Google removes 4 online lending apps due to serious privacy risks

Robie de Guzman   •   September 1, 2021   •   573

Google Play Store has removed four online lending apps (OLA), namely, JuanHand, Pesopop, CashJeep, and Lemon Loan, due to the serious privacy risks they pose to individuals who download the apps, the National Privacy Commission (NPC) said Wednesday.

In a statement, the NPC welcomed Google’s action and urged other online lending apps to use lawful and reasonable methods when processing data of loan applicants.

“For other OLAs, the NPC strongly urges you to employ know-your-customer (KYC) and debt collection practices that are aligned with NPC Circular No. 20-01, where we laid out guidelines on the processing of personal data for loan-related transactions,” NPC Commissioner Raymund Liboro said.

This development comes after the NPC said it coordinated with Google LLC and the National Telecommunications Commission to take down the said apps.

The NPC earlier directed the said apps to stop the processing of their borrowers’ personal data following complaints from some of its users.

“JuanHand, Lemon Loan, CashJeep, and Pesopop’s processing of their borrowers’ information such as contacts, location, photos, media files, email, and social media data, pose serious privacy concerns that expose borrowers to privacy risks and harms,” the agency said.

Nat’l Privacy Commission probing alleged COMELEC data hacking

Robie de Guzman   •   January 12, 2022

MANILA, Philippines – The National Privacy Commission (NPC) on Wednesday said it is looking into the alleged hacking of Commission on Elections (COMELEC) data as reported by a local media publication.

In a statement, the NPC said it has issued separate orders to the COMELEC, Manila Bulletin and Mr. Art Samaniego to appear for a clarificatory meeting via teleconference on January 25 on the alleged hacking and data breach incident involving the COMELEC servers.

The NPC issued the statement two days after the Manila Bulletin published a report claiming a breach on COMELEC servers.

The commission said it received information about the report on January 8 from Samaniego, Technology Editor & IT Head of the Manila Bulletin, regarding a suspected breach on COMELEC servers wherein an estimated 60 gigabytes of data, which possibly contain personal information and sensitive personal information, were allegedly accessed and downloaded by a certain group of hackers.

The NPC said its Complaints and Investigation Division commenced an independent investigation and issued a notice to COMELEC requiring them to explain the alleged hacking and data breach.

“The COMELEC must address the serious allegations made in the Manila Bulletin news report and determine whether personal data were indeed compromised, particularly personal information, sensitive personal information, or data affecting the same, which were processed in connection with the upcoming 2022 national and local elections,” NPC Commissioner John Henry Naga said.

“COMELEC is also directed to conduct a comprehensive investigation on the matter and submit to the NPC the results thereof no later than January 21, 2022,” he added.

The poll body earlier said it is still validating the alleged hacking of poll data.

“Rest assured that the NPC does not tolerate any act in violation of the Data Privacy Act including negligence in implementing organizational, physical, and technical security measures on personal data processing systems, whether in government or private institutions,” Naga said.

Duterte appoints Naga as Privacy Commission chief

Robie de Guzman   •   December 17, 2021

MANILA, Philippines – President Rodrigo Duterte has designated a new chief for the National Privacy Commission (NPC), Malacañang announced Friday.

Acting Presidential Spokesperson and Cabinet Secretary Karlo Nograles said Duterte has named John Henry Du Naga as NPC Commissioner for a term of three years.

The president signed Naga’s appointment paper on December 14, he added.

“We wish Mr. Naga success as we are confident that his years of professional experience in the Department of Information and Communications Technology and the NPC will contribute to our goal of a competitive, knowledge-based and innovative nation where the flow of information remains free while upholding people’s right to privacy and data protection,” Nograles said.

Prior to his appointment, Naga served as deputy commission of NPC.

He will replace Privacy Commissioner Raymund Liboro, whose term expired in March 2019 but remained in his office in a holdover capacity.

He also served as Department of Information and Communications Technology (DICT) assistant secretary in 2016 then became the chief of staff of then DICT Acting Secretary Eliseo Rio in June 2018.

Before joining the government service, Naga served as a Provincial Board Member for two terms in the Province of Masbate, and a telecommunications lawyer.

Cyberattack on S&R compromised 22,000 data subjects – NPC

Robie de Guzman   •   November 25, 2021

MANILA, Philippines – The National Privacy Commission (NPC) reported that some 22,000 data subjects were affected in the ransomware attack on S&R Membership Shopping.

In a statement, the NPC said it has received an initial breach notification report on November 15, 2021, 4:47 PM, from S&R Membership Shopping in relation to a cyber-attack that may have compromised its members’ contact information.

The NPC said the firm discovered the cyberattack incident on November 14, 2021.

“The company has then submitted an supplemental breach report today, November 24, 2021, confirming that the subject of the ransomware attack was the S&R membership system affecting twenty-two thousand (22,000) data subjects,” the commission said.

Citing the company’s report, the NPC said the attack compromised S&R’s personal data such as date of birth, contact number, and gender.

“Based on the S&R’s disclosure and confirmation from their data protection officer (DPO), credit cards and other financial information were not among the compromised personal data,” the agency said.

“They informed the Commission that they instituted measures to secure their system, recover compromised data, prevent further disclosure, and recurrence of similar attacks,” it added.

The company earlier said that its team has implemented cybersecurity protocols that enabled them to resume system operations. It also assured that the data affected in the attack were only confined to contact information and its members’ financial data are safe as these are protected by encryption measures as required by regulation.

The NPC reminded the S&R of its obligation to fully disclose and individually notify the affected data subject.

The commission likewise directed them to provide the technical report of the incident from the third-party cyber security firm.


The Philippine Broadcast Hub

UNTV, 915 Barangay Philam,

EDSA, Quezon City M.M. 1104

(+632) 8396-8688 (Tel) (General inquiries)


UNTV is a major TV broadcast network with 24-hour programming. An Ultra High Frequency station with strong brand content that appeal to everyone, UNTV is one of the most trusted and successful Philippine networks that guarantees wholesome and quality viewing experience.