No, we are not giving our National ID database to Meta
- Art Samaniego
- PHT
- Art Samaniego, DICT, Meta
DECODED: TECH, TRUTH, AND THREATS
When reports surfaced that the Department of Information and Communications Technology (DICT) wanted Meta to use the Philippine National ID for account verification, the reaction was immediate. Will Facebook get our National ID data? Will Meta have access to our names, addresses, birthdays, and biometrics? Are we handing one of the governmentβs most sensitive databases to a foreign technology company?
These are fair questions. Filipinos should be cautious whenever government-held personal information is involved with a private technology company. But the proposal, as described so far, does not involve turning over the Philippine Identification System (PhilSys) database to Meta.
DICT Secretary Henry Aguda has proposed using PhilSys as part of Metaβs account verification process. Under the setup being discussed, the Philippine Statistics Authority (PSA), which manages PhilSys, would check the identity. Meta would receive a limited response indicating whether the information matched government records.
In practical terms, Meta asks. PSA checks. PSA answers. The database stays with the government.
Consider a familiar situation. Someone enters an establishment where customers must be above a certain age. The establishment needs proof that the person meets the age requirement. It does not need his fingerprints, home address, family information, and every other detail contained in a government record.
Digital verification can work in much the same way.
Suppose someone creates a Facebook account and Meta wants to confirm that the person is a legitimate National ID holder. The verification request could be sent to a government-controlled service. PSA checks its records and returns the result required for verification.
It could be as limited as βmatchβ or βno match.β
Meta does not need a copy of the PhilSys database to do that. It should not receive fingerprints or other biometric data collected by the government. Nor should it have unrestricted access to PSA servers or receive copies of Filipinosβ National ID records.
Computer systems already exchange limited information this way. One organization can confirm information held by another without being granted access to the other organizationβs database. The requesting system asks a specific question and receives only the answer it is authorized to receive.
Still, the proposal deserves scrutiny because we have not seen the final technical design.
Before National ID verification is required for Meta users, DICT, PSA, and Meta should explain exactly what information will pass between their systems. What information will Meta send to PSA? What will PSA return? Will Meta receive an identifier linked to a PhilSys record? Will verification records be stored, and for how long?
There are other questions. Can information obtained through verification be used for advertising or profiling? Can it be shared among Facebook, Instagram, Messenger, WhatsApp, and Threads? What happens to verification records after an account is deleted?
The answers cannot be buried in a lengthy privacy policy that few people will read.
The rule should be straightforward: Meta receives only the information required to verify an account, and nothing beyond that.
If Meta only needs confirmation that someone is a legitimate National ID holder, PSA should not provide unrelated demographic information. If the issue is age, the system could simply confirm that the person meets the required age rather than providing their full date of birth.
A Privacy Impact Assessment should also be made public before implementation. The National Privacy Commission should review what information is collected, transmitted, retained, and deleted. Independent cybersecurity testing should be conducted before millions of Filipinos are expected to rely on the system.
Identity verification also raises issues that technology alone cannot answer.
Journalists, whistleblowers, abuse victims, and other people sometimes have legitimate reasons for maintaining online identities that are not directly connected to their legal names. There are also Filipinos who may have trouble obtaining or accessing their National ID. False matches, identity theft, and account recovery will inevitably become part of the discussion.
And we should be careful about claims that National ID verification will solve fake accounts, scams, and online abuse.
The experience with SIM registration should have taught us that registering an identity does not automatically stop criminal activity. Scammers adjust. Identities can be stolen. Accounts can be compromised, rented or sold.
Verification may make abuse more difficult, but it will not make it disappear.
There is plenty to question about the proposal. Privacy advocates are right to demand safeguards, and the government has an obligation to explain how the system will work before asking Filipinos to trust it.
But saying that the government is giving Meta the National ID database is not supported by what has been proposed so far.
If the final design allows Meta to collect unnecessary PhilSys information, retain government-linked identity data, or use verification information for advertising and profiling, then we should object.
For now, the technology allows for a much simpler arrangement: Meta asks PSA whether an identity checks out. PSA answers without opening its database to Meta.
That is how it should be built.
And before anyone is required to use it, DICT, PSA, the National Privacy Commission, and Meta should show Filipinos that this is, in fact, how they built it.
Public trust will not come from telling Filipinos that the system is safe. DICT must show them why it is safe.
And that is the challenge for DICT. Call everyone to the table, answer every legitimate concern, and put the proposed safeguards under public scrutiny before anything is implemented. Do not ask Filipinos to simply take the governmentβs word for it.
If DICT is confident that the National ID database will remain protected and beyond Metaβs reach, then it should be prepared to prove it.
The questions are already on the table. Now DICT owes the public the answers.
