Philippines • Based on the DICT–NPC–SEC public advisory of 18 March 2026
The short answer: A late payment does not give an online lender the right to threaten you, shame you or message the people in your phone. The DICT–NPC–SEC joint advisory of 18 March 2026 says lending and financing companies, and anyone lending through an online lending platform (OLP), may contact only a guarantor who expressly consented, not the rest of your contact list. Collection that uses threats is prohibited. Report unfair collection to the SEC, misuse of your contacts or data to the National Privacy Commission (NPC), and threats, fraud or scams to the cybercrime units. A complaint does not cancel a valid loan, which can still be collected lawfully.
If you are being threatened right now
- Threat of physical harm: get to a safe place and go to the nearest police station. Do not meet an unknown collector alone. Keep the threatening message: the PNP Anti-Cybercrime Group can take the digital evidence.
- Demand to pay a new personal e-wallet, or a claim that police will arrest you today: do not pay and never share an OTP. Check the balance through the number on your original contract or the lender’s verified website. The sender may be an impersonator.
- Your contacts are being messaged or you are being shamed online: screenshot everything with dates and sender details, and ask the people contacted to keep what they received. You do not have to wait for repeated abuse before reporting.
- You already paid a suspicious account: report it at once to your own bank or e-wallet through its official channel, and keep the transaction reference numbers.
Where and how to report
Choose the route by the problem. One incident often raises more than one issue, so more than one report is normal.
| Problem | Where to report | What to submit |
|---|---|---|
| Unfair collection by a lending or financing company or its collector | SEC Financing and Lending Companies Department: imessage.sec.gov.ph or hotline 1-4732 (1-4SEC), as listed in the joint advisory | Company and app name, loan reference, dated timeline, contract, screenshots, call logs, proof third parties were contacted |
| Contact-list scraping, excessive app permissions or disclosure of your data | NPC, by notarized complaint-assisted form or verified complaint (NPC complaint instructions) | Permission screenshots, privacy notice, messages that disclosed the debt, names of people contacted, your requests to the lender |
| Threats, harassment, fraud or scams online | DICT Cyber Hotline 1326@dict.gov.ph; NBI Cybercrime Division ccd@nbi.gov.ph, (632) 8523-8231 to 38; PNP-ACG acg@pnp.gov.ph, (632) 8723-0401 loc. 7491 | Timeline, screenshots, sender numbers, and transaction IDs and receiving account details if money was sent |
| Loan from a bank or other BSP-supervised institution | The institution’s own complaint channel first, then the BSP Consumer Assistance Mechanism through BSP Online Buddy | The institution’s reference number, its reply and your evidence |
The cybercrime contacts above are as listed in the joint advisory. The SEC, not the BSP, regulates financing and lending companies, online lending apps and their collection agencies, according to the BSP’s complaint-filing notice. The SEC’s complaints page for lending and financing companies explains its current process. The NPC complaint form can be filed by the data subject or an authorised representative, and the NPC says it has 30 calendar days to give due course to or dismiss a complaint.
A simple report sequence: (1) preserve the original evidence before deleting or blocking anything; (2) identify the lender, app and collector as precisely as possible; (3) write down dates, exact words and which contacts were approached; (4) attach the contract, payment records and screenshots; (5) file with the SEC for collection misconduct, the NPC for privacy violations and the cybercrime units for threats or scams; (6) save every reference number and add new incidents to the same timeline.
Deadlines: the SEC, NPC and advisory pages checked for this guide set no deadline for a borrower’s complaint. Report while the evidence is fresh. First concrete action: screenshot the harassing messages with dates and sender details today, then file with the SEC through imessage.sec.gov.ph.
What collectors may and may not do
The rules come from the Data Privacy Act, NPC Circular No. 20-01 on loan-related processing of personal data (as amended by NPC Circular No. 2022-02), and SEC Memorandum Circular No. 18, s. 2019 on unfair debt collection. The joint advisory restates them.
