The National Privacy Commission (NPC) just issued a formal notice: creating, posting, or sharing AI-generated images of real people without permission isn’t just sketchy—it’s illegal in the Philippines. On August 11, 2026, the Commission reminded the public that synthetic media depicting identifiable persons violates the Data Privacy Act of 2012 (DPA), and violations carry criminal penalties, civil liability, and possible administrative sanctions.

If you’ve ever used an AI image generator to create a photo of someone else, or shared one online, this changes things. Here’s what Filipinos need to understand about the new privacy enforcement push.

Why the NPC Is Cracking Down Now/h

The explosion of AI image generators—from DALL-E and Midjourney to open-source tools available free online—has made it trivially easy to create photorealistic images of anyone, doing anything, saying anything. A person’s face and likeness are personal data under Philippine law. When you feed someone’s photo into an AI tool and generate a new image, you’re processing their personal data without permission.

The NPC observed “increasing circulation” of these synthetic media and decided to clarify what Filipino law actually says about them. This isn’t a new rule; it’s enforcement of an existing one.

Key Reason This Matters to Filipinos:

The Philippines doesn’t have a specific “deepfake law” yet, but the DPA is broad enough to cover it. That means:

  • Creating AI-generated images of someone’s face without consent = unauthorized processing of personal data
  • Posting or sharing those images = further processing and potential false data dissemination
  • Criminal penalties apply (not just civil fines)

What the Law Actually Says About AI-Generated Images

The NPC’s position is clear: a person’s face and likeness are personal information. Under the DPA, processing personal data requires a lawful basis—consent is the most obvious one, but the law also allows processing for legitimate purposes like journalism, artistic expression, or public interest reporting (with strict limits).

The Three Key Violations:

1. Unauthorized Processing (Section 25 of DPA) If you create an AI image of someone without any lawful basis, you’re violating the DPA. This applies whether you use it privately or post it online.

2. False Personal Data (Section 16(e) of DPA) If the AI-generated image shows someone doing something they never did, saying something they never said, or being somewhere they never were—it’s false personal data. The person depicted can demand removal and file a complaint with the NPC.

3. Criminal and Civil Liability Depending on the extent and nature of the violation, you face criminal penalties, civil liability, and administrative sanctions. This isn’t a slap-on-the-wrist situation.

What About Satire, Parody, and News Reporting?

The NPC acknowledges that satire, parody, commentary, and journalism may fall under constitutional protections—but only if certain conditions are met:

  • The synthetic nature must be disclosed. If you present an AI-generated image as real, you lose the protection.
  • The use must be necessary for the purpose. Using someone’s actual photorealistic likeness must be essential to achieve the journalistic or artistic goal.
  • The context matters. Posting a clearly labeled parody is different from spreading a deepfake without disclosure.

In other words: you can’t hide behind “but it’s satire” if you’re actually just using AI to fabricate damaging false content about someone.

Who Gets Protected? Everyone—Including Public Officials’ Families

Here’s an important distinction: public officials are data subjects under the DPA too. However, their right to privacy is balanced against the public’s right to information on matters of public concern.

But here’s the catch: fabricated images of public officials convey no actual information about how they do their jobs. An AI-generated video of a senator doing something they never did tells you nothing about their actual conduct.

And family members—especially minor children—get full protection. The NPC will treat complaints involving AI-generated images of minors with “utmost priority.” Using AI to create synthetic media of someone’s child is treated as a serious violation.

What You Can Actually Do if Someone Creates an AI Image of You

The NPC gives you concrete steps:

1. Demand Removal You can demand that the person or entity that posted or circulated the AI image remove it. This demand should be made in writing, clearly, and in good faith.

2. File a Complaint with the NPC If they refuse, you can file a formal complaint with the National Privacy Commission. The process is free and accessible to all Filipinos.

3. The NPC Will Investigate The Commission can investigate on the basis of your complaint or on its own initiative. If warranted, they can issue compliance orders and cease-and-desist orders during the investigation.

4. Platform Removal The NPC can furnish copies of these orders to online platforms (Facebook, Twitter, TikTok, etc.) and relevant government agencies. Platforms are expected to provide accessible reporting mechanisms and remove content promptly based on lawful demands.

What This Means in Practice:

If someone posts an AI-generated image of you on Facebook or TikTok, you can:

  • Ask them directly to remove it (via the platform’s messaging)
  • Report it to the platform itself
  • File a complaint with the NPC if the platform doesn’t act
  • The NPC can then order the platform to take it down

Biometric Data and Why It Matters

The NPC also clarifies that AI-generated images created from someone’s face may constitute biometric information—data that directly identifies an individual. Biometric data has even stricter handling requirements under the DPA.

This matters because it means the law treats AI-generated images of your face as seriously as it treats fingerprints or iris scans. It’s not just a photo; it’s personally identifying biological data being processed.

The Honest Limitations (And What’s Still Unclear)

Here’s what the NPC didn’t fully clarify:

  1. Detection and enforcement: The NPC has limited resources. How aggressively will they enforce this against casual users vs. bad actors? Still to be seen.
  1. Platform responsibility: The NPC expects online platforms to provide “accessible mechanisms for reporting.” But most Filipino social media users don’t know the NPC exists. Awareness is low.
  1. What counts as “necessary”? The NPC says using someone’s likeness must be “necessary” for journalism or art, but they didn’t publish detailed guidelines. This will likely be decided case-by-case.
  1. Criminal vs. civil enforcement: The notice mentions criminal penalties, but the NPC isn’t a law enforcement agency. Criminal prosecution would require cooperation from the Department of Justice or National Bureau of Investigation.
  1. International content: What about AI images created outside the Philippines? The DPA’s reach is still being tested in courts.

What This Means for Filipino Content Creators and Tech Users

For meme creators and social media users: If you’re generating funny AI images of celebrities, public figures, or friends as jokes, you’re technically in violation. Posting them online multiplies the risk. The NPC’s notice is a clear signal: stop, or expect legal consequences.

For educators, journalists, and artists: You have more latitude—but you must disclose that images are AI-generated and justify why you’re using someone’s actual likeness. A clearly labeled AI parody or commentary piece is defensible; a deepfake spread without context is not.

For companies and marketing agencies: If you’re considering using AI image generation to create fake testimonials, deepfake ads, or synthetic celebrity endorsements, don’t. The legal risk is now explicitly stated by the NPC.

For everyday Filipinos: If someone creates an AI image of you and shares it online, you have legal recourse. Document it, report it to the platform, and file a complaint with the NPC if needed.

The TechPatrol Take

This notice from the NPC is significant because it moves synthetic media from a “maybe it’s unethical” gray zone into clear legal territory. The Philippines is joining a small but growing list of countries taking a hard stance on AI-generated deepfakes and unauthorized synthetic media.

What’s striking is that the NPC didn’t wait for new legislation. They enforced existing privacy law creatively. The DPA, passed in 2012, already prohibits unauthorized processing of personal data. The NPC simply applied it to AI-generated images—and made it clear that this wasn’t a novel interpretation, but a straightforward application of existing rights.

The bigger picture: as AI image generators become more sophisticated and accessible, every country will face this problem. The Philippines is being deliberate about protecting citizens’ right to their own likeness.

What Happens Next?

Near term (next 3-6 months):

  • The NPC will likely receive more complaints about AI-generated images
  • Online platforms will be pressured to improve reporting mechanisms for this type of content
  • Some high-profile cases may be investigated

Medium term (6-12 months):

  • Expect clarification from the NPC on what “necessary” means for journalistic/artistic use
  • Possible coordination with law enforcement on criminal cases
  • Guidelines for content creators and platforms

Long term:

  • Congress may introduce a dedicated “deepfake” or synthetic media law with clearer penalties
  • Courts will start issuing precedent-setting rulings
  • Other Southeast Asian countries may adopt similar approaches

How to Stay Compliant (And Protect Yourself)

If You Create AI Images:

  • Don’t use real people’s faces. Stick to fictional characters or abstract concepts.
  • If you must use someone’s likeness: Get written consent first.
  • If it’s for journalism/commentary: Clearly disclose that it’s AI-generated and explain why the actual likeness was necessary.
  • Don’t spread it as real. Ever.

If Someone Creates an AI Image of You:

  • Screenshot and save evidence. Document when and where you found it.
  • Ask for removal politely first. Many creators don’t know it’s illegal.
  • Report to the platform. Use their reporting tools.
  • File with the NPC if they refuse. The Commission has the authority to order removal and investigate.

Contact the NPC here: www.privacy.gov.ph