How Can BPOs Secure Bulk SIM Registrations?
Introduction
Business process outsourcing (BPO) and telemarketing companies often require thousands of Philippine mobile numbers for customer support, appointment setting, collections, surveys, and outbound campaigns. Maintaining these numbers lawfully requires more than purchasing SIM cards in volume: each SIM must be properly registered, assigned to an identifiable end-user, and used in a manner consistent with telecommunications, data privacy, and anti-fraud requirements.
The governing rule is that every SIM must be registered with the public telecommunications entity (PTE) before activation. A BPO that acquires SIMs for official business use should therefore establish a documented registration, custody, assignment, monitoring, and deactivation process.
What Law Governs Bulk SIM Registration?
The principal statute is the [Subscriber Identity Module (SIM) Registration Act](#L1.3), which requires all end-users to register their SIMs with the relevant PTE as a condition for activation. SIMs sold by PTEs, agents, resellers, or other entities must remain deactivated until the end-user completes registration.
The registration requirement applies to existing as well as newly acquired SIMs. Failure to register an existing SIM within the prescribed period results in automatic deactivation, although reactivation may be obtained after proper registration.
The implementing rules likewise cover new and existing SIMs and require registration before activation. They also recognize that SIM registration involves the processing of personal data and require PTEs to provide mechanisms for data-subject rights and to process registration data only for lawful purposes under the Data Privacy Act.
Who Should Be the Registered End-User?
For a private BPO corporation, SIMs acquired for company operations should generally be registered under the name of the juridical entity, not under the names of individual agents who merely use the numbers in the course of employment. The company should present its registration documents and designate authorized representatives who will complete the registration process.
The registration process for a juridical entity requires the entity’s business or registration information and the full name of its authorized signatory. The company should also be prepared to provide the documents required by the PTE and the applicable implementing rules, including its certificate of registration and the corporate authority designating the representative.
The special rule under [NTC Memorandum Order No. 001-01-2023](#I1.0) applies to government entities. It clarifies that government offices may use a department or office order, or a similar document signed by the head of the government entity, instead of a board resolution or special power of attorney. That government-specific clarification does not replace the corporate authorization requirements applicable to a private BPO.
What Documents Should a BPO Prepare?
A private BPO should maintain a registration dossier containing, at minimum, the following:
- Certificate of registration or equivalent proof of juridical personality;
- Corporate authority identifying the officers or employees authorized to register SIMs;
- Valid identification documents of the authorized representatives and signatories;
- Company address and contact information consistent with corporate and PTE records; and
- Internal SIM inventory showing each mobile number, SIM serial number, assigned user, department, date of activation, and status.
The PTE may require additional information or documents under its registration procedures. Before a bulk submission, the BPO should obtain the PTE’s current documentary checklist and confirm whether registration will be completed through an enterprise channel, physical outlet, or approved electronic process.
How Should the Bulk Registration Process Work?
Bulk registration should be handled as a controlled corporate process rather than as a series of individual employee registrations. The company should first identify the numbers required, verify that the SIMs are issued to or lawfully acquired by the company, and prepare a complete inventory matched to the company’s registration records.
- Appoint authorized representatives. The board or appropriate corporate officer should issue a written authority identifying the persons permitted to transact with the PTE.
- Prepare the SIM inventory. Record the mobile number, SIM serial number, intended department, assigned employee or workstation, and activation status.
- Submit the corporate documents. Provide the PTE with the company’s registration documents and the authority of the designated representatives.
- Complete registration before activation. SIMs should not be distributed for operational use until the registration process has been completed and activation confirmed.
- Reconcile the PTE records. Compare the PTE’s confirmation or enterprise account records against the company’s internal inventory.
- Control reassignment and retirement. When an employee leaves, a campaign ends, or a number is no longer needed, the BPO should immediately retrieve, suspend, reassign, or deactivate the SIM in accordance with the PTE’s procedures.
Because registration requires the mobile number and SIM serial number to be recorded, inventory accuracy is important. A mismatch between the physical SIM, its serial number, and the company’s records can delay activation or create difficulties in proving authorized custody.
Can SIMs Be Registered Under Individual Agents?
Registration under individual agents may be appropriate where the SIM is genuinely owned and used by the individual rather than acquired and controlled by the BPO. However, if the company purchases the SIMs, pays for the service, assigns the numbers for official campaigns, and controls their operational use, registering the SIMs under employees merely to avoid corporate documentation creates compliance and accountability risks.
The company should avoid using employees as nominal registrants for company-owned numbers. The registration record should reflect the actual end-user or controlling entity, while the company’s internal records should identify the particular employee, team, device, or campaign using each SIM.
What Data Privacy Duties Apply?
SIM registration records contain identifying information and must be handled under the [Data Privacy Act of 2012](#L1.3) and the privacy obligations incorporated into the SIM registration rules. PTEs must protect registration data, use it for legitimate purposes, and provide mechanisms for the exercise of data-subject rights.
The [SIM Registration Act](#L1.11) treats registration information as confidential. Disclosure of the subscriber’s full name and address is generally restricted, subject to legally recognized exceptions such as compliance with a law, a court order or legal process upon a finding of probable cause, a statutory investigative process, or the subscriber’s written consent. A waiver of confidentiality cannot be imposed as a condition for approving a subscription agreement.
A BPO should therefore limit access to registration records to personnel with a legitimate business need. Its privacy program should include access controls, retention rules, incident-response procedures, and written instructions prohibiting employees from copying, selling, or disclosing registration information without authority.
What Security Controls Should Be Implemented?
The BPO should maintain technical and organizational safeguards over both the SIMs and the related records. Appropriate controls include:
- assigning each SIM to a responsible employee, workstation, or operational unit;
- maintaining a central register of active, suspended, lost, replaced, and retired SIMs;
- restricting access to SIMs and registration records through role-based permissions;
- requiring prompt reporting of lost devices, unauthorized use, or suspected compromise;
- reviewing unusual call volumes, repeated complaints, and activity inconsistent with the assigned campaign; and
- securely storing corporate authorizations, identity documents, and PTE confirmations.
The PTE’s responsibility to secure registration information does not eliminate the BPO’s own duties as the company that controls the devices, assigns the numbers, and directs the outbound activity. Contractual arrangements with the PTE should also be reviewed for security, confidentiality, suspension, replacement, and audit provisions.
What Restrictions Apply to Telemarketing Use?
SIM registration authorizes the connection of the SIM to an identified end-user; it does not authorize unlawful, deceptive, abusive, or fraudulent calls. A BPO must separately ensure that its campaigns comply with applicable consumer-protection, privacy, telecommunications, and sector-specific rules.
Campaign managers should maintain approved scripts, calling-hour policies, complaint-handling procedures, suppression lists, and escalation channels. Numbers should not be rotated merely to evade complaints, blocking measures, or regulatory monitoring. Any use involving personal data should have a lawful purpose and should be supported by appropriate notices, consent where required, or another lawful basis under the Data Privacy Act.
In [Smart Communications, Inc. v. National Telecommunications Commission, General Register No. 151908, 2003](#J1.1), the Supreme Court recognized the NTC’s authority to impose rules concerning subscriber identification and the use of prepaid SIM cards. Although the decision concerns an earlier regulatory setting, it illustrates that PTEs and the NTC may impose enforceable telecommunications requirements affecting subscriber identification and network use.
What Happens When a SIM Is Lost or an Employee Leaves?
The BPO should have a written offboarding and loss-reporting procedure. Once a SIM is lost, compromised, or no longer required, the company should promptly notify the PTE, request blocking or replacement when appropriate, update its inventory, and revoke the former user’s access to related systems.
An employee’s departure should automatically trigger a review of all mobile numbers, devices, authentication credentials, applications, and customer accounts assigned to that employee. Reassignment should occur only after the company records the new custodian and confirms the PTE’s applicable procedure.
Can a BPO Use Foreign or Visitor Registration Rules?
Foreign-national registration rules are intended for foreign end-users, including tourists and persons holding other types of Philippine visas. They should not be used as a substitute for registering SIMs acquired and controlled by a Philippine BPO as a juridical entity.
Where a foreign employee personally uses a company-provided SIM, the company should confirm with the PTE whether the SIM is to be registered under the corporation or under the individual based on ownership and end-user classification. The company should not assume that a foreign employee’s visa documents resolve the separate question of who actually controls the corporate account.
Recommended Compliance Checklist
| Area | Recommended measure |
|---|---|
| Corporate authority | Issue a board resolution, secretary’s certificate, or equivalent corporate authorization for designated registrants. |
| Inventory | Record every mobile number, SIM serial number, device, custodian, department, campaign, and status. |
| Registration | Register company-controlled SIMs under the proper juridical entity and complete registration before activation. |
| Privacy | Restrict registration data to authorized personnel and document lawful processing, retention, and disclosure practices. |
| Operations | Use approved scripts, complaint controls, calling-hour rules, and campaign-specific monitoring. |
| Offboarding | Block, retrieve, replace, or deactivate SIMs that are lost, compromised, unused, or assigned to departing personnel. |
Final Observations
A large BPO can lawfully maintain thousands of local mobile numbers, but the arrangement should be built around accurate corporate registration and continuous operational control. The company should not treat SIM registration as a one-time procurement formality.
The safest approach is to register company-controlled SIMs under the proper juridical entity, authorize designated representatives, maintain a reconciled inventory, protect registration data, and monitor actual use. Before deployment, the BPO should also obtain the PTE’s current enterprise-registration requirements because implementation procedures may vary among providers.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