| Issue | What is allowed | Red flag | What to do |
|---|---|---|---|
| Lender identity and terms | A registered, licensed company with a stated legal name; loan amount, charges and due dates shown before you accept | The app hides its operator, copies a licensed firm’s name, or rushes you past the terms | Check the SEC list of recorded online lending platforms; an app-store listing alone proves nothing |
| App permissions | Camera or gallery access only for identity verification or similar specified purposes, turned off once done | Unnecessary permissions, unbridled contact-list access, pre-ticked consent boxes | Screenshot the permission screen and privacy notice, then revoke access you no longer need |
| References and guarantors | A character reference is for verification only; a guarantor must separately consent before being bound | A collector demands payment from a reference or another person in your contacts | Ask the person contacted to save the message; report to the NPC and the SEC |
| Collection contact | The lender may ask you to pay a valid debt through verified channels | Threats of violence, threats to harm your reputation or property, threats of action that cannot legally be taken | Keep call logs and dated screenshots; report to the SEC, and threats to the cybercrime units |
| Your personal data | Data kept only as long as the loan, legal claims or the law require, then securely disposed of | Refusing to explain how data is used, or spreading your data to shame you | Write to the lender’s privacy contact; if unresolved, complain to the NPC (see the NPC rights guide) |
| Disputed balance | You may question charges and ask for a written statement; a valid balance remains collectable | No breakdown, or a demand to pay a personal account under threat of exposure | Request an itemised statement; pay only verified amounts through official channels and keep receipts |
The joint advisory describes unfair collection practices as those that use threats of violence or other criminal means to harm a person, their reputation or property, or that threaten action that cannot legally be taken. It also warns about deceptive design, such as pre-ticked boxes or consent that is easy to give and hard to withdraw, which may invalidate consent. Violations can lead to administrative sanctions, including fines and suspension or revocation of the authority to operate. SEC rules for financing and lending companies change; check the SEC’s current issuances before relying on an older summary.
NPC action against loan apps: a dated example
The 2026 advisory does not name or rank current violators. It identifies conduct: scraping contact lists, contacting references, relatives or co-workers to collect, threats and public shaming, unnecessary permissions and over-long data retention. An unrecorded platform is not exempt.
For a concrete historical example, on 25 August 2021 the NPC announced immediate takedown orders against JuanHand, Pesopop, CashJeep and Lemon Loan, citing excessive access to contacts and social-media data that could be used to harass and shame borrowers. That is a 2021 enforcement action, not a statement of the apps’ present regulatory status. Check current SEC and NPC records before treating an old article or social-media list as a blacklist.
Scam and harassment protection checklist
| When | Practical step | Why it matters |
|---|---|---|
| Before downloading | Download only from official sources and match the app to a registered company on the SEC list and its advisories | Scam apps copy the names and branding of genuine lenders |
| Before agreeing | Save the contract, disclosure statement, payment schedule, privacy notice and support contacts | You need the original terms to challenge surprise charges or a false balance |
| At the permission prompt | Decline unrelated access; tell your character references before naming them | Broad phone access enables contact-list harassment |
| When a demand arrives | Verify it through the lender’s official channel; never share an OTP or pay a new personal wallet | Impersonators and payment-diversion scams rely on urgency |
| After harassment | Save full screenshots, call logs, the app listing, receipts, names of contacted people and a dated timeline | Specific evidence lets an agency tell lawful collection from intimidation |
| Once a permission is no longer needed | Revoke it in phone settings and change any password you shared | This limits further access, though it cannot undo data already copied |
Illustrative scenarios
These are fictional examples, not findings against any company.
“Your office will know by lunch.” A collector threatens to message Ana’s co-workers and posts a graphic calling her a scammer in a group chat. Ana saves the messages and group details, asks members to keep what they received, files a collection complaint with the SEC and a privacy complaint with the NPC, and sends the threat evidence to a cybercrime unit.
“We need every contact to approve your loan.” Ben’s cousin, listed only as a character reference, receives repeated demands to pay. A reference is for verification only, so Ben reports the contact-list misuse to the NPC and the collection conduct to the SEC; his cousin can document the disclosure too.
“Pay this wallet now or police will arrest you.” Cora does not pay the new wallet or share an OTP. She checks her balance through the number on her original agreement, saves the sender’s number and wallet details, and reports suspected fraud to the cybercrime units.
“The balance doubled, but no breakdown.” Diego writes to the lender’s official support channel with his receipts and asks for an itemised statement. If the abuse continues, he files with the SEC and keeps paying any verified, undisputed amount through official channels.
Sources
- DICT–NPC–SEC Advisory on Online Lending Platforms (18 March 2026) — prohibited processing, guarantors, permissions, retention and reporting contacts.
- NPC Circular No. 20-01 and NPC Circular No. 2022-02 (1 December 2022) — processing of personal data for loan-related transactions.
- SEC Memorandum Circular No. 18, s. 2019 — prohibition on unfair debt collection practices of financing and lending companies.
- NPC — File a complaint and NPC — Data subject rights.
- NPC — Takedown of four online lending apps (25 August 2021).
- SEC — Complaints against lending and financing companies and SEC list of recorded online lending platforms.
- BSP — How to file a complaint against a BSP-supervised institution.
Disclaimer
This guide is general information, not legal advice or a ruling on any lender, collector or individual debt. A complaint about abusive collection does not by itself cancel a valid loan. Agency contacts and procedures can change; verify them on the official SEC and NPC pages before filing, and seek qualified help for a specific case.
Related articles
- Data Subject Rights: Action Matrix and Reporting Routes
- How to File a Data Privacy Complaint With the NPC
- Financial Products and Services Consumer Protection Act: RA 11765
- Cybercrime reporting directory for the Philippines
Sources rechecked as of: October 3, 2026

