May we collect or import these fields? Purpose, field inventory, lawful-basis analysis and source restrictions. Excessive fields, unexplained sensitive data or unclear authority.
May the vendor collect for us? Role assessment, PIA coverage, agreement and collection-method evidence. The vendor proposes bypassing safeguards or cannot explain its method.
May we reuse the dataset for AI? Purpose-change assessment, notices, PIA and a separate copyright/licensing review. The original purpose does not cover the proposed use, or rights remain unresolved.
May the dataset remain in production? Retention rationale, access record, rights-request handling and periodic review. The purpose has ended or ongoing processing cannot be justified.

This record is a suggested internal control, not an NPC filing requirement. For AI use, read which privacy rules apply to AI training data; privacy compliance and copyright permission require separate assessments.

What Is Prohibited

  • Circumventing technical measures. Bypassing logins, paywalls, rate limits or anti-bot controls is unauthorised scraping.
  • Breaching terms of service as part of the collection.
  • Scraping sensitive personal information without a valid lawful basis and enhanced security.
  • Harmful downstream uses — the Advisory names identity fraud, doxxing, unauthorised surveillance, malicious profiling and credential theft.
  • Indiscriminate collection of whatever a site exposes, with the purpose decided afterwards.

Heightened scrutiny applies where the data concerns minors, elderly persons or persons with disabilities.

Scraping for AI Training

Advisory 2026-01 does not contain provisions addressed specifically to AI model training, and it neither expressly permits nor expressly prohibits it. What it does do is apply general obligations that bite hard in a training context: purpose limitation, minimisation, notice, retention limits, and a requirement to implement “mechanisms to identify, monitor, and limit possible sources of bias.”

Copyright is a separate question from privacy and is not governed by this Advisory. For that side, see web scraping and copyright in AI training and AI training data and copyright. If you are on the receiving end, see how to stop AI scraping of your work.

Practical Scenarios

Building a sales list from public business directories

Names, roles and work email addresses are personal data. A lawful basis is needed, notice is owed, and the purpose must be declared and adhered to. “It was on their website” is not the answer.

Monitoring marketplace listings for counterfeits

Legitimate purpose, but seller names and shop details are personal data. Minimise to what enforcement actually requires, and set a retention period tied to the enforcement action rather than keeping the corpus indefinitely.

Buying a dataset from a vendor

You become a controller of that data. Diligence on how it was collected is part of your own compliance, not the vendor’s problem alone — see the vendor and SaaS security checklist.

Scraping a site that blocks bots

If the site deploys technical measures and the scraper defeats them, the Advisory treats the collection as unauthorised regardless of how public the underlying page looks.

Documentation You Should Keep

  • The PIA report for the scraping activity, dated and signed.
  • A written record of the lawful basis relied on and the reasoning.
  • The declared purpose and any change to it.
  • The notice given to data subjects and how it was delivered.
  • A data inventory and flow map for scraped data.
  • Retention and disposal records.
  • Vendor contracts and diligence for any purchased or outsourced collection.

What Should You Do?

  1. Inventory every scraping activity already running, including ones inside marketing or analytics tools.
  2. For each, write down the lawful basis and the declared purpose. If neither is clear, stop the activity until it is.
  3. Run or update a PIA covering the activity.
  4. Fix the notice gap — decide how affected people are informed.
  5. Set retention periods and enforce deletion.
  6. Review technical measures on the sites you scrape and stop anything that circumvents them.
  7. Fold the activity into your data privacy compliance checklist.

Common Mistakes

  • Treating public as consent. The Advisory rules this out in terms.
  • Skipping the PIA. It is a stated obligation for scraping, not a nice-to-have.
  • Collecting first, deciding the purpose later. That is indiscriminate scraping.
  • Assuming a foreign vendor’s compliance covers you. The controller remains accountable.
  • Confusing copyright and privacy. Clearing one does not clear the other.
  • Ignoring notice because it seems impractical. The Advisory allows for the next practical opportunity; it does not allow for never.

FAQs

Does the advisory cover a website that only hosts public profiles?

Yes. Section 1 includes controllers hosting publicly available personal data, and Section 5 addresses their notices, safeguards and response to unauthorized scraping. Hosting and collecting are separate roles.

Can we rely only on a lead vendor’s promise of compliance?

A promise is not a substitute for the verification procedures required by Section 7(A). Seek evidence of sources, lawful collection and the intended use, then document your own assessment.

Is manual collection exempt because it is not automated?

No automatic exemption follows from using manual collection. Section 2(A)’s definition includes manual extraction of publicly available personal data. The particular processing still needs to be assessed under the DPA.

Does a website’s permission settle all privacy and copyright issues?

No. Site permission does not replace the required DPA lawful basis or authorize every use of a third party’s copyrighted material. Assess access, personal-data processing and intellectual-property rights separately. See Advisory 2026-01, Sections 3–4 and 7.

Is web scraping illegal in the Philippines?

No, not as such. Scraping personal data is regulated: it is lawful only where the Data Privacy Act’s obligations are met, and unauthorised where it circumvents technical measures or breaches terms of service.

Does the Advisory apply to data that is not personal?

Its subject is publicly available personal data. Purely non-personal data falls outside the Data Privacy Act, though other rules such as contract or copyright may still apply.

Do I really have to notify people I scraped?

Yes. The Advisory requires notice before processing or at the next practical opportunity.

Can I rely on legitimate interests instead of consent?

A basis other than consent may be available under Section 12, but it has to be identified, justified and documented for the specific activity rather than assumed.

Does this cover scraping by a foreign company of Philippine data?

The Data Privacy Act has extraterritorial reach in defined circumstances. Whether it applies turns on the facts of the processing and the link to the Philippines.

What happens if the NPC finds a violation?

Enforcement can include compliance orders and, for offences under the Act, penalties. See Data Privacy Act penalties.

Is scraping for AI training allowed?

The Advisory contains no provision specific to AI training. The general obligations apply, and NPC Advisory 2024-04 addresses AI systems processing personal data.

Official Sources

  • National Privacy Commission — NPC Advisory No. 2026-01, “Guidelines on Data Scraping of Publicly Available Personal Data,” 13 April 2026: privacy.gov.ph
  • National Privacy Commission — Advisories and Circulars index: privacy.gov.ph/pips-and-pics/advisories-circulars
  • Republic Act No. 10173, Data Privacy Act of 2012, Sections 12 and 13
  • NPC Advisory No. 2024-04, Guidelines on Artificial Intelligence Systems Processing Personal Data
  • NPC Advisory No. 2024-01, Model Contractual Clauses for Cross-Border Transfers

Last materially reviewed: 1 October 2026.

Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.