NPC Issues Guidelines on Data Scraping of Publicly Available Personal Data

On 13 April 2026, the National Privacy Commission (NPC) issued NPC Advisory No. 2026-01 entitled Guidelines on Data Scraping of Publicly Available Personal Data. The guidelines apply to Personal Information Controllers (PICs) and Personal Information Processors (PIPs) that engage in data scraping practices and technologies and PICs that host publicly available personal data which may be subject to data scraping.

 

The Guidelines define data scraping as the automated or manual process of extracting publicly available personal data, including text, images, audio and video recordings, and user profiles, from websites, applications, or other online sources. This includes using scraping tools or technologies to access websites through HTTP requests, parsing HTML content of webpages, identifying and extracting specific data elements, e.g., text, images, structuring the data to remove irrelevant information, and storing it in a structured format (e.g., databases or JSON files) for further analysis or use.

 

The NPC then added that conduct of lawful data scraping by PICs is allowed under these guidelines, including those performed for and on its behalf by third parties, provided that they fulfill their obligations under the Data Privacy Act (DPA) including:

 

A. PICs shall clearly define the specific and legitimate purpose for scraping publicly available personal data. Such purpose shall not be contrary to law, morals, public order, or public policy. Processing shall be limited to such specified and declared purpose (e.g., data matching, data enhancing, profiling, identity resolution) and shall not be used for purposes that are unrelated or not reasonably expected by data subjects.

B. PICs shall determine the most appropriate lawful basis for processing personal data obtained through data scraping, including any further disclosures of such data to third parties, under Section 12 or 13 of the DPA. The public availability of personal data does not constitute consent by the data subject to its processing for purposes beyond those reasonably contemplated at the time it was provided, nor does it relieve a PIC of its obligations under the DPA.

C. PICs shall inform data subjects, through an appropriate privacy notice or consent form (where processing is consent-based), before the processing takes place, or at the next practical opportunity that their personal data are processed using data scraping practices and technologies in addition to the requirements of Section 3 of NPC Circular No. 2023-04.

D. PICs shall ensure that scraped personal data are adequate, relevant, suitable, and necessary in relation to its purpose, and shall refrain from excessive or indiscriminate data scraping. PICs shall also assess whether data scraping is reasonable under the circumstances and whether its declared purpose/s could not be reasonably fulfilled by other less intrusive means.

E. In the design, development, or deployment of data scraping technologies, PICs shall take into consideration the reasonable privacy expectations of data subjects. They shall adopt appropriate technical, organizational, and physical security measures to protect data subjects and uphold data privacy rights, including, where applicable, the use of privacy-enhancing technologies.

F. PICs engaged in data scraping shall conduct a Privacy Impact Assessment (PIA) covering such activities, including those performed for and on its behalf by third parties. The PIA shall be performed in accordance with NPC issuances and shall assess, at a minimum: (1) the nature, scope, and purpose of the intended data scraping; (2) the risks to the rights and freedoms of data subjects, including the risks from the aggregation of scraped data with other datasets; and (3) the measures to be adopted to address or mitigate such risks. The PIA shall be reviewed and updated periodically, or whenever there is a material change in the scope, purpose, or nature of the data scraping activity.

G. Data scraping involving sensitive personal information is prohibited, unless the PIC can demonstrate: (a) a valid lawful basis under Section 13 of the DPA; (b) that the collection is strictly necessary and proportional to a legitimate purpose; and (c) that enhanced technical, organizational, and physical security measures are in place.

H. Data scraping involving personal data of vulnerable data subjects, including, but not limited to, minors, the elderly, and persons with disabilities, is subject to heightened scrutiny. In such cases, PICs must demonstrate that the processing does not exploit the capacity of data subjects.

 

Furthermore, unauthorized data scraping is said to occur when it is conducted in violation of applicable laws, the Data Privacy Act and its IRR, NPC issuances or the terms of service or terms of use of websites or applications.

 

The NPC also provided guidelines to be considered by PICs whose websites, applications, or other online platforms host publicly available personal data.

 

Finally, the guidelines laid out the following considerations to for PICs in the use of scraped personal data:

 

A. PICs that obtain personal data sourced from other PICs independently engaged in the conduct of data scraping activities shall establish policies and procedures, including the use of contractual or other reasonable means, for verifying and ensuring that personal data under this arrangement was obtained in compliance with the requirements of the DPA, its IRR, and the various issuances of the NPC, including this Advisory. To this effect, any further processing of personal data obtained through data scraping activities under Section 4 of the Advisory shall likewise be considered unauthorized.

B. PICs shall disclose, in their privacy notices, when personal data are obtained from publicly available sources, including the source of the data, the purpose of the collection, and the manner of processing.

C. In the use, analysis, or interpretation of scraped personal data, the PICs shall implement mechanisms to identify, monitor, and limit possible sources of bias, unfairness, or discriminatory treatment against data subjects.

D. PICs shall not use scraped personal data in a manner that would cause harm to the data subject, including, but not limited to:
1. Identity fraud or targeted cyberattacks;
2. Doxxing or the malicious public disclosure of personal data intended to harass or intimidate;
3. Unauthorized sale or disclosure of personal data for malicious purposes;
4. Unauthorized surveillance or intelligence gathering;
5. Large-scale scraping of social media sites for unauthorized profiling; and
6. The collection of login credentials or unauthorized access to users’ accounts.

E. PICs shall not use scraped data for purposes beyond those originally declared unless:
1. An appropriate lawful basis under Sections 12 and 13 of the DPA exists;
2. Sufficient notice is given to affected data subjects;
3. A new PIA is conducted; and
4. Compliance with any other requirements under the Advisory.

 

The full issuance may be accessed here.

Post a Comment