For Lending & Financing

Data privacy compliance for lending companies

You scanned this from our Lending Risk Summary. Lending and financing companies face both SEC and NPC oversight — and lending apps draw the closest scrutiny of any sector. Here is what that means in plain terms.

Questions, answered

We are registered with the SEC. Do we also have NPC obligations?

Yes. The SEC regulates you as a lending or financing company (your licence, disclosures, interest practices). The National Privacy Commission separately regulates how you handle borrower personal data under RA 10173. Lending and financing companies are squarely on the NPC’s radar, and the two regulators have coordinated on abusive practices.

Why are lending apps under so much scrutiny?

The NPC has issued repeated advisories and enforcement actions against online lending apps for harvesting phone contacts, shaming borrowers, and unauthorised processing. If you operate or use a lending app, the way it accesses contacts, photos, and location is exactly what regulators inspect first.

What borrower data counts as sensitive, and why does it matter?

Government IDs, financial details, and information about a borrower’s ability to pay are sensitive or high-risk personal data. Processing it triggers stricter duties — lawful basis, consent done correctly, security measures, and retention limits — all of which a DPO puts in place.

Does a lending company need a Data Protection Officer?

Yes — processing borrower personal data is your core activity and is done at scale, which is precisely when RA 10173 requires a designated DPO. The DPO is also your registered point of contact with the NPC.

What about collections and debt-shaming complaints?

Contacting a borrower’s relatives or co-workers, or disclosing their debt, is a frequent source of NPC complaints and penalties. Lawful collection practices and a privacy-compliant script protect you from both NPC action and SEC sanctions.

How fast must we report a data breach?

You must assess and, where required, notify the NPC and affected borrowers within 72 hours of knowing about a breach. We prepare the response plan in advance so you are not improvising during the clock.

Can you act as our external DPO and fix this end to end?

Yes. As a TÜV Certified DPO (Cert #7000532) in Region 8, I can serve as your designated DPO, handle NPC registration, build your Privacy Management Program, review your app and collection practices, and train your staff.

Lend with borrower data handled lawfully

Talk to a TÜV Certified Data Protection Officer — no obligation, no jargon.

Atty. Renerio de Dios Jr. · TÜV Cert #7000532 · Dulag, Leyte · serving all of Region 8