Can Businesses Scrape Public Social Media Data?

Can Businesses Scrape Public Social Media Data?

Introduction

Businesses increasingly collect names, photographs, contact details, professional information, comments, and other data from publicly accessible social media profiles. They may use this information for advertising, fraud detection, customer verification, market research, recruitment, or identity matching.

Public availability, however, does not automatically make personal data free from privacy regulation. Under the Data Privacy Act of 2012, the collection, recording, organization, storage, retrieval, use, disclosure, and other handling of personal data generally constitutes processing. A business that scrapes information from public social media profiles may therefore be a personal information controller or processor and must comply with applicable privacy requirements.

The National Privacy Commission has consistently treated public accessibility as relevant but not conclusive. The legality of scraping depends on the purpose, lawful basis, transparency measures, proportionality, security safeguards, and manner by which the information is collected and used.

What Is Personal Data Scraping?

Data scraping is the automated or systematic extraction of information from websites, social media platforms, online directories, or other digital sources. Scraping may involve copying information from public profiles, compiling it into a database, enriching it with data from other sources, and using it to create profiles or make decisions about individuals.

The Implementing Rules and Regulations of the Data Privacy Act define processing broadly to include collection, recording, organization, storage, updating, retrieval, consultation, use, consolidation, blocking, erasure, and destruction of personal data. Accordingly, a business may be processing personal data even if it does not initially create or publish the information.

Public social media data may include names, photographs, usernames, employment information, location details, contact information, interests, opinions, online activities, and inferred characteristics. When these details relate to an identified or identifiable individual, they may fall within the protection of the Data Privacy Act.

Does Public Availability Mean Consent?

No. Public availability is not the same as consent. A person’s decision to make information visible to other users does not necessarily authorize every form of collection, republishing, profiling, sale, or disclosure by a business.

The National Privacy Commission’s guidance on publicly available personal data states that personal data protections continue to apply even when information is accessible online. The guidance also requires data scraping activities to comply with lawful processing, purpose limitation, transparency, proportionality, and other requirements of the Data Privacy Act.

This does not mean that every collection of public information is prohibited. It means that the business must identify a lawful basis and ensure that the processing is fair, necessary, reasonably expected, and limited to a legitimate purpose.

Governing Philippine Privacy Rules

The principal statute is R.A. No. 10173, or the Data Privacy Act of 2012. Its general principles require that personal data be processed according to transparency, legitimate purpose, and proportionality.

Transparency requires the data subject to receive reasonable information about the processing, including the nature and purpose of the collection, the types of data involved, the manner of use, retention, disclosure, and the rights available to the data subject.

Legitimate purpose requires that the processing be compatible with a declared and specified purpose that is not contrary to law, morals, or public policy.

Proportionality requires that the processing be adequate, relevant, suitable, necessary, and not excessive in relation to the declared purpose. Personal data should not be collected merely because it is technically accessible or potentially useful.

The IRR of R.A. No. 10173 applies to processing by natural and juridical persons in the government and private sector. It may also apply to acts performed outside the Philippines when, among other circumstances, the processing concerns a Philippine citizen or resident, occurs in the Philippines, or involves an entity with sufficient links to the Philippines.

Lawful Bases for Scraping Public Profiles

Consent is only one possible lawful basis. Under the Data Privacy Act, processing may also be allowed when it is necessary for compliance with a legal obligation, protection of vital interests, performance of a public function, fulfillment of a contract, or pursuit of a legitimate interest that is not overridden by the fundamental rights and freedoms of the data subject.

A business invoking legitimate interest should be able to identify a real and lawful interest, demonstrate that the processing is necessary for that interest, and assess whether the individual’s privacy rights override the business purpose. The mere commercial value of a database is not, by itself, sufficient justification.

The National Privacy Commission has recognized that legitimate interest may apply even where the processor is an unregistered association. That recognition does not eliminate the need to satisfy the requirements of necessity, proportionality, transparency, and protection of the data subject’s rights.

Why Purpose Matters

The same publicly available information may be lawful to use for one purpose but unlawful for another. For example, collecting a public professional biography to respond to a specific business inquiry is materially different from compiling thousands of profiles for undisclosed behavioral advertising or political profiling.

A business should therefore define its purpose before scraping. The purpose should be specific enough to explain why each category of data is needed and how it will be used.

Using scraped information for a new or materially different purpose may require a fresh lawful-basis assessment, additional notice, a privacy impact assessment, and other safeguards. The National Privacy Commission’s guidance on data scraping states that scraped data should not be used beyond originally declared purposes unless an appropriate lawful basis exists, sufficient notice is given, a new privacy impact assessment is conducted, and the other requirements of the guidance are satisfied.

When Is Social Media Scraping Likely to Be Unlawful?

Scraping is particularly risky when it involves one or more of the following circumstances:

  • No identified lawful basis: The business collects data simply because the profiles are public.
  • Undisclosed processing: Individuals are not informed that their information is being collected, combined, profiled, or sold.
  • Excessive collection: The business collects entire profiles or unrelated information when only limited data are necessary.
  • Hidden identity: The operator conceals its ownership, contact information, or privacy notice.
  • Inaccurate or harmful republishing: The platform allows users or third parties to add, alter, or republish information without verification.
  • Profiling and sensitive inferences: The data are used to infer health, political affiliation, religion, sexual orientation, financial condition, or other sensitive characteristics without sufficient justification.
  • Bypassing technical restrictions: The scraper circumvents access controls, rate limits, robots restrictions, authentication requirements, or other technical safeguards.
  • Malicious or abusive use: The information is used for doxing, harassment, surveillance, identity fraud, targeted cyberattacks, or unauthorized sale.

The National Privacy Commission’s 2026 guidance expressly treats scraping as unauthorized when it violates applicable law, the Data Privacy Act, its IRR, National Privacy Commission issuances, or the terms of service of the relevant website or application. Circumventing technical measures or using deceptive design, misrepresentation, or similar methods may also constitute unauthorized scraping.

National Privacy Commission Guidance on Publicly Available Data

In NPC Advisory No. 2026-01, the National Privacy Commission emphasized that the Data Privacy Act, its IRR, and privacy issuances apply to publicly available personal data. The guidance covers personal information controllers and processors that scrape data and controllers that host publicly available personal data subject to scraping.

The guidance is significant because it rejects the assumption that public visibility removes privacy obligations. A business must still examine the legal basis, purpose, notice, data minimization, retention period, security measures, data-subject rights, and possible consequences of the processing.

The guidance also identifies harmful examples such as identity fraud, targeted cyberattacks, doxing, malicious disclosure, unauthorized surveillance, intelligence gathering, large-scale social media profiling, and collection of login credentials or unauthorized access to accounts.

Lessons from the PH-Check.com Order

In NPC CDO 22-001, the National Privacy Commission ordered the cessation of processing, collection, and display of personal data obtained from the DTI Business Name Registration System. The matter involved publicly available government information, but public accessibility did not excuse noncompliance with privacy principles.

The Commission found significant concerns where the website lacked an adequate privacy notice, failed to clearly identify the purpose of processing, concealed the identity of its operators, and provided no effective means for data subjects to exercise their rights.

The Commission also considered the risk of false or unauthorized disclosures because users could edit information displayed on the website. The decision illustrates that republishing data from an official or public source may still violate the Data Privacy Act when the new use is not transparent, legitimate, proportionate, or adequately secured.

Public Social Media Profiles and Reasonable Privacy

In Vivares, et al. v. St. Theresa’s College, et al., G.R. No. 203335, 2014, the Supreme Court explained that informational privacy in social networking sites depends in part on the user’s expressed intention to restrict access through available privacy settings. Information made accessible to a broad audience may carry a weaker expectation of privacy than information restricted to a selected group.

That principle does not mean that businesses may freely harvest and repurpose every publicly visible post. The case concerns the constitutional assessment of privacy expectations; it does not abolish the statutory duties imposed by the Data Privacy Act on personal information controllers and processors.

The distinction is important. A person may have limited constitutional privacy expectations regarding a public post while still possessing statutory rights concerning the collection, use, retention, disclosure, correction, objection, or deletion of personal data.

Legitimate Interest Requires Necessity and Balancing

A business relying on legitimate interest should conduct a documented assessment addressing three questions:

  1. What specific lawful interest is being pursued?
  2. Is scraping necessary to accomplish that interest, or can the purpose reasonably be achieved through less intrusive means?
  3. Are the interests of the business outweighed by the privacy rights and freedoms of the individuals?

In the discussion of informational privacy in KAPIT, et al. v. City of Manila, et al., G.R. Nos. 261892, 262192, and 263752, 2026, the Court emphasized that the word “necessary” in the Data Privacy Act requires more than a general assertion of governmental or institutional purpose. The information sought must be acquired through narrowly tailored means that are necessary to accomplish the relevant mandate.

Although the case involved government processing, the same reasoning is instructive for private businesses: a broad business objective does not automatically justify collecting every available data point. The collection must be sufficiently connected to the stated purpose and limited to what is needed.

Special Concerns Involving Sensitive Personal Information

Sensitive personal information receives greater protection under the Data Privacy Act. This includes information relating to race or ethnic origin, marital status, age, color, religious, philosophical, or political affiliations, health, education, genetic or sexual life, proceedings for an offense, and government-issued identifying information.

Scraping public profiles may expose sensitive information directly or allow a business to infer it. A company should not assume that sensitivity disappears merely because the individual posted the information publicly.

Processing sensitive personal information generally requires a specific exception under the Data Privacy Act. A business should therefore avoid collecting sensitive data unless it can clearly establish the applicable legal basis, necessity, safeguards, and purpose.

Data Subject Rights

Individuals whose information is scraped may generally invoke rights recognized under the Data Privacy Act, subject to statutory qualifications. These include the right to be informed, the right to access, the right to object, the right to dispute inaccuracy, the right to request blocking or removal in appropriate cases, and the right to damages for unlawful or unauthorized processing.

A business should maintain a functioning channel for privacy inquiries and requests. A privacy notice should explain how individuals may contact the controller, request access or correction, object to processing, and raise complaints.

The continued online availability of information does not necessarily defeat a request concerning further dissemination. The discussion of informational privacy in KAPIT, et al. v. City of Manila, et al. recognized that a person may retain an interest in preventing further dissemination of information that was illegally disclosed and, in appropriate circumstances, in preventing continued storage or availability.

Scraping Versus Accessing an Account

Collecting information visible on a public page is different from obtaining login credentials, bypassing authentication, accessing private content, or taking over an account. The latter may involve separate criminal, civil, or administrative violations.

In Disini, Jr., et al. v. The Secretary of Justice, et al., G.R. No. 203335, 2014, the Supreme Court upheld the regulation of identity theft involving the acquisition, use, misuse, or deletion of another person’s identifying information for an illegitimate purpose. The Court also distinguished this from acquiring and disseminating information made public by the user, where the required unlawful intent is absent.

This distinction should not be read as a general authorization for commercial scraping. Even where conduct does not amount to identity theft, it may still violate the Data Privacy Act, contractual website restrictions, intellectual property rights, or other applicable laws.

Business Compliance Checklist

Before collecting personal information from public social media profiles, a business should:

  • Define the specific and legitimate purpose of the collection.
  • Identify and document the lawful basis for processing.
  • Determine whether the information includes sensitive personal information.
  • Collect only the minimum data reasonably necessary.
  • Review the platform’s terms of service and technical restrictions.
  • Do not bypass authentication, access controls, or anti-scraping measures.
  • Prepare a clear and accessible privacy notice.
  • Explain collection, use, disclosure, retention, profiling, and data-subject rights.
  • Conduct a privacy impact assessment for large-scale, systematic, or high-risk scraping.
  • Establish controls for accuracy, correction, deletion, retention, and security.
  • Restrict access within the organization and impose contractual safeguards on processors.
  • Maintain records showing why the processing is necessary and proportionate.

Possible Liability

Unauthorized processing may result in administrative orders, cease-and-desist directives, corrective measures, civil liability, and criminal penalties under the Data Privacy Act and related rules. The IRR of R.A. No. 10173 provides penalties for unauthorized processing of personal and sensitive personal information, including imprisonment and fines, subject to the statutory requirements and circumstances of the offense.

A business may also face liability for negligent access, inaccurate or harmful disclosures, failure to implement reasonable security measures, breach of contract with the platform, defamation, identity-related offenses, or other violations depending on the facts.

The use of third-party scraping vendors does not automatically eliminate the business’s responsibility. A personal information controller should conduct due diligence, define instructions, impose security and confidentiality duties, and monitor the processor’s compliance.

Typical Examples

Public professional information for a specific recruitment purpose. This may be defensible if the business collects only relevant information, provides appropriate notice, avoids sensitive inferences, and uses the data consistently with the stated purpose.

Mass harvesting for undisclosed advertising. This presents a high privacy risk because the collection is extensive, the purpose may not be reasonably expected, and the business may lack a clear lawful basis and notice mechanism.

Scraping public names and photographs to publish accusations. This may violate privacy principles and create liability for malicious disclosure, defamation, or other unlawful conduct, particularly where allegations are unverified.

Collecting public posts to infer political or health information. This is especially sensitive. The business should not proceed without a strong legal basis, strict necessity, appropriate safeguards, and a careful assessment of the impact on data subjects.

Conclusion

Businesses may sometimes collect information from public social media profiles, but public visibility is not a blanket exemption from Philippine privacy law. The decisive questions are whether the processing has a lawful basis, serves a specific legitimate purpose, is necessary and proportionate, is transparent to data subjects, respects platform restrictions, and is protected by appropriate organizational and technical safeguards.

Businesses should treat large-scale social media scraping as a privacy-governance activity rather than merely a technical exercise. Before deployment, they should complete a documented privacy impact assessment, consult their data protection officer or counsel, limit the information collected, provide meaningful notice, and establish procedures for objections, corrections, removal requests, retention, and security incidents.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH