How Should Businesses Draft Social Media Community Guidelines?

How Should Businesses Draft Social Media Community Guidelines?

Introduction

Branded corporate social media pages are public-facing communication channels, but they are not required to function as unmoderated forums. Businesses may establish rules governing comments and remove content that is abusive, threatening, discriminatory, defamatory, fraudulent, or unrelated to the page’s purpose.

Deletion, however, should not appear arbitrary or retaliatory. A clearly written community-guidelines policy helps show that moderation is based on previously announced standards, applied consistently, and limited to what is reasonably necessary to protect users, the business, and the integrity of the page.

The policy should also account for privacy obligations. Comment moderation may involve the collection, review, retention, hiding, deletion, or disclosure of personal information, all of which may constitute processing under the Data Privacy Act.

What Should Community Guidelines Accomplish?

A corporate social media policy should perform four functions:

  • Give users advance notice of the conduct and content that are not permitted;
  • Define the available moderation actions, such as hiding, deleting, restricting, blocking, or reporting;
  • Provide a consistent basis for enforcement across users, topics, and platforms; and
  • Protect lawful criticism from being removed merely because it is unfavorable to the business.

A policy is strongest when it distinguishes between abusive conduct and legitimate disagreement. A negative review, complaint about service, or criticism of a company ordinarily should not be removed solely because it damages the business’s image.

Legal Foundations for Comment Moderation

Responsible online conduct and respectful language

The Code of Professional Responsibility and Accountability requires lawyers to ensure that online posts uphold the dignity of the legal profession, shield it from disrepute, and maintain respect for the law (Administrative Matter No. 22-9-1-SC, Code of Professional Responsibility and Accountability, Section 37).

Although these provisions directly regulate lawyers, they illustrate an important drafting principle for corporate pages: online rules should identify prohibited conduct in clear and objective terms rather than relying on vague standards such as “negative comments” or “posts unfavorable to the company.”

The Supreme Court has held that lawyers must use dignified and proper language in personal and professional dealings, including electronic and social media communications. In Baltao v. Falcis III (Administrative Case No. 14443, 2025), the Court treated abusive and profane online language as conduct inconsistent with the standards imposed on members of the legal profession.

Privacy and the processing of personal information

Comment moderation may involve personal information, including names, profile identifiers, photographs, contact details, account information, or information appearing in a user’s complaint. The National Privacy Commission has recognized that posting photographs containing personal data on social media may constitute processing under the Data Privacy Act (NPC 19-1438, 2025).

Accordingly, a business should avoid collecting or publicly reposting more personal information than necessary to address the comment. Moderators should also be instructed not to publish private messages, identification documents, phone numbers, addresses, or other sensitive information merely to defend the company publicly.

Lawful processing does not remove the duty to comply with the principles of transparency, legitimate purpose, and proportionality under R.A. No. 10173. The National Privacy Commission has emphasized that processing may have a lawful basis yet still fail the proportionality requirement, potentially resulting in civil consequences (NPC 19-1438, 2025).

Legitimate interest and moderation purposes

A business may have a legitimate interest in protecting its page from harassment, fraud, threats, impersonation, malicious disclosure of personal information, and conduct that prevents other users from accessing the page safely. The National Privacy Commission has recognized that the legitimate-interest basis may apply even to an unregistered association, provided that the processing satisfies the applicable legal requirements and privacy principles (NPC 22-180 and 22-181, 2022).

This does not mean that every deletion is automatically lawful. The business should identify the moderation purpose, assess whether the action is necessary, and avoid using comment moderation as a disguised method of suppressing lawful criticism.

What Prohibited Conduct Should the Policy Cover?

Community guidelines should use specific categories supported by examples. The following categories are generally suitable for a branded corporate page:

  • Threats and intimidation: threats of physical harm, property damage, or unlawful retaliation;
  • Harassment and personal attacks: repeated targeting, abusive insults, stalking, bullying, or intimidation of employees, customers, or other users;
  • Discriminatory or hateful content: attacks based on race, ethnicity, nationality, religion, sex, gender, disability, age, or other protected characteristics;
  • Fraud and impersonation: fake accounts, deceptive promotions, phishing links, fraudulent claims of affiliation, or attempts to obtain passwords or payment information;
  • Unlawful disclosure of personal information: publishing private addresses, telephone numbers, identification documents, medical information, or other sensitive data without authority;
  • Sexual exploitation or child-abuse material: content that must be reported and handled under applicable criminal laws, including R.A. No. 11930 and its implementing rules;
  • Spam and malicious technical content: repetitive commercial posts, malware, harmful links, automated flooding, or coordinated disruption; and
  • Off-topic commercial solicitation: promotional content that materially interferes with the page’s stated purpose.

Each category should contain a short explanation and, where appropriate, examples. The policy should not prohibit “negative,” “controversial,” or “embarrassing” comments without further definition because those terms may capture legitimate consumer complaints and public-interest discussion.

How Should the Policy Address Defamation?

A business may prohibit knowingly false statements presented as facts, fabricated allegations, and coordinated campaigns intended to cause unlawful harm. It should nevertheless distinguish factual disputes, honest opinions, poor reviews, and complaints from deliberately false factual assertions.

Online statements may raise issues under the Revised Penal Code and the Cybercrime Prevention Act. In Tan v. People of the Philippines (G.R. No. 265929, 2026), the Supreme Court stated that in criminal libel proceedings involving public officials, the prosecution must prove actual malice beyond reasonable doubt, consisting of knowledge of falsity or reckless disregard for truth or falsity. The decision concerns criminal liability and should not be converted into a blanket corporate power to delete all criticism.

Where a comment may be defamatory, the business should preserve the original post, record the relevant account information, and obtain legal advice before making public accusations against the user. Moderation may be appropriate, but public exposure of the user’s identity may create separate privacy concerns.

What Moderation Actions Should Be Listed?

The guidelines should explain that the business may take proportionate action depending on the seriousness, frequency, and context of the violation. Possible actions include:

  • removing or hiding the comment;
  • limiting the user’s ability to comment;
  • blocking or restricting the account;
  • reporting suspected criminal or platform violations;
  • preserving relevant records for an investigation; and
  • referring complaints to a private customer-service channel.

The policy should state that the business may act immediately when content involves threats, child sexual abuse or exploitation, fraud, malware, doxxing, or an imminent risk of harm. For less serious violations, a warning or request to edit the content may be more proportionate than immediate blocking.

Where the page uses automated moderation tools, the business should provide a reasonable escalation process for mistaken removals. Automated systems may misclassify sarcasm, complaints, quotations, or discussions of sensitive subjects.

Recommended Policy Language

The following model may be adapted for a corporate page:

Community Guidelines. “We welcome questions, feedback, complaints, and respectful disagreement. To protect users and maintain a useful discussion space, we may hide or remove content that contains threats, harassment, discriminatory attacks, unlawful disclosure of personal information, impersonation, fraud, malicious links, spam, sexually exploitative material, or knowingly false factual claims presented to cause unlawful harm.”

“We do not remove comments merely because they criticize our products, services, personnel, or business decisions. We may limit or remove content when necessary to enforce these guidelines, protect personal information, comply with law, respond to credible threats, or preserve the security and integrity of this page.”

“Depending on the circumstances, we may issue a warning, hide or delete content, restrict commenting, block an account, preserve records, report content to the platform or appropriate authorities, or refer the matter to our customer-support channel. We may update these guidelines prospectively and will apply them consistently, subject to the context of each post.”

Privacy Provisions to Include

The policy should contain a short privacy notice explaining that comments and account information may be reviewed for moderation, security, customer-service, compliance, and dispute-resolution purposes. It should identify the general purpose of the processing and direct users to the company’s privacy notice.

Moderators should follow these safeguards:

  • collect only information reasonably necessary for moderation or investigation;
  • avoid copying personal information into public responses;
  • move account-specific complaints to a private channel;
  • limit internal access to moderation records;
  • retain records only for as long as reasonably necessary; and
  • delete or securely dispose of information when the retention purpose ends, subject to legal holds or applicable obligations.

If a user posts private information about another person, the business should promptly hide or remove the material, limit further disclosure, preserve only what is necessary for investigation, and consider whether notification to the affected person or referral to the proper authority is required.

How Should Businesses Apply the Rules Consistently?

Companies should maintain an internal moderation matrix. It should identify the type of conduct, the usual response, the person authorized to decide, and the circumstances requiring escalation.

Content or conductUsual responseEscalation
Respectful negative reviewKeep visible and respond professionallyCustomer-service referral if needed
Profanity directed at another userWarning, hide, or remove depending on severityRestrict repeat offenders
Threat of physical harmPreserve, hide, and restrict accessSecurity team and appropriate authorities
Publication of a private address or identification documentRemove or hide immediatelyPrivacy officer and affected person
Suspected child sexual abuse materialDo not download, copy, or redistributePlatform and competent authorities under applicable law

Moderators should record the date, account, content category, action taken, reason, and approving officer. The record should not reproduce sensitive information unnecessarily. A short, factual log is usually preferable to an extensive internal circulation of the offending material.

Common Drafting Errors

First, prohibiting criticism. A rule stating that “negative comments will be deleted” is overbroad and may undermine the company’s credibility. The policy should target conduct and content that cause a defined risk, not viewpoint alone.

Second, using undefined language. Terms such as “offensive,” “inappropriate,” or “harmful” should be accompanied by examples and applied in context. The more serious the moderation action, the greater the need for a specific basis.

Third, threatening users with public exposure. Publishing a user’s identity, workplace, contact details, or other personal information may create privacy and reputational risks. A business should use proper reporting and legal channels instead.

Fourth, deleting evidence before review. Immediate removal may be necessary for harmful content, but the company should first preserve the minimum information needed for an internal investigation or lawful referral, without redistributing the material.

Fifth, failing to train moderators. A well-written policy will not protect the company if moderators apply it inconsistently, engage in arguments, disclose confidential information, or remove complaints for personal reasons.

Recommended Compliance Process

Before publishing the guidelines, the business should identify the page’s purpose, define prohibited categories, coordinate the rules with its privacy notice, and designate responsible moderators.

After publication, the company should train moderators, use a consistent decision log, review difficult cases, and periodically assess whether the rules are being applied fairly. Significant changes should be announced prospectively rather than used to justify action against earlier conduct without notice.

For content involving threats, fraud, child exploitation, serious privacy violations, or possible criminal libel, the company should consult counsel and preserve relevant information in a lawful and secure manner. It should not conduct its own public trial through the comment section.

Conclusion

Community guidelines can provide a sound basis for removing abusive comments from a branded corporate page, but they should not be drafted as a license to suppress criticism. The most defensible policy is transparent, specific, proportionate, privacy-conscious, and applied consistently.

Businesses should identify prohibited conduct with concrete examples, preserve lawful complaints and disagreement, document moderation decisions, train personnel, and establish an escalation channel for serious incidents. These measures help demonstrate that comment deletion serves a legitimate moderation purpose rather than retaliation against unfavorable speech.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH