Last materially reviewed: September 3, 2026
Direct Answer
Deepfakes are not automatically illegal in every situation in the Philippines, and there is not yet one comprehensive enacted law that bans all deepfakes. But creating, publishing, sharing or using a deepfake can already create legal liability under existing laws depending on what the content depicts, whose identity or personal data is used, whether consent exists, whether the content is deceptive or defamatory, and whether it is used for fraud, harassment, impersonation or another unlawful purpose.
In August 2026, the National Privacy Commission specifically reminded the public that a real person’s face and likeness are personal information under the Data Privacy Act (NPC Notice, August 2026). The NPC said that generating AI images or videos using an identifiable person’s likeness, and posting or sharing them, are forms of personal-data processing that must have a legitimate purpose and satisfy a lawful basis under the Data Privacy Act.
Primary authorities: National Privacy Commission guidance on AI-generated likenesses and, where applicable, Republic Act No. 10175. Pending deepfake bills are not treated as enacted law.
Key Takeaways
- There is no blanket rule making every deepfake illegal.
- The Data Privacy Act can apply when a real, identifiable person’s face, likeness or other personal data is used.
- Deepfakes used for scams, impersonation, identity theft, forgery or fraud can trigger cybercrime and other criminal laws.
- Defamatory deepfakes can create cyber-libel or civil-defamation risk depending on the facts.
- Non-consensual sexual or intimate synthetic media presents especially serious legal and privacy risks.
- Senate Bill No. 1714, the proposed Digital Likeness and Deepfake Regulation Act, remained pending in committee as of September 3, 2026.
Jump to a Section
- Deepfakes and data privacy
- When a deepfake may become illegal
- What victims should do
- Proposed deepfake law
- Business and creator risks
Deepfakes and the Data Privacy Act
The NPC’s August 11, 2026 notice on the use of real persons’ likenesses in AI-generated images is one of the clearest current Philippine statements on synthetic media. It explains that a person’s face and likeness are personal information and that photos or videos can, in some cases, constitute biometric information capable of identifying a person.
The NPC further states that generating AI content from a real person’s likeness and posting or sharing the result are forms of processing personal data. This means the usual Data Privacy Act principles can become relevant, including lawful processing, legitimate purpose, proportionality, transparency, security and data-subject rights.
When Can a Deepfake Create Legal Liability?
1. Fraud and Scams
A cloned voice or synthetic video used to convince someone to transfer money, disclose credentials or enter a transaction can potentially involve fraud, computer-related fraud, forgery, identity theft or other offenses depending on the method and evidence.
2. Identity Theft or Impersonation
RA 10175 expressly penalizes computer-related identity theft involving identifying information belonging to another person when the statutory elements are met. A deepfake used to impersonate a person can therefore create much more serious risk than a harmless parody.
3. Defamation and Cyber Libel
A fabricated video or image that falsely attributes disgraceful conduct, criminality or other defamatory acts to an identifiable person can create defamation risk. If published online, cyber-libel rules may become relevant. See Online Libel in the Philippines.
4. Privacy Violations
Even where a deepfake is not defamatory or fraudulent, use of an identifiable person’s likeness can still trigger data-protection issues. Consent is not the only possible lawful basis under the Data Privacy Act, but a creator or publisher needs a legitimate, legally supportable basis for processing.
5. Harassment, Threats or Sexualized Content
Deepfakes used to humiliate, threaten, extort, sexually harass or target a person may interact with other criminal, civil, workplace, child-protection or gender-based harassment laws. The exact offense depends on the content, victim, conduct and evidence.
Decision Snapshot
| Deepfake use | Risk level |
|---|---|
| Clearly labeled parody of a fictional character | Generally lower, subject to IP and other rights |
| Real person’s face used without explanation | Privacy and personality-right concerns |
| Fake CEO voice instructs staff to transfer money | High — possible fraud and identity-related offenses |
| Fake video falsely showing a person committing a crime | High — defamation, privacy and other claims possible |
| Sexualized deepfake of a real person | Very high — serious privacy, harassment and potential criminal issues |
| AI-generated political satire clearly disclosed | Different free-expression analysis; deception and election rules may still matter |
What Should You Do If Someone Makes a Deepfake of You?
- Preserve the evidence. Save the URL, account, post, image or video, timestamps, comments and shares.
- Capture the full context. Screen-record the page before it is deleted or altered.
- Report it to the platform. Use impersonation, synthetic-media, privacy, harassment or intimate-content reporting tools where appropriate.
- Request removal. Send a documented removal request to the uploader and platform when safe and useful.
- Assess privacy remedies. If your likeness or personal data was used unlawfully, consider the NPC process.
- Report cybercrime when necessary. Fraud, threats, extortion, identity theft or serious impersonation can be reported to CICC, PNP-ACG or NBI-CCD. Use our cybercrime reporting guide.
- Get legal advice quickly. Defamation and criminal claims can have prescriptive periods and procedural requirements.
Is There a Specific Deepfake Bill?
Yes. Senate Bill No. 1714, filed January 27, 2026, is titled the proposed Digital Likeness and Deepfake Regulation Act. Its stated purpose is to safeguard likeness, identity and publicity rights by regulating deepfake creation and use through disclosure, consent, platform accountability, remedies and penalties. As of September 3, 2026, the bill remained pending in committee and was not yet law.
Other AI-governance bills may also affect future synthetic-media rules. For the wider legislative picture, see AI Law in the Philippines: Current Rules, Bills and Regulations.
What Should Businesses and Creators Do?
- Obtain appropriate rights or lawful basis before using a real person’s likeness.
- Clearly disclose synthetic or altered media when a reasonable viewer could be misled.
- Do not use cloned voices or faces for authorization of payments or high-risk transactions without independent verification.
- Create an approval process for AI-generated advertising featuring real people.
- Maintain records of consent, licenses, prompts, source assets and approvals.
- Give people a rapid way to report misuse of their likeness.
Frequently Asked Questions
Is making a funny deepfake of a celebrity automatically a crime?
No. Context, purpose, deception, personal-data processing, defamation, commercial use, intellectual-property rights and other factors matter. A parody is not legally identical to a fake endorsement or scam.
Can I report a deepfake to the National Privacy Commission?
Potentially, if the deepfake involves unlawful processing of your personal data or likeness. The NPC’s August 2026 notice expressly treats use of a real person’s likeness in AI-generated imagery as personal-data processing.
Is a deepfake scam covered by RA 10175?
It can be when the conduct satisfies offenses such as computer-related fraud, identity theft, forgery or another cybercrime provision.
Is the Deepfake Regulation Act already in force?
No. Senate Bill No. 1714 remained pending in committee as of September 3, 2026.
