Compliance · 7 min read

The Data Privacy Act (RA 10173): What Lenders Need to Know

If your lending business collects names, government IDs, income documents, or contact details from borrowers — you handle personal data covered by Republic Act 10173, the Data Privacy Act. Getting that right is both a legal obligation and part of operating a business that borrowers can trust. This article covers the general principles that matter most for lending operations; it is not legal advice, and you should verify your specific obligations with the National Privacy Commission (NPC) or your own counsel.

What the Data Privacy Act means for lending operations

The Data Privacy Act of 2012 establishes rules for how organizations collect, store, use, and share personal information. The National Privacy Commission oversees compliance and handles complaints from individuals whose rights may have been violated.

Lending companies, cooperatives, and microfinance institutions are covered because they routinely process the personal data of borrowers, guarantors, and co-makers. The law applies regardless of the size of your portfolio — whether you manage fifty active loans or five thousand, if you process personal information about individuals, the act's obligations apply to you. The NPC issues advisories and circulars that refine how the law is applied in specific contexts, so it is worth monitoring those directly as requirements can evolve.

What counts as personal data in your loan portfolio

Under RA 10173, personal information is any data from which an individual can be identified — directly or in combination with other information. In a typical lending operation, that covers records you gather every day:

  • Application forms with name, address, date of birth, and contact details
  • Government-issued ID copies: PhilSys, SSS, TIN, UMID, driver's license, or passport
  • Proof of income: payslips, business permits, ITRs, or financial statements
  • Photographs and signatures collected during KYC or loan release
  • Emergency contact details and co-maker or guarantor information
  • Loan repayment history and account balances

Some data — including certain government ID numbers and health or financial information used in specific contexts — may qualify as sensitive personal information under the law, which carries stricter handling requirements. The NPC's guidelines describe how these categories are treated; if you are unsure how to classify data you collect, consult the NPC or a qualified adviser.

Core obligations for personal information controllers

Organizations that decide how and why personal data is processed are called personal information controllers (PICs) under the law. Most lending companies and cooperatives are PICs with respect to their borrowers' data. As a PIC, you carry several baseline obligations:

Collect only what you need. The principle of proportionality means the data you collect should be adequate, relevant, and limited to the purpose for which it is gathered. If a piece of information is not needed to assess or administer the loan, question whether you should collect it at all.

Inform borrowers before you collect. At or before the time of collection, borrowers should receive a privacy notice explaining what data is being collected, why, how long it will be kept, and who it may be shared with. A brief, plain-language statement is more useful than a lengthy document that nobody reads.

Secure a proper lawful basis for processing. Consent is one of the lawful bases under RA 10173. For consent to be valid, it must be specific, informed, and freely given. Pre-checked boxes or consent buried in multi-page loan agreements may not meet the standard. For some processing — such as credit checks necessary to evaluate a loan application — there may be other lawful bases; confirm with the NPC what applies in each context.

Protect the data you hold. You are required to implement reasonable and appropriate organizational, physical, and technical security measures to protect personal data from unauthorized access, disclosure, alteration, or loss. The NPC provides guidance on minimum standards, but a useful starting point is ensuring that borrower records are not accessible to every staff member — access should follow the need-to-know principle.

Honor data subjects' rights. Borrowers have the right to access their personal data, correct inaccurate records, and — under certain conditions — request erasure or object to processing. Have a documented process for receiving and responding to these requests within the timeframes the NPC specifies.

Sharing borrower data: what is allowed and what is not

Lending operations sometimes need to share borrower data — with credit bureaus, external credit investigators, or collection agents. RA 10173 permits sharing only when there is a lawful basis: the borrower has consented, sharing is necessary to carry out a contract, or another condition specified in the act applies.

Sharing personal data with parties for purposes the borrower did not agree to — such as selling or renting borrower contact lists to marketers — is prohibited. If you engage third-party providers who will process borrower data on your behalf (such as a cloud-based loan management system), you should have a written data-sharing or processing agreement in place. These providers are classified as personal information processors under the law.

Collection practices that involve disclosing a borrower's account status to people in their social or professional network — a pattern the NPC has taken enforcement action against in the digital lending sector — are not compliant. Contact should be limited to authorized channels, and account details should only be shared with the borrower and their duly authorized representatives.

For background on how document-level controls and audit trails support compliance during examinations, see the CDA compliance checklist for cooperatives, which covers parallel record-keeping obligations.

Building a data-responsible lending operation

Data privacy compliance is not a one-time setup task. It requires keeping your processes and records current:

  • Designate a Data Protection Officer (DPO). Organizations that process personal data are required to appoint a DPO — someone responsible for overseeing compliance, handling requests from data subjects, and coordinating with the NPC when needed.
  • Document your data flows. Know what personal data you collect, where it is stored, who has access, how long it is retained, and when it is deleted. A simple, maintained data inventory is more useful than a policy document that nobody updates.
  • Set retention schedules. Keep borrower records only as long as needed — typically the life of the loan plus any legally required retention period. Establish a routine for deleting or anonymizing records that have passed their retention window.
  • Train your team. Loan officers, branch managers, and collection agents handle borrower data daily. Regular reminders about basic practices — not sharing system credentials, not discussing account details in public, using secure communication channels instead of personal chat apps — have more impact than thick policy manuals.
  • Have a breach response plan. If personal data is compromised — a lost device, unauthorized system access, or data exposure — the NPC may require notification to affected individuals and the commission within a defined timeframe. Know the steps before an incident occurs.

If your operation is still tracking borrower records in spreadsheets or across separate apps and chat threads, moving to a unified loan management system reduces both data privacy risk and the operational burden of responding to access or correction requests.

Lenduh's lending platform keeps borrower records centralized and access-controlled, with audit logs showing who accessed what and when — the documented trail that supports both data privacy compliance and any investigation that follows a potential incident. If you want to see how that works in practice, reach out for a walkthrough.

Running a tighter, more trustworthy operation

Treating borrower data with care is also just good business. Borrowers who trust that their information is handled professionally are more likely to stay with you and refer others. That trust is built through clear policies, trained staff, and systems that keep sensitive records out of unsecured spreadsheets and personal devices.

RA 10173 is the law; the NPC is the authoritative source on what it currently requires. For anything beyond general principles, verify your specific obligations directly with the commission or your legal adviser before making compliance decisions.

See Lenduh in action

Modern lending software for Philippine teams — back office, field officers, and members in one platform, with CDA-ready compliance and audit trails built in.