Philippines NPC Flags Large-Scale Data Scraping as Processing | TLY

AI Regulation Tracker  /  Data privacy

Philippines Privacy Regulator Says Large-Scale Data Scraping Is Regulated Processing

NPC Advisory No. 2026-01, issued April 13, 2026, tells anyone scraping publicly available personal data that the Data Privacy Act still applies, that public availability is not consent, and that automated large-scale collection carries the full weight of a controller obligation.

The Leveraged Years AI Regulation News

For years the working assumption in a lot of data teams has been that if information sits on a public web page, it is fair game. Scrape it, store it, feed it into a model, resell it. The Philippine National Privacy Commission has now said in writing that this assumption does not hold under Philippine law. NPC Advisory No. 2026-01, issued on April 13, 2026, is titled Guidelines on Data Scraping of Publicly Available Personal Data, and it treats scraping as what it is: the processing of personal data, with all the duties that come attached.

The line that matters most is short and direct. The advisory states that "the public availability of personal data does not constitute consent by the data subject to its processing." That sentence closes the loophole that a lot of scraping operations have quietly relied on. Publishing a phone number, a name, or a professional profile on a public site is not the same as agreeing that anyone may harvest it at scale and use it for a new purpose. Consent under the Data Privacy Act has to be freely given, specific, and informed, and none of that is satisfied by the mere fact that a page was reachable without a login.

What does the advisory actually require?

The advisory applies to personal information controllers and processors that scrape data, and it also reaches the controllers that host public-facing personal data which others might scrape. In practice, if you run automated collection against Philippine residents, you need to identify a lawful basis for processing that is not just "it was public." You are expected to run a privacy impact assessment, apply data minimization, and honor the transparency obligations in the law, including disclosing in your privacy notice when personal data was obtained from publicly available sources, what the source was, and how the data is being processed. Large-scale and commercially driven scraping draws heightened scrutiny, which is the NPC's way of saying the bigger and more automated your operation, the more it expects to see a documented legal footing behind it.

None of these obligations are new inventions. They come straight from RA 10173, the Data Privacy Act of 2012. What the advisory does is remove any argument that scraping public data sits outside that framework. It maps the general rules of the Act onto a specific practice that had been operating in a grey zone, and it does so at a moment when AI training pipelines have made mass scraping a mainstream activity rather than a niche one.

Why should a US professional care about a Philippine advisory?

Two reasons. First, the Data Privacy Act has extraterritorial reach. It can apply to processing that relates to Philippine citizens and residents even when the entity doing the processing sits outside the country, particularly where there is a link to the Philippines through operations, equipment, or the targeting of Philippine data subjects. A US company scraping data that includes Philippine residents is not automatically outside the NPC's view simply because its servers are in the United States. Second, this advisory is part of a broader pattern. Regulators across several jurisdictions are converging on the same conclusion, which is that "it was public" is not a lawful basis for processing personal data at scale. When you see the same position appear in market after market, it stops being a local quirk and starts being the baseline that counsel should assume.

What US attorneys and their clients should do now

For attorneys advising clients that scrape, build data products, or train models, the practical work is provenance and documentation. Know where your training and enrichment data actually came from. If any of it was scraped from public sources that include Philippine residents, be ready to state your lawful basis, show a privacy impact assessment, and point to transparency disclosures that name public sources as an origin of the data. For clients that host public-facing personal data, the advisory is a reminder that they carry obligations too, and that leaving personal data exposed to bulk scraping is itself a risk worth reviewing. This is guidance, so it does not carry a fresh penalty schedule of its own. But the underlying Act does, and the NPC has now told everyone how it reads the law. Building the paper trail before an inquiry lands is far cheaper than assembling it afterward.

Questions professionals are asking

Does the NPC advisory ban data scraping?

No. It does not prohibit scraping outright. It confirms that scraping publicly available personal data is regulated processing under the Data Privacy Act, so it must have a lawful basis and satisfy the Act's obligations. Lawful data scraping is allowed if the controller meets those duties. What the advisory rejects is the idea that public availability alone is a legal basis.

Is public data considered consent under Philippine law?

No. The advisory states that the public availability of personal data does not constitute consent by the data subject to its processing. Consent under the Data Privacy Act must be freely given, specific, and informed. Finding data on a public page does not meet that standard, so scrapers need a different lawful basis or must satisfy the Act another way.

Can the Philippine Data Privacy Act reach a US company?

It can. The Data Privacy Act has extraterritorial features and can apply to processing that relates to Philippine residents even where the controller is based abroad, especially where there is a link to the Philippines through operations, equipment, or targeting of Philippine data subjects. A US firm scraping data that includes Philippine residents should not assume it is outside the NPC's reach.

What should a scraper document to comply?

Identify a lawful basis for processing that is not simply that the data was public, run a privacy impact assessment, apply data minimization, and disclose in your privacy notice when personal data was obtained from publicly available sources, including the source and the manner of processing. Large-scale and commercial scraping should expect heightened scrutiny.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how the Data Privacy Act and NPC guidance apply to your situation with qualified Philippine data-protection counsel.