Last materially reviewed: September 3, 2026
Direct Answer
Doxxing is not governed by one standalone Philippine “doxxing law,” but malicious disclosure of another person’s personal data can create liability under the Data Privacy Act and other laws depending on how the information was obtained, used and disclosed. In 2026, the National Privacy Commission expressly identified doxxing as the malicious public disclosure of personal data intended to harass or intimidate in its guidance on scraped publicly available personal data.
Primary guidance: NPC Advisory No. 2026-01 and the NPC Notice to the Public dated May 22, 2026.
Key Takeaways
- There is no single offense named “doxxing” that covers every situation.
- The NPC recognizes malicious public disclosure of personal data intended to harass or intimidate as doxxing in its 2026 scraping advisory.
- Data Privacy Act liability depends on the facts, including the source, processing, disclosure and lawful basis involved.
- Threats, harassment, illegal access or other cybercrime offenses may also apply.
- Victims should preserve the post, URL, account, timestamps and any resulting threats or harassment.
- Report the content to the platform and consider NPC or law-enforcement remedies depending on the incident.
Decision Snapshot
| Situation | Possible route |
| Personal data posted to intimidate you | Privacy complaint and/or law-enforcement assessment may be appropriate. |
| Data came from a hacked database | Cybercrime and privacy issues can overlap. |
| Post includes threats | Preserve both the data disclosure and the threatening language. |
| Public information was aggregated for harassment | Public availability does not automatically make every harmful use lawful. |
What Does the NPC Say About Doxxing?
NPC Advisory No. 2026-01 states that Personal Information Controllers should not use scraped personal data in ways that cause harm, specifically listing “doxxing or the malicious public disclosure of personal data intended to harass or intimidate.” See Section 7(D) of the Advisory.
What If the Data Came From a Leak or Unauthorized Access?
In May 2026, the NPC warned that unauthorized access, use, disclosure, sharing or further dissemination of another person’s personal data may give rise to civil, administrative or criminal liability under the Data Privacy Act and other applicable laws. The NPC also advised the public not to repost files or screenshots known or implied to have come from unauthorized access.
What Evidence Should a Victim Preserve?
- full URL of the post or page;
- screenshots showing the account and content;
- date and time of publication;
- comments, shares or messages showing harassment or threats;
- the source of the disclosed data if known;
- platform report confirmation; and
- records of resulting harm or contact attempts.
Where Can You Complain?
If the issue is primarily a personal-data violation, review Cybercode’s NPC complaint guide. If the incident also involves hacking, threats, fraud or other cybercrime, use the cybercrime reporting guide.
Frequently Asked Questions
Is posting someone’s address always illegal?
Not automatically in every context. The legal analysis depends on the source, purpose, lawful basis, surrounding conduct and applicable laws.
Can publicly available information still be used unlawfully?
Yes. Public availability does not automatically authorize every form of collection, aggregation, profiling or harmful disclosure.
Should I ask the platform to remove the post?
Yes, but preserve evidence first where practical. A platform takedown does not replace a formal complaint when legal action is warranted.
Related Cybercrime Guides
Official Sources
General educational information only.
