NPC Advisory No. 2026-01: The National Privacy Commission's New Rules on Data Scraping and What Foreign Companies in the Philippines Must Do Now
Introduction: The End of the “Public Data, No Rules” Assumption
For years, a convenient misconception circulated among foreign companies entering the Philippine market: if personal data is publicly posted — on LinkedIn, a corporate website, a government registry, a social media profile — it is free to collect, aggregate, and use. Some legal teams treated publicly available personal data the same way they treated press clippings. This assumption was always legally fragile. As of April 13, 2026, it is definitively dead.
The National Privacy Commission (NPC), the regulatory body created under Republic Act No. 10173 (the Data Privacy Act of 2012), issued NPC Advisory No. 2026-01 — “Guidelines on Scraping Publicly Available Personal Data” — expressly confirming that:
- The scraping of publicly available personal data is fully subject to RA 10173 and its Implementing Rules and Regulations (IRR).
- Public availability does not constitute consent or any other valid lawful basis for processing.
- Automated data collection — whether conducted by the entity itself or by a third-party personal information processor (PIP) — constitutes regulated personal data processing.
- Privacy Impact Assessments (PIAs) are mandatory for scraping activities.
- Entities that host publicly available personal data have affirmative obligations to deter unauthorized scraping.
The Advisory was published on the official NPC website on May 21, 2026, and is effective immediately. Foreign companies that scrape publicly available Philippine personal data for any commercial purpose — lead generation, AI training datasets, marketing analytics, risk scoring, or platform operations — must treat this as a compliance priority, not a policy footnote.
Background: Why the NPC Issued This Advisory Now
The Philippines is one of the world’s largest business process outsourcing (BPO) destinations and one of the fastest-growing digital economies in Southeast Asia. Foreign companies — particularly those in technology, financial services, human resources, and market intelligence — have increasingly relied on automated data collection to build Philippine consumer and business profiles. The methods range from the benign (scraping corporate registration data from the SEC’s public portal) to the legally fraught (extracting personal contact details from LinkedIn, job boards, or e-commerce platforms at scale).
The NPC’s concern is not hypothetical. In the years since RA 10173 took effect in 2016, the NPC has observed a proliferation of commercial data brokers, recruitment technology platforms, and AI training data providers operating in or targeting the Philippines without any apparent awareness of — or regard for — data protection obligations. The Advisory is explicitly designed to close that gap.
The Advisory also arrives in a broader regulatory context. The European Union’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Singapore’s Personal Data Protection Act (PDPA) have all progressively restricted or prohibited unconstrained scraping of publicly available personal data. The NPC’s Advisory aligns Philippine practice with international standards and signals that the Philippines intends to enforce these norms seriously.
The Legal Framework: RA 10173 and Its IRR
Any analysis of NPC Advisory No. 2026-01 must begin with the primary law it interprets and applies: Republic Act No. 10173, signed on August 15, 2012, and effective September 8, 2012. The full text is available on LawPhil and the Official Gazette.
The IRR to RA 10173, issued on August 24, 2016, took effect on September 9, 2016, and remains the primary implementing instrument. Full NPC enforcement began in March 2017.
Key Definitions
Under Section 3 of RA 10173, the following definitions are foundational to understanding the Advisory:
- Personal Information — any information from which the identity of an individual is apparent or can be reasonably and directly ascertained, or from which it can be demonstrated that a person can be identified.
- Sensitive Personal Information (SPI) — personal information covering an individual’s race, ethnic origin, marital status, age, color, religious affiliations, philosophical or political affiliations, health, education, genetic or sexual life, legal records, employment history, and financial accounts.
- Personal Information Controller (PIC) — any natural or juridical person who controls the collection, holding, processing, or use of personal information. Foreign companies that scrape or use scraped data are PICs.
- Personal Information Processor (PIP) — any natural or juridical person who processes personal information under the instructions of a PIC. Third-party scraping service providers are PIPs.
- Processing — any operation or set of operations performed upon personal information, including collection, recording, organization, storage, updating, modification, retrieval, consultation, use, consolidation, blocking, and erasure.
- Data Scraping — the automated or manual extraction of personal data from online sources, including websites, applications, databases, and public registries.
The NPC’s central assertion in Advisory No. 2026-01 is that data scraping — including scraping of publicly available personal data — is a “processing” activity under RA 10173. All the law’s requirements follow from that classification.
The Lawful Basis Problem
Under Section 12 of RA 10173, personal information may only be processed under any of several enumerated lawful bases, including:
- The data subject’s consent (freely given, specific, informed, and unambiguous);
- The processing is necessary to fulfill a *contract with the data subject;
- The processing is necessary for legal obligations;
- The processing is necessary to protect life or public safety;
- The processing is necessary for legitimate interests (subject to a balancing test against data subject rights).
