On 23 September 2025, National Privacy Commission (NPC) issued a Cease and Desist Order (CDO) against Tools for Humanity (TFH), the company behind WorldApp, the Orb, World ID and Worldcoin, to cease all data processing operations in the Philippines. TFH’s goal is simple yet profoundly relevant in the age of artificial intelligence (AI): to verify whether a user is a real human, not a bot. The Commission’s 66-page Order sets out procedural history, a detailed factual record, and its legal conclusion that TFH’s activities violated the Data Privacy Act (RA 10173) and NPC guidance on consent and biometric data. [1]
The NPC’s decision, citing privacy concerns, claims to defend citizens’ rights – a worthy cause and rightfully a primordial consideration in this digital age. However, the case of TFH’s digital identity project World in the Philippines clearly demonstrates the delicate balance governments face in regulating new and emerging technologies while ensuring sufficient data privacy protection.
While the NPC’s mandate to safeguard personal data is beyond question, its decision disallowing the technology in the Philippines may paradoxically undermine technological innovation and future data protection efforts. TFH embraces pioneer privacy-enhancing methods that can redefine how digital identity works—offering a system where people can prove their humanity without revealing who they are. Disallowing the adoption of this technology might be a barrier of entry for even newer and unfamiliar technologies in the future, discouraging foreign investors from entering the Philippine market.
The NPC’s Findings
The NPC’s order raised several issues surrounding TFH’s data processing practices, such as:
- Absence of a formal consent form. The Commission criticized TFH for relying solely on a Privacy Notice and a checkbox consent mechanism.
- Processing of sensitive personal information. It found that even temporary processing of biometric data (specifically, iris scans and taking temporary photo of a subject’s ID) fell under the DPA’s definition of “sensitive personal information.”
- Lack of full disclosure. The Privacy Notice allegedly failed to sufficiently explain TFH’s business operations and data use.
- Cross-border data transfers. The notice indicated that personal data could be processed or stored in multiple jurisdictions.
- Access to geolocation data. The app’s collection of location data was considered additional processing.
- No signature for consent. The NPC took issue with the lack of a handwritten or electronic signature, deeming the checkbox insufficient proof of consent.
TFH’s Position
While the company acknowledges that it processes biometric information (such as an iris scan), it stresses that such processing is momentary—lasting only long enough to generate an anonymized iris code. This code, once created, cannot identify an individual and is mathematically impossible to reverse-engineer. The original image is permanently deleted after ten seconds.
TFH argues that because no identifiable data is retained or stored, its processing does not constitute a privacy risk under the DPA. The company further emphasizes that:
- Data collected for app navigation is voluntary and separate from biometric verification.
- All platforms (World App, World ID, the Orb, and WLD) maintain detailed Privacy Notices outlining data use, sharing, retention, and user rights.
- It employs a “just-in-time” consent mechanism, consistent with international privacy standards.
- The World ID—an anonymized digital credential—does not store or use personal data, and is not employed for logins to websites or crypto apps.
- WLD tokens are not payments for data but optional incentives to encourage engagement.
- TFH’s technology aligns with international standards on anonymized data, which define it as information that can no longer be used to identify an individual “by any means reasonably likely to be used.”
The company also highlights that its technology was designed to enhance online safety, creating a privacy-preserving “Proof of Human” system that prevents AI bots and fake accounts from exploiting digital ecosystems.
The Legal Debate: Consent, Processing, and Anonymization
The NPC’s decision raises critical questions under the Data Privacy Act. Does the fleeting use of biometric data—without storage—constitute “processing”? And if such data is immediately anonymized, can it still be classified as “personal information”?
Under Section 3(c) of the DPA, “processing” includes collection, recording, and storage. Yet, the DPA’s intent is to protect identifiable personal information. If data has been transformed into an anonymized format where identification is no longer possible, it arguably falls outside the Act’s protective scope.
Moreover, the insistence on signed consent forms seems inconsistent with global practice. Under modern privacy frameworks—including the EU’s GDPR—digital consent via checkboxes or pop-ups is valid, provided it is informed and freely given. The NPC’s view risks rendering most app-based consent systems in the country noncompliant.
An Opportune Time For Collaboration
The case of TFH in the Philippines provides a valuable opportunity for developers and regulators to create a collaborative and iterative model, well aware of the fast-paced and ever dynamic space of the digital world. It would be ideal for regulators like the NPC to host programs which engage developers in dialogue or technical validation, possibly taking a sandbox approach for new technologies, to allow innovators to demonstrate compliance and adjust frameworks as necessary.
This approach would also support broader government objectives. In early October 2025, President Ferdinand “Bongbong” Marcos Jr. directed the DICT and other agencies to intensify efforts to eliminate online financial scams ahead of the Christmas season — a national priority to make e-commerce and digital payments safer for Filipinos. The government’s anti-fraud priority seeks both stronger protections for consumers and a thriving digital economy where people feel confident transacting online[2]. TFH’s technology, which was designed to verify human authenticity online, could potentially complement this policy goal, once found compliant to the Philippines’ digital privacy standards.
[1] BELARMINO, J. A. S., NAGA, J. H. D., & DE JESUS, N. N. (2025, September 23). IN THE MATTER OF WORLD APP PROCESSING OF PERSONAL INFORMATION. privacy.gov.ph. https://privacy.gov.ph/wp-content/uploads/2025/10/FINAL-2025.09.23-Cease-and-Desist-Order-CID-CDO-25-001-Application-for-Issuance-of-Cease-and-Desist-Order-for-In-the-Matter-of-World-App-Processing-of-Personal-Information_SGD.pdf
[2] Presidential Communications Office. (2025, October 7). News releases – president Marcos directs DICT to eliminate online scams during Christmas season. Presidential Communications Office. https://mirror.pco.gov.ph/news_releases/president-marcos-directs-dict-to-eliminate-online-scams-during-christmas-season/?utm_source=chatgpt.com