BSP online lending crackdown plans could bring stricter action against threatening messages, repeated calls to relatives, public shaming, and other abusive collection practices linked to online lending applications in the Philippines.
While these tactics are already prohibited, enforcement remains divided among several regulators. The agency handling a complaint may depend on whether the loan came from a bank, a registered lending company, a third-party collection agency, or an unregistered mobile application.

That setup could change as regulators consider the proposed transfer of online lending supervision from the Securities and Exchange Commission to the Bangko Sentral ng Pilipinas.
The shift could give the BSP a wider role in policing abusive collection practices and place more digital lenders under the same consumer-protection framework already applied to banks and other supervised financial institutions.
Debt collection has legal limits
Lenders may pursue repayment of valid and unpaid obligations. However, they cannot threaten borrowers, insult them, misrepresent themselves, or use public humiliation as a collection strategy.
Existing SEC rules on unfair debt collection prohibit lending and financing companies from using abusive language, threats of violence, false representations, and the unauthorized disclosure of a borrower’s personal information.
Collectors are also restricted from contacting borrowers at unreasonable hours, except in limited circumstances allowed by regulation.
These protections do not cancel a legitimate debt. They regulate how lenders and their representatives may seek repayment.
Collectors cannot freely involve relatives and friends
Some borrowers report receiving warnings that their relatives, employers, or social media contacts will be informed about their unpaid loans.
The use of a borrower’s phonebook as a collection tool has raised serious privacy concerns. Government guidance states that lenders should not contact people in a borrower’s contact list unless they were formally identified as guarantors or co-makers.
The National Privacy Commission has also warned online lenders against collecting unnecessary phone data or using personal information to harass and publicly shame borrowers.
This means access to a phone’s contacts, photographs, messages, or location should not automatically give a lender permission to use that information during collection.
Third-party agencies do not erase accountability
Many lenders outsource overdue accounts to external collection companies. Borrowers may therefore receive calls from an agency whose name does not appear in the original loan agreement.
Outsourcing does not necessarily remove the lender’s responsibility. Financial institutions are expected to monitor the conduct of authorized agents and service providers acting on their behalf.
Borrowers facing abusive collection should document both the name of the collection agency and the original lender. Screenshots, call logs, payment records, loan agreements, and copies of threatening messages may help regulators identify the responsible parties.
App permissions add another layer of risk
A 2026 study on digital lending applications examined hundreds of Android loan apps across several emerging markets, including the Philippines.
Researchers found that some applications transmitted contacts, messages, location details, or media files before users completed registration. Such information could later be used to pressure borrowers or involve people who were never part of the loan.
The findings show that consumer risk may begin even before a loan is approved.
Stronger BSP oversight could lead to more consistent rules and complaint procedures for online lenders. Effective protection, however, will still depend on privacy enforcement, traceable collection agents, app-store cooperation, and penalties strong enough to discourage repeat violations.
