SIM registration law, privacy and safety illustration

Privacy and data protection

What Happens to Your Data Under RA 11934?

What a carrier collects for SIM registration, where the record is kept, why selfies may be used, when disclosure is lawful, how long data remains and which privacy rights still apply.

By Roman Mercado · Fact-checked August 9, 2026 · Independent and unaffiliated

The short answer

Your serving carrier keeps the SIM registration record in its own protected SIM Register. RA 11934 restricts that register to SIM processing, activation and deactivation unless another part of the law permits use or disclosure. Registration information is confidential, but narrow legal exceptions apply, and relevant data must be retained for ten years after the number is deactivated.

Submit data only to the carrier. PH SIM Registration is an independent information site. We never request or store a mobile number, OTP, ID, passport, selfie or registration reference.

What information is collected

The Act establishes a core registration record. A carrier may display additional verification or contact fields in its current privacy notice, but those should be explained rather than silently treated as statutory fields.

What information is collected
Data categoryWhy it appears
Identity detailsFull name, date of birth and sex are named in Section 5.
AddressThe owner registration form requires an address; foreign nationals provide an address in the Philippines and proof where applicable.
SIM identifiersThe assigned mobile number and SIM serial information connect the verified person or entity to the subscription.
Identity documentA valid government-issued photo ID or similar qualifying document verifies the end-user.
DeclarationThe registrant confirms that the documents are true and that they completed the form.
Foreigner documentsPassport, nationality, local address and the applicable travel, immigration, employment or school evidence support the foreign-user category.
Organization documentsRegistration certificate and authority documents identify the entity and its representative.
ID image, OCR and selfieCarriers may use images and automated extraction or face checks to verify identity and deter fraud. Their current privacy notice should explain the processing.
Contact or technical dataA carrier may collect an email, alternate contact or security/device information under its disclosed process. These are not all listed as universal statutory fields.

Where the registration record goes

Section 6 requires every public telecommunications entity to maintain its own database. That database is the carrier’s SIM Register. RA 11934 does not create a public directory where anyone can search a mobile number and see the subscriber’s identity.

  • Globe/TM records: held through Globe’s registration and account environment.
  • Smart/TNT records: held through Smart’s registration and account environment.
  • DITO records: held through DITO’s registration and account environment.
  • GOMO records: registration is app-led through the official GOMO PH environment.

This website links to those official routes but does not proxy, frame or reproduce their forms. Use the official-link and phishing checklist before uploading an identity document.

What the carrier may use the SIM Register for

The statutory SIM Register is to be used for processing, activating or deactivating a SIM or subscription and not for another purpose unless the Act otherwise provides. The carrier must also comply with the Data Privacy Act and its general principles.

Registration is not blanket marketing consent. The National Privacy Commission required telcos to separate commercial or promotional consent and directed removal of registration-page notices for third-party data sharing. A subscriber must not be forced to waive statutory confidentiality as a condition of service approval.

Read every live privacy notice. Required identity processing and optional promotional consent are different decisions. An optional marketing control should be clearly identified and capable of being declined or later withdrawn through the carrier’s stated route.

Why a carrier may request a selfie

RA 11934 requires identity evidence with a photo, while carrier platforms may add selfie or liveness verification to match the registrant to that document. The NPC says selfie processing must satisfy transparency, legitimate purpose, proportionality and the other safeguards of the Data Privacy Act.

  • The official platform should explain that a selfie or face check is being performed.
  • The verification should serve a legitimate identity or anti-fraud purpose.
  • The amount and manner of processing should be proportionate to that purpose.
  • The carrier remains responsible for preventing misuse, unauthorized processing and security incidents.

A selfie request is not a reason to send an image to a shop assistant’s personal phone, a social-media account or a guide website. For upload problems, use the ID and selfie error guide.

Is SIM registration data confidential?

Yes. Section 9 says registration information is to be treated as confidential, and the Act penalizes unlawful disclosure by carriers, agents or employees. However, confidentiality has defined exceptions.

Is SIM registration data confidential?
Possible disclosure basisWhat it means
Another applicable lawFull name and address may be disclosed when a law obligates the carrier to do so consistently with the Data Privacy Act.
Court order or legal processThe Act recognizes disclosure under qualifying legal process upon a finding of probable cause.
Section 10 subpoenaA competent authority may require information for the investigation described in Section 10, based on a sworn complaint involving a specified number and alleged criminal, malicious, fraudulent or unlawful use.
Written subscriber consentThe subscriber may authorize disclosure. A waiver of confidentiality cannot be made a condition of approving the subscription.

These exceptions do not make the register open to a curious employer, seller, relative or stranger. A carrier should not reveal the named subscriber merely because someone asks who owns a number.

How long is the data retained?

RA 11934 requires the relevant registration data to be kept for ten years from the time the end-user deactivates the mobile number. While the number remains active, its registration record remains necessary for the carrier’s SIM Register.

Deactivation does not mean immediate deletion. A lost, transferred, replaced, expired or voluntarily deactivated line can still have an archived statutory record. The carrier may remove data from an active operational view while retaining the record required by law.

Do not promise that a carrier can erase every registration field on request. A lawful retention obligation can limit the right to erasure or blocking. The carrier should explain the basis for retaining data and address any inaccurate information.

Security duties and cyber incidents

  • Carriers must keep end-user data secured and protected at all times.
  • They must meet DICT minimum information-security standards consistent with relevant law and internationally accepted cybersecurity standards.
  • DICT is directed to conduct annual compliance audits.
  • RA 11934 requires a cyber-attack on the SIM Register to be reported to DICT within 24 hours of detection.
  • Data Privacy Act breach assessment and notification duties may also apply according to the facts; not every technical incident produces the same notice to every subscriber.

Do not infer that silence means no incident occurred, and do not claim that every suspected glitch is a breach. If a carrier sends a genuine security notice, verify it through the carrier’s official app or domain before selecting links.

Your rights as a data subject

The NPC identifies rights to be informed, access, object, rectify, erasure or blocking, data portability, file a complaint and claim damages where applicable. How a right applies depends on the carrier’s legal obligations and the facts.

Your rights as a data subject
RightPractical SIM-registration use
Be informedRead what is collected, why, who receives it, how long it is retained and how to contact the carrier’s data protection team.
AccessAsk whether and how personal data relating to you is processed, subject to lawful limits and identity verification.
RectifyDispute an inaccurate name, birth date, address or other record and ask for the carrier’s correction procedure.
ObjectObject to optional processing where the applicable lawful basis permits it; required statutory registration cannot necessarily be refused while keeping service active.
Erase or blockRequest relief in qualifying circumstances, recognizing the Act’s ten-year post-deactivation retention requirement.
ComplainRaise the issue with the carrier, then use the NPC process for a personal-data violation or NTC for a telecommunications-service complaint.

How to raise a data concern with a carrier

  1. Identify the exact concern

    Separate an inaccurate registration record, unwanted marketing, an access request, suspected disclosure and a service outage. They may go to different teams.

  2. Use the carrier’s official privacy or support route

    Navigate from the carrier’s own domain or app. Do not send identity documents to an address copied from an unofficial forum.

  3. Describe the number and requested outcome safely

    Provide only what the verified channel requires. State whether you want access, correction, an explanation, optional-consent withdrawal or investigation.

  4. Complete identity verification

    A carrier may need to confirm that the requester is the data subject. Never provide an OTP to an inbound caller or chat account.

  5. Keep the written trail

    Save the request, case reference, carrier response and relevant screenshots. Avoid posting the number, ID or response publicly.

  6. Escalate to the correct regulator

    For an unresolved personal-data violation, follow the NPC’s complaint mechanics. For a carrier service/registration dispute, see how to complain to NTC.

Protect your registration data

  • Open the carrier platform from a verified domain or official app-store listing.
  • Never let a reseller receive or type the OTP outside an authorized assisted process.
  • Do not leave ID copies, selfies or passport pages in public chats or shared photo albums.
  • Save the control/reference number privately.
  • Reject cash offers to register SIMs for someone else or for resale.
  • Report loss, unauthorized ownership changes and suspicious registration messages promptly.

Frequently asked questions

Who stores my SIM registration data?

Your serving public telecommunications entity maintains its own SIM Register. This independent guide does not receive registration data.

Is there a public government database of SIM owners?

No public lookup is created by RA 11934. Carriers maintain confidential registers subject to the law’s limited disclosure provisions.

Can the carrier use registration data for marketing?

Required registration processing and optional marketing consent are different. NPC instructed telcos to separate commercial/promotional choices and remove third-party-sharing tick boxes from the registration flow.

Can law enforcement access registration data?

Only through the qualifying law, court process, subpoena procedure or other basis described in Sections 9 and 10; it is not an unrestricted public-access system.

Is my data deleted when the SIM is deactivated?

No. The Act requires relevant information to be retained for ten years from deactivation.

Can I correct an inaccurate registration record?

Yes. Report the change to the carrier and use its identity-verified correction process. The law directs the carrier to clearly note changes in its database.

Can I demand immediate deletion?

You may exercise applicable data-subject rights, but the carrier can have a legal duty to retain the SIM record. Ask it to explain the retention basis and address any inaccurate or unlawfully processed data.

Where do I report a privacy violation?

First raise the issue in writing with the carrier. If it remains unresolved, follow the National Privacy Commission’s current complaint procedure and evidence requirements.

Official sources

Privacy provisions and official guidance checked August 9, 2026. A carrier’s current privacy notice controls the additional fields and processing shown in its live platform.