Public contact details can look like an easy source of B2B leads. But “public” does not mean unrestricted. In April 2026, the Philippines’ National Privacy Commission issued specific guidance for organizations that scrape publicly available personal data. The practical message is clear: start with purpose, necessity, lawful basis, transparency, security, and accountability—not with a tool or a target count.
Quick answer
Data scraping for B2B leads in the Philippines may be allowed in some circumstances, but publicly available personal data remains protected by the Data Privacy Act. A business must define a specific legitimate purpose, identify an appropriate lawful basis, limit collection to necessary data, provide required notice, conduct a privacy impact assessment, apply safeguards, control vendors, and delete data when it is no longer needed. Circumventing technical protections or ignoring website terms may be unauthorized.
This article provides general operational information, not legal advice. Ask your data protection officer or qualified Philippine counsel to assess your facts before collection begins.
TLDR checklist before collecting anything
- Separate company information from personal data about an identifiable person.
- Write down the specific purpose and intended use.
- Determine the lawful basis; public visibility is not consent.
- Confirm that scraping is necessary and proportionate.
- Review the source website’s terms and technical restrictions.
- Conduct and document a privacy impact assessment.
- Provide an appropriate privacy notice at the required time.
- Collect only relevant fields and avoid sensitive data.
- Put security, retention, disposal, objection, and correction processes in place.
- Audit any vendor or lead-list provider; outsourcing does not remove accountability.
Start with the decision workflow: jump to the privacy-aware operational checklist, then take your completed notes to your DPO or counsel before any collection begins.
What the NPC advisory covers
NPC Advisory No. 2026-01 applies to organizations that scrape publicly available personal data and to organizations hosting such data. It defines scraping broadly enough to include automated or manual extraction from websites, applications, social platforms, and other online sources.
The advisory distinguishes public accessibility from unrestricted reuse. A name, personal email address, mobile number, profile, image, or other data about an identifiable person can remain personal data even when it appears on a public page. Company facts about a juridical entity may be different, but a business directory can contain both company and personal information. Classify each field instead of treating the entire source as one category.
| Decision point | Question to document | Warning sign |
|---|---|---|
| Purpose | What specific, legitimate outcome requires this data? | “We may use it later” |
| Lawful basis | Which DPA basis applies to collection and later use? | Assuming public means consent |
| Necessity | Can the goal be met with fewer fields or a less intrusive method? | Collecting every available field |
| Transparency | How and when will people be informed? | No privacy notice or source disclosure |
| Security | Who can access, export, enrich, and delete the data? | Shared files and uncontrolled copies |
| Retention | When will unused or outdated data be deleted? | Keeping lists indefinitely |
Decision takeaway: if purpose, lawful basis, necessity, notice, or disposal cannot be documented, pause collection. On smaller screens, swipe within the table to compare all columns.
A privacy-aware operational workflow
1. Define the exact lead-generation purpose
Avoid a broad objective such as “build a database.” State the intended market, offer, fields, contact method, decision owner, and success measure. Explain why each personal-data field is needed for that purpose.
2. Classify the information
Separate organization name, industry, and company website from a named employee’s email, phone number, profile, photo, or behavior. Flag sensitive personal information and data involving vulnerable people for heightened review. The NPC advisory sets stricter conditions for sensitive information and heightened scrutiny for vulnerable data subjects.
3. Establish the lawful basis
The advisory says public availability does not itself constitute consent for purposes beyond what was reasonably contemplated. Determine the appropriate basis under the Data Privacy Act for collection, disclosure, enrichment, profiling, outreach, and any later reuse. Do not assume one basis covers every stage.
4. Test necessity and proportionality
Ask whether a smaller list, fewer fields, official business contact channel, opt-in campaign, referral, partnership, or contextual advertising could achieve the same goal with less intrusion. The advisory says scraped data should be adequate, relevant, suitable, and necessary, and discourages excessive or indiscriminate collection.
5. Review terms and restrictions
Check the source site’s terms of service, robots exclusions, access restrictions, and other technical controls. The NPC describes circumvention or bypass of protective measures, deceptive patterns, and misrepresentation as unauthorized practices. This checklist does not provide evasion instructions.
6. Complete a privacy impact assessment
Document the nature, scope, source, purpose, affected people, aggregation risks, access, security, retention, rights handling, vendors, and mitigations. Review the PIA when the purpose, scale, dataset, tool, or process changes.
7. Build transparency and rights handling
The privacy notice should explain when personal data came from public sources, identify the source, state the collection purpose, and describe processing. Create a working route for access, correction, objection, and other applicable rights. Coordinate the notice timing with your DPO or counsel.
8. Control enrichment and outreach
Do not silently add unrelated datasets or repurpose a list for a new campaign. Verify accuracy before contact, avoid sensitive inferences, respect objections, suppress opted-out records, and keep outreach relevant to the documented purpose.
9. Secure, retain, and dispose
Limit access by role, log exports, protect transfers, prevent uncontrolled copies, and define deletion dates. The NPC says scraped personal data should be retained only as long as necessary for the declared purpose and securely disposed of afterward.
Buying a scraped lead list does not transfer responsibility
A vendor should be able to explain sources, fields, purpose, lawful basis, notices, safeguards, retention, subcontractors, and rights handling. Appropriate agreements should prohibit unauthorized scraping and circumvention. The NPC makes clear that the organization using a processor remains accountable.
Ask for evidence rather than a verbal assurance:
- source inventory and collection dates;
- field-level classification and necessity;
- applicable privacy notice;
- PIA or relevant risk summary;
- deletion and suppression process;
- security controls and incident procedure;
- contractual limits on reuse and onward disclosure;
- process for verifying that supplied data was obtained lawfully.
Measure business quality without rewarding risky volume
After legal and DPO approval, request an operational lead-workflow review covering permitted fields, access, suppression, CRM stages, retention, and qualified-outcome reporting. Do not send personal data or credentials for the initial review.
A large list is not a useful outcome. Track records reviewed, records approved for use, contacts attempted, objections, valid business conversations, qualified opportunities, booked meetings, and customers. Record invalid, irrelevant, duplicate, outdated, and suppressed contacts separately.
Avoid optimizing staff or vendors solely on names collected or messages sent. Volume incentives can encourage excessive collection, poor verification, and outreach that damages trust.
Frequently asked questions
Is scraping public data always legal in the Philippines?
No universal answer applies. The NPC says scraping may be allowed if the organization fulfills its Data Privacy Act obligations. The source, fields, purpose, lawful basis, scale, safeguards, notice, and later use all matter.
Does a public LinkedIn profile or directory listing equal consent?
No. Public availability does not automatically constitute consent to processing for unrelated or unexpected purposes.
Can a business scrape company names and websites?
Company information and personal data require careful distinction. A company website may also publish names, personal contact details, or profiles about identifiable people. Classify the actual fields and obtain legal guidance for the proposed use.
Can we bypass a CAPTCHA or other anti-scraping control?
The NPC identifies circumvention of technical measures as an unauthorized scraping practice. Do not bypass controls or misrepresent your access.
Do we need a privacy impact assessment?
The 2026 advisory says organizations engaged in scraping publicly available personal data should conduct a PIA covering the activity, including scraping performed on their behalf by third parties.
Can we keep the list for future campaigns?
Not automatically. Retention should be tied to the declared purpose, and data should be securely disposed of when no longer necessary. A new use may require a lawful basis, notice, and a new PIA.
Build a lead system that can survive scrutiny
Responsible B2B lead generation begins with a defined market and offer, a lawful and proportionate data process, transparent outreach, reliable suppression, and measurement based on qualified outcomes—not a hidden spreadsheet of uncertain origin.
Rightjob Solutions can help map the operational workflow, access controls, CRM fields, suppression process, and conversion measurement around your approved policy. We do not provide legal advice or scrape protected data for an initial assessment. Review our Digital Marketing services or book a consultation after your DPO or counsel confirms the permitted approach.