Critically, the fact that data is publicly available is not among these lawful bases. The Advisory makes this explicit: public availability does not constitute consent, does not satisfy the legitimate interests test by default, and does not exempt an entity from the law’s requirements. A foreign company that scrapes 50,000 Filipino professionals’ LinkedIn profiles for recruitment marketing purposes cannot rely on those profiles being publicly visible. It needs a valid lawful basis — and in most cases, that means obtaining consent.
NPC Advisory No. 2026-01: Key Provisions
1. Scope — Who the Advisory Applies To
The Advisory has two distinct but overlapping scopes:
Entities that scrape. Any PIC — foreign or domestic — that scrapes publicly available personal data of individuals in the Philippines is subject to the Advisory. This includes foreign companies that scrape Philippine data from outside the country; RA 10173 applies extraterritorially to the processing of Philippine residents’ data regardless of where the processor is located.
Entities that host publicly available personal data. Any PIC that operates a platform, website, or application on which personal data is publicly accessible has new affirmative obligations. If a third party scrapes that data, the host may also bear regulatory responsibility depending on the circumstances.
This dual scope means that a foreign company operating a Philippine-facing job board, a real estate portal, or a B2B marketplace is caught on both sides: as a potential scraper of competitor data, and as a host with obligations to protect user data from unauthorized scraping.
2. Privacy Impact Assessments Are Mandatory
One of the Advisory’s most significant requirements is the mandatory conduct of Privacy Impact Assessments (PIAs) for data scraping activities.
A PIA is a systematic process of evaluating the potential privacy risks of a data processing activity and identifying measures to mitigate them. Under the RA 10173 IRR, PIAs are required for high-risk processing activities. The Advisory now specifies that scraping — including scraping conducted through third-party PIPs — qualifies as high-risk processing that requires a PIA.
The PIA must address:
- The scope and purpose of the scraping activity.
- The categories of personal data being collected.
- The source and accessibility of the data.
- The lawful basis for processing.
- The risks to data subjects, including the risk of secondary use, re-identification, profiling, and discrimination.
- The safeguards in place to mitigate those risks.
- Risks arising from data aggregation (where scraped data is combined with other datasets to create richer profiles).
- Risks arising from downstream use — what happens to the data after it is scraped, including transfer to third parties or use in AI training.
PIAs must be conducted before scraping begins and regularly updated as the scope or nature of the activity changes. For foreign companies, this means that commissioning a third-party PIP to scrape Philippine data does not relieve the commissioning PIC of PIA obligations; the PIA must cover the full processing chain.
3. Secondary Processing and Repurposing
The Advisory introduces a critical restriction on secondary processing — the use of scraped data for purposes beyond what was originally declared at the time of collection.
If a foreign company scrapes publicly available personal data for one declared purpose (e.g., market research) and subsequently uses that data for a different purpose (e.g., selling leads to third-party advertisers, or training an AI model), it must:
- Establish a new lawful basis for the secondary use.
- Provide updated notice to affected data subjects.
- Conduct a fresh PIA addressing the new purpose.
This provision has significant implications for AI training. Foreign companies that scraped Philippine personal data before this Advisory was issued and subsequently used it to train machine learning models will need to reassess whether that training constitutes a secondary processing activity requiring a new lawful basis.
4. Enhanced Obligations for Data Hosts
Entities that host publicly available personal data — including foreign companies operating Philippine-facing websites — now have affirmative obligations that were not previously codified. Specifically, they must:
- Inform users that their data may be subject to scraping by third parties.
- Disclose the categories of data that are publicly accessible.
- Provide mechanisms for data subjects to object to the scraping of their personal data.
- Implement technical and organizational measures to deter unauthorized scraping — including rate limiting, bot detection, CAPTCHA, and access controls.
These obligations effectively require platform operators to take reasonable steps to prevent the very scraping activity that other PICs are now prohibited from conducting without a valid lawful basis. The NPC has created a two-way compliance street.
5. Sensitive and Vulnerable Data
The Advisory reinforces the heightened protection for Sensitive Personal Information (SPI) under RA 10173. Scraping SPI is generally prohibited, absent strict statutory conditions (e.g., explicit consent, necessity for medical purposes, or legal proceedings). The Advisory also introduces a new vulnerability angle: scraping involving minors, the elderly, or other vulnerable individuals will be subject to heightened scrutiny, even if the data is technically publicly available.
For foreign companies in sectors such as elder care, education, financial services, or insurance that might scrape publicly available records to build profiles of vulnerable individuals, this is a particularly important warning.
Penalties for Non-Compliance
The Advisory does not create new penalties — it clarifies the application of RA 10173’s existing penalty structure to data scraping activities. The penalties under Sections 25 through 33 of RA 10173 are substantial:
Sensitive Personal Information Violations (Section 25(b))
Processing of SPI without the data subject’s consent and without any of the exceptions under Section 13 of RA 10173 carries:
- Imprisonment: 3 to 6 years
- Fine: PHP 500,000 to PHP 4,000,000
Note: The IRR to RA 10173 (Rule 10, Section 2(b)) specifies this range. Some secondary sources previously cited a range of 2-7 years imprisonment, but the correct range — as confirmed against the official text of RA 10173 Section 25(b) as published on lawphil.net — is 3 to 6 years imprisonment and a fine of not less than PHP 500,000 but not more than PHP 4,000,000.
Unauthorized Processing Violations (Section 25(a))
Processing personal information without the consent of the data subject and without any lawful basis under Section 12 carries:
- Imprisonment: 1 to 3 years
- Fine: PHP 100,000 to PHP 500,000
Accessing Without Authority (Section 27)
Knowingly accessing another person’s personal information without being authorized to do so carries:
- Imprisonment: 6 months to 2 years
- Fine: PHP 100,000 to PHP 500,000
Improper Disposal (Section 29)
Improper disposal of personal information — which could apply to the careless handling of scraped datasets — carries:
- Imprisonment: 6 months to 2 years
- Fine: PHP 100,000 to PHP 500,000
Beyond criminal penalties, the NPC has broad administrative enforcement powers under RA 10173, including:
- Compliance orders requiring cessation of non-compliant processing.
- Compulsory registration of data processing systems with the NPC.
- Mandatory conduct of PIAs.
- Referral to the Department of Justice for criminal prosecution.
Civil liability to data subjects for damages is also available under Section 33 of RA 10173.
Practical Implications for Foreign Companies
Immediate Compliance Steps
For foreign companies that are already conducting or commissioning data scraping activities involving Philippine personal data, the Advisory requires urgent action:
1. Conduct an immediate data audit. Identify all sources of Philippine personal data currently being scraped — whether by the company directly or through third-party PIPs. Map the categories of data, the purposes, and the downstream uses.
2. Conduct or update PIAs. For every scraping activity identified, a PIA must be in place. If PIAs were conducted before this Advisory and have not been updated to reflect the Advisory’s requirements, they must be refreshed.
3. Establish or revisit lawful bases. For each scraping activity, document the specific lawful basis under Section 12 of RA 10173. If consent is the basis, assess whether the consent obtained meets the “freely given, specific, informed, and unambiguous” standard. If legitimate interests is the basis, conduct and document a balancing test.
4. Review third-party arrangements. Contracts with third-party PIPs that conduct scraping on your behalf must include data privacy obligations, PIA obligations, restrictions on sub-processing, and breach notification requirements. If your PIP is scraping data on your behalf without a compliant contract, both you and the PIP face regulatory exposure.
5. Assess secondary uses. If scraped data is being used for purposes beyond the original collection purpose, a new lawful basis, new PIA, and updated notice are required before continued use.
6. Update privacy notices. Foreign company websites and applications targeting Philippine users must be reviewed to ensure they adequately disclose data scraping practices and provide data subject rights information in compliance with RA 10173.
New Projects and AI Training
For foreign companies planning to use Philippine personal data for AI training, the Advisory creates a clear framework that cannot be sidestepped by invoking the “public data” argument. Any AI training dataset that includes scraped Philippine personal data requires:
- A valid lawful basis for the initial scraping.
- A PIA addressing the risks of AI training use.
- Consent (or another applicable lawful basis) for the specific use in machine learning model training.
- Compliance with the NPC’s evolving guidance on AI and personal data processing.
Companies that have already trained models using scraped Philippine data should treat this as an open compliance item requiring immediate legal review.
Cross-Border Data Transfers
A common arrangement for foreign companies is scraping or collection of Philippine personal data, followed by transfer to an overseas server or parent company for processing. This raises the cross-border transfer issue under Section 16 of RA 10173.
Cross-border transfers of Philippine personal data are permitted only where:
- The receiving country ensures an adequate level of protection for the data; or
- The PIC or PIP provides contractual protections equivalent to RA 10173 standards (the NPC-prescribed standard contractual clauses); or
- The data subject provides consent after being informed of the risks.
Foreign companies transferring scraped Philippine personal data to servers in countries without an NPC-recognized adequacy determination (e.g., many jurisdictions) must put compliant contractual safeguards in place. The EU-US Data Privacy Framework does not automatically satisfy this requirement in the Philippine context; a separate analysis is required.
The Intersection with the EU GDPR and International Standards
The Advisory’s approach is consistent with international trends in data protection law. The GDPR’s Recital 47 acknowledges that publicly available personal data can support legitimate interests, but the European Data Protection Board has consistently held that this does not mean scraping publicly available data is unregulated processing. The Advisory adopts the same position, with a narrower legitimate interests pathway.
For foreign companies that already maintain GDPR-compliant data practices, much of the Advisory’s substance will be familiar. The key differences for Philippine compliance are:
- PIA is mandatory for scraping activities rather than merely required for high-risk processing.
- The NPC’s approval must be express, not implied — NPC inaction on any submission does not constitute approval.
- NPC registration requirements may apply depending on the scale and nature of the processing.
- The data host obligations under the Advisory go beyond what most GDPR frameworks require and may necessitate platform-level technical changes.
What the NPC’s Enforcement Posture Signals
The NPC has been steadily building its enforcement capacity since 2017. Recent high-profile cases — including enforcement actions against telecommunications companies, government agencies, and major e-commerce platforms — demonstrate a willingness to impose significant penalties and issue compliance orders. Advisory No. 2026-01 signals that the NPC is actively turning its attention to the commercial data broker and AI training data sector.
Foreign companies should not assume that being located outside the Philippines insulates them from NPC enforcement. RA 10173 applies extraterritorially, and the NPC has legal authority to investigate and impose sanctions on foreign PICs processing Philippine residents’ data. Practical enforcement against foreign entities requires international cooperation mechanisms, but the NPC has been actively building relationships with counterparts in the EU, Singapore, Japan, and other jurisdictions through the Global Privacy Enforcement Network (GPEN).
Conclusion: No More Excuses for Non-Compliance
NPC Advisory No. 2026-01 is unambiguous in its central message: publicly available does not mean freely usable. The era of treating public personal data as a free resource for commercial scraping, AI training, lead generation, or analytics is over in the Philippines. The Advisory brings the country’s data protection practice into closer alignment with international standards and signals serious regulatory intent.
For foreign companies operating in or targeting the Philippine market, the compliance checklist is now clear. Audit your data sources. Conduct your PIAs. Establish your lawful bases. Review your third-party contracts. Update your privacy notices. And for any AI training program that touches Philippine personal data — do not assume that publicly available data is a shortcut around these requirements. The NPC has said otherwise, and it has said so in terms that leave no room for misinterpretation.
This article is for informational purposes only and does not constitute legal advice. For guidance on RA 10173 compliance, NPC Advisory No. 2026-01, or data scraping practices in the Philippines, please contact TTFC Law to speak with a member of our Data Privacy and Technology practice group.
Related Articles
SEC Memorandum Circular No. 15, Series of 2025: The Beneficial Ownership Disclosure Rules of 2026 and What Foreign Corporations Must Do Now
The Securities and Exchange Commission's revised Beneficial Ownership Disclosure Rules — effective January 1, 2026 — represent the most significant tightening of corporate transparency obligations for foreign corporations operating in the Philippines in nearly seven years. With mandatory 7-day reporting of ownership changes, a new HARBOR registry, reduced reporting thresholds from 25% to 20%, and penalties increased up to 500% from prior levels, foreign investors can no longer treat beneficial ownership disclosure as a checkbox exercise. This comprehensive guide explains every requirement, the new categories, the expanded disclosure fields, the nominee reporting obligation, and the step-by-step compliance roadmap for foreign corporations.
How to Hire Foreign Employees in the Philippines in 2026: A Comprehensive Guide to the AEP and 9G Visa Process
The Philippines' revised Alien Employment Permit (AEP) rules under DO 248, s. 2025 introduced the Economic Needs Test, mandatory Understudy Training Programs for incentivized employers, and Certificate of Exemption requirements — changes that fundamentally alter how foreign employers must structure their Philippine hiring in 2026. This guide walks foreign investors and their counsel through every step of the AEP and 9G visa process with verified legal citations.
BOI vs. PEZA: The Foreign Investor's Registration Guide for 2026
A comprehensive comparison of Board of Investments (BOI) and Philippine Economic Zone Authority (PEZA) registration for foreign investors in the Philippines — covering incentives, eligibility, sector fit, and the 2026 SIPP landscape under RA 12066 (CREATE MORE Act).