FB777 and the Data Privacy Act Philippines: What It Requires
RA 10173, the Data Privacy Act of 2012, requires any Philippine-facing site collecting a name, ID number or bank detail to state what it collects and why, secure it, and let you complain to the National Privacy Commission if it does not.
- FB777 and the CICC Hotline
- The CICC hotline is 1326, staffed 24/7, and a cicc report scam call should lead with the domain name, the date, what went wrong, and any screenshots or transaction references you already have — the same evidence a WHOIS lookup and an SSL check would have surfaced beforehand.
- FB777 on RA 9487
- RA 9487, approved on 20 June 2007, amended Section 10 of PD 1869 and gave PAGCOR another 25-year franchise term from the 2008 expiry of its original one, without changing PAGCOR's underlying power to license and regulate games of chance.
- FB777 SSL Certificate Check
- An SSL certificate check opens the padlock icon next to the address bar, reads which certificate authority issued it and which exact domain it covers, and confirms that domain matches what you're actually looking at — proof the connection is encrypted, not proof the operator is licensed.
- FB777 WHOIS Lookup
- A WHOIS lookup takes the bare domain, runs it through a free WHOIS tool, and returns the registration date, registrar and, where not hidden, the registrant — enough to tell a fresh copycat domain from one that has existed for years.
The Data Privacy Act Philippines law, RA 10173, was approved in 2012 and applies to any site that collects a name, an ID number or a bank detail from someone in the country — a casino site included, whatever else it may or may not have verified with PAGCOR. It runs on a separate track from the licensing question covered on the PD 1869 page: a site can fail one of these checks and pass the other, so neither substitutes for the other.
Four Things RA 10173 Requires of Any Site Holding Your Data
| # | Requirement | What it looks like in practice |
|---|---|---|
| 1 | State what personal data it collects | A privacy notice naming the fields — ID, bank details, contact number |
| 2 | State why it collects each item | A stated purpose, not a blanket “for verification” |
| 3 | Secure the data it holds | Reasonable technical and organisational safeguards |
| 4 | Allow a complaint to the National Privacy Commission | A named contact or process for a data-related complaint |
None of these four is optional, and a site that meets none of them is not automatically unlicensed by PAGCOR either — the two questions run independently, which is why the RA 9487 page and this one cover different laws rather than the same one twice. A site can read as fully transparent about your data and still hold no PAGCOR licence at all, and the reverse is just as possible.
Filing an NPC Complaint
The National Privacy Commission is the body RA 10173 created to receive complaints about misuse of personal data, separate from any regulator that handles gambling licences specifically.
- Gather the specific data involved — what was collected, and what happened to it.
- Note the date, the site or app involved, and any response you already received from it.
- Submit the complaint through the National Privacy Commission’s own published process, not through PAGCOR, which handles licensing complaints on a separate track entirely.
A complaint to the National Privacy Commission proceeds whether or not the same site turns out to hold a PAGCOR licence, and checking a site’s SSL setup first, on the SSL certificate check page, tells you whether the connection carrying your data was even encrypted in the first place. Keeping a copy of whatever privacy notice the site showed you, even a screenshot taken before you agreed to it, makes any later complaint far easier to support with specifics rather than memory alone.
FAQ
Does the Data Privacy Act apply to sites based outside the Philippines?
Yes — RA 10173 covers the processing of personal data of people in the Philippines, regardless of where the site or company collecting it is based. A casino site asking a Filipino player for ID still sits under the law.
What counts as personal data under RA 10173?
A name, address, ID number, date of birth, and bank or e-wallet account details all count, along with anything else that can identify a specific person. A site that asks for these has to say what it does with them.
How do I file an NPC complaint?
The National Privacy Commission accepts complaints against any entity that misuses personal data, and its own site sets out the form and evidence it wants. The four requirements below are what to check before deciding whether a complaint is worth filing.