Skip to content Skip to sidebar Skip to footer

Is the Data Privacy Act protecting or failing Filipinos?

There are few things more unsettling in the digital age than answering a call from an unknown number, only to hear the person on the other end greet you by your full legal name.

That experience has become increasingly familiar to some Filipinos. A recent viral discussion on Threads featured users who said scammers already knew not only their names but also secondary phone numbers used exclusively for banking and savings.

The accounts highlight how fraud schemes are becoming more targeted, with cybercriminals using verified personal information to make their approaches appear credible.

How scammers build detailed profiles

Cybercriminals are increasingly moving away from mass-text scams and toward highly targeted spear-phishing and voice phishing, or vishing, attacks that rely on stolen personal data to gain a victim’s trust.

According to Aura, a digital security company, this level of detail is rarely the result of a hacked personal device. Instead, it is often linked to downstream data breaches and the underground trade of stolen information.

Aura said phone numbers appeared in 39% of data breaches recorded in 2024, making them one of the most commonly exposed pieces of personal information. Once leaked, these records can be combined with other stolen data, such as names, addresses, and financial affiliations, to create detailed victim profiles.

Data from e-commerce platforms, delivery services, corporate databases, and other organizations affected by security breaches may eventually be compiled into so-called “combo lists” — collections of stolen records sold in underground online marketplaces. These databases allow cybercriminals to cross-reference multiple sources of information, making scams more personalized and convincing.

Data Privacy Act has limits

The country’s primary law governing personal information is Republic Act No. 10173, or the Data Privacy Act of 2012. It requires Personal Information Controllers (PICs) to implement safeguards that protect consumer data and authorizes the National Privacy Commission (NPC) to investigate breaches and penalize organizations that fail to comply.

However, while the law provides mechanisms to hold organizations accountable for failing to protect personal information, its reach becomes limited once stolen data has already spread beyond the country.

Although the NPC can investigate breaches and impose penalties on local organizations, it has little control over international underground marketplaces where stolen records are bought, sold, and redistributed.

According to a 2024 academic study on dark web economies and cybercriminal data markets, personally identifiable information (PII) is often repeatedly bundled, traded, and resold by decentralized criminal networks once it enters the underground market.

Because digital records can be copied indefinitely, a single data breach may continue circulating long after the original incident, making it difficult for victims to regain control of their personal information.

The NPC also previously raised concerns over the handling of personal data during the rollout of the SIM Registration Act, ordering telecommunications companies to remove hidden consent tick boxes from registration portals to prevent unnecessary collection and sharing of subscriber information.

As more personal information finds its way into underground databases, cybersecurity experts say consumers should remain cautious when receiving unsolicited calls, text messages, or emails—even if the caller appears to know personal details. Verifying requests through official channels and refusing to disclose passwords or one-time passwords remain among the most effective ways to avoid becoming a victim of fraud.

READ: