Notice to the Public
On August 11, Tuesday, the National Privacy Commission (NPC) issued a statement addressing the increasing circulation of A.I. (Artificial Intelligence)-generated content, but not limited to, images and videos depicting real and identifiable persons without prior consent by the said person. The Commission reminds the public that under the Data Privacy Act of 2012 (DPA) that A.I.-generated content depicting real persons may still include biometric data traceable to the individual.
Processing A.I. generation using identifiable person’s visuals without prior consent or approval by the Commission is regarded as unlawful and directly violates Data Privacy Act Sec. 25 emphasizing unauthorized processing of an individual’s likelihood and identity through A.I. generative channels. This act may also violate other penal codes and can be subject to civil and administrative liabilities and may carry criminal penalty also.
Further, the Commission expounds on meaning of “Fabricated” in A.I.-generated image and video as a photographic and video depiction using a real person’s identity, doing something that the person did not do in real life or just outright depicting false information about the person. The Commission stated that any persons who have suffered from this malicious spreading of A.I.-generated content may demand removal, blocking, or destruction of the content upon submitting proof that the depiction is not real, as per DPA Sec. 16 (e). Likewise, the person also has the right to file a formal complaint to the Commission regarding those who initiated this illegal act.
While the Commission outright sets proper regulatory advisory regarding the use of A.I., the commission is also aware of the thin boundary between using A.I.-generated picture and video as every citizen’s freedom of speech and the intention behind circulating these contents. This notice aims to be a protection for those who are victims of unwanted and unconsented AI generated content featuring their identity.
Deepfakes and how they work
The Commission did not exactly state the category of this A.I.-generative contents depicting real persons, but under its implications in the Philippines society, this act can be considered as “Deepfake”. Deepfake is the byproduct of A.I. in forms of photos, videos, audios, generated to look or sound as if a real person is doing something that is not actually done in real life. The A.I. depictions can look real by copying a real person’s voice, mannerisms, and face. In the Philippines, reports state that deepfakes are commonly used for fraud scams, harassment, reputational attacks, and identity misuse in transactions.
With the information above mentioned, it can be observed that deepfakes continue to shape the cybercrime landscape of the country – from voice clone phishing scams initiated for victims to transfer money, generated deepfake content used for extortion and harassment purposes, and generated fake news videos used for false agendas and propaganda, complaints and escalation measures demands from victims continue to rise, needing government protection for victims exposed to ill-use of A.I.-generative content. By providing a set of protection laws, anyone can be preserved for the risk of harm relating to A.I.-misuse in terms of financial loss, identity theft, fraud, scams, harassment, and extortions.
Existing legislation
If someone has noticed their identity has been ‘deep-faked’, there are certain legal remedies they may pursue. Republic Act 10175 covers the “misuse of a person’s face, voice, or persona to make viewers believe the victim acted or spoke”. The Act includes computer-related identity theft, which may be especially relevant when personal identifiers are used to misrepresent identity or commit related harms. Estafa laws—those that cover fraud—are also adjacent and usually applicable to deep-fake cases, also relevant to the misuse of information gathered from an individual.
The existing laws such as above are still ever evolving to meet the nature of A.I. threats. There is drafted legislation, for example, that aims to more comprehensively cover the scope, remedial action, and punishment of bad actors. However lacking the legislation is at the time of this writing, the House and the Senate have recognized the threat of said actors. The law follows that which is relevant to the people. Reiterating the point of the issuance of the statement by the National Privacy Commission, the thin line between free speech and A.I.-generated content is something to be wary of; and in future drafts, the hope is that the delineation becomes clearer and becomes more concrete.
A.I. and Financial Institutions
Financial institutions are particularly vulnerable to the existential problem of deep fakes and artificial intelligence. Problem areas would be the identification, interaction, and withdrawal processes among others. A “person” can mimic a legitimate individual, who, either creating a fake identity or hijacking the identity of another, threatens the integrity of the institution. It would be a threat that institutions must take note of, especially with the exponential speed at which AI is progressing.
DOPAY: Your secure partner
At DOPAY, we are an institution that is acutely aware of the importance of customer verification. Aside from the cross-checking of documentary requirements, we also conduct liveliness checks to ensure that the transacting consumer is both legitimate and protected (from the threat of hacking, impersonation, and deep faking). DOPAY employs a department that is specifically dedicated to ensuring security—in each touch point, from account creation to fund withdrawal.
Additionally, DOPAY also exercises the use of the blockchain to keep records secure. Through the blockchain’s decentralized nature, each touch point is unalterable and accounted for. We are among the few digital platforms that fully utilize the blockchain across all services—not just our cryptocurrency trading platform.
We understand that in this A.I.-driven world, bad actors are becoming more of a concern. That is why we put safety as a paramount priority—in fact, it is one of the core pillars that we build our platform around. By transacting with DOPAY, you can rest assured that you are safe.
DOPAY is an Electronic Money Issuer (EMI) and Virtual Asset Service Provider (VASP) that is regulated by the Bangko Sentral ng Pilipinas. DOPAY adheres to comprehensive security protocols set out by regulations; moreover, we adopt a proactive approach that goes beyond the stated.
From remittance to crypto-trading, and to fund transfers, each step of the way is protected by our rigorous protocols without hindering the ease of use of our services, and ultimately, without posing a hurdle to you.
Download the DOPAY app today!






