Legal & Tax Updates [Back to list]
NPC Issues Guidelines on Scraping of Publicly Available Personal Data
The National Privacy Commission (NPC) has issued NPC Advisory No. 2026-01, establishing comprehensive guidelines on the scraping of publicly available personal data. While recognizing the increasing use of automated and manual scraping technologies to extract text, images, audio, video, and user profiles from online platforms, the NPC emphasizes that public availability does not remove an individual’s fundamental privacy rights. The Advisory reiterates that the protections under the Data Privacy Act (DPA), its Implementing Rules and Regulations (IRR), and relevant NPC issuances apply to the processing of publicly available personal data. The guidelines cover Personal Information Controllers (PICs) and Personal Information Processors (PIPs) that conduct data scraping, as well as hosting PICs whose platforms contain publicly available personal data that may be scraped.
Under the guidelines, publicly available personal data refers to information readily accessible to the general public without restrictions, authorization, or authentication. This includes information required by law to be publicly accessible and information intentionally made public by data subjects, such as content posted on public social media platforms. Importantly, public availability of personal data does not constitute consent by the data subject to its processing beyond those reasonably contemplated at the time it was provided. The Advisory further emphasizes that public availability of personal data does not relieve the PICs of their obligations under the DPA.
The Advisory imposes heightened compliance obligations on entities engaged in data scraping. PICs must transparently inform data subjects through appropriate privacy notices or consent forms. In addition, Section 3(F) requires scraping entities to conduct a formal Privacy Impact Assessment (PIA) covering both their internal operations and activities performed on their behalf by third-party PIPs. The PIA must assess (1) the nature, scope, and purpose of the intended data scraping, (2) the risks to the rights and freedoms of data subjects, and (3) the measures to be adopted to address or mitigate such risks.
Under Section 3(G) of the Advisory, scraping sensitive personal information is prohibited unless the PIC can demonstrate a lawful basis under Section 13 of the DPA, strict necessity and proportionality, and enhanced security measures. Scraping data relating to vulnerable data subjects is likewise subject to heightened regulatory scrutiny.
The Advisory also defines unauthorized scraping and establishes obligations for platforms hosting publicly available personal data. Scraping is unauthorized when conducted in violation of applicable laws, NPC issuances, or the terms of service or use of the targeted website or application. The guidelines prohibit bypassing technical barriers, such as CAPTCHAs, as well as using deceptive design patterns or misrepresentation to harvest personal data. Hosting PICs must protect users by informing them of scraping risks, indicating whether third-party scraping is permitted, and providing mechanisms to object. They must also implement active defenses, including monitoring bot activity, imposing rate limits, restricting access, and blocking suspicious behavior.
Ultimately, accountability remains a non-delegable responsibility under the guidelines. Section 6 provides that PICs remain accountable for ensuring that data scraping activities, including those conducted by third-party PIPs, comply with the DPA and NPC issuances. Section 7 further prohibits the use of scraped data in ways that cause harm, including identity fraud, doxxing, unauthorized surveillance, unauthorized profiling, and the collection of login credentials.
